SiteCheck Signatures

  1. Home
  2. SiteCheck Signatures
  3. malware-entry-mwdarkleech3


Description: A higly conditional server-side malware (Darkleech or cdorked) was identified in the server. This is an ongoing campaign and it means the server was compromised with malicous Apache modules or binaries. More details here:

1- New Apache Module Injection

2- Apache Binary Backdoors on Cpanel-based servers

3- Server Compromises – Understanding Apache Module iFrame Injections and Secure Shell Backdoor

Domains involved:
.. others  (randomly generated)

Affecting: Any type of linux-based server.

Latest update: 2013/Jun

Malware dump:

<iframe src="httx://