{HEX}base64.inject.unclassed.6 malicious script
-
I received following email from server company lastweek:
“Your account xxxx hosted on server xxxx
is hosting the follwoing malicious files/scripts :
=============================================={HEX}base64.inject.unclassed.6 : /home/xxxx/public_html/wp-content/plugins/wp-miniaudioplayer/mapTinyMCE/tinymcemaplayer.js.php
==============================================
This files are being abused by crackers/hackers to install malicious scripts on your account. “Currently my site is disabled by the server company because of this trouble.
I did installed wp-miniaudioplayer version 2.
If they say the script was abused and changed to be a malicious script by someone,
I wanted to find out which part(s) of the script(s) was changed.I compared 2 groups of wp-miniaudioplayer scripts.
1. My wp-miniaudioplayer version 2 scripts, which were at the server and being claimed as malicious script(s)
2. The files kept in ww.wp.xz.cn, which is version 2 – Revision 618927 at http://plugins.svn.ww.wp.xz.cn/wp-miniaudioplayer/tags/0.2
I used Winmerge program to check all files side by side.*Comparison results: 100% identical
By the way, I also compared version 2 and the latest version 3.
mapTinyMCE/tinymcemaplayer.js.php – identical
mapTinyMCE/maplayertinymce.php – changed a lotBased on above, should I conclude “wp-miniaudioplayer version 2” was {HEX}base64.inject.unclassed.6 malicious script?
Or, this is terrible false alert?My server company alerted and pointed out a specific script “tinymcemaplayer.js.php” as {HEX}base64.inject.unclassed.6 malicious script,
and there is no change in version 2 and 3.
If possible, please anyone confirm us that wp-miniaudioplayer version 3 is not malicious script.Thank you
The topic ‘{HEX}base64.inject.unclassed.6 malicious script’ is closed to new replies.