Sucuri Blog
  • Products
    • Website Security Platform
    • Website Firewall (WAF)
    • Multi-Site plans
    • Custom & Enterprise Plans
    • Partnerships
  • Features
    • Detection
      Website Monitoring & Alerts
    • Protection
      Future Website Hacks
    • Performance
      Speed Up Your Website
    • Response
      Help For Hacked Websites
    • Backups
      Disaster Recovery Plan
  • Resources
    • Guides
    • Webinars
    • Infographics
    • Blog
    • SiteCheck
    • Reports
    • Email Courses
  • Pricing
  • Immediate Help
  • Login
Sucuri Blog
  • Products
    • Website Security Platform
    • Website Firewall (WAF)
    • Multi-Site plans
    • Custom & Enterprise Plans
    • Partnerships
  • Features
    • Detection
      Website Monitoring & Alerts
    • Protection
      Future Website Hacks
    • Performance
      Speed Up Your Website
    • Response
      Help For Hacked Websites
    • Backups
      Disaster Recovery Plan
  • Resources
    • Guides
    • Webinars
    • Infographics
    • Blog
    • SiteCheck
    • Reports
    • Email Courses
  • Pricing
  • Immediate Help
  • Login
  • Immediate Help
Login
Login

New Customer?

Sign up now.
  • Submit a ticket
  • Knowledge base
  • Chat now

Browsing Category

Sucuri Labs

336 posts
Fake WordPress Plugin SiteSpeed Hosts Malicious Ads & Backdoors
  • Sucuri Labs
  • Website Malware Infections
  • Website Security

Smoker Backdoor: Evasion Techniques in Webshell Backdoors

  • Luke Leal
  • August 13, 2020
“Smoker Backdoor” is a PHP webshell backdoor that uses hexadecimal and decimal obfuscation in conjunction with the PHP function goto to evade detection from malware…
Read the Post
Uncommon Radixes Obfuscation
  • Security Education
  • Sucuri Labs
  • Website Malware Infections
  • Website Security

String Concatenation: Obfuscation Techniques

  • Krasimir Konov
  • August 12, 2020
While string concatenation has many valuable applications in development — such as making code more efficient or functions more effective — it is also a…
Read the Post
W97M/Downloader Malware Dropper Served from Compromised Websites
  • Sucuri Labs
  • Website Malware Infections
  • Website Security

PHP Binary Downloader

  • Luke Leal
  • August 7, 2020
When possible, an attacker will want to avoid using specific functions in their PHP code that they know are more likely to be flagged by…
Read the Post
Down the Malware Rabbit Hole Part 2
  • Sucuri Labs
  • Website Malware Infections
  • Website Security

PHP Backdoor Obfuscated One Liner

  • Luke Leal
  • August 5, 2020
In the past, I have explained how small one line PHP backdoors use obfuscation and strings of code in HTTP requests to pass attacker’s commands…
Read the Post
Clever SEO Spam Injection
  • Sucuri Labs
  • Website Malware Infections
  • Website Security

SEO Hacktool: Sitemap Generator

  • Luke Leal
  • July 30, 2020
An XML sitemap is an important part of a website’s SEO and exists to help search engine crawlers index new URLs on your website. For…
Read the Post
Reverse String WooCommerce
  • Ecommerce Security
  • Sucuri Labs
  • Website Malware Infections
  • Website Security
  • WordPress Security

Reverse String WooCommerce WordPress Credit Card Swiper

  • Ben Martin
  • July 27, 2020
As 2020 continues to be the worst year in almost anybody’s lifetime, allow me to take this opportunity to stoke the fires of your existential…
Read the Post
Skimmers Magento GitHub
  • Magento Security
  • Sucuri Labs
  • Website Malware Infections
  • Website Security

Skimmers in Images & GitHub Repos

  • Denis Sinegubko
  • July 22, 2020
MalwareBytes recently shared some information about web skimmers that store malicious code inside real .ico files. During a routine investigation, we detected a similar issue.…
Read the Post
Malicious Magento User Creator
  • Magento Security
  • Sucuri Labs
  • Website Security

Malicious Magento User Creator

  • Krasimir Konov
  • July 21, 2020
We recently found a simple malicious script leveraging Magento’s internal functions to create a new admin user with the admin role “Inchoo” ⁠— probably referring…
Read the Post
Fake WordPress Plugin SiteSpeed Hosts Malicious Ads & Backdoors
  • Sucuri Labs
  • Website Security
  • WordPress Security

Fake WordPress Plugin SiteSpeed Serves Malicious Ads & Backdoors

  • Krasimir Konov
  • July 16, 2020
Fake WordPress plugins appear to be trending as an effective way of establishing a foothold on compromised websites. During a recent investigation, we discovered a…
Read the Post
Trojan Spyware and BEC Attacks
  • Security Advisory
  • Security Education
  • Sucuri Labs
  • Vulnerability Disclosure

Vulnerabilities Digest: June 2020

  • John Castro
  • July 6, 2020
Highlights for June 2020 Cross site scripting is still the most common vulnerability in WordPress Plugins. Bad actors are taking advantage of the lack of…
Read the Post
Labs Notes Monthly Recap – May/2020
  • Sucuri Labs
  • Website Malware Infections
  • Website Security

Labs Notes Monthly Recap – May/2020

  • Juliana Lewis
  • June 3, 2020
In 2020, we doubled up our research efforts to report on many new attacks and hacks that we see in the wild. We believe that…
Read the Post
Search
Sucuri Sidebar Malware Removal to Signup Page
Sucuri Logo

Let’s Connect

Products
Website Firewall Website Security Platform WordPress Security Website Backups Hack Assistance Pricing
Solutions
DDoS Protection Malware Detection Malware Removal Malware Prevention Blacklist Removal SEO Spam Removal
USE CASES
Developers Ecommerce Agency Plans Enterprise Services HTTPS/2 Virtual Patching
Support
Knowledge Base SiteCheck Guides Research Labs Report Abuse Status Report
Company
About Sucuri Contact Blog Referral Partners Testimonials
Terms of Use Privacy Policy Do Not Sell My Personal Information Frequently Asked Questions

© 2025 GoDaddy Mediatemple, Inc., d/b/a Sucuri. All rights reserved.

back to top

'