News:

SMF 2.1.4 has been released! Take it for a spin! Read more.

Main Menu

Malicious cache/data file

Started by skb, February 07, 2017, 06:30:44 AM

Previous topic - Next topic

skb

I recently gor an email from my host that they blocked Port port 80, 443, 587 and 465 for my site as they found a malicious file on my site. The file under reference was named data_(then some text & numbers)SMF-modsettings.php. I was told that a "quarantine" folder had been created and the said file was there for me to check. C-Panel did not show any such folder. I did a full home directory scan and nothing fishy was found. Finally I was able to unblock the ports. My questions;

(1) What are these data_ files in the cache ?
(2) No mods have been un/installed recently, what could be the source of the malware ?
(3) Preventive measures, if any ? 

SMF 2.1.4 / TP 2.2.2

Illori

the data_ files are the cache files for the SMF file cache.

Dzonny

You should ask your host to provide you a full path to that file that they said is malicious, so you can see it. We can't tell much without more details though, it may be that this is just a false-positive as well.

Do you have any other software running on your host? Which SMF version are you running?

Kindred

Слaва
Украинi

Please do not PM, IM or Email me with support questions.  You will get better and faster responses in the support boards.  Thank you.

"Loki is not evil, although he is certainly not a force for good. Loki is... complicated."

Advertisement: