Home Testimonials Company Support 1–888–873–0817
PRICING SUPPORT LOGIN
Home Notes Malware Signatures About

Malware entry: MW:MROBH:3

Description: Code used to insert a malicious javascript on many sites hosted at GoDaddy, Bluehost and many other hosting companies.

Loads malware from:
http://whereisdudescars.com/
http://nowisisdudescars.com/
http://sippa.dottasink.net/

It infects all PHP files, targeting specifically Wordpress sites.

Clean up:: Run the following script: http://blog.sucuri.net/2010/05/simple-cleanup-solution-for-latest.html or contact support@sucuri.net for help.

Malware dump (base 64 added to the .php files):




For all our web-based malware signatures, go here: http://labs.sucuri.net/?malwaredb