Quantcast
Channel: Topic Tag: malware | WordPress.org
Viewing all articles
Browse latest Browse all 3861

CooLMinE on "Is my webserver compromised ?"

$
0
0

Extra information from the event log:

Name: Backdoor:PHP/WebShell.J
ID: 2147683134
Severity: Severe
Category: Backdoor
Path: containerfile:_C:\Windows\Temp\php99EB.tmp;containerfile:_C:\Windows\Temp\phpDC36.tmp;file:_C:\Windows\Temp\php99EB.tmp->revslider/error.php;file:_C:\Windows\Temp\phpDC36.tmp->revslider/error.php
Detection Origin: Local machine
Detection Type: Concrete
Detection Source: System
User: NT AUTHORITY\NETWORK SERVICE
Process Name: Unknown
Signature Version: AV: 1.191.4893.0, AS: 1.191.4893.0, NIS: 113.69.0.0
Engine Version: AM: 1.1.11302.0, NIS: 2.1.11005.0
Name: Backdoor:PHP/WebShell.J
ID: 2147683134
Severity: Severe
Category: Backdoor
Path: file:_C:\Windows\Temp\php9CBA.tmp
Detection Origin: Local machine
Detection Type: Concrete
Detection Source: Real-Time Protection
User: NT AUTHORITY\IUSR
Process Name: C:\Program Files (x86)\PHP\v5.4\php-cgi.exe
Signature Version: AV: 1.191.4552.0, AS: 1.191.4552.0, NIS: 113.67.0.0
Engine Version: AM: 1.1.11302.0, NIS: 2.1.11005.0

Viewing all articles
Browse latest Browse all 3861

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>