Quantcast
Channel: Topic Tag: malware | WordPress.org
Viewing all articles
Browse latest Browse all 1906

If you could help with interpreting results of Internal Scan thanks

$
0
0

HI

I’m new to your plugin. It seems to work well, it’s just hard to interpret some of them, without firstly having a heart attack thinking there are major issues.

I have some results that I’m not understanding if you could help please?

Is this just staandard errorlogs that it is picking up the txt in case issue?

What is heur.alienfile.gen ?

FILE: wp-admin/error_log
FILE_MD5: 2c83d10a00b6251bcba2427d205559ef
SEVERITY: enSuspiciousThreatType
ENGINE: fscanner
THREAT_SIG: adb26923219a37e0507bd5f7371eac9e
THREAT_NAME: Heur.AlienFile.gen
THREAT: Unknown file in core directory…
DETAILS: Detected unknown file in core directory FILE: wp-admin/includes/error_log
FILE_MD5: ee4071191807adc872b75470059ff1f1
SEVERITY: enSuspiciousThreatType
ENGINE: fscanner
THREAT_SIG: ee4071191807adc872b75470059ff1f1
THREAT_NAME: Heur.AlienFile.gen
THREAT: Unknown file in core directory…
DETAILS: Detected unknown file in core directory FILE: wp-includes/ID3/error_log
FILE_MD5: 3c9be92865a237304b75638b72321e4d
SEVERITY: enSuspiciousThreatType
ENGINE: fscanner
THREAT_SIG: 3c9be92865a237304b75638b72321e4d
THREAT_NAME: Heur.AlienFile.gen
THREAT: Unknown file in core directory…
DETAILS: Detected unknown file in core directory

ALSO this one does that mean its a trojan there? How do I know whether that is actual trojan and not a false positive?

If you could advise would be greatly appreciated.

FILE: wp-content/plugins/woocommerce-pdf-invoices-packing-slips/vendor/phenx/php-font-lib/index.php
FILE_MD5: 2a997265330410f8b508fe71d402a144
SEVERITY: enMaliciousThreatType
ENGINE: fscanner
THREAT_SIG: 2a997265330410f8b508fe71d402a144
THREAT_NAME: Trojan.PHP.Redir.gen.30
THREAT: …
DETAILS: Detected malicious PHP redirection

And this one? Could that just be standard modifed core file rather than suspicious?

FILE: wp-content/languages/plugins/akismet-en_AU.mo
FILE_MD5: f88cc2a8b988d413f360aed9d207b525
SEVERITY: enSuspiciousThreatType
ENGINE: fscanner
THREAT_SIG: 11f97411e4f78fdd53029a4d6da1a821
THREAT_NAME: Heur.CoreFile.gen
THREAT: Modified core file…
DETAILS: Detected modified core file

Thanks in advance


Viewing all articles
Browse latest Browse all 1906

Trending Articles