• About Us
  • Privacy
  • Terms
    • DMCA
  • AdChoices
  • Contact Us
  • Careers
  • Dictionary
  • Donate
Nyongesa Sande
No Result
View All Result
  • Radio
  • Events
  • How To
  • AI
  • Business
    • Shop
    • Money
    • Billionaires
  • Finance
  • Gadgets
  • Lifestyle
  • Sports
  • Autos
Nyongesa Sande
No Result
View All Result
  • Radio
  • Events
  • How To
  • AI
  • Business
  • Finance
  • Gadgets
  • Lifestyle
  • Sports
  • Autos

Home » Balada Injector infrastructure: November 2023

Balada Injector infrastructure: November 2023

November 19, 2023
in Webmaster
Reading Time: 3 mins read
A A
3D rendering Glowing text Ransomware attack on Computer Chipset. spyware, malware, virus Trojan, hacker attack Concept

3D rendering Glowing text Ransomware attack on Computer Chipset. spyware, malware, virus Trojan, hacker attack Concept

SummarizeFacebookXTelegramWhatsappLinkedIn

Here are the main Balada Injector domains and IP addresses observed during the month of September, 2023 — some of which were also used in attacks not directly related to the Newspaper theme.

ADVERTISEMENT

Balada Injector Domains:

  • decentralappps[.]com
  • statisticscripts[.]com
  • dataofpages[.]com
  • listwithstats[.]com
  • promsmotion[.]com
  • stablelightway[.]com
  • specialtaskevents[.]com
  • getmygateway[.]com
  • stratosbody[.]com
  • specialnewspaper[.]com (note the Newspaper in the domain name)

For a short period of time, Balada Injector was hiding some of their servers behind a CloudFlare firewall, but their domains didn’t last long there. They inevitably had to return back to pointing domains back directly to their own servers.

Balada Injector Server IPs:

ADVERTISEMENT
  • 2.59.222.113
  • 2.59.222.119
  • 2.59.222.121
  • 2.59.222.122
  • 2.59.222.158
  • 185.39.206.158
  • 185.39.206.159
  • 185.39.206.160
  • 185.39.206.161
  • 80.66.79.252
  • 80.66.79.253
  • 88.151.192.253
  • 88.151.192.254
  • 89.23.103.32
  • 89.23.103.246

Mitigation steps

September, 2023 was one of the busiest months for Balada Injector malware. Our SiteCheck remote website scanner detected various types of Balada Injector on over 17,000 websites — almost twice the number of detections in the previous month of August. Over 9,000 of these detections were related to the Newspaper theme vulnerability.

We observed a rapid cycle of modifications to their injected scripts alongside new techniques and approaches. We saw randomized injections and obfuscation types, simultaneous use of multiple domains and subdomains, abuse of CloudFlare, and multiple approaches to attack administrators of infected WordPress sites.

September was also a very challenging month for thousands of users of the tagDiv Newspaper theme. The Balada Injector malware campaign performed a series of attacks targeting both the vulnerability in the tagDiv Composer plugin and blog administrators of already infected sites.

Our advice to users of the Newspaper theme is to follow these steps:

  1. Scan your site and remove all injected Balada malware. Our SiteCheck scanner detects most Balada Injector variations as malware.injection?35.*. If you continue with the following steps before completely removing the malware, it may reinfect your site while you are logged in as an administrator.
    • Remove the initial injection, which can be found in the “td_live_css_local_storage” option in the wp_options table.
    • Remove secondary injections, which can be found at the top of .js files like /wp-includes/js/jquery/jquery-migrate.min.js,  /wp-includes/js/jquery/jquery.min.js and /wp-includes/js/wp-emoji-release.min.js.
    • Check files like index.php, wp-blog-header.php  and your theme’s header.php and footer.php files for injections. Remove any malicious code you find there.
  2. Make sure that the tagDiv Composer plugin is patched to at least version 4.2. This will help to prevent reinfections via the known security vulnerability.
  3. Keep your Newspaper theme updated with the latest patches. We’ve seen these injections on sites that use various different versions of the Newspaper themes: 10.x, 11.x, 12.x. Some were as old as version 8.x.
  4. Make sure all other themes and plugins are up-to-date. This is a security best practice and will help protect your website from known vulnerabilities and software bugs.
  5. Remove all unwanted admin users. Check for any recently created admins, especially if their usernames are “greeceman” or end with “mann” and they use “@mail.com” emails.
  6. Make sure there are no unwanted plugins such as wp-zexit or wp-swamp installed on your site. Remember, by default such plugins hide themselves in the WordPress admin interface, so make sure to actually check what kind of plugins you have in the wp-content/plugins directory.
  7. Check the 404.php file of the Newspaper theme. There may be a backdoor there.
  8. Scan your entire website for backdoors. It’s not uncommon for the Balada injector and other attacks to use the initial backdoor to upload several other backdoors into random files. Integrity control systems may help notice new and modified files.
  9. Change all of your website passwords, including the database password. Balada Injector is known for stealing information from wp-config.php files. Make sure all of your user credentials are strong, unique and secure to help prevent reinfection.

Now after reading how website malware may target WordPress admins to escalate some minor injection into the whole site take over, let’s revisit some security practices specifically for WordPress administrators.

