/wp-vcd-malware-sample

Wordpress malware sample with IOC

Primary LanguagePHPThe UnlicenseUnlicense

MAIN FILE wp-vcd.php This file in "WP-INCLUDES" make this work generate files and propagate it self

List of files generated:
	- class.wp.php EMPTY FILE INSIDE "WP-INCLUDES/CLASS.WP.PHP"
	- wp-tmp.php INSIDE "TMP/WP-TMP.PHP"
	- text inside "functions-theme-infected.php"

DOMAINS USED http://www.merna.cc/code9.php http://www.mlimus.com/code.php http://www.mlimus.me/code.php http://www.mlimus.xyz/code.php http://www.plimur.net/code.php http://www.plimur.me/code.php http://www.plimur.xyz/code.php http://www.denom.cc/code.php http://www.denom.pw/code.php http://www.denom.top/code.php

http://www.denom.cc/o.php
http://www.denom.cc/admin.txt

IN "functions-theme-infected.php" DISPLAY ANY "FUNCTIONS.PHP" INSIDE "WP-CONTENT/THEMES/ANYTHEMENAME"

INCLUDES/POST.PHP

class.theme-modules.php