Spam:PHP/Mailer.D3xter.A
Spam script “D3xter Sp Mailer”
Spam script “D3xter Sp Mailer”
Unclassed scripts with malicious code embedded in base64 and/or gzipped code.
Spam script “Cav7 Mailer”
jq shell
j0k3r spam script
“FaTaLisTiCz FX29” shell
“SoLdaT.eXe Mailer.V2” script
CGI telnet-based web shells
CryptoPHP is a threat that uses backdoored Joomla, WordPress and Drupal themes and plug-ins to compromise webservers on a large scale. CryptoPHP is spread through published pirated themes and plug-ins free for anyone to use (instead of having pay for them). After being installed on a webserver the backdoor has several options of being controlled which include command and control server communication, mail communication as well as manual control.
The detected file contains an injected piece of code that allows execution of the CryptoPHP malware. Removing this injection could potentially break a website.
See for more information: http://blog.fox-it.com/2014/11/18/cryptophp-analysis-of-a-hidden-threat-inside-popular-content-management-systems/
“COLUMBUSSheLL”
“egyspider” shell
“LoVe511 Mail3R”
“err0r” shell
“v23au” base64-encoded scripts
“ana21” malware
Phishing pages for Ayi.com
CryptoPHP is a threat that uses backdoored Joomla, WordPress and Drupal themes and plug-ins to compromise webservers on a large scale. CryptoPHP is spread through published pirated themes and plug-ins free for anyone to use (instead of having pay for them). After being installed on a webserver the backdoor has several options of being controlled which include command and control server communication, mail communication as well as manual control.
The detected file is the core backdoor source. Removing it could potentially break a website.
See for more information: http://blog.fox-it.com/2014/11/18/cryptophp-analysis-of-a-hidden-threat-inside-popular-content-management-systems/
“sec4ever.com / xsecurity” upload script
“PHP eMailer created by BlackSHOP”
“CrazyweB” shell
Outlook phishing pages
“some_util” web shell
“MrYcef Mailer”
“Ckutels xMailer” spam script
“Cordoba” mailerscript
“Bulk Mailer By HolaKo”
“DDOS BOT PHP coded By RELOAD-X” packet flooder
Dropbox phishing pages
“kick” packet flooder
“PRO Mailer V2 [Powered By #WAEL]”
“SexCrime” web shell
Packet flooder “floodergiflood”
“lopphp” shell
“sea16” web shell
Spam scripts using obscured SMTP connections
“[S][h][a][u][n] Mass Mailer By Kobra Crew”
Phishing pages for Chase.com
“juniormafia MasS Mailer”
Morgan Stanley phishing pages
“jalanG” web shell
“e107” IRC bot
Packet flooder “Perl Anonymail”
Packet flooder “Small”
Packet flooder “Win32 Delf I”
Defacement injection scripts
“oldwolf” IRC bot
“karawan” IRC bot
Generic forged request flooder scripts
“Arabhack” IRC bot
PHP-based IRC bot by “vj_denie”
“devil” IRC bot
PHP-based IRC bot by “hajar”
“fx29” IRC bot
Defacement injection script by “Albania”
“jok” web shell
“WHMCS Decoder” script
“BOSS” mailer
“Data Cha0s Connect Back Backdoor” shell
“SoakSoak.Ru” malware
Similar spam scripts allowed to be accessed from IP ranges 6.185.239.* and 8.138.118.*
“the3gayskeeters / Yogyacarderlink” mailer script
“sesuai” auto-injection scripts
“NeW_Sh3LL by Net-Thug” shell
“genol” IRC bot
“Mailer By thePro3ject [Junk]”
“Shepdoy Multi Bot Scanner” IRC bot
“UberCracker” IRC bot
“rafflesia” IRC bot
“putr4XtReme” IRC bot
“pitbull” IRC bot
Phishing pages for NatWest Personal Banking
“KAdot” shell
Scripts allowing execution of arbitrary commands using GET-, POST- or cookie-based request data
Spam script “Bombam mailer”
PHP-based website proxy injector by “hexon”
“Mig33” mailer
“C102Shell” shell
Packet flooder targeting Skype servers
“antichat” shell
“VPS Injector” script
“karwadanger” shell
“Rofik” shell
Spam script “Forever2008”
“yellsoft” mailer scripts
“magnum” IRC bot
“bRuNo” IRC bot
“v0ld3m0rt” shell
Spam script “EmailBomb”
Phishing pages for HM Revenue & Customs
Packet flooder “gewse”
Spam script “Akpumpin Mailer”
“FakoMasT3r” shell
“Violaoeucc0101” mailer
“TDshell” shell
“nob0dyCr3w” shell
“Vrs-hCk” shell
“SimShell” shell
