wflogs being flagged by server as a suspicious process
-
Hi,
I want to make sure nothing malicious is going on on my server.. basically, I am getting email alerts from my web host stating that a Suspicious process is running under a cpanel account I have a wordpress site running wordfence on.
The files being referenced are in a subfolder wflogs (wordfence).
Any help most appreciated!
The email I have received details the following:
—————————————————————————————Executable:
/usr/bin/php
Command Line (often faked in exploits):
/usr/bin/php
Network connections by the process (if any):
tcp: XXXXXXXX -> XXXXXXXXX
Files open by the process (if any):
/usr/local/apache/logs/error_log
/usr/local/apache/logs/error_log
/var/cpanel/locale/en.cdb.79762 (deleted)
/tmp/.ZendSem.B9xDks (deleted)
/tmp/ZCUDymDx2n (deleted)
/dev/urandom
/home/cpanelaccountname/public_html/websitelocation/wp-content/wflogs/ips.php
/home/cpanelaccountname/public_html/websitelocation/wp-content/wflogs/config.tmp.HoVh4M (deleted)
/home/cpanelaccountname/public_html/websitelocation/wp-content/wflogs/attack-data.php
- The topic ‘wflogs being flagged by server as a suspicious process’ is closed to new replies.