• Hi. A couple different sites of mine are being flagged w/ random code being inserted into a theme file, but when I go to download the actual theme file and review it / remove the potential code, it’s not showing in the php file. See below. Is this malicious, a false positive, or nothing to be concerned about? Thanks!

    Filename: wp-content/themes/EXAMPLESITE/page-comingsoon.php

    File Type: Not a core, theme, or plugin file from www.ads-software.com.

    Details: This file appears to be installed or modified by a hacker to perform malicious activity. If you know about this file you can choose to ignore it to exclude it from future scans. The matched text in this file is: <?php\x0a/*\x0aTemplate Name: Coming Soon\x0a*/\x0a?>\x0a\x0a<?php\x0a/**\x0a * The template for displaying the header\x0a *\x0a * Displays all of the head element and everything up until the “site-content” div.\x0a *\x0a * @package Wor…

    The issue type is: IOC:PHP/modifiedHeader.7496
    Description: Extra PHP tags at the beginning of a Twenty* theme header file, often an indicator of compromise

Viewing 3 replies - 1 through 3 (of 3 total)
Viewing 3 replies - 1 through 3 (of 3 total)
  • The topic ‘Random “x0a *\x0a *” code being flagged’ is closed to new replies.