Possible malicous file
-
I found a file called maile.php on the server.
First lines make me think it could be malware:
"mailer inbox, mailer inbox to all, inbox 2013, inbox 2014, send inbox, send inbox to hotmail aol gmail, script mailer inbox, how to send inbox, send anonymous emails, alboraaq send inbox, unlimitid send inbox,by rocky & poter
TEAM ALBORAAQ
CONTACT[at]ALBORAAQ[dot]COM
HTTP://WWW.ALBORAAQ.COM
( TOOLS - 2014 ) "Is there a way I can find out if it really is malware?
-
Looks like Malware to me. There are online submissions sites for this stuff.
-
-
Thanks, scanning now. Sucuri didn't find anything which I had tried before posting.
-
You could try here too:
https://www.virustotal.com/ -
Took a chance to download the file and then upload to http://virustotal.com.
So far: PHP.Agent-AQ[Trj], VULCB21.Webshell, Trojan Mailfinder.PHP.Mailer.ac (and .p)
Thanks guys...time to boot this customer.
-
-
@technobabble said:
Thanks guys...time to boot this customer.
Booting a customer for a virus? does that mean we can do end user replacements too if they get viruses?
-
@thecreativeone91 said:
@technobabble said:
Thanks guys...time to boot this customer.
Booting a customer for a virus? does that mean we can do end user replacements too if they get viruses?
I was wondering that too... booting a client because of a virus?
-
@thecreativeone91 said:
does that mean we can do end user replacements too if they get viruses?
YES.
Although I don't know where we're going to find completely new staff for every business ever.
-
@MattSpeller said:
@thecreativeone91 said:
does that mean we can do end user replacements too if they get viruses?
YES.
Although I don't know where we're going to find completely new staff for every business ever.
Plenty of people looking for jobs out there.
-
@thecreativeone91 said:
@MattSpeller said:
@thecreativeone91 said:
does that mean we can do end user replacements too if they get viruses?
YES.
Although I don't know where we're going to find completely new staff for every business ever.
Plenty of people looking for jobs out there.
But do you want to hire those people?
-
@thecreativeone91
LOL...no, the customer seemed sketchy when he signed up for hosting services and then added that file to the server. So booting = cancelling his service.
-
@technobabble said:
@thecreativeone91
LOL...no, the customer seemed sketchy when he signed up for hosting services and then added that file to the server. So booting = cancelling his service.
Oh, you are thinking that it was intentional?
-
@scottalanmiller Yep...just checked with my cc provider and they have been trying to buy products and the cards are failing multiple times...I'm calling this fraud and scamming.
-
@technobabble Report his {censored} <content removed by moderator> @)(#&$)@&#$ to the Feds.
-
@technobabble said:
@scottalanmiller Yep...just checked with my cc provider and they have been trying to buy products and the cards are failing multiple times...I'm calling this fraud and scamming.
Sounds like it is time to run away.