Monday, September 25, 2017

Malware Code In WordPress Theme

Found in single.php file

<?php
$x0d="pr\x65\147\137\155at\143h";
$x0b = $_SERVER['HTTP_USER_AGENT'];$x0c="\x20\015\012\040\x20\040\040\x20\040\x20\040\074a\040h\162ef\075'\150\164\164\x70\x3a\x2f\x2f\167\x77\x77\056\x61\172wpt\150\145\x6d\145\x73\x2e\143\157\x6d\057\x63\141te\x67\x6fr\171/g\145\156\x65r\141\x6c-\167\160-\164\x68e\155\x65s/'\x3eO\x6e\154\151\x6e\x65\040\106\162\145e W\160\x20\x54\x68\145\x6d\145\x73\x3c\x2f\141\x3e\x20";if ($x0d('*bot*', $x0b)) {echo $x0c;} else {echo ' ';}