• Resolved whitstable58

    (@whitstable58)


    Hi,
    I’m getting this warining from my WordFence Security plugin
    Filename: wp-content/uploads/tCapsule/backups/sirthoma_wpsite-backup.sql.7a8bb95205c47141a8b6ef7c43856c1d5fb42daf-wptc-secret
    ‘This file appears to be installed by a hacker to perform malicious activity. If you know about this file you can choose to ignore it to exclude it from future scans. The text we found in this file that matches a known malicious file is: “eval\”;a:2:{i:0;s:5:\”EAPLq\”;i:1;s:35:\”/[^a-z\\/\’\”]eval\\([^\\)]+[\’\”\\s\\);]+/i\”;}s:9:\”auth_pass\”;a:2:{i:0;s:5:\”CCIGG\”;i:1;s:24:\”/\\$auth_pass[ =\\t]+.+;/i\”;}s:21:\”document.write iframe\…”. The infection type is: Suspicious eval with base64 decode.’
    When I try to delete I get An error occurred

    An invalid file was requested for deletion.’

    Wordfence said
    ‘I am not sure what was in that file but since it is gone I think we will have to assume you are safe. Time Capsule creates those files and then it deletes them. Perhaps they are temporary files that Time Capsule only needs for a short period of time. If you are concerned you could contact the authors of the Time Capsule plugin and show them the warning and ask them if they have an idea about what could have been in the file. Unfortunately it’s hard for me to say since I don’t know what all the Time Capsule stores. ‘

    Thoughts/Actions?
    Thanks

Viewing 1 replies (of 1 total)
  • Plugin Author WPTimeCapsule

    (@wptimecapsule)

    Hi Colin,

    I’ve replied to your ticket earlier last month. Just thought of addressing the same for future readers as well 🙂
    We create those temporary files during backup in order to backup your database and once the backup is completed, we delete those files.
    While running the backup, we write all the contents of your database on to a file and then they are backed up. Now when WordFence scanned this file, it could have found “Suspicious eval with base64 decode.”
    Please check your database contents as there could be something suspicious. We do not create any new permanent files, we only create temporary files so there shouldn’t be anything to worry about WPTC.

    Regards,
    Tauseef

    • This reply was modified 9 years, 5 months ago by WPTimeCapsule.
Viewing 1 replies (of 1 total)

The topic ‘malicious activity?’ is closed to new replies.