waikey
Member
The new virus from domain donatelloflowfirstly . ga is now attacking wordpress site.
the virus will generate(maybe download) a file named with "_t" or "_a", the file will scan the whole site, then inject a line of JS code to those files, then inject the code to all post and pages
The JS code will redirect your site to domains: blackwaterforllows . ga , donatelloflowfirstly . ga , and blackwaterforllows . ga . ..
many site got infected but people still don't know where is the backdoor, so be aware of the nulled plugins and themes these days.
Hope the expert in this forum can check some popular plugins such as wp-rocket (since my site got injected with this nulled plugin).
the virus will generate(maybe download) a file named with "_t" or "_a", the file will scan the whole site, then inject a line of JS code to those files, then inject the code to all post and pages
The JS code will redirect your site to domains: blackwaterforllows . ga , donatelloflowfirstly . ga , and blackwaterforllows . ga . ..
many site got infected but people still don't know where is the backdoor, so be aware of the nulled plugins and themes these days.
Hope the expert in this forum can check some popular plugins such as wp-rocket (since my site got injected with this nulled plugin).