VirusTotal doesn't detect the backdoor

Virustotal is a software not magician, it can not detect each and everything. Be careful when using nulled themes, why do you even use nulled, if you can not afford them just find a free alternative. Nulled themes/plugins are a serious security risk.
 
When you use or get nulled themed it will be highly likely happened that why most people who use nulled stuff will only put them onto a server that can handle it losing or things going wrong since if you put a nulled theme or plugin it is fairly likely it hacked or not the best.

Using any website security service will never be 100% correct since you get at least 100,000 of kinds of viruses or other things bad on nulled things.
 
Maldet
Another quick way to check website files for viruses, Trojans, web shells is Maldet-a free scanner for Linux, which is focused on hosting platforms and working with website files.

Maldet is already pre-installed on the virtual hosting servers of most providers. For self-installation on a VPS, use the following commands:

Download the archive:

 
Are you sure this file is the same file?

What amazes me is how on the first time you got a red flag and you still uploaded the file into your server...
 
Never use Nulled themes from untrusted websites. Buy the theme or get it from BHW. If you install nulled theme/ plugins chances are your hosting and website might be compromised sooner or later.
 
If i got this right, VT detected the backdoor via the Microsoft engine on the 1st run, on the 2nd try it didn't detect anything. Right?

The backdoor didn't go anywhere obviously. If you check the scan result, on the 2nd try the Microsoft engine reported a timeout, so it didn't scan the file. And because that was the only positive on the 1st run, there was no positive on the 2nd.

Not every engine works all the time, so keep that in mind.
Microsoft didn't reported a timeout. It worked well but no backdoor be detected on 2nd, 3rd... try.

Maldet
Another quick way to check website files for viruses, Trojans, web shells is Maldet-a free scanner for Linux, which is focused on hosting platforms and working with website files.

Maldet is already pre-installed on the virtual hosting servers of most providers. For self-installation on a VPS, use the following commands:

Download the archive:
Thank you. I will try.

Are you sure this file is the same file?

What amazes me is how on the first time you got a red flag and you still uploaded the file into your server...
I'm quite sure it is the same file.
I didn't scan it at the first, but after get hacked.
And then I scaned the nulled theme and got a red flag by microsoft.
Days later I just wanna check if any other engines would flag it. So re-scaned it. And found no security vendors flagged.

Try others like metadefender, hybrid-analysis and post here the results.
But I have deleted the file from my computer.
I just clicked the "Reanalyze file" button on the top right of VT to have a 2nd, 3rd try.
 
But I have deleted the file from my computer.
I just clicked the "Reanalyze file" button on the top right of VT to have a 2nd, 3rd try.

I once encountered the same problem, but I don't know what is that.

First, I got a plugin from here, VT scan told me that file has 1 bad thing, but I chose scan it again in Virustotal website, amazingly then it is clean.

Later, I think maybe 1st time the Virustotal gave false positive since some engines of it is not good at detect things, its common issues, then 2nd time maybe they whitelisted the false positive thing. No idea if this is possible or not, but seems your situation is different.

I installed that plugin, in fact, its WPRocket shared by popular member, and I think it is good, till now, bad thing didn't happen (at least I didn't notice).

BTW, please learn how to use "quote" function, don't reply one by one.
 
Microsoft didn't reported a timeout. It worked well but no backdoor be detected on 2nd, 3rd... try.
Gotcha.

The url of the scan result stays the same, but it always points to the latest scan. When i made my post and checked the url, the MS engine reported a timeout on that specific result. Apparently the scan was re-done 2 hours ago, your link points to that now and the result shows no timeout for MS indeed, yet no detection.
 
screenshot-www.virustotal.com-2021.10.13-18_02_20.png

Don't Zip a Zip file always extract the file into single folder and scan one by one
 
Back
Top