Malware records all detections of malicious code identified by the security system during the analysis of your web hosting.Each row represents a specific detection performed on a file. In other words, each record indicates that the system has found a file that matches a malware detection rule or a known pattern of malicious behavior.
Unlike other collections related to web activity, here it does not record accesses, visits, or HTTP requests, but security events related to potentially compromised files.
This collection is especially useful when you want to answer questions like:
Although it includes technical information, it can also be useful for non-specialized users, since it allows you to easily locate which files require review.
For example, this collection allows you to:
Detect compromised files: It allows you to identify the files in which the system has found malicious code or behaviors considered dangerous.
Locate the malware: Each detection indicates the full path of the affected file, making it easy to quickly locate where the problem is within the hosting.
Identify the type of threat: Each detection is associated with a malware rule or signature that indicates what behavior or threat family has been recognized. This helps to understand if it is, for example, a webshell, hidden code for fraudulent SEO positioning, or another type of malware.
Analyze when a threat appeared: Thanks to the detection date, it is possible to review when the incidents began to appear and detect if there is a recurrence over time.
Check if an infection remains active: If the same file or the same rule appears repeatedly over several days, it may indicate that the threat has not been completely removed or that the site remains compromised.
Not all detections necessarily mean that the file has been executed or that the site has suffered a successful attack. What they indicate is that the system has found content that matches a known malware signature and that it should be reviewed.
Data type: categorical text
Indicates the action recorded during the security analysis. This field allows you to distinguish the type of event recorded. You will be able to see if it was cleaned or detected.
Data type: categorical text
Indicates the name of the file where the malware was detected. It is one of the first fields usually consulted to quickly identify which file is affected.
Example usage:
Data type: categorical text
Contains the full path of the file where the malware was detected. This field allows you to exactly locate the file within the hosting.
Example usage:
Data type: categorical text
Indicates the process or type of operation that generated the event.
Data type: categorical text
Indicates the security rule or signature that allowed the malware to be identified. Each rule represents a specific type of threat or a known pattern of malicious behavior.
For example, names related to the following may appear:
Example usage:
if multiple detections use the same rule, they are probably related to the same infection or the same malware family.
Data type: date and time
Indicates the exact date and time when the detection was recorded. It allows you to know when a threat appeared and analyze its evolution over time.
Example usage: