example-malware-vulnerabilities

Examples of PHP Malware. A location of examples of malware found on hacked PHP sites. If you see PHP code simular to these types of examples, then you know your site has been compromised. Remove these codes and files ASAP. For educational purposes only. For easier read, view the PHP files in RAW.

Types of file name/directory signature

.../web/pngised.php
!.../web/ucwmptgc.php
!.../web/wjcilhrcz.php
!.../web/wp-config.php
!.../web/cgi-bin/index.php
!.../web/css/futura_300.font.php.suspected
!.../web/css/gdsr.php
!.../web/css/index.php
!.../web/downloads/index.php
!.../web/fonts/index.php
!.../web/images2/freebooks.php
!.../web/images2/jquery.serialScroll-1.2.1-min.php
!.../web/newfolde_r/index.php
!.../web/newfolde_r/loymbfs.php.suspected
!.../web/scripts/index.php
!.../web/stats_namechange_to_block/index.php
!.../web/stats_namechangedMay2007/index.php
!.../web/statsbackupHW/index.php
!.../web/stats~/index.php
!.../web/webfonts/index.php
!.../web/wp-admin/css/colors/ectoplasm/smwbeshi.php
!.../web/wp-admin/images/extra_mp.font.php.suspected
!.../web/wp-admin/js/jquery-spoiler.php
!.../web/wp-content/bexmedia.php
!.../web/wp-content/pdf.php
!.../web/wp-content/plugins/backupbuddy/_importbuddy/importbuddy/controllers/index.php
!.../web/wp-content/plugins/backupbuddy/controllers/ajax/download_archive.php
!.../web/wp-content/plugins/backupbuddy/controllers/ajax/view_log.php
!.../web/wp-content/plugins/backupbuddy/css/index.php
!.../web/wp-content/plugins/backupbuddy/destinations/_s3lib3/Aws/DeviceFarm/Exception/shadowbox-base.php
!.../web/wp-content/plugins/backupbuddy/destinations/_s3lib3/Aws/Emr/Exception/mootools-1.2.1-core-yc.php.suspected
!.../web/wp-content/uploads/bb-plugin/tmiinlib.php
!.../web/wp-includes/SimplePie/Content/Type/ixiuepzf.php
!.../web/wp-includes/js/rjrytxmh.php
!.../web/wp-includes/js/tinymce/skins/lightgray/ja.catslwi.php
!.../web/wp-includes/theme-compat/iquyrcen.php
!.../web/wp-admin/includes/jquery.jgrowl.php.suspected
!.../web/wp-includes/class-wp-role.php
!.../web/wp-includes/inbex.php
!.../web/wp-includes/js/tinymce/cwlfwbyi.php