Anonymousfox hack
-
Hi,
My website was hacked some weeks ago. After some cleaning and security measures it has been pretty calm; no more admin users created nor email accounts in Cpanel. But I wonder how can I be sure?In the Live Traffic tab in Wordfence I noticed that some coinciding attempts to login were coming from the Netherlands. And I noticed that one of the blocked attempts was this one:
https://delasciencealassiette.fr/ubpxwlwy.php?Fox=d3wL7Can anyone explain why a .php file different from the usuals “.aws/credentials” or “info.php” or “config.js” attempts?
Can you help me to know what I can do to be assured that there are no infected files that the scan might be missing?
EDIT: I also found all these visitor entries in clicky analytics:
10:28 Brazil flag 187.72.192.0 /ubpxwlwy.php 10:28 The United States flag 72.240.108.0 /ubpxwlwy.php?Fox=d3wL7 10:28 Poland flag 91.150.166.0 /ubpxwlwy.php?Fox=d3wL7 10:28 The United States flag 208.53.243.0 /ubpxwlwy.php?Fox=d3wL7 10:28 The United States flag 205.213.108.0 /ubpxwlwy.php
Grateful
RodThe page I need help with: [log in to see the link]
- The topic ‘Anonymousfox hack’ is closed to new replies.