{"id":2067,"date":"2024-05-27T15:55:21","date_gmt":"2024-05-27T07:55:21","guid":{"rendered":"https:\/\/zaf.web.id\/blog\/?p=2067"},"modified":"2024-09-18T10:37:38","modified_gmt":"2024-09-18T02:37:38","slug":"berburu-malware-di-server-linux","status":"publish","type":"post","link":"https:\/\/zaf.web.id\/blog\/berburu-malware-di-server-linux\/","title":{"rendered":"Berburu Malware di Server Linux"},"content":{"rendered":"<p>Beberapa tahun terakhir sangat banyak website yang tiba-tiba didalamnya terdapat laman dengan kata kunci slot, judi, gacor, dan seterusnya. Ini umumnya diakibatkan kurangnya perhatian terhadap pengelolaan website. Seringnya menggunakan plugin atau template dari sumber yang tidak terpercaya membuat malware bisa dengan mudah memperbanyak diri.<\/p>\n<p>Beberapa bulan terakhir cukup aktif untuk membersihkan website yang terkena malware tersebut. Saya coba share beberapa command yang sering saya gunakan dan sekiranya dapat membantu dalam mencari dampak maupun induk dari malware yang ada pada website dalam sebuah server linux.<\/p>\n<h2>Mencari kata kunci yang berkaitan dengan slot atau judi<\/h2>\n<p>Untuk mencari dampak malwarenya, memberikan kita lokasi dimana malware mempublish halaman slot judi yang mereka gunakan untuk claim di google search console<\/p>\n<p><code>grep -rnw . \\<br \/>\n-e 'game online' \\<br \/>\n-e 'slot' \\<br \/>\n-e 'gacor' \\<br \/>\n-e 'judi online' \\<br \/>\n-e 'product key' \\<br \/>\n-e 'casino' \\<br \/>\n-e 'taruhan' \\<br \/>\n-e 'poker' \\<br \/>\n-e 'betting' \\<br \/>\n-e 'sbobet' \\<br \/>\n-e 'togel' \\<br \/>\n-e 'jackpot' \\<br \/>\n-e 'agen bola' \\<br \/>\n-e 'bandar' \\<br \/>\n-e 'slot online' \\<br \/>\n-e 'kasino' \\<br \/>\n-e 'rolet' \\<br \/>\n-e 'dadu' \\<br \/>\n-e 'sportsbook' \\<br \/>\n-e 'live casino' \\<br \/>\n-e 'slot machine' \\<br \/>\n-e 'baccarat' \\<br \/>\n-e 'sic bo' \\<br \/>\n-e 'blackjack' \\<br \/>\n-e 'gambling' \\<br \/>\n-e 'online betting' \\<br \/>\n-e 'sports betting' \\<br \/>\n-e 'live poker' \\<br \/>\n-e 'online poker' \\<br \/>\n-e 'bet' \\<br \/>\n-e 'odds' \\<br \/>\n-e 'vip casino' \\<br \/>\n-e 'poker online' \\<br \/>\n-e 'judi bola' \\<br \/>\n-e 'taruhan bola' \\<br \/>\n-e 'bandar bola' \\<br \/>\n-e 'dominoqq' \\<br \/>\n-e 'qq online' \\<br \/>\n-e 'poker qq' \\<br \/>\n-e 'bandarq' \\<br \/>\n-e 'bandarqq' \\<br \/>\n-e 'tembak ikan' \\<br \/>\n-e 'lottery' \\<br \/>\n-e 'judi dadu' \\<br \/>\n-e 'keno' \\<br \/>\n-e 'game betting' \\<br \/>\n-e 'esports betting' \\<br \/>\n-e 'online slots' \\<br \/>\n-e 'casino games' \\<br \/>\n-e 'taruhan online' \\<br \/>\n-e 'deposit pulsa' \\<br \/>\n-e 'bonus deposit' \\<br \/>\n-e 'free spin' \\<br \/>\n-e 'welcome bonus' \\<br \/>\n-e 'high roller' \\<br \/>\n-e 'kenzototo' \\<br \/>\n-e 'presidenslot' \\<br \/>\n-e 'davo88' \\<br \/>\n-e 'neko4d' \\<br \/>\n-e 'madetoto' \\<br \/>\n-e 'sbctoto' \\<br \/>\n-e 'psgslot' \\<br \/>\n-e 'pahlawan4d' \\<br \/>\n-e 'wangi4d' \\<br \/>\n-e 'raden4d' \\<br \/>\n-e 'cerdas4d' \\<br \/>\n-e 'mentos4d' \\<br \/>\n-e 'wawasan4d' \\<br \/>\n-e 'eurotogel' \\<br \/>\n-e 'bri4d' \\<br \/>\n-e 'bni4d' \\<br \/>\n-e 'palu4d' \\<br \/>\n-e 'ungutoto' \\<br \/>\n-e 'oyo4d' \\<br \/>\n-e 'nasa4d' \\<br \/>\n-e 'klix4d' \\<br \/>\n-e 'ahha4d' \\<br \/>\n-e 'deluna4d' \\<br \/>\n-e 'key4d' \\<br \/>\n-e 'target4d' \\<br \/>\n-e 'gelora4d' \\<br \/>\n-e 'cnnslot' \\<br \/>\n-e 'neng4d' \\<br \/>\n-e 'bimabet' \\<br \/>\n-e 'slotbesar' \\<br \/>\n-e 'prada4d' \\<br \/>\n-e 'mudah4d' \\<br \/>\n-e 'sawer4d' \\<br \/>\n-e 'bmw4d' \\<br \/>\n-e 'tante4d' \\<br \/>\n-e 'ayah4d' \\<br \/>\n-e 'erigo4d' \\<br \/>\n-e 'janda4d' \\<br \/>\n-e 'OLO4D' \\<br \/>\n-e 'cici4d' \\<br \/>\n-e 'sihoki' \\<br \/>\n-e 'RHINO88' \\<br \/>\n-e 'win88' \\<br \/>\n-e 'babawin' \\<br \/>\n-e 'ice3bet' \\<br \/>\n-e 'mpo08' \\<br \/>\n-e 'catur777' \\<br \/>\n-e 'ronaldo4d' \\<br \/>\n-e 'dewaslot99' \\<br \/>\n-e 'MPO2QQ' | awk -F: '{print $1\":\"$2}'<\/code><\/p>\n<h2>Mencari string &#8220;eval&#8221;, &#8220;chr&#8221;, dan &#8220;goto&#8221; dalam script<\/h2>\n<p>Induk malware umumnya di-obfuscate agar tidak mudah ketahuan, dan syntax yang paling sering digunakan adalah &#8220;eval&#8221;, &#8220;chr&#8221;, dan &#8220;goto&#8221;.<\/p>\n<p><code>grep -rnw . -e 'eval(' --include=&#42;.php --include=&#42;.phtml<br \/>\ngrep -rnw . -e 'chr' --include=&#42;.php --include=&#42;.phtml<br \/>\ngrep -rnw . -e 'goto ' --include=&#42;.php --include=&#42;.phtml<\/code><\/p>\n<h2>Mencari string &#8220;@include&#8221; dalam script<\/h2>\n<p>Script yang terinfeksi oleh malware biasanya di-include di bagian tertentu dalam script, baik di paling atas, tengah, maupun dibawah.<\/p>\n<p><code>grep -rnw . -e '@include \"' --include=\\*.php --include=\\*.phtml<\/code><\/p>\n<h2>Perluas pencarian menggunakan Yara rules<\/h2>\n<p><a href=\"https:\/\/github.com\/VirusTotal\/yara\">Yara<\/a> memiliki banyak rules yang sudah dibuat oleh berbagai praktisi, scanning bisa menggunakan rules malware dari repo ini <a href=\"https:\/\/github.com\/23Pstars\/yara-rules\">https:\/\/github.com\/23Pstars\/yara-rules<\/a><\/p>\n<p><code>yara -s -r \/path\/to\/yara-rules\/malware_index.yar . &gt; results.txt 2&gt;\/dev\/null<\/code><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Beberapa tahun terakhir sangat banyak website yang tiba-tiba didalamnya terdapat laman dengan kata kunci slot,&hellip;<\/p>\n","protected":false},"author":1,"featured_media":2083,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_crdt_document":"","_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[272,58],"tags":[314,315,313,140,312],"class_list":["post-2067","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","category-server","tag-bersihkan-malware","tag-bersihkan-slot-wordpress","tag-judi","tag-malware","tag-slot"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Berburu Malware di Server Linux - Ahmad Zafrullah<\/title>\n<meta name=\"description\" content=\"Mencari malware serta dampak dan infeksinya pada website yang berbasis WordPress, OJS, atau CMS lainnya didalam server Linux.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/zaf.web.id\/blog\/berburu-malware-di-server-linux\/\" \/>\n<meta property=\"og:locale\" content=\"id_ID\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Berburu Malware di Server Linux - Ahmad Zafrullah\" \/>\n<meta property=\"og:description\" content=\"Mencari malware serta dampak dan infeksinya pada website yang berbasis WordPress, OJS, atau CMS lainnya didalam server Linux.