nbs-system / php-malware-finder

GNU Lesser General Public License v3.0
293 stars 55 forks source link

No malware detected #2

Closed danjde closed 4 years ago

danjde commented 4 years ago

Hi Devs and thanks for your wonderful work!

Recently I've discovered some malicious php script, inside my Joomla installation. I've found this malicious code, inside a map component, using Website Antivirus Scanner for Joomla, so I've installed php-malware-finder and thest again the php code, but with no evidence of that specific malicious code.

Are you interested to deeper the situation?

Many thanks!

davide

wargio commented 4 years ago

can you share what this malicious code looks like?

danjde commented 4 years ago

Hi @wargio, yes, here all files marked as containing malicious code: [deleted] NB Antivirus scan tells me as malware type for each files: php.var.function.14

then those with suspected malicious code (heuristic): [deleted]

I've scanned also them via Wordfence (wordpress) plugin, with no results.

Thanks!

wargio commented 4 years ago

I think is a false positive of your antivirus. the files are clean for me.

danjde commented 4 years ago

What kind of method have you used?

Thanks!

wargio commented 4 years ago

i just opened the files and read them.

danjde commented 4 years ago

Ok, well. Yes, it could also be that a company pretends to detect infected files to induce the user to buy the license but it seems to me a bit on the limit...

Anyway thanks!!

Davide