Re: [Ilugc] php malware from wordpress blog

2012-04-11 Thread Raja Subramanian
On Wed, Apr 11, 2012 at 10:06 PM, Raja Subramanian wrote: > The malware sample is here: http://pastebin.com/7X9imPGp > > Can anyone decipher what this script is doing and how much damage > it has caused? Sorry to reply to my own post. PHP programmers have nothing other than eval and base64_encod

Re: [Ilugc] php malware from wordpress blog

2012-04-11 Thread Balasubramaniam Natarajan
Hi Raja, Can you upload all the files ? I don't see any one has captured it. http://malwr.com/analysis/e1f3a6fc6f497df6f837822fd122d485/ https://www.virustotal.com/file/4421c2669aaadfebd79de1b5fa8b969854bc3c8782fa144f25f7e6f0a1cc40a6/analysis/1334164847/ On Wed, Apr 11, 2012 at 10:06 PM, Raja S

[Ilugc] php malware from wordpress blog

2012-04-11 Thread Raja Subramanian
Hi, I have had a recent malware injection on a WordPress website I host. The malware sample is here: http://pastebin.com/7X9imPGp Can anyone decipher what this script is doing and how much damage it has caused? This stuff appeared in several files in my WP installation, new files created insid