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/zaf.web.id\/blog\/berburu-malware-di-server-linux\/\" \/>\n<meta property=\"og:site_name\" content=\"Ahmad Zafrullah\" \/>\n<meta property=\"article:publisher\" content=\"http:\/\/www.facebook.com\/23Pstars\" \/>\n<meta property=\"article:author\" content=\"http:\/\/www.facebook.com\/23Pstars\" \/>\n<meta property=\"article:published_time\" content=\"2024-05-27T07:55:21+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-09-18T02:37:38+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/zaf.web.id\/blog\/wp-content\/uploads\/2024\/05\/Screenshot-2024-09-05-at-23.45.21.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1366\" \/>\n\t<meta property=\"og:image:height\" content=\"948\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Zaf\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@23Pstars\" \/>\n<meta name=\"twitter:site\" content=\"@23Pstars\" \/>\n<meta name=\"twitter:label1\" content=\"Ditulis oleh\" \/>\n\t<meta name=\"twitter:data1\" content=\"Zaf\" \/>\n\t<meta name=\"twitter:label2\" content=\"Estimasi waktu membaca\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 menit\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/zaf.web.id\\\/blog\\\/berburu-malware-di-server-linux\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zaf.web.id\\\/blog\\\/berburu-malware-di-server-linux\\\/\"},\"author\":{\"name\":\"Zaf\",\"@id\":\"https:\\\/\\\/zaf.web.id\\\/blog\\\/#\\\/schema\\\/person\\\/ba4e955d59a1e6a8284857e74b14e5ed\"},\"headline\":\"Berburu Malware di Server Linux\",\"datePublished\":\"2024-05-27T07:55:21+00:00\",\"dateModified\":\"2024-09-18T02:37:38+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/zaf.web.id\\\/blog\\\/berburu-malware-di-server-linux\\\/\"},\"wordCount\":200,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/zaf.web.id\\\/blog\\\/#\\\/schema\\\/person\\\/ba4e955d59a1e6a8284857e74b14e5ed\"},\"image\":{\"@id\":\"https:\\\/\\\/zaf.web.id\\\/blog\\\/berburu-malware-di-server-linux\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/i0.wp.com\\\/zaf.web.id\\\/blog\\\/wp-content\\\/uploads\\\/2024\\\/05\\\/Screenshot-2024-09-05-at-23.45.21.png?fit=1366%2C948&ssl=1\",\"keywords\":[\"bersihkan malware\",\"bersihkan slot wordpress\",\"judi\",\"malware\",\"slot\"],\"articleSection\":[\"Security\",\"Server\"],\"inLanguage\":\"id\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/zaf.web.id\\\/blog\\\/berburu-malware-di-server-linux\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/zaf.web.id\\\/blog\\\/berburu-malware-di-server-linux\\\/\",\"url\":\"https:\\\/\\\/zaf.web.id\\\/blog\\\/berburu-malware-di-server-linux\\\/\",\"name\":\"Berburu Malware di Server Linux - Ahmad Zafrullah\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zaf.web.id\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/zaf.web.id\\\/blog\\\/berburu-malware-di-server-linux\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/zaf.web.id\\\/blog\\\/berburu-malware-di-server-linux\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/i0.wp.com\\\/zaf.web.id\\\/blog\\\/wp-content\\\/uploads\\\/2024\\\/05\\\/Screenshot-2024-09-05-at-23.45.21.png?fit=1366%2C948&ssl=1\",\"datePublished\":\"2024-05-27T07:55:21+00:00\",\"dateModified\":\"2024-09-18T02:37:38+00:00\",\"description\":\"Mencari malware serta dampak dan infeksinya pada website yang berbasis WordPress, OJS, atau CMS lainnya didalam server Linux.