malicious activity?
-
Hi,
I’m getting this warining from my WordFence Security plugin
Filename: wp-content/uploads/tCapsule/backups/sirthoma_wpsite-backup.sql.7a8bb95205c47141a8b6ef7c43856c1d5fb42daf-wptc-secret
‘This file appears to be installed by a hacker to perform malicious activity. If you know about this file you can choose to ignore it to exclude it from future scans. The text we found in this file that matches a known malicious file is: “eval\”;a:2:{i:0;s:5:\”EAPLq\”;i:1;s:35:\”/[^a-z\\/\’\”]eval\\([^\\)]+[\’\”\\s\\);]+/i\”;}s:9:\”auth_pass\”;a:2:{i:0;s:5:\”CCIGG\”;i:1;s:24:\”/\\$auth_pass[ =\\t]+.+;/i\”;}s:21:\”document.write iframe\…”. The infection type is: Suspicious eval with base64 decode.’
When I try to delete I get An error occurredAn invalid file was requested for deletion.’
Wordfence said
‘I am not sure what was in that file but since it is gone I think we will have to assume you are safe. Time Capsule creates those files and then it deletes them. Perhaps they are temporary files that Time Capsule only needs for a short period of time. If you are concerned you could contact the authors of the Time Capsule plugin and show them the warning and ask them if they have an idea about what could have been in the file. Unfortunately it’s hard for me to say since I don’t know what all the Time Capsule stores. ‘Thoughts/Actions?
Thanks
The topic ‘malicious activity?’ is closed to new replies.