• Resolved K1nsey6

    (@k1nsey6)


    I have the most recent free version of Nelio Content plugin installed, which I love, but I’m now getting a message from my host about plugins/nelio-content/admin/css/setup.min.css being a malicious file. Which results in getting multiple outbound ports blocked. I want to keep using Nelio but I can’t have blocked ports.

    I had seen other posts about prior similar issues with other files and thought maybe this one slipped through the cracks in getting a fix.

Viewing 7 replies - 1 through 7 (of 7 total)
  • Plugin Author David Aguilera

    (@davilera)

    Hi! Thanks for reporting this issue. I’ve been looking at the file and I don’t see anything wrong in it… can you please tell me what tool is reporting it as a malicious file?

    Thread Starter K1nsey6

    (@k1nsey6)

    It has been reported from my host.

    This is the content of the email.

    ‘Dear Customer,

    As provider of Shared Hosting services, we monitor the usage of all our customers to ensure that our Quality of Service is not adversely affected. Our goal is to ensure that one customer should not affect all the other customers on the same server.

    As part of our routine monitoring, we have observed that some of the files hosted on this server belonging to shopartifakts.com hosted under your account, has some malicious files hosted. In order to prevent blacklisting of our service with various service providers, we have blocked outbound port 80, 443, 587 and 465 for this domain name as a precautionary measure. Here are the details of the files that were detected to be malicious.

    /home/shopao4j/public_html/K1nsey6.com/wp-content/plugins/nelio-content/admin/css/setup.min.css

    We strongly suggest you to scan all the above listed files for any vulnerabilities. If the files are part of some plugins of your CMS, then we suggest you to update the plugin to the latest version or contact the plugin developer directly.

    Steps to un-block port 80, 443, 587 and 465

    Login to cPanel

    In the find section, search for “Port 80”.

    Under “Health Checks and Monitoring” tab, click on Port 80 icon and follow instructions on the screen.

    If you have any queries, please feel free to contact our Support team.

    Regards, The Whois.com Hosting Team

    Disclaimer: This is an auto-generated email sent by our monitoring system. Please contact our Support HelpDesk for further information.’

    When I log into my cPanel I find those ports have been blocked and when I uninstall the plugin nothing else gets reported.

    Thread Starter K1nsey6

    (@k1nsey6)

    Apparently Sitelock is flagging the file as malicious

    Plugin Author David Aguilera

    (@davilera)

    Thanks for the feedback. I’ve contacted Sitelock via Twitter; let’s see if they can shed some light.

    Plugin Author David Aguilera

    (@davilera)

    Hi there!

    I’ve been talking to Sitelock via Twitter and they tell me you should contact them directly. Can you please do so and let me know what they tell you?

    Regards,
    David

    Plugin Author David Aguilera

    (@davilera)

    We removed the script that triggered the warning in the last version of the plugin (1.4.5) and moved the rules in a different script. We think that the warning might have occurred simply because of the script’s name (we contacted sitelock, but they didn’t help us at all).

    Thread Starter K1nsey6

    (@k1nsey6)

    Sitelock never responded to me either, however this latest update is no longer flagging as malicious

Viewing 7 replies - 1 through 7 (of 7 total)
  • The topic ‘Malicious files detected’ is closed to new replies.