SiteCheck Signatures

  1. Home
  2. SiteCheck Signatures
  3. malware-entry-mwmrobh1

malware-entry-mwmrobh1

Description: Code used to insert a malicious javascript on many
wordpress sites. Loading the malware from:
http://www.indesignstudioinfo.com/ls.php
http://zettapetta.com/js.php
http://zettapetta.com/js2.php
http://holasionweb.com/oo.php
http://www.losotrana.com/js.php

Generally infecting the footer.php (or all PHP files in some cases).

Clean up:: Run the following script:
http://blog.sucuri.net/2010/05/simple-cleanup-solution-for-latest.html

Malware dump (base 64 added to the .php files):