Multiple Infections/Re-infections
-
Our server, with many WP sites, plus a few servers external to us that we know of, with WP sites, have been hit very hard this week: garbage files, flat HTML files, edited plugin/core files, stealthy changed files (timestamp doesn’t change)…and, in one case external to us, a completely erased installation. We stomp them out and they re-infect by morning.
Wordfence is running on those sites and is somewhat effective, but not always unfortunately. Plus, some of the files turn up as “not part of a core or plugin”, but, in fact, are part of the core or plugin (they’ve had garbage appended to them). So those can’t just be deleted off-hand, but need to be manually checked (the WF viewer fails on some types).
Some of the common plugins/themes among the 4 sites on our server that have been hit so far:
Genesis Templating Engine
Wordpress SEO (Yoast SEO)
Simple Lightbox
NextGen Gallery
Genesis Extender
Gravity Forms
Wordfence (one premium install among a bunch of free ones)Just putting this out in case others see a pattern and knows something. I’ve yet to find the source, but our datacenter says it looks like the infection may have started back in August and only triggered this week. It appears the main purpose is to allow the relay of spam. All I know is that I’ve been working 3 days non-stop stomping these things.
- The topic ‘Multiple Infections/Re-infections’ is closed to new replies.