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/zaf.web.id\\\/blog\\\/berburu-malware-di-server-linux\\\/#breadcrumb\"},\"inLanguage\":\"id\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/zaf.web.id\\\/blog\\\/berburu-malware-di-server-linux\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"id\",\"@id\":\"https:\\\/\\\/zaf.web.id\\\/blog\\\/berburu-malware-di-server-linux\\\/#primaryimage\",\"url\":\"https:\\\/\\\/i0.wp.com\\\/zaf.web.id\\\/blog\\\/wp-content\\\/uploads\\\/2024\\\/05\\\/Screenshot-2024-09-05-at-23.45.21.png?fit=1366%2C948&ssl=1\",\"contentUrl\":\"https:\\\/\\\/i0.wp.com\\\/zaf.web.id\\\/blog\\\/wp-content\\\/uploads\\\/2024\\\/05\\\/Screenshot-2024-09-05-at-23.45.21.png?fit=1366%2C948&ssl=1\",\"width\":1366,\"height\":948},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/zaf.web.id\\\/blog\\\/berburu-malware-di-server-linux\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/zaf.web.id\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Berburu Malware di Server Linux\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/zaf.web.id\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/zaf.web.id\\\/blog\\\/\",\"name\":\"Ahmad Zafrullah\",\"description\":\"Work to Learn is better than Learn how to Work\",\"publisher\":{\"@id\":\"https:\\\/\\\/zaf.web.id\\\/blog\\\/#\\\/schema\\\/person\\\/ba4e955d59a1e6a8284857e74b14e5ed\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/zaf.web.id\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"id\"},{\"@type\":[\"Person\",\"Organization\"],\"@id\":\"https:\\\/\\\/zaf.web.id\\\/blog\\\/#\\\/schema\\\/person\\\/ba4e955d59a1e6a8284857e74b14e5ed\",\"name\":\"Zaf\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"id\",\"@id\":\"https:\\\/\\\/i0.wp.com\\\/zaf.web.id\\\/blog\\\/wp-content\\\/uploads\\\/2024\\\/09\\\/zaf_auto_x2.jpeg?fit=300%2C300&ssl=1\",\"url\":\"https:\\\/\\\/i0.wp.com\\\/zaf.web.id\\\/blog\\\/wp-content\\\/uploads\\\/2024\\\/09\\\/zaf_auto_x2.jpeg?fit=300%2C300&ssl=1\",\"contentUrl\":\"https:\\\/\\\/i0.wp.com\\\/zaf.web.id\\\/blog\\\/wp-content\\\/uploads\\\/2024\\\/09\\\/zaf_auto_x2.jpeg?fit=300%2C300&ssl=1\",\"width\":300,\"height\":300,\"caption\":\"Zaf\"},\"logo\":{\"@id\":\"https:\\\/\\\/i0.wp.com\\\/zaf.web.id\\\/blog\\\/wp-content\\\/uploads\\\/2024\\\/09\\\/zaf_auto_x2.jpeg?fit=300%2C300&ssl=1\"},\"sameAs\":[\"http:\\\/\\\/zaf.web.id\",\"http:\\\/\\\/www.facebook.com\\\/23Pstars\",\"https:\\\/\\\/x.com\\\/23Pstars\"],\"url\":\"https:\\\/\\\/zaf.web.id\\\/blog\\\/author\\\/zaf\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Berburu Malware di Server Linux - Ahmad Zafrullah","description":"Mencari malware serta dampak dan infeksinya pada website yang berbasis WordPress, OJS, atau CMS lainnya didalam server Linux.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/zaf.web.id\/blog\/berburu-malware-di-server-linux\/","og_locale":"id_ID","og_type":"article","og_title":"Berburu Malware di Server Linux - Ahmad Zafrullah","og_description":"Mencari malware serta dampak dan infeksinya pada website yang berbasis WordPress, OJS, atau CMS lainnya didalam server Linux.","og_url":"https:\/\/zaf.web.id\/blog\/berburu-malware-di-server-linux\/","og_site_name":"Ahmad Zafrullah","article_publisher":"http:\/\/www.facebook.com\/23Pstars","article_author":"http:\/\/www.facebook.com\/23Pstars","article_published_time":"2024-05-27T07:55:21+00:00","article_modified_time":"2024-09-18T02:37:38+00:00","og_image":[{"width":1366,"height":948,"url":"https:\/\/zaf.web.id\/blog\/wp-content\/uploads\/2024\/05\/Screenshot-2024-09-05-at-23.45.21.png","type":"image\/png"}],"author":"Zaf","twitter_card":"summary_large_image","twitter_creator":"@23Pstars","twitter_site":"@23Pstars","twitter_misc":{"Ditulis