Malware notification from Server
-
Hi,
Our server notified the below details,referring that it could be malware.
So to confirm i downloaded the plugin from here https://ww.wp.xz.cn/plugins/contact-forms-builder/ and checked the file in this path : contact-forms-builder/frontend/js/bootstrap-formhelpers.min.js and found the same code is existing there.
Could you please explain if this is malware or not.Thanks,
Shyam
Notification from server team is copied below,Malware found on javascript file: https://www.airhosted.ch/wp-content/plugins/contact-forms-builder/frontend/js/bootstrap-formhelpers.min.js.pagespeed.jm.2dILsWYCHp.js
http://sucuri.net/malware/entry/MW:JS:GEN2?malware.generic_jsobfuscator.1.2 var _0xf556=[“\x42\x6F\x6F\x74\x73\x74\x72\x61\x70\x20\x46\x6F\x72\x6D\x20\x48\x65\x6C\x70\x65\x72\x73\x20\x72\x65\x71\x75\x69\x72\x65\x73\x20\x6A\x51\x75\x65\x72\x79″,”\x4A\x61\x6E\x75\x61\x72\x79″,”\x46\x65\x62\x72\x75\x61\x72\x79″,”\x4D\x61\x72\x63\x68″,”\x41\x70\x72\x69\x6C”,”\x4D\x61\x79″,”\x4A\x75\x6E\x65″,”\x4A\x75\x6C\x79″,”\x41\x75\x67\x75\x73\x74″,”\x53\x65\x70\x74\x65\x6D\x62\x65\x72″,”\x4F\x63\x74\x6F\x62\x65\x72″,”\x4E\x6F\x76\x65\x6D\x62\x65\x72″,”\x44\x65\x63\x65\x6D\x62\x65\x72″,”\x53\x55\x4E”,”\x4D\x4F\x4E”,”\x54\x55\x45″,”\x57\x45\x44″,”\x54\x48\x55″,”\x46\x52\x49″,”\x53\x41\x54″,”\x22\x41\x6E\x64\x61\x6C\x65\x20\x4D\x6F\x6E\x6F\x22\x2C\x20\x41\x6E\x64\x61\x6C\x65\x4D\x6F\x6E\x6F\x2C\x20\x6D\x6F\x6E\x6F\x73\x70\x61\x63\x65″,”\x41\x72\x69\x61\x6C\x2C\x20\x22\x48\x65\x6C\x76\x65\x74\x69\x63\x61\x20\x4E\x65\x75\x65\x22\x2C\x20\x48\x65\x6C\x76\x65\x74\x69\x63\x61\x2C\x20\x73\x61\x6E\x73\x2D\x73\x65\x72\x69\x66″,”\x22\x41\x72\x69\x61\x6C\x20\x42\x6C\x61\x63\x6B\x22\x2C\x20\x22\x41\x72\x69\x61\x6C\x20\x42\x6F\x6C\x64\x22\x2C\x20\x47\x61\x64\x67\x65\x74\x2C\x20\x73\x61\x6E\x73\x2D\x73\x65\x72\x69\x66″,”\x22\x41\x72\x69\x61\x6C\x20\x4E\x61\x72\x72\x6F\x77\x22\x2C\x20\x41\x72\x69\x61\x6C\x2C\x20\x73\x61\x6E\x73\x2D\x73\x65\x72\x69\x66″,”\x22\x41\x72\x69\x61\x6C\x20\x52\x6F\x75\x6E\x64\x65\x64\x20\x4D\x54\x20\x42\x6F\x6C\x64\x22\x2C\x20\x22\x48\x65\x6C\x76\x65\x74\x69\x63\x61\x20\x52\x6F\x75\x6E\x64\x65\x64\x22\x2C\x20\x41\x72\x69\x61\x6C\x2C\x20\x73\x61\x6E\x73\x2D\x73\x65\x72\x69\x66″,”\x22\x41\x76\x61\x6E\x74\x20\x47\x61\x72\x64\x65\x22\x2C\x20\x41\x76\x61\x6E\x74\x67\x61\x72\x64\x65\x2C\x20\x22\x43\x65\x6E\x74\x75\x72\x79\x20\x47\x6F\x74\x68\x69\x63\x22\x2C\x20\x43\x65\x6E\x74\x75\x72\x79\x47\x6F\x74\x68\x69\x63\x2C\x20\x22\x41\x70\x70\x6C\x65\x47\x6F\x74\x68\x69\x63\x22\x2C\x20\x73\x61\x6E\x73\x2D\x73\x65\x72\x69\x66″,”\x42\x61\x73\x6B\x65\x72\x76\x69\x6C\x6C\x65\x2C\x20\x22\x42\x61\x73\x6B\x65\x72\x76\x69\x6C\x6C\x65\x20\x4F\x6C\x64\x20\x46\x61\x63\x65\x22\x2C\x20\x22\x48\x6F\x65\x66\x6C\x65\x72\x20\x54\x65\x78\x74\x22\x2C\x20\x47\x61\x72\x61\x6D\x6F\x6E\x64\x2C\x20\x22\x54\x69\x6D\x65\x73\x20\x4E\x65\x77\x20\x52\x6F\x6D\x61\x6E\x22\x2C\x20\x73\x65\x72\x69\x66″,”\x22\x42\x69\x67\x20\x43\x61\x73\x6C\x6F\x6E\x22\x2C\x20\x22\x42\x6F\x6F\x6B\x20\x41\x6E\x74\x69\x71\x75\x61\x22\x2C\x20\x22\x50\x61\x6C\x61\x74\x69\x6E\x6F\x20\x4C\x69\x6E\x6F\x74\x79\x70\x65\x22\x2C\x20\x47\x65\x6F\x72\x67\x69\x61\x2C\x20\x73\x65\x72\x69\x66″,”\x22\x42\x6F\x64\x6F\x6E\x69\x20\x4D\x54\x22\x2C\x20\x44\x69\x64\x6F\x74\x2C\x20\x22\x44\x69\x64\x6F\x74\x20\x4C\x54\x20\x53\x54\x44\x22\x2C\x20\x22\x48\x6F\x65…
The topic ‘Malware notification from Server’ is closed to new replies.