• Hello,

    Since July 19, Wordfence has been sending me notifications about successful administrator logins by users with usernames similar to:

    wpsvc_e7c633876ebf

    The notifications come from different IP addresses and different hosts.

    However:

    • this user does not exist in the WordPress Users list,
    • the user does not exist in the database,
    • Wordfence Full Scan does not report modified files or signs of malware,
    • there are no visible signs that the website has been compromised.

    Could you please tell me whether this could be related to ManageWP Worker or any remote connection/service used by ManageWP?

    Or is this something that should be considered suspicious?

    Thank you for your help.

Viewing 1 replies (of 1 total)
  • Plugin Support wfpeter

    (@wfpeter)

    Hi @sapphiredesign, sorry to see that and thanks for reaching out about it!

    Based on what you’ve described, this activity does not appear to be related to ManageWP. Remote management services log in using your existing admin account, not a separate generated username like this.

    I am certainly swaying towards the access being suspicious. It’s worth checking with your hosting provider if it’s a username format they recognise for legitimate server-side WordPress maintenance, or another plugin.

    If you’ve exhausted the possibility that they’re genuine, our site cleaning instructions may be useful to check that your site is up-to-date and ensure it’s no longer compromized:
    https://www.wordfence.com/docs/how-to-clean-a-hacked-wordpress-site-using-wordfence/

    Many thanks,
    Peter.

Viewing 1 replies (of 1 total)

You must be logged in to reply to this topic.