oleh":"Zaf","Estimasi waktu membaca":"2 menit"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/zaf.web.id\/blog\/berburu-malware-di-server-linux\/#article","isPartOf":{"@id":"https:\/\/zaf.web.id\/blog\/berburu-malware-di-server-linux\/"},"author":{"name":"Zaf","@id":"https:\/\/zaf.web.id\/blog\/#\/schema\/person\/ba4e955d59a1e6a8284857e74b14e5ed"},"headline":"Berburu Malware di Server Linux","datePublished":"2024-05-27T07:55:21+00:00","dateModified":"2024-09-18T02:37:38+00:00","mainEntityOfPage":{"@id":"https:\/\/zaf.web.id\/blog\/berburu-malware-di-server-linux\/"},"wordCount":200,"commentCount":0,"publisher":{"@id":"https:\/\/zaf.web.id\/blog\/#\/schema\/person\/ba4e955d59a1e6a8284857e74b14e5ed"},"image":{"@id":"https:\/\/zaf.web.id\/blog\/berburu-malware-di-server-linux\/#primaryimage"},"thumbnailUrl":"https:\/\/i0.wp.com\/zaf.web.id\/blog\/wp-content\/uploads\/2024\/05\/Screenshot-2024-09-05-at-23.45.21.png?fit=1366%2C948&ssl=1","keywords":["bersihkan malware","bersihkan slot wordpress","judi","malware","slot"],"articleSection":["Security","Server"],"inLanguage":"id","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/zaf.web.id\/blog\/berburu-malware-di-server-linux\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/zaf.web.id\/blog\/berburu-malware-di-server-linux\/","url":"https:\/\/zaf.web.id\/blog\/berburu-malware-di-server-linux\/","name":"Berburu Malware di Server Linux - Ahmad Zafrullah","isPartOf":{"@id":"https:\/\/zaf.web.id\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/zaf.web.id\/blog\/berburu-malware-di-server-linux\/#primaryimage"},"image":{"@id":"https:\/\/zaf.web.id\/blog\/berburu-malware-di-server-linux\/#primaryimage"},"thumbnailUrl":"https:\/\/i0.wp.com\/zaf.web.id\/blog\/wp-content\/uploads\/2024\/05\/Screenshot-2024-09-05-at-23.45.21.png?fit=1366%2C948&ssl=1","datePublished":"2024-05-27T07:55:21+00:00","dateModified":"2024-09-18T02:37:38+00:00","description":"Mencari malware serta dampak dan infeksinya pada website yang berbasis WordPress, OJS, atau CMS lainnya didalam server Linux.","breadcrumb":{"@id":"https:\/\/zaf.web.id\/blog\/berburu-malware-di-server-linux\/#breadcrumb"},"inLanguage":"id","potentialAction":[{"@type":"ReadAction","target":["https:\/\/zaf.web.id\/blog\/berburu-malware-di-server-linux\/"]}]},{"@type":"ImageObject","inLanguage":"id","@id":"https:\/\/zaf.web.id\/blog\/berburu-malware-di-server-linux\/#primaryimage","url":"https:\/\/i0.wp.com\/zaf.web.id\/blog\/wp-content\/uploads\/2024\/05\/Screenshot-2024-09-05-at-23.45.21.png?fit=1366%2C948&ssl=1","contentUrl":"https:\/\/i0.wp.com\/zaf.web.id\/blog\/wp-content\/uploads\/2024\/05\/Screenshot-2024-09-05-at-23.45.21.png?fit=1366%2C948&ssl=1","width":1366,"height":948},{"@type":"BreadcrumbList","@id":"https:\/\/zaf.web.id\/blog\/berburu-malware-di-server-linux\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/zaf.web.id\/blog\/"},{"@type":"ListItem","position":2,"name":"Berburu Malware di Server Linux"}]},{"@type":"WebSite","@id":"https:\/\/zaf.web.id\/blog\/#website","url":"https:\/\/zaf.web.id\/blog\/","name":"Ahmad Zafrullah","description":"Work to Learn is better than Learn how to Work","publisher":{"@id":"https:\/\/zaf.web.id\/blog\/#\/schema\/person\/ba4e955d59a1e6a8284857e74b14e5ed"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/zaf.web.id\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"id"},{"@type":["Person","Organization"],"@id":"https:\/\/zaf.web.id\/blog\/#\/schema\/person\/ba4e955d59a1e6a8284857e74b14e5ed","name":"Zaf","image":{"@type":"ImageObject","inLanguage":"id","@id":"https:\/\/i0.wp.com\/zaf.web.id\/blog\/wp-content\/uploads\/2024\/09\/zaf_auto_x2.jpeg?fit=300%2C300&ssl=1","url":"https:\/\/i0.wp.com\/zaf.web.id\/blog\/wp-content\/uploads\/2024\/09\/zaf_auto_x2.jpeg?fit=300%2C300&ssl=1","contentUrl":"https:\/\/i0.wp.com\/zaf.web.id\/blog\/wp-content\/uploads\/2024\/09\/zaf_auto_x2.jpeg?fit=300%2C300&ssl=1","width":300,"height":300,"caption":"Zaf"},"logo":{"@id":"https:\/\/i0.wp.com\/zaf.web.id\/blog\/wp-content\/uploads\/2024\/09\/zaf_auto_x2.jpeg?fit=300%2C300&ssl=1"},"sameAs":["http:\/\/zaf.web.id","http:\/\/www.facebook.com\/23Pstars","https:\/\/x.com\/23Pstars"],"url":"https:\/\/zaf.web.id\/blog\/author\/zaf\/"}]}},"jetpack_publicize_connections":[],"jetpack_featured_media_url":"https:\/\/i0.wp.com\/zaf.web.id\/blog\/wp-content\/uploads\/2024\/05\/Screenshot-2024-09-05-at-23.45.21.png?fit=1366%2C948&ssl=1","jetpack_sharing_enabled":true,"jetpack-related-posts":[{"id":1954,"url":"https:\/\/zaf.web.id\/blog\/mitigasi-malware-di-web-server-dan-cara-membersihkannya\/","url_meta":{"origin":2067,"position":0},"title":"Mitigasi Malware di Web Server dan Cara Membersihkannya","author":"Zaf","date":"November 23, 2022","format":false,"excerpt":"Malware selalu menjadi hal yang merepotkan. Umumnya pembuat malware tidak membuat malware untuk sekedar ajang pamer layaknya defacement. Malware dibuat demi tujuan yang lebih besar dan masif, dan biasanya tidak berjalan secara sendiri-sendiri melainkan menjadi sebuah network atau perkumpulan. Discovery Disuatu pagi tiba-tiba salah satu website yang kami kelola menunjukkan\u2026","rel":"","context":"dalam &quot;Security&quot;","block_context":{"text":"Security","link":"https:\/\/zaf.web.id\/blog\/category\/security\/"},"img":{"alt_text":"Mencari induk malware","src":"https:\/\/i0.wp.com\/zaf.web.id\/blog\/wp-content\/uploads\/2022\/11\/6.-cari-dan-hapus-file-ico.png?fit=795%2C241&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/zaf.web.id\/blog\/wp-content\/uploads\/2022\/11\/6.-cari-dan-hapus-file-ico.png?fit=795%2C241&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/zaf.web.id\/blog\/wp-content\/uploads\/2022\/11\/6.-cari-dan-hapus-file-ico.png?fit=795%2C241&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/zaf.web.id\/blog\/wp-content\/uploads\/2022\/11\/6.-cari-dan-hapus-file-ico.png?fit=795%2C241&ssl=1&resize=700%2C400 2x"},"classes":[]},{"id":981,"url":"https:\/\/zaf.web.id\/blog\/serangan-adware-via-htaccess\/","url_meta":{"origin":2067,"position":1},"title":"Serangan Adware via .htaccess","author":"Zaf","date":"Desember 17, 2016","format":false,"excerpt":"Bukan pertama kalinya beberapa server kami mendapatkan serangan dengan teknik yang berbagai macam jenis, bentuk, dan dampaknya. Pagi ini\u00a0sempat kaget karena semua website yang ada dalam server Gili Air\u00a0kami diarahkan ke situs iklan ketika diakses dari perangkat mobile. Saat ditelusuri ternyata semua file .htaccess nya telah disusupi semua, untuk mendeteksi\u2026","rel":"","context":"dalam &quot;Server&quot;","block_context":{"text":"Server","link":"https:\/\/zaf.web.id\/blog\/category\/server\/"},"img":{"alt_text":".htaccess malware