Sucuri Blog
  • Products
    • Website Security Platform
    • Website Firewall (WAF)
    • Multi-Site plans
    • Custom & Enterprise Plans
    • Partnerships
  • Features
    • Detection
      Website Monitoring & Alerts
    • Protection
      Future Website Hacks
    • Performance
      Speed Up Your Website
    • Response
      Help For Hacked Websites
    • Backups
      Disaster Recovery Plan
  • Resources
    • Guides
    • Webinars
    • Infographics
    • Blog
    • SiteCheck
    • Reports
    • Email Courses
  • Pricing
  • Immediate Help
  • Login
Sucuri Blog
  • Products
    • Website Security Platform
    • Website Firewall (WAF)
    • Multi-Site plans
    • Custom & Enterprise Plans
    • Partnerships
  • Features
    • Detection
      Website Monitoring & Alerts
    • Protection
      Future Website Hacks
    • Performance
      Speed Up Your Website
    • Response
      Help For Hacked Websites
    • Backups
      Disaster Recovery Plan
  • Resources
    • Guides
    • Webinars
    • Infographics
    • Blog
    • SiteCheck
    • Reports
    • Email Courses
  • Pricing
  • Immediate Help
  • Login
  • Immediate Help
Login
Login

New Customer?

Sign up now.
  • Submit a ticket
  • Knowledge base
  • Chat now

Luke Leal

121 posts
Luke Leal is a member of the Malware Research team and joined the company in 2015. Luke's main responsibilities include threat research and malware analysis, which is used to improve our tools. His professional experience covers over eight years of deobfuscating malware code and using unique data from it to help in correlating patterns. When he’s not researching infosec issues or working on websites, you might find Luke traveling and learning about new things. Connect with him on Twitter.
Down the Malware Rabbit Hole Part 2
  • Sucuri Labs
  • Website Malware Infections
  • Website Security

PHP Backdoor Obfuscated One Liner

  • Luke Leal
  • August 5, 2020
In the past, I have explained how small one line PHP backdoors use obfuscation and strings of code in HTTP requests to pass attacker’s commands…
Read the Post
Clever SEO Spam Injection
  • Sucuri Labs
  • Website Malware Infections
  • Website Security

SEO Hacktool: Sitemap Generator

  • Luke Leal
  • July 30, 2020
An XML sitemap is an important part of a website’s SEO and exists to help search engine crawlers index new URLs on your website. For…
Read the Post
Person in sweatshirt with hood
  • Ecommerce Security
  • Security Education
  • Website Security

Spox Phishing Kit Harvests Chase Bank Credentials

  • Luke Leal
  • July 13, 2020
Phishing kits are the back end components to a phishing attack and are often designed to make it easier to deploy a phishing page. These…
Read the Post
Pirated WordPress & Magento Plugins
  • Ecommerce Security
  • Magento Security
  • Website Malware Infections
  • Website Security
  • WordPress Security

Pirated WordPress Plugins Bundled with Backdoors

  • Luke Leal
  • July 8, 2020
One widespread belief among webmasters is that attackers typically only compromise websites in a couple of ways: by exploiting vulnerabilities or stealing login credentials. Although…
Read the Post
Steam Phishing
  • Security Education
  • Website Security

Steam Phishing Campaign Uses CS:GO Skin Gambling Lure

  • Luke Leal
  • May 20, 2020
Attackers regularly target online gaming accounts as they can quickly sell any transferable items along with account logins to a third party. This scenario has…
Read the Post
PinnacleCart Server-Side Skimmer & Backdoor
  • Ecommerce Security
  • Website Malware Infections
  • WordPress Security

WordPress Malware Collects Sensitive WooCommerce Data

  • Luke Leal
  • May 15, 2020
During a recent investigation, our team found malicious code that reveals how attackers are performing reconnaissance to identify if sites are actively using WooCommerce in…
Read the Post
  • Sucuri Labs
  • Website Malware Infections
  • Website Security

B374k Web Shell Packer

  • Luke Leal
  • May 13, 2020
PHP web shells are a type of backdoor which, when left on compromised websites, allow attackers to maintain unauthorized access after initial compromise. To further…
Read the Post
YouTube Phishing Malware Campaign
  • Security Education
  • Website Malware Infections
  • Website Security

YouTube Account Recovery Phishing

  • Luke Leal
  • May 12, 2020
Phishing attacks against targeted channels have been successful in the past, as explained last year on ZDNet. Recently, our Remediation team found an interesting phishing…
Read the Post
Poste Italiane Phishing
  • Security Education
  • Website Security

Phishing Campaign Targets Poste Italiane & SMS OTP Verification

  • Luke Leal
  • April 29, 2020
When creating phishing lures, attackers may cite recent major regulatory changes within the context of their social engineering scheme to confuse or further entice victims…
Read the Post
WordPress Redirect Hack via Test0.com/Default7.com
  • Website Malware Infections
  • Website Security
  • WordPress Security

Obfuscated WordPress Malware Dropper

  • Luke Leal
  • April 21, 2020
It goes without saying that evasive maneuvering is at the top of a hacker’s priority list. Most often, they try to evade detection by obfuscating…
Read the Post
Labs Note
  • Magento Security
  • Sucuri Labs
  • Website Malware Infections

Magento JavaScript Skimmer Targets Tarjetas de Crédito

  • Luke Leal
  • April 17, 2020
A website owner recently contacted us regarding a payment problem on their Magento website. A suspicious payment card form was loading for customers who were…
Read the Post
Search
Sucuri Sidebar Malware Removal to Signup Page
Sucuri Logo

Let’s Connect

Products
Website Firewall Website Security Platform WordPress Security Website Backups Hack Assistance Pricing
Solutions
DDoS Protection Malware Detection Malware Removal Malware Prevention Blacklist Removal SEO Spam Removal
USE CASES
Developers Ecommerce Agency Plans Enterprise Services HTTPS/2 Virtual Patching
Support
Knowledge Base SiteCheck Guides Research Labs Report Abuse Status Report
Company
About Sucuri Contact Blog Referral Partners Testimonials
Terms of Use Privacy Policy Do Not Sell My Personal Information Frequently Asked Questions

© 2025 GoDaddy Mediatemple, Inc., d/b/a Sucuri. All rights reserved.

back to top

'