Image: uzcert.uz · rights & removal
ATTENTION! The deleted malicious software on WordPress sites is being restored in a few seconds!
Reporting by Uzbekistan UZCERT IncidentsRead the original at uzcert.uz
Executive Summary
Facts Only
* A malicious program named SC restores deleted malicious files within seconds.
* The restoration occurs by placing parts in various locations like site files, the database, and server memory.
* Deleting a single file is insufficient to remove the infection due to mutually linked persistence mechanisms.
* Malicious components are placed in at least eight different locations allowing for self-restoration.
* The program uses the .user.ini file and autoprependfile directive to load code before PHP execution, potentially bypassing WordPress startup.
* Malicious plugins can exist simultaneously in wp-content/plugins and wp-content/mu-plugins.
* Full copies of malicious code are stored in the database in gzip + Base64 format under unknown names.
* The program uses System V shared-memory to store code outside disk files, persisting data even after file deletion.
* Malicious code is added to functions.php within active theme files as a restoration mechanism.
* The program can hide itself from the WordPress control panel plugin list and modify user rights in the database.
* Command and control infrastructure uses approximately 20 public Ethereum RPC gateway addresses.
Full Take
From the original · Uzbekistan UZCERT Incidents
ATTENTION! The deleted malicious program on WordPress sites is being restored in a few seconds!Read the full story at uzcert.uz
Sentinel — Human
The text presents a deep, structured analysis of a specific malware persistence technique within WordPress environments, exhibiting high technical specificity consistent with expert reporting rather than general synthetic output.
