• Resolved Barbarianmonkey

    (@barbarianmonkey)


    Hey,

    The Wordfence config files in my installation seem to get infected far often and that too by the same malware by the looks of it. It appends a massive amount of garbled text (base64 encoded or something) onto the config files for Wordfence. This happens every few days. I’ve attached a screenshot of a file that’s currently infected.

    View post on imgur.com

    If needed, you can find the entire text body as a comment on the imgur link provided.

    The config files have the following permissions and are owned by www-data:
    attack-data.php – 660
    config-livewaf.php – 660
    config-synced.php – 660
    config-transient.php – 660
    config.php – 660
    GeoLite2-Country.mmdb – 755
    ips.php – 660
    rules.php – 664

    The infection can happen to any of these files that are owned by www-data. All the rest of my files are owned by ubuntu. Those owned by Ubuntu don’t get infected.

Viewing 1 replies (of 1 total)
  • Plugin Support wfphil

    (@wfphil)

    Hi @barbarianmonkey

    You can delete the wflogs directory containing the firewall configuration files and it will be automatically regenerated on any page load.

    Then you will have to run through the Learning Mode process again though.

    You will also have to run through our site cleaning guide.

    Thanks.

    • This reply was modified 5 years, 2 months ago by wfphil.
Viewing 1 replies (of 1 total)
  • The topic ‘Wordfence files getting infected frequently’ is closed to new replies.