Showing revision 1

MaliciousPHP

2021: notice malicious PHP files written in EVERY apache-writable directory in the filesystem.

The malware is index.php files which do an include of a hidden .ico file e.g. .37eb5bf3.ico

Decode the php with https://www.unphp.net/

2021-02-28

 find / -regex ".*/\..*ico" -ls