Massive Admedia/Adverting iFrame Infection

This past weekend we registered a spike in WordPress infections where hackers injected encrypted code at the end of all legitimate .js files. The distinguishing features of this malware are: 32 hex digit comments at the beginning and end of the malicious code. E.g. /*e8def60c62ec31519121bfdb43fa078f*/ This comment is unique on every infected site. Most likely an MD5
Read More

The post Massive Admedia/Adverting iFrame Infection appeared first on Sucuri Blog.

Read more: Massive Admedia/Adverting iFrame Infection

Story added 1. February 2016, content source with full text you can find at link above.