Hacked and defaced site - 18 days ago - detected Trojan.Generic.1389340 (B)

See: http://killmalware.com/opticamonsalves.cl/#
Re: https://www.virustotal.com/nl/url/ea2c92188d1bbc8cbf7cf6d3b725e2764696c6dec1d88229cdd7a3f1d5b0626d/analysis/1424548598/
Web application version:
WordPress version: WordPress
Wordpress version from source: 3.8.5
Wordpress Version 3.8.0 based on: htxp://www.opticamonsalves.cl//wp-admin/js/common.js
WordPress directory: htxp://www.opticamonsalves.cl/wp-content
WordPress theme: htxp://www.opticamonsalves.cl/wp-content/themes/AutoInsurance/
WordPress version outdated: Upgrade required.
Outdated WordPress Found: WordPress Under 4.0
Does avast detect as Win32:Trojan-gen ? → http://www.zone-h.org/mirror/id/23408256
http://www.zone-h.org/archive/notifier=Team%20System%20Dz
3 potentiall suspicious files: http://quttera.com/detailed_report/opticamonsalves.cl
Severity: Potentially Suspicious
Reason: Detected PDF file containing potentially suspicious instructions
Details: Detected hidden CSS declaration → https://www.uploady.com/download/vI7iCqVFxaL/~cdMyNEsz4cW9QPC

polonus

The malicious uri as such: http://linkeddata.informatik.hu-berlin.de/uridbg/index.php?url=http%3A%2F%2Fwww.opticamonsalves.cl%2Fwp-content%2Fplugins%2Fphoto-gallery%2Fjs%2Fjquery.fullscreen-0.4.1.js%3Fver%3D0.4.1&useragentheader=&acceptheader=
Security Header status: https://www.uploady.com/download/yxE_3pabPNO/s5hVL0aAKm~G4SFQ
On warning: Instructs the browser to interpret the page as a specific content type rather than relying on the browser to make assumptions.

See google issues: http://www.dnsinspect.com/github.com/1424549656

polonus (volunteer website security analyst and website error-hunter)