Phishing:PHP/Generic.A
Generic phishing script
Generic phishing script
Generic web shells
Script that proxies access to a remotely hosted web shell
Generic spam scripts
Scripts used by attackers to copy local files up to the affected server.
Files that leverage an infected server to send email, usually for spam mail or to attract victims for phishing sites.
Files that leverage an infected server to send email, usually for spam mail or to attract victims for phishing sites.
Files that use PHP to place malicious external JavaScript references into visited pages.
Category under which all phishing kit files are marked.
Note: Despite the presence of “HTML” in the name, this category includes all active portions of a phishing operation, including PHP-based form processing, credential mailers, and card validation JavaScript. “Benign” portions of phishing kits, like CSS and images, do not get marked.
Catch-all category for ASP-based backdoor files.
HTML-based browser redirection using
Catch-all category for malicious executable binary files.
Rarely used category for static HTML code that doesn’t fit into other categories.
PHP-based redirects to malicious sites with the intended destination of an illegal pharmaceutical site.
Catch-all category for shell files used to install or compile malware to compromise a system.
Test file from the European Expert Group for IT Security. See https://www.eicar.org/?page_id=3950 for more information.
Files that leverage an infected server to send email, usually for spam mail or to attract victims for phishing sites.
PHP-based redirects to malicious sites, usually utilizing the header() function.
Scripts used by attackers to copy local files up to the affected server.
Advertisment injections and injectors
Scripts allowing execution of arbitrary commands using GET-, POST- or cookie-based request data (based on register_globals)
Scripts that redirection visitors to external pages
“Web shell by oRb”
Generic packer which uses $GLOBALS.
Generic packer that uses Gzip compressed Base64 encoded data.
Generic packer.
Generic packer that creates a dynamic function which uses Gzip compressed Base64 encoded data as input.
Website defacement pages and scripts
Scripts that include external content in the website
Phishing pages for PayPal
“c99” shell
Packet flooder “Bomber Flooder”
Dropper scripts for the Mayhem botnet virus.
Spam script “Gu3ssWho?”
Spam script “Leaf PHPMailer”
Phishing pages to intercept user data of WordPress websites
Scripts executing commands supplied in POST-based request data
Scripts used for sending spam using local e-mail sockets
Phishing pages for Wells Fargo
CaZaNoVa163 SMTP Mailer
Spam script “Sab3on”
FOPO creates equivalent PHP obfuscated code which requires no special server runtime for execution.
Pages redirecting the user to various kinds of phishing sites
“b374k” shell
“Priv8” shell
File upload scripts
“Filesman” shell
PRIV8 mailer script
Phishing pages for Rabobank bank.
Phishing pages for banking.
“BArNEr” web shell
Phishing pages for Knab bank.
PHP bot scripts
File manager
“SadrazaM | Casus” shell
Phishing pages for creditcards.
Generic packer that uses base64_decode.
Scripts to scan and index webhosting accounts
“Web Shell by boff”
“cPanel d0mains config stealer” shell
Apple phishing pages
Injected redirects to pharmacy advertisment websites
“X-Cpanel Cracker by IST Team”
“Blackshell” shell
Pro Mailer spam script
Uses chr() and intval() encoding:
$p12 = “intval”;
$R0 = $K1e($p12($K1e($p12($K1e($p12(“5” . $K1e($p12(“51”)))) . $K1e($p12($K1e($p12($K1e($p12(“5” . $K1e($p12(“51”)))) . $K1e($p12(“51”)))) . $K1e($p12(“5” . $K1e($p12(“51”)))))))) . $K1e($p12(“5” . $K1e($p12(“55”))))))
“private shell by $Kanjut”
“Dark Shell” shell
Generic PHP-based IRC bot scripts
“MzH” spam script
Generic packer that uses Gzip compressed Base64 encoded data.
“bypass” web shell
A malicious version of the LoginWall WordPress plug-in that injects pages with spam content.
Malware injected with other malware
“INBOX” mailer script
PHP-based IRC bot “pBot”
Phishing pages for ING Bank
File related to Zeus malware
PHP-based website proxy scripts
“PhpConfigSpy” shell
Spam script “Postman mailer”
Phishing pages for Rezult Group
Spam script “NEW-MEG4-MAIL”
Packet flooder targeting IRC servers
“Rebels” mailer
SMTP mailer
Spam script “XSender”
Packet flooder “Udp”
Generic shells allowing submission of arbitrary commands for execution
“r57” shell
Packet flooder “mailspam”
“0x00 PHP shell”
Scripts flooding UDP packets
“QuadCore-SHELL” shell
“urlerr XSS scan” scripts
“libworker” PHP bot
Scripts exposing the local PHP configuration
Spam script “Horux-Mailer”
“ByroeNet” IRC bot
Executable scripts with not otherwise specified malicious purposes
Spam script “PerlMailer”
Defacement scripts by zoneh
“shell.andalas_oku” shell
Malware aimed at Joomla installations
“recky a.k.a bogel” shell
dangerous mailer script
Scripts used for executing arbitrary SQL queries
Scripts with a not otherwise specified purpose, with code inserted through base64 encoded strings.
Defacement scripts by GirGiti
Spam script “Mister Spy Mailer”
Generic PHP-based agent scripts
Spam script “InBox Dr-XeOn galak Crypter Niahahhhah”
Spam script “Sopyan”
Scanner that finds UDP broadcast ip addresses.
Packet flooder “Vadim”
“pawet” database dumper
“RootShell” shell
Spam script “DarkMailer”
Phishing pages for Hotmail and Windows Live Mail
Gmail phishing pages
“T E A M C O D E R” shell
Spam script “Allucard”
Defacement scripts by Albanian Hacker
“shaje3 <
Defacement scripts by JyhackTeam
Standoutmedia er et webbureau dedikeret til WordPress platformen.
Vi driver egne hostingløsninger, hvor tusindvis af kunder hver dag modtager sikkerhedsopdateringer.
Læs mere om os her: https://standoutmedia.dk/