inject","src":"https:\/\/i0.wp.com\/zaf.web.id\/blog\/wp-content\/uploads\/2016\/12\/Screen-Shot-2016-12-15-at-5.34.42-PM-1024x680.png?resize=350%2C200&ssl=1","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/zaf.web.id\/blog\/wp-content\/uploads\/2016\/12\/Screen-Shot-2016-12-15-at-5.34.42-PM-1024x680.png?resize=350%2C200&ssl=1 1x, https:\/\/i0.wp.com\/zaf.web.id\/blog\/wp-content\/uploads\/2016\/12\/Screen-Shot-2016-12-15-at-5.34.42-PM-1024x680.png?resize=525%2C300&ssl=1 1.5x"},"classes":[]},{"id":484,"url":"https:\/\/zaf.web.id\/blog\/serangan-campaign-malware\/","url_meta":{"origin":2067,"position":2},"title":"Serangan Campaign Malware","author":"Zaf","date":"Desember 18, 2014","format":false,"excerpt":"Hari ini dipenghujung tahun 2014 ini adalah hari paling merepotkan selama mengelola salah satu Cloud milik LRsoft.\u00a0Pasalnya server mendapat kado natal istimewa berupa malware yang menginfeksi 60 lebih website yang\u00a0ada didalamnya, sehingga ketika domain web tersebut diakses via browser akan muncul peringatan block halaman dari layanan Google seperti gambar dibawah:\u2026","rel":"","context":"dalam &quot;Server&quot;","block_context":{"text":"Server","link":"https:\/\/zaf.web.id\/blog\/category\/server\/"},"img":{"alt_text":"Block dari Google","src":"https:\/\/i0.wp.com\/zaf.web.id\/blog\/wp-content\/uploads\/2014\/12\/malware-frommshead.php_.png?resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/zaf.web.id\/blog\/wp-content\/uploads\/2014\/12\/malware-frommshead.php_.png?resize=350%2C200 1x, https:\/\/i0.wp.com\/zaf.web.id\/blog\/wp-content\/uploads\/2014\/12\/malware-frommshead.php_.png?resize=525%2C300 1.5x"},"classes":[]},{"id":1741,"url":"https:\/\/zaf.web.id\/blog\/mengenal-dan-mencegah-ransomware\/","url_meta":{"origin":2067,"position":3},"title":"Mengenal dan Mencegah Ransomware","author":"Zaf","date":"Desember 12, 2019","format":false,"excerpt":"Ransomware merupakan jenis malware yang dapat melakukan enkripsi terhadap berkas dengan skema public-private key. Korban perlu membayar tebusan jika ingin berkasnya dikembalikan seperti semula.","rel":"","context":"dalam &quot;Blog&quot;","block_context":{"text":"Blog","link":"https:\/\/zaf.web.id\/blog\/category\/blog\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/zaf.web.id\/blog\/wp-content\/uploads\/2019\/12\/ransomware.jpg?fit=976%2C549&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/zaf.web.id\/blog\/wp-content\/uploads\/2019\/12\/ransomware.jpg?fit=976%2C549&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/zaf.web.id\/blog\/wp-content\/uploads\/2019\/12\/ransomware.jpg?fit=976%2C549&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/zaf.web.id\/blog\/wp-content\/uploads\/2019\/12\/ransomware.jpg?fit=976%2C549&ssl=1&resize=700%2C400 2x"},"classes":[]},{"id":620,"url":"https:\/\/zaf.web.id\/blog\/email-malware-dengan-macros-di-microsoft-word\/","url_meta":{"origin":2067,"position":4},"title":"Email Malware dengan Macros di Microsoft Word","author":"Zaf","date":"Juli 9, 2015","format":false,"excerpt":"Beberapa hari yang lalu ada email masuk yang berisi permohonan aplikasi Internship di perusahaan kami, sebetulnya biasa saja namun sedikit terkejut karena applier-nya kelihatannya bukan berasal dari Indonesia. Setahun terakhir ini kami memang menerima beberapa mahasiswa untuk program Internship di perusahaan kami, namun yang masuk hanya dari\u00a0program akademik wilayah NTB.