Generic:PHP/Cryptophp.Injected.A

CryptoPHP is a threat that uses backdoored Joomla, WordPress and Drupal themes and plug-ins to compromise webservers on a large scale. CryptoPHP is spread through published pirated themes and plug-ins free for anyone to use (instead of having pay for them). After being installed on a webserver the backdoor has several options of being controlled which include command and control server communication, mail communication as well as manual control.

The detected file contains an injected piece of code that allows execution of the CryptoPHP malware. Removing this injection could potentially break a website.

See for more information: http://blog.fox-it.com/2014/11/18/cryptophp-analysis-of-a-hidden-threat-inside-popular-content-management-systems/

Generic:PHP/Cryptophp.A

CryptoPHP is a threat that uses backdoored Joomla, WordPress and Drupal themes and plug-ins to compromise webservers on a large scale. CryptoPHP is spread through published pirated themes and plug-ins free for anyone to use (instead of having pay for them). After being installed on a webserver the backdoor has several options of being controlled which include command and control server communication, mail communication as well as manual control.

The detected file is the core backdoor source. Removing it could potentially break a website.

See for more information: http://blog.fox-it.com/2014/11/18/cryptophp-analysis-of-a-hidden-threat-inside-popular-content-management-systems/