This Scampage was using a A PHP library for detecting the browser but the lib file named BrowserDetection.php has been modified that has a base64 coded api (url hosting is suspended currently after our reporting) . Now first this api got hit and send server and other infos and also got a reponse from the api and it execute that response on the server so this malicious response can be used to take over server.