The remediation store held 281 legit files misclassified as malware: - 251 EOL-only: live docroot CRLF vs baseline LF (old deploy artifact); strip-trailing-cr diff = 0 (byte-identical modulo line endings). - 30 com_users (archlinexp.eu): Joomla 2018->2019 point-release drift (copyright + Referrer-Policy header), 0 malware markers. The 729 droppers + real injections (event/joomla/storage/helix3) remain. Audit: audit/store-cleanup-2026-07-19.md. Fully revertable. Assisted-by: claude-code@claude-opus-4-8 |
||
|---|---|---|
| _module_disable/www.archline.hu | ||
| audit | ||
| logs | ||
| var/www/hosting | ||
| .gitattributes | ||
| AGENTS.md | ||
| last-dry-run.log | ||
| README.md | ||
Quarantine git-store — WARNING: LIVE BUT INERT MALWARE SAMPLES
This repository is the git-backed quarantine store of the malware remediator. It follows a git-backed granular remediation and recovery model: each quarantine commit corresponds to a single malware family and is individually revertable.
The contents are LIVE but INERT malware samples. Do NOT execute or open the files in any runnable or interpretable environment (browser, PHP/Python interpreter, shell). Storage serves evidence and recovery purposes only.
Selective restore of a single quarantine commit: git revert <sha>.
Access is restricted to the authorized operator group — this repository is NOT public.