I installed a new wordpress and used a nulled theme which downloaded from weaplay.
Hours later I found my sever CPU and RAM were full 100%, all the time. (there are 8 CPUs and 32G RAM of my server)
After VirusTotal scanned the theme, there was a coinminer backdoor detected by Microsoft.
However, today I reanalyzed the zip theme, the same file. I am shocked to find that "No security vendors flagged this file as malicious".
Backdoor was gone.
https://www.virustotal.com/gui/file/f8ab5252d8ccf9be9b7c4766a2c4119bba408e5ba1320d5293a770d8e04e1676
The same file but different result.
I'm confused.
I'm quite sure there must be backdoors for the theme. But why VT dosen't deted it now??
Hours later I found my sever CPU and RAM were full 100%, all the time. (there are 8 CPUs and 32G RAM of my server)
After VirusTotal scanned the theme, there was a coinminer backdoor detected by Microsoft.
However, today I reanalyzed the zip theme, the same file. I am shocked to find that "No security vendors flagged this file as malicious".
Backdoor was gone.
https://www.virustotal.com/gui/file/f8ab5252d8ccf9be9b7c4766a2c4119bba408e5ba1320d5293a770d8e04e1676
The same file but different result.
I'm confused.
I'm quite sure there must be backdoors for the theme. But why VT dosen't deted it now??