skip to Main Content

Visbot Malware is being reported from the Magento Security Scan tool on my Magento 2 store. This is malware that looks to have infected Magento 1 stores from 2016. For some reason it is being reported on my clean Magneto 2 server. The file referenced below does not exist. Has anyone else seen this?

One or more ‘Visbot’ malware checks failed.
media/tmp/design/file/default_luma_logo.jpg

Our hosting company Nexcess malware scanner did not pick anything up. Ecomscan didn’t either. Neither did sitelock server scan.

enter image description here

2

Answers


  1. I saw this error during my weekly scan on March 28, 2021.

    One or more ‘Visbot’ malware checks failed.
    media/tmp/design/file/default_luma_logo.jpg

    The file doesn’t exist. I rescanned my site and the error no longer shows up. I’m thinking it’s most likely a false positive / issue with Magento’s scanning script.

    By the way, I just moved off of Nexcess and onto Cloudways (Linode data center). Much more bang for your buck. Nexcess service and support (for Magento) is not as good since it merged with Liquid Web.

    Login or Signup to reply.
  2. I had same issue with Magento 2.4.2-p1.
    I asked Magento and they confirmed it is a false positive.
    Here is their answer :

    Hi,

    I’ve been updated that this is a false positive. Currently, the HTTP
    200 response with a non-empty response body to

    {/pub}/media/tmp/design/file/default_luma_logo.jpg will trigger the
    alert…

    The standard Magento behavior prior to 2.4.2 is to return HTTP 404
    response, the 2.4.2 returns the image placeholder. As far as we see,
    for any image request under ‘/media/tmp/’ this store returns an image
    placeholder if the file is not available. Please restrict the access
    to ‘{/pub}media/tmp/design/file/default_luma_logo.jpg’ at the
    webserver level.

    Thank You,

    Login or Signup to reply.
Please signup or login to give your own answer.
Back To Top
Search