I'm looking for suspicious files as our site appears to have been compromised recently. I have found a file buried in a wp-contents > upload folder called wpcima.php. When I google this file name I find other examples, and loading the file displays a password prompt.
Is this a normal file?