diff --git a/definitions/patterns_raw.txt b/definitions/patterns_raw.txt index 67919b1..bef302a 100644 --- a/definitions/patterns_raw.txt +++ b/definitions/patterns_raw.txt @@ -261,16 +261,14 @@ tmhapbzcerff IndoXploit FaisaL Ahmed aka rEd X -#Malware/Attack strings +# WP-VCD Malware https://www.getastra.com/blog/911/how-to-fix-wp-vcd-backdoor-hack-in-wordpress-functions-php/ wp-vcd class.theme-modules.php -file_exists(ABSPATH . 'wp-includes/wp-tmp.php' +wp-tmp.php tmpcontentx function wp_temp_setupx -wp-tmp.php derna.top/code.php stripos($tmpcontent, $wp_auth_key) -#https://www.getastra.com/blog/911/how-to-fix-wp-vcd-backdoor-hack-in-wordpress-functions-php/ #Miscellaneous uname -a