# moves a file or directory to quarantine preserving the path relative to $olsVhostsPath function malwareQuarantineMove() { local src="$1" local dst="$malwareQuarantinePath/${appDate}_$appTime/$(dirname -- "${src#"$olsVhostsPath/"}")" mkdir -p -- "$dst" || return 1 mv -- "$src" "$dst/" || return 1 } # copies a file to quarantine preserving the path relative to $olsVhostsPath (for partial cleanup) function malwareQuarantineCopy() { local src="$1" local dst="$malwareQuarantinePath/${appDate}_$appTime/$(dirname -- "${src#"$olsVhostsPath/"}")" mkdir -p -- "$dst" || return 1 cp -p -- "$src" "$dst/" || return 1 } function malwareUserList() { local output error databaseList if ! run output error mariadbDatabaseListGet; then printDanger "$error" return 1 fi mapfile -t databaseList < <(awk 'NF' <<< "$output") (( ${#databaseList[@]} > 0 )) || return local inList inList=$(printf "'%s'," "${databaseList[@]}") inList="${inList%,}" local sql sql=$(cat << 'EOF' SET SESSION group_concat_max_len = 1000000; SELECT GROUP_CONCAT(CONCAT( "SELECT CONVERT('", t.table_schema, "' USING utf8mb4) COLLATE utf8mb4_unicode_ci AS db_name,", " ID,", " CONVERT(user_login USING utf8mb4) COLLATE utf8mb4_unicode_ci AS user_login,", " user_registered,", " CONVERT('", t.table_name, "' USING utf8mb4) COLLATE utf8mb4_unicode_ci AS table_name", " FROM `", t.table_schema, "`.`", t.table_name, "`", " WHERE user_login LIKE 'adm\\_%' OR user_login LIKE 'admin\\_%' OR user_login LIKE 'administrator\\_%' OR user_login LIKE 'backup\\_%'" ) SEPARATOR ' UNION ALL ') INTO @sql FROM information_schema.tables t WHERE t.table_schema IN (__IN_LIST__) AND EXISTS (SELECT 1 FROM information_schema.columns c WHERE c.table_schema=t.table_schema AND c.table_name=t.table_name AND c.column_name='user_login') AND EXISTS (SELECT 1 FROM information_schema.columns c WHERE c.table_schema=t.table_schema AND c.table_name=t.table_name AND c.column_name='ID') AND EXISTS (SELECT 1 FROM information_schema.columns c WHERE c.table_schema=t.table_schema AND c.table_name=t.table_name AND c.column_name='user_registered'); PREPARE stmt FROM @sql; EXECUTE stmt; DEALLOCATE PREPARE stmt; EOF ) sql="${sql/__IN_LIST__/$inList}" mariadbMasterRootQuery "$sql" } function malwareOptionsList() { local output error databaseList if ! run output error mariadbDatabaseListGet; then printDanger "$error" return 1 fi mapfile -t databaseList < <(awk 'NF' <<< "$output") (( ${#databaseList[@]} > 0 )) || return local inList inList=$(printf "'%s'," "${databaseList[@]}") inList="${inList%,}" local sql sql=$(cat << 'EOF' SET SESSION group_concat_max_len = 1000000; SELECT GROUP_CONCAT(CONCAT( "SELECT CONVERT('", t.table_schema, "' USING utf8mb4) COLLATE utf8mb4_unicode_ci AS db_name,", " CONVERT('", t.table_name, "' USING utf8mb4) COLLATE utf8mb4_unicode_ci AS table_name,", " option_id,", " CONVERT(option_name USING utf8mb4) COLLATE utf8mb4_unicode_ci AS option_name", " FROM `", t.table_schema, "`.`", t.table_name, "`", " WHERE option_name LIKE 'sc\\_%'", " OR option_value LIKE 'H4sIAAAAAAA%'" ) SEPARATOR ' UNION ALL ') INTO @sql FROM information_schema.tables t WHERE t.table_schema IN (__IN_LIST__) AND EXISTS (SELECT 1 FROM information_schema.columns c WHERE c.table_schema=t.table_schema AND c.table_name=t.table_name AND c.column_name='option_id') AND EXISTS (SELECT 1 FROM information_schema.columns c WHERE c.table_schema=t.table_schema AND c.table_name=t.table_name AND c.column_name='option_name') AND EXISTS (SELECT 1 FROM information_schema.columns c WHERE c.table_schema=t.table_schema AND c.table_name=t.table_name AND c.column_name='option_value'); PREPARE stmt FROM @sql; EXECUTE stmt; DEALLOCATE PREPARE stmt; EOF ) sql="${sql/__IN_LIST__/$inList}" mariadbMasterRootQuery "$sql" | sort -t$'\t' -k1,1 -k2,2 -k4,4 } function malwareCronList() { local output error databaseList if ! run output error mariadbDatabaseListGet; then printDanger "$error" return 1 fi mapfile -t databaseList < <(awk 'NF' <<< "$output") (( ${#databaseList[@]} > 0 )) || return local inList inList=$(printf "'%s'," "${databaseList[@]}") inList="${inList%,}" local sql sql=$(cat << 'EOF' SET SESSION group_concat_max_len = 1000000; SELECT GROUP_CONCAT(CONCAT( "SELECT CONVERT('", t.table_schema, "' USING utf8mb4) COLLATE utf8mb4_unicode_ci AS db_name,", " CONVERT('", t.table_name, "' USING utf8mb4) COLLATE utf8mb4_unicode_ci AS table_name,", " option_id,", " CONVERT(option_name USING utf8mb4) COLLATE utf8mb4_unicode_ci AS option_name", " FROM `", t.table_schema, "`.`", t.table_name, "`", " WHERE option_name = 'cron'", " AND option_value LIKE '%\"sc_cron_fetch\"%'" ) SEPARATOR ' UNION ALL ') INTO @sql FROM information_schema.tables t WHERE t.table_schema IN (__IN_LIST__) AND EXISTS (SELECT 1 FROM information_schema.columns c WHERE c.table_schema=t.table_schema AND c.table_name=t.table_name AND c.column_name='option_id') AND EXISTS (SELECT 1 FROM information_schema.columns c WHERE c.table_schema=t.table_schema AND c.table_name=t.table_name AND c.column_name='option_name') AND EXISTS (SELECT 1 FROM information_schema.columns c WHERE c.table_schema=t.table_schema AND c.table_name=t.table_name AND c.column_name='option_value'); PREPARE stmt FROM @sql; EXECUTE stmt; DEALLOCATE PREPARE stmt; EOF ) sql="${sql/__IN_LIST__/$inList}" mariadbMasterRootQuery "$sql" | sort -t$'\t' -k1,1 -k2,2 }