Hi, the email is below. I’m using the free version of Wordfence 5.3.8 (I let my subscription lapse a couple months ago and am waiting for my department to approve a renewal).
I ended up querying through all the database tables one at a time as suggested but a more detailed message including the name/url of the sub-site or post would be appreciated in the future if possible.
Thanks — E
This email was sent from your website [network site name] by the Wordfence plugin.
Wordfence found the following new issues on [network site name].
Alert generated at Tuesday 24th of March 2015 at 04:46:26 AM
Critical Problems:
* Comment with author Amir wright contains a suspected malware URL.
[image of suspect URL]
NOTE: You are using the free version of Wordfence. Upgrading to the paid version of Wordfence gives you two factor authentication (sign-in via cellphone) and country blocking which are both effective methods to block attacks. A Premium Wordfence license also includes remote scanning with each scan of your site which can detect several additional website infections. Premium members can also schedule when website scans occur and can scan more than once per day.
As a Premium member you also get access to our priority support system located at https://support.wordfence.com/ and can file priority support tickets using our ticketing system.
Click here to sign-up for the Premium version of Wordfence now.
https://www.wordfence.com/wordfence-signup/