Reposted from The Sophos Naked Security Blog.
Troj/PHPShll-B: Malware injects itself into WordPress installations
On Friday, a colleague in our IT department asked about a Mal/Badsrc-C malware detection that had been found by Sophos products on one of their friends' websites.
When I initially downloaded the website it looked clean. However, the automated systems inside SophosLabs were detecting the webpage as being infected with Mal/Badsrc-C.
So, I investigated a little more deeply - repeating the download after setting the User-Agent in my browser to pretend to be Internet Explorer.
This time I saw:
>>> Virus 'Mal/Badsrc-C' found in file index.html
Continue reading at The Sophos Naked Security Blog
Anatomy of a Wordpress Hack at the Loudmouthman Blog