# Malware / planted IOC set — www.archline.hu Authoritative source: `cadline/infra` incidens-doksi (#17), §7/13/14/16 (human-tracked). These items are **excluded from the baseline** so the HIDS baseline-diff flags them on the live server. Machine-readable path list: [`malware-iocs.paths`](malware-iocs.paths). ## Trojanized core — restored to clean vanilla (NOT patched) The 3 injected core files are provided **clean** by the official Joomla 3.8.11 package in `core/`; the live (malware) versions are simply not used: | File | Injection | |---|---| | `plugins/authentication/joomla/joomla.php` | credential-stealer, C2 `leitungs-shop.de`, exfil on every login (§16.3) | | `libraries/joomla/session/storage.php` | session-init loader for the dropped backdoor | | `libraries/joomla/event/event.php` | framework-level output injector | ## Dropped core backdoors — excluded (not in vanilla) | File | Nature | |---|---| | `libraries/joomla/session/cache.php` | obfuscated eVaL backdoor (dropped) | | `administrator/components/com_joomlaupdate/never.php` | cookie-gated RCE (2026-07-10) | ## Root webshells — excluded - `wp-stomp.php` — SEO-cloaking injector - `hyjhxp.php` — WSO webshell ## Attacker modules (entire dir) — excluded - `modules/mod_seolite` — chain root (base64+LZW+eval) - `modules/mod_articles_single` — webshell (the monolith wrongly kept it; §14.2) ## Dropped webshells inside legit dirs — only the dropped file excluded - `modules/mod_al_upload/b8.php` (legit module base kept) - `modules/mod_course_list/a1.php` (legit module base kept) - `templates/trada/html/mod_articles_category/meant.php` (legit 2015 template kept) - `templates/category/tiny.php` (Tiny File Manager backdoor) ## Template infection / SEO spam - `templates/shaper_helix3/index.php` — fbwjedi cloaking block → the clean template index.php is used (the infected live one is excluded and replaced). - `templates/system/links.db` — Sape SEO link-spam (23KB serialized). ## Planted components (entire dir) — excluded - `com_extplorer` (planted CVE-carrying file manager, 2024-07-15) - `com_joml_incf`, `com_sys_rom` (webshells) ## Scan artifacts (not real files) — excluded - `*.php.json`, `*.phtml.json`, `h3x_*`, `_h3x_*` (web-hids inventory outputs) ## Non-malware note (hygiene, not excluded) - `components/com_users/controllers/registration.php` carries a hardcoded reCAPTCHA secret (Cadline's own leaked secret) — the file stays (real source); the secret is to be rotated on cleanup. Not quoted here (redaction).