• Resolved pietvgijssel

    (@pietvgijssel)


    I wanted to report this issues, but the form didnot work. So here it is:

    We got the message from Cloudways that 3 of our applications are infected. The cause looks te same.

    /uploads/2025/02/spbct_1739452688/admin.php

    The comment of Cloudways when I asked if this is a false positive warning:

    I reviewed the reported files on the affected applications. Although the files are located under the spbct_* directory, which is commonly used by the CleanTalk Security plugin for temporary files, the contents of these admin.php files do not match the behavior expected from a legitimate CleanTalk component.
     
    The same file is present across all affected applications with an identical hash, and its functionality includes actions such as:
    Loading the WordPress environment.
    Accepting commands through HTTP request parameters.
    Logging in as an administrator without normal authentication.
    Downloading content from remote URLs and writing it to the server.
    Copying itself into various WordPress directories.
     
    These capabilities are commonly associated with a PHP backdoor rather than a legitimate security plugin file.
    Based on our verification, we do not believe this is a false positive. We recommend treating these files as malicious. As a precaution, we advise removing or quarantining the detected files, verifying the integrity of the CleanTalk plugin by reinstalling it from the official source if needed, and performing a full malware scan of the application. Additionally, we recommend reviewing administrator accounts and rotating application credentials after cleanup.

    The page I need help with: [log in to see the link]

Viewing 2 replies - 1 through 2 (of 2 total)
Viewing 2 replies - 1 through 2 (of 2 total)

You must be logged in to reply to this topic.