Wordfence erkennt potentielle Malware!

  • Hallo Leute!


    Der letzte Wordfence-Scan berichtet mir folgende Warnungen:

    [h=2]File appears to be malicious: wp-admin/includes/network.php[/h]
    [TABLE="class: wfIssue"]

    [tr]


    [TH]Filename:[/TH]

    [td]

    wp-admin/includes/network.php

    [/td][/tr][tr]


    [TH]File type:[/TH]

    [td]

    Not a core, theme or plugin file.

    [/td][/tr][tr]


    [TH]Issue first detected:[/TH]

    [td]

    16 mins ago.

    [/td][/tr][tr]


    [TH]Severity:[/TH]

    [td]

    Critical

    [/td][/tr][tr]


    [TH]Status[/TH]

    [td]

    New

    [/td][/tr]


    [/TABLE]
    This file appears to be installed by a hacker to perform malicious activity. If you know about this file you can choose to ignore it to exclude it from future scans. The text we found in this file that matches a known malicious file is: "\x65\x76\x61\x6C\x28".


    [h=2]File appears to be malicious: wp-admin/network/system.php[/h]
    [TABLE="class: wfIssue"]

    [tr]


    [TH]Filename:[/TH]

    [td]

    wp-admin/network/system.php

    [/td][/tr][tr]


    [TH]File type:[/TH]

    [td]

    Not a core, theme or plugin file.

    [/td][/tr][tr]


    [TH]Issue first detected:[/TH]

    [td]

    16 mins ago.

    [/td][/tr][tr]


    [TH]Severity:[/TH]

    [td]

    Critical

    [/td][/tr][tr]


    [TH]Status[/TH]

    [td]

    New

    [/td][/tr]


    [/TABLE]
    This file appears to be installed by a hacker to perform malicious activity. If you know about this file you can choose to ignore it to exclude it from future scans. The text we found in this file that matches a known malicious file is: "\x65\x76\x61\x6C\x28".



    [h=2]File appears to be malicious: wp-admin/sapatani.php[/h]
    [TABLE="class: wfIssue"]

    [tr]


    [TH]Filename:[/TH]

    [td]

    wp-admin/sapatani.php

    [/td][/tr][tr]


    [TH]File type:[/TH]

    [td]

    Not a core, theme or plugin file.

    [/td][/tr][tr]


    [TH]Issue first detected:[/TH]

    [td]

    16 mins ago.

    [/td][/tr][tr]


    [TH]Severity:[/TH]

    [td]

    Critical

    [/td][/tr][tr]


    [TH]Status[/TH]

    [td]

    New

    [/td][/tr]


    [/TABLE]
    This file appears to be installed by a hacker to perform malicious activity. If you know about this file you can choose to ignore it to exclude it from future scans. The text we found in this file that matches a known malicious file is: "\x65\x76\x61\x6C\x28".



    [h=2]This file may contain malicious executable code: /data/web/e40673/html/apps/wordpress-16948/wpinstall - Copy.php[/h]
    [TABLE="class: wfIssue"]

    [tr]


    [TH]Filename:[/TH]

    [td]

    wpinstall - Copy.php

    [/td][/tr][tr]


    [TH]File type:[/TH]

    [td]

    Not a core, theme or plugin file.

    [/td][/tr][tr]


    [TH]Issue first detected:[/TH]

    [td]

    16 mins ago.

    [/td][/tr][tr]


    [TH]Severity:[/TH]

    [td]

    Critical

    [/td][/tr][tr]


    [TH]Status[/TH]

    [td]

    New

    [/td][/tr]


    [/TABLE]
    This file is a PHP executable file and contains an eval() function and base64() decoding function on the same line. This is a common technique used by hackers to hide and execute code. If you know about this file you can choose to ignore it to exclude it from future scans.



    [h=2]WordPress core file modified: wp-includes/version.php[/h]
    [TABLE="class: wfIssue"]

    [tr]


    [TH]Filename:[/TH]

    [td]

    wp-includes/version.php

    [/td][/tr][tr]


    [TH]File type:[/TH]

    [td]

    Core

    [/td][/tr][tr]


    [TH]Issue first detected:[/TH]

    [td]

    17 mins ago.

    [/td][/tr][tr]


    [TH]Severity:[/TH]

    [td]

    Critical

    [/td][/tr][tr]


    [TH]Status[/TH]

    [td]

    New

    [/td][/tr]


    [/TABLE]
    This WordPress core file has been modified and differs from the original file distributed with this version of WordPress.


    [h=2]WordPress core file modified: wp-config-sample.php[/h]
    [TABLE="class: wfIssue"]

    [tr]


    [TH]Filename:[/TH]

    [td]

    wp-config-sample.php

    [/td][/tr][tr]


    [TH]File type:[/TH]

    [td]

    Core

    [/td][/tr][tr]


    [TH]Issue first detected:[/TH]

    [td]

    18 mins ago.

    [/td][/tr][tr]


    [TH]Severity:[/TH]

    [td]

    Critical

    [/td][/tr][tr]


    [TH]Status[/TH]

    [td]

    New

    [/td][/tr]


    [/TABLE]
    This WordPress core file has been modified and differs from the original file distributed with this version of WordPress.



    [h=2]WordPress core file modified: index.php[/h]
    [TABLE="class: wfIssue"]

    [tr]


    [TH]Filename:[/TH]

    [td]

    index.php

    [/td][/tr][tr]


    [TH]File type:[/TH]

    [td]

    Core

    [/td][/tr][tr]


    [TH]Issue first detected:[/TH]

    [td]

    18 mins ago.

    [/td][/tr][tr]


    [TH]Severity:[/TH]

    [td]

    Critical

    [/td][/tr][tr]


    [TH]Status[/TH]

    [td]

    New

    [/td][/tr]


    [/TABLE]
    This WordPress core file has been modified and differs from the original file distributed with this version of WordPress.


    Ich nehme an, dass die letzten drei eher wurscht sind, ich denke, das liegt wohl an den Firewall- und Hardening-Einstellungen, die ich bisher vorgenommen habe. Die ersten vier bereiten mir mehr Sorgen...
    Was ist eure Meinung dazu?

    Danke, LG

    • Anzeige

    Hallo!

    Wenn du gerade an deiner Website arbeitest oder dein aktuelles Hosting überdenkst: Wir betreiben mit NetzLiving eine Hosting-Plattform, die speziell auf Performance, Sicherheit und einfache Verwaltung ausgelegt ist.

    • ✔️ Schnelle Ladezeiten (optimiert für WordPress & Co.)
    • ✔️ Deutsche Server & DSGVO-konform
    • ✔️ Persönlicher Support (kein 0815-Ticket-System)

    Mehr erfahren

  • Die ersten vier bereiten mir mehr Sorgen...

    Mir auch, vor allem weil ja ein Hardening durchgeführt wurde.

    WordPress ist "frei" wie in Freiheit es zu nutzen, aber nicht im Sinne von Freibier. Wer also glaubt man bekommt rund um WordPress alles kostenlos, der irrt. Hilfe ist ein Geschenk für das man sich bedankt, dafür gibt es den 'Gefällt mir' Button. Wer das nicht kann und sich selbst nicht zu helfen weiss, muss sich bezahlte Unterstützung suchen.

Jetzt mitmachen!

Sie haben noch kein Benutzerkonto auf unserer Seite? Registrieren Sie sich kostenlos und nehmen Sie an unserer Community teil!