What WordPress Malware looks like

A look at some malware infected WordPress files.

Imagem de capa

Recently, I had the opportunity to take a look at a website which was brought down by it’s hosting partner because it failed to clear malware scans. The malware was found in a bunch of wordpress PHP files.

As shown in the screenshots, the malicious code was injected into the beginning or at the end of these files, and after looking at dozens of such samples, it can be spotted easily.

_config.yml

_config.yml

Just removing this additional code by hand, cleared all the malware scans and the website was brought online.

Also, I discovered that anti-malware tools for desktop usage is completely useless against malware that attacks websites. More on that later.