Strange maybe infected files Joomla

Discussion regarding Joomla! 5.x security issues.

Moderators: mandville, General Support Moderators

Forum rules
Forum Rules
Absolute Beginner's Guide to Joomla! <-- please read before posting, this means YOU.
Forum Post Assistant / FPA - If you are serious about wanting help, you will use this tool to help you post.
Windows Defender SmartScreen Issues <-- please read this if using Windows 10.
Post Reply
komir
Joomla! Enthusiast
Joomla! Enthusiast
Posts: 186
Joined: Sat Jul 03, 2010 1:52 pm

Strange maybe infected files Joomla

Post by komir » Mon Feb 05, 2024 9:32 pm

Hi, today in the root of my page, I got a lot of folders named strange, like "kdgsh" or " aadest" ...
Inside all of them is an index.php file
I sent those files to Virustotal, but nothing was found.
I downloaded them and posted them here, if someone can look to see what that is.
!!!I DON'T KNOW IF THEY ARE POSSIBLY INFECTED, SO WORK WITH CAUTION!!!
For additional security, files are locked with a password.
joomla
The page is working normally; there are no problems. I searched them with online tools, but nothing was found
Last edited by toivo on Mon Feb 05, 2024 10:00 pm, edited 1 time in total.
Reason: mod note: removed attachment - please observe the forum rule: "Do not post any malicious code, scripts, exploits or URLs to the forum, including hacks, cracks and phishing."

User avatar
toivo
Joomla! Master
Joomla! Master
Posts: 17501
Joined: Thu Feb 15, 2007 5:48 am
Location: Sydney, Australia

Re: Strange maybe infected files Joomla

Post by toivo » Mon Feb 05, 2024 10:13 pm

If something or someone has tampered with the website, possibly starting with the web server, the website has been hacked. The best plan of attack is to do a full software audit using an online service, for example Phil Taylor's mySites.guru, where the first audit is free. Phil also fixes hacked sites for a fixed fee.
Toivo Talikka, Global Moderator

komir
Joomla! Enthusiast
Joomla! Enthusiast
Posts: 186
Joined: Sat Jul 03, 2010 1:52 pm

Re: Strange maybe infected files Joomla

Post by komir » Mon Feb 05, 2024 10:29 pm

Here are contents of two php files

Code: Select all

 redacted 

Code: Select all

 redacted 
Last edited by toivo on Mon Feb 05, 2024 10:57 pm, edited 1 time in total.
Reason: mod note: code removed

User avatar
toivo
Joomla! Master
Joomla! Master
Posts: 17501
Joined: Thu Feb 15, 2007 5:48 am
Location: Sydney, Australia

Re: Strange maybe infected files Joomla

Post by toivo » Mon Feb 05, 2024 11:03 pm

Please post the results from the Forum Post Assistant (FPA) by following the instructions at https://forumpostassistant.github.io/docs/ so that our volunteer Joomla experts can review the configuration.

Do you have a full backup of the website from the time before the website was compromised, including the filesystem and the database schema?

Please note that attaching malicious code to forum topics is agains the forum rules:
Do not post any malicious code, scripts, exploits or URLs to the forum, including hacks, cracks and phishing.
Toivo Talikka, Global Moderator

helpwithjoomla
Joomla! Enthusiast
Joomla! Enthusiast
Posts: 156
Joined: Sat Sep 21, 2019 7:29 pm
Contact:

Re: Strange maybe infected files Joomla

Post by helpwithjoomla » Fri Feb 09, 2024 10:01 pm

I've seen this before. Oddly named directories or files are likely signs of hacking. You may want to engage a company like Sucuri to review and clean your site.
Joomla Developers Available To Help With Joomla!
https://www.helpwithjoomla.com


Post Reply

Return to “Security in Joomla! 5.x”