\u2026","rel":"","context":"dalam &quot;Coretan&quot;","block_context":{"text":"Coretan","link":"https:\/\/zaf.web.id\/blog\/category\/coretan\/"},"img":{"alt_text":"Email Internship Malware","src":"https:\/\/i0.wp.com\/zaf.web.id\/blog\/wp-content\/uploads\/2015\/07\/Screen-Shot-2015-07-01-at-8.58.50-AM-1024x378.png?resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/zaf.web.id\/blog\/wp-content\/uploads\/2015\/07\/Screen-Shot-2015-07-01-at-8.58.50-AM-1024x378.png?resize=350%2C200 1x, https:\/\/i0.wp.com\/zaf.web.id\/blog\/wp-content\/uploads\/2015\/07\/Screen-Shot-2015-07-01-at-8.58.50-AM-1024x378.png?resize=525%2C300 1.5x"},"classes":[]},{"id":2073,"url":"https:\/\/zaf.web.id\/blog\/perbaikan-web-dengan-mesin-ojs-setelah-migrasi-ke-proxy-cloudflare\/","url_meta":{"origin":2067,"position":5},"title":"Perbaikan Web dengan Mesin OJS Setelah Migrasi ke Proxy Cloudflare","author":"Zaf","date":"Agustus 29, 2024","format":false,"excerpt":"Masalah Dampak yang sering dialami setelah proses migrasi ke proxy cloudflare adalah web menjadi redirect berkali-kali. Sesuaikan Konfigurasi Terdapat beberapa penyesuaian yang perlu dilakukan pada file config.inc.php Atur agar selalu menggunakan https base_url = \"https:\/\/domain.com\" Matikan SSL otomatis force_ssl = Off force_login_ssl = Off Matikan session check IP juga agar\u2026","rel":"","context":"dalam &quot;Security&quot;","block_context":{"text":"Security","link":"https:\/\/zaf.web.id\/blog\/category\/security\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/zaf.web.id\/blog\/wp-content\/uploads\/2024\/08\/ERR_TOO_MANY_REDIRECTS-in-chrome-e1724895816567.png?fit=1200%2C501&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/zaf.web.id\/blog\/wp-content\/uploads\/2024\/08\/ERR_TOO_MANY_REDIRECTS-in-chrome-e1724895816567.png?fit=1200%2C501&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/zaf.web.id\/blog\/wp-content\/uploads\/2024\/08\/ERR_TOO_MANY_REDIRECTS-in-chrome-e1724895816567.png?fit=1200%2C501&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/zaf.web.id\/blog\/wp-content\/uploads\/2024\/08\/ERR_TOO_MANY_REDIRECTS-in-chrome-e1724895816567.png?fit=1200%2C501&ssl=1&resize=700%2C400 2x, https:\/\/i0.wp.com\/zaf.web.id\/blog\/wp-content\/uploads\/2024\/08\/ERR_TOO_MANY_REDIRECTS-in-chrome-e1724895816567.png?fit=1200%2C501&ssl=1&resize=1050%2C600 3x"},"classes":[]}],"jetpack_likes_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p4zLnS-xl","_links":{"self":[{"href":"https:\/\/zaf.web.id\/blog\/wp-json\/wp\/v2\/posts\/2067","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zaf.web.id\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zaf.web.id\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zaf.web.id\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/zaf.web.id\/blog\/wp-json\/wp\/v2\/comments?post=2067"}],"version-history":[{"count":3,"href":"https:\/\/zaf.web.id\/blog\/wp-json\/wp\/v2\/posts\/2067\/revisions"}],"predecessor-version":[{"id":2070,"href":"https:\/\/zaf.web.id\/blog\/wp-json\/wp\/v2\/posts\/2067\/revisions\/2070"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/zaf.web.id\/blog\/wp-json\/wp\/v2\/media\/2083"}],"wp:attachment":[{"href":"https:\/\/zaf.web.id\/blog\/wp-json\/wp\/v2\/media?parent=2067"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zaf.web.id\/blog\/wp-json\/wp\/v2\/categories?post=2067"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zaf.web.id\/blog\/wp-json\/wp\/v2\/tags?post=2067"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}