• I was looking in my RankMath 404 Monitor and there are several items that do not look right from last week.

    Randoms URIs such as:
    up.php
    wp-content/plugins/wpdiscuz/themes/default/style-rtl.css
    wp-content/plugins/fancy-product-designer/inc/custom-image-handler.php
    wp-content/langar.php
    test.php?Ghost=send
    config.php
    There are many more though.

    Referer for most is Anonymousfox.co but I noticed a few from binance.com
    A few were from my site (these are some of them):
    /wp-admin/sitas.php
    /wp-content/plugins/woocommerce-jetpack/includes/js/wcj-cart-customization.js
    //wp-content/plugins/woocommerce-jetpack/includes/js/wcj-bookings.js
    Note: I do not have woocommerce but see two files in phpMyAdmin for WooCommerce

    User-Agent is some variation of
    Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36Chrome 90.0.4430.85

    My site appear fine. I did find a new user I didn’t recognize and deleted. I’ve not received any new log in alerts but not I would if it was for another user.
    I reset my wp-admin password and my database password.

    I’m unsure what else to do. I have limited knowledge and am not sure if I have been hacked or if this is just an attempt.

    Any advice is appreciated!

Viewing 7 replies - 1 through 7 (of 7 total)
  • Take a careful read of this guide. It should help you identify if there is a real issue here, and also provides steps to help rectify it.

    When you’re done, you may want to implement some (if not all) of the recommended security measures and start backing up your site.

    Thread Starter linglis17

    (@linglis17)

    I need to edit the above information regarding WooCommerce. I do not have two folders in myPHPAdmin for WC (they are for Yoast which I had at one point but no longer have).

    I’m unsure what else to do. I have limited knowledge and am not sure if I have been hacked or if this is just an attempt.

    I suggest you to ask your hosting provider to scan your site for any malware.

    `Randoms URIs such as:
    up.php
    wp-content/plugins/wpdiscuz/themes/default/style-rtl.css
    wp-content/plugins/fancy-product-designer/inc/custom-image-handler.php
    wp-content/langar.php
    test.php?Ghost=send
    config.php
    There are many more though.`

    Yeah, that’s a type of attack:

    https://security.stackexchange.com/questions/40291/strange-requests-to-web-server

    Thread Starter linglis17

    (@linglis17)

    Thank you both for the information. I’ve read through both and am not sure I can do everything needed because there is a disconnect between my knowledge and recommendations.

    I updated passwords for my database as well as my wp login.

    I’ve deleted a few plugins that I thought I could do without. I now have eight.

    I have all my services with Netsol. They use Codeguard and the last successful database backup was in May. I’ve been unable to update to the latest WP until I paid for their support services and finally got hold of someone yesterday who took the time to manually update it for me. I guess I can restore a previous version but then I’m back to an outdated WP and have learned their paid support may take weeks for to update again. (Bashing Netsol is not going to help me – it is what it is).

    I ran the Sucuri Sitecheck and show no malware and not blacklisted. There are three security suggestions, one of which is to install WAF – Any benefit to Sucuri vs Wordfence? I have the free version of Wordfence now <obvioiusly not enough.

    The other two suggestions…I’m not sure I know where to begin even after clicking through to instructions mainly because I only know how to access files for Theme Editor and myPHPAdmin. How do I get to everything else? Or am I overlooking?

    Thread Starter linglis17

    (@linglis17)

    I just updated Wordfence to paid.

    Thread Starter linglis17

    (@linglis17)

    Okay so to update, Wordfence shows I’m protected, no problems. 404 monitor still shows attacks. Spent some time on phone with Netsol today and they basically say with the security in place I should be fine. Of course, nothing I can do to stop attacks – after all, they know where I’m at now.

    I guess I’m wondering how to proceed. How do I get my wp-config, etc, etc. Do I download an ftp file client to see if there is code interjected somewhere?

    Of course, nothing I can do to stop attacks – after all, they know where I’m at now.

    You can try blocking the IP addresses that are trying those URLs. I think you have taken good security measures against attacks.

Viewing 7 replies - 1 through 7 (of 7 total)

The topic ‘Have I been hacked?’ is closed to new replies.