  • Even though WordPress admins can post articles, please use your admin account only for administrative tasks. Use more appropriate roles such as author, contributor and editor to create, edit, and post content instead.
  • If you logged as a WordPress administrator, try not to browse your own website in the same browser before you log out. Balada injector uses this scenario to make site admins further infect their own sites. If you need to test site pages, consider using a different browser or a private/incognito window of the same browser, where you will navigate without being identified as a site administrator.
  • If you don’t normally edit theme and plugin files, please disable the theme and plugin editors in the WordPress admin interface. 
Was this article helpful?
YesNo
Tags: Balada Injector domains
ADVERTISEMENT
Previous Post

The Mysterious Disappearance of Ssenyondo Achilles: A Dark Chapter in Uganda’s Political Discourse

Next Post

How to Fix the WordPress White Screen of Death

RelatedPosts

Domain Name Registration in Hargeisa, Somaliland
Webmaster

Domain Name Registration in Hargeisa, Somaliland

12 months ago

In today’s highly connected digital world, having a strong online presence is essential for businesses, freelancers, and organizations alike. One...

Top Web Hosting Companies for U.S. Bloggers
Webmaster

Cloud Hosting vs Shared Hosting Explained

7 months ago

When launching a website, one of the first decisions you’ll face is choosing a hosting plan. To make the right...

What is the 403 Forbidden Error?
Webmaster

What is the 403 Forbidden Error?

2 years ago

The 403 Forbidden error indicates that the server understands the request but can’t provide additional access. This means that the...

Georgia State University (gsu.edu)
Websites

Georgia State University (gsu.edu)

2 years ago

Atlanta, the country, and the globe are greatly impacted by Georgia State's colleges and institutions, which are hubs for innovation...

BERT & SEO: How Google’s AI-powered search works
Webmaster

Mastering Google’s Index: Effective Solutions for “Crawled – Currently Not Indexed” Status

2 years ago

Unlock the secrets to resolving the "Crawled – Currently Not Indexed" status in Google Search Console with our comprehensive guide....

Tribune Media (tribunemedia.com)
Websites

Tribune Media (tribunemedia.com)

2 years ago

Quality news, entertainment, and sports content power Tribune Media's wide array of more than 42 television and digital businesses. Tribune...

quantcast-(quantcast.com)
Websites

quantcast-(quantcast.com)

2 years ago

Digital marketing firm Quantcast Corporation offers real-time advertising and free audience demographic assessment. quantcast – quantcast.com

Group Renault: group.renault.com
Websites

Group Renault: group.renault.com

2 years ago

Currently producing a variety of vehicles and vans, Groupe Renault is a global automobile company headquartered in France. Group Renault...

The Risks of Pirated Software
Webmaster

The Risks of Pirated Software

1 year ago

For small and medium-sized businesses aiming to minimize expenses, pirated software might appear to be a tempting solution. However, this...

SEO for Private Equity Firms: A Comprehensive Guide to Organic Traffic
Webmaster

SEO for Private Equity Firms: A Comprehensive Guide to Organic Traffic

11 months ago

In a competitive industry like private equity, securing a strong online presence is crucial to attracting potential investors and standing...

Load More
Next Post
How to Launch a WordPress Website

How to Fix the Wordpress White Screen of Death

How to block an IP address from accessing your website

How to block an IP address from accessing your website

Categories

Trending News

  • Thika

    Thika

    518 shares
    Share 207 Tweet 130
  • Top U.S. Clinics for IVF Treatment in 2025

    634 shares
    Share 254 Tweet 159
  • Complete Guide to the FA Cup 2025-26: Draws, Fixtures, Results & Everything You Need to Know

    473 shares
    Share 189 Tweet 118
  • What Is the Juja Preparatory School Fee Structure 2025 – 2026?

    650 shares
    Share 260 Tweet 163
  • List of 2022 – 2027 mps contacts in Kenya

    1105 shares
    Share 442 Tweet 276
  • Msamaria Mwema Shuttle Routes and Prices from Nairobi

    509 shares
    Share 204 Tweet 127
  • Precious Blood Riruta School Fees, KCSE Performance and Contacts

    473 shares
    Share 189 Tweet 118
  • Top 10 Richest People in Shanxi Province (2025)

    482 shares
    Share 193 Tweet 121
  • Top 10 Richest People in South Africa in 2025

    484 shares
    Share 194 Tweet 121
  • The Junction Mall

    494 shares
    Share 198 Tweet 124
ADVERTISEMENT

Shop Best Offers On AliExpress

Support Independent Journalism

If you appreciate our content, help us keep the site running by making a donation.

Donate Now
ADVERTISEMENT
Nyongesa Sande

Nyongesa Sande delivers breaking news, technology updates, billionaire profiles, inventions, AI trends, and inspiring facts.

CC-BY 4.0 Except where otherwise noted, content on this site is licensed under Creative Commons Attribution-Share Alike 4.0 License ; additional terms may apply. By using this site, you agree to the Terms of Use and Privacy Policy.

No Result
View All Result
  • Tech News
  • Banking
  • Biography
  • Politics
  • Presidents
  • How To
  • Wiki
  • Real Estate
  • Health
  • Gadget Reviews
  • Top 10
  • History
  • Companies
  • Sports
  • Loans
  • Finance
  • Travel
  • Breaking News
  • AI
  • Electric Vehicle
  • Motivation
  • Phone Prices
  • Hosting
  • Shopping Malls
  • Africa
  • Business
  • Insurance
  • Restaurants
  • Investment
  • Classifieds
  • KenyanBaze
  • Shop Anything

CC-BY 4.0 Except where otherwise noted, content on this site is licensed under Creative Commons Attribution-Share Alike 4.0 License ; additional terms may apply. By using this site, you agree to the Terms of Use and Privacy Policy.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.