“iTSecTeam” shell
“akatsuki” shell
Spam script “EgyMailer”
“BH-LSC log cleaner” scripts
“KetEk” IRC bot
“xeratuta” web shell
“Ketemu” shell
Spam script “BlackMailer”
Spam script “Alanche Mailer”
Phishing pages for Alikay Naturals
Packet flooder “Boom flooder”
Defacement injection script by “Ckrid”
“Nested buoamv” mailer
“NCC” shell
“h4ntu” shell
“hackru” shell
“simorghev” shell
“Macker” shell
“ibl13Z” shell
Phishing pages for Crèdit Mutuel
“cpwrap” script aimed at cPanel environments
“KcB” IRC bot
“ly0kha” shell
Spam script “Fmail”
Phishing pages for ICICI Bank
Phishing pages for Craigslist
Packet flooder “excess flooder”
Defacement notice by “buno”
“libworker” IRC bot
Spam script “ZombBomber”
“hide” shell
“r3v3ng4ns” shell
“c100” shell
“xakep” shell
Spam script “Ebomb09”
“rgod” shell
“N2” connback shell
“ins_cyberz” IRC bot
“jpg-php lib v1.1.0 PHP shell”
Spam script “AnonymousMail”
Phishing pages for the Royal Bank of Canada
Phishing pages for Banque Populaire
“cPanel Turbo Force” shell
PHP-based IRC bot by “dcom”
“s3n4t00r” scripts
Spam script “MailBomber”
“iskorpitx” script that downloads various defacement pages
Spam script “GhostMail”
“MulCiShell” shell
“Uchiha” shell
“Peterson” shell
Spam script “ImapSpam”
“DataCha0s” connback shell
“cbLorD” web shell
“RemoteAdmin” shell
Spam script “ParaMail”
Phishing pages for Smile Bank
Phishing pages for Abbey National / Santander
“EGFM Sh3ll” shell
PHP Chaploit malware
“avi” shell
“ZfxId” scripts
“shellcomm” shell
Spam script “MailSender”
“mic22” shell
“ItsmYarD” shell
“jambihackerlink” shell
Spam script “Fela mailer”
“AresU” connback shell
“bf404” scripts with malicious code embedded
“PHP eMailer by Peterson” spam script
Spam script “IPmail”
Phishing pages for Absa Bank
Phishing pages for Cahoot Banking
“Dr.Z0mbie Prv8” shell
“Mustijan” script
“Bilgi” shell
File browser script “tur334vl”
“x0rg” shell
Spam script “AnonyMail”
“GFS” shell
Phishing pages for Yorkshire Bank
“S O M B R A – SystemBR” shell
Packet flooder “SMS”
“swordfs” config scanner script
“odix” packet flooder
Spam scripts controlled by submitting XML POST-data
Spam script “BYSCRA3ZY”
Phishing pages for Alliance Leicester
Phishing pages for HSBC Banking
“Xhackers Shell by Crazy_Hacker”
PHP-based IRC bot by “InsideTeam”
“BwS” shell
Phishing pages for First National Bank
“Yudi e57shell” shell
Spam script “BomberMailer”
“DxShell” shell
Phishing pages for Kiwibank
“Google Analist” upload script
PHP-based IRC bot by “Uchiha”
“c0li” apache log injector script
“n0va” web shell
Packet flooder “oey flooder”
Spam script “BL4CKUN1X”
Phishing pages for Barclays
Phishing pages for Nationwide Banking
“UnixUnited / robotcop” shell
“cPanel FTP Crack” script
“PHPJackal” shell
Spam script “10hack Mailer”
“MaZuRRel” shell
Spam script “Anonmail”
Defacement injection script by “Byronet”
PHP-based IRC bot by “sniper”
“Storm7Shell” shell
“webadmin” shell
Fakeproc scripts
Phishing scripts by Attijari
AIM packet flooder
Spam script “Sphinx Mailer”
Phishing pages for Clydesdale Bank
Spam script “HackStock”
Spam script “UnixStats Mass MaiLer”
Database injector “0813”
“s72” shell
Spam script “youngest mailer”
“lama” shell
Spam script targeting Hotmail
Malicious scripts released by “CM Hacker”
Phishing pages for Windows Live Mail
“sansursansursansur” shell
“ekin0x” shell
“Romnous rfiscan” scripts
Phishing scripts by auc61
cPanel exploit by “aria”
Spam script “Madys Mailer”
Phishing pages for Egg Online
Spam script “AnonEBomber”
“inlove17” shell
“myshellexec” shell
“Jerem” shell
Spam script “Dallas Mailer”
“winx” shell
Spam script “Anubis Mailer”
Packet flooder targeting ICQ servers
Phishing pages for America Online
“ra1” shell
“nsTView” shell
“xscan” IRC bot
Defacement scripts by r00t3r
Database injector script “DbKiss”
Packet flooder “Anarklik”
Phishing pages for Halifax Bank
Standoutmedia er et webbureau dedikeret til WordPress platformen.
Vi driver egne hostingløsninger, hvor tusindvis af kunder hver dag modtager sikkerhedsopdateringer.
Læs mere om os her: https://standoutmedia.dk/