Linux premium119.web-hosting.com 4.18.0-553.47.1.lve.el8.x86_64 #1 SMP Tue Apr 8 13:54:31 UTC 2025 x86_64
LiteSpeed
Server IP : 162.0.229.123 & Your IP : 216.73.217.71
Domains :
Cant Read [ /etc/named.conf ]
User : hyperdis
Terminal
Auto Root
Create File
Create Folder
Localroot Suggester
Backdoor Destroyer
Readme
/
home /
hyperdis /
Delete
Unzip
Name
Size
Permission
Date
Action
.app_backup
[ DIR ]
drwxr-xr-x
2025-02-11 15:28
.cagefs
[ DIR ]
drwxrwx--x
2024-02-01 14:51
.caldav
[ DIR ]
drwxr-xr-x
2026-06-17 14:35
.cl.selector
[ DIR ]
drwxr-xr-x
2026-06-17 10:31
.clwpos
[ DIR ]
drwxr-xr-x
2021-11-06 06:34
.cpanel
[ DIR ]
drwx------
2026-06-18 03:50
.cphorde
[ DIR ]
drwxr-xr-x
2024-03-30 19:21
.htpasswds
[ DIR ]
drwxr-x---
2026-06-11 10:28
.nc_plugin
[ DIR ]
drwx--x--x
2024-02-01 14:42
.pki
[ DIR ]
drwxr-xr-x
2019-12-23 13:25
.razor
[ DIR ]
drwxr-xr-x
2023-03-15 12:02
.softaculous
[ DIR ]
drwx--x--x
2024-06-28 23:34
.spamassassin
[ DIR ]
drwxr-xr-x
2021-02-12 17:34
.subaccounts
[ DIR ]
drwxr-xr-x
2020-07-24 00:44
.trash
[ DIR ]
drwxr-xr-x
2026-06-13 00:44
.wp-cli
[ DIR ]
drwxr-xr-x
2020-07-17 19:58
465nafh.com.ng
[ DIR ]
drwxr-x---
2026-06-13 00:37
Enefoze.com
[ DIR ]
drwxr-x---
2026-06-14 04:02
TELSTATECH.COM
[ DIR ]
drwxr-x---
2026-06-13 00:31
abidencare.co.uk
[ DIR ]
drwxr-x---
2026-06-13 00:37
access-logs
[ DIR ]
drwxr-x---
2026-06-17 12:09
acehealth-caresolution.com
[ DIR ]
drwxr-x---
2026-06-13 00:37
alphanursinghome.com.ng
[ DIR ]
drwxr-x---
2026-06-13 00:50
arawares.com.ng
[ DIR ]
drwxr-x---
2026-06-13 00:53
azuahealthcare.ng
[ DIR ]
drwxr-x---
2026-06-13 00:38
beerific.ng
[ DIR ]
drwxr-x---
2026-06-14 04:02
bespoke.ng
[ DIR ]
drwxr-x---
2026-06-14 04:02
bio-carelabs.com
[ DIR ]
drwxr-xr-x
2026-06-13 00:38
cache
[ DIR ]
drwxr-xr-x
2026-06-13 00:37
cssakwaibom.com.ng
[ DIR ]
drwxr-x---
2026-06-13 00:36
dantatafarms.com.ng
[ DIR ]
drwxr-x---
2026-06-14 04:02
divine-diagnosis.com
[ DIR ]
drwxr-x---
2026-06-13 00:39
enhancehealthscotland.com
[ DIR ]
drwxr-x---
2026-06-13 00:36
etc
[ DIR ]
drwxr-x---
2026-06-17 14:35
ezetogs.com.ng
[ DIR ]
drwxr-x---
2026-06-14 04:02
firstchoiceagency.uk
[ DIR ]
drwxr-x---
2026-06-17 14:33
ghpropertiesaffair.com
[ DIR ]
drwxr-x---
2026-06-14 04:02
ghpropertiesaffair.com.ng
[ DIR ]
drwxr-x---
2026-06-14 04:02
graceful-heritagecare.com
[ DIR ]
drwxr-x---
2026-06-13 00:48
helpdesk.hyperdistribution.com.ng
[ DIR ]
drwxr-x---
2026-06-14 04:02
logs
[ DIR ]
drwxr-xr-x
2026-06-17 12:40
lscache
[ DIR ]
drwxrws---
2026-05-20 08:34
mail
[ DIR ]
drwxr-x--x
2026-06-17 14:35
manorhealthcare.org.uk
[ DIR ]
drwxr-x---
2026-06-17 15:40
marketeering.ng
[ DIR ]
drwxr-x---
2026-06-13 00:49
masccarehome.com.ng
[ DIR ]
drwxr-x---
2026-06-13 00:49
pejehealthcare.co.uk
[ DIR ]
drwxr-x---
2026-06-13 00:49
pepper-staffing.co.uk
[ DIR ]
drwxr-x---
2026-06-18 02:26
perl5
[ DIR ]
drwxr-xr-x
2026-05-20 08:34
prestigediagnostica.com
[ DIR ]
drwxr-x---
2026-06-13 00:49
public_ftp
[ DIR ]
drwxr-xr-x
2026-05-20 08:34
public_html
[ DIR ]
drwxr-x---
2026-06-18 01:35
pulchritudebynana.com
[ DIR ]
drwxr-x---
2026-06-14 04:02
reginamundihomes.ng
[ DIR ]
drwxr-x---
2026-06-13 00:35
seven-resourcingnursing.com
[ DIR ]
drwxr-x---
2026-06-18 01:35
softaculous_backups
[ DIR ]
drwx--x--x
2026-06-12 10:51
ssl
[ DIR ]
drwxr-xr-x
2026-06-17 15:42
telewanathan.com
[ DIR ]
drwxr-x---
2026-06-13 00:28
telstatech.com.ng
[ DIR ]
drwxr-x---
2026-06-17 15:29
tmp
[ DIR ]
drwxr-xr-x
2026-06-17 17:05
tohluwany.com
[ DIR ]
drwxr-x---
2026-06-13 00:32
unthlabs.com
[ DIR ]
drwxr-xr-x
2026-06-13 00:32
urbansignaturehomes.com
[ DIR ]
drwxr-x---
2026-06-18 01:35
wellcarehomes.com.ng
[ DIR ]
drwxr-x---
2026-06-13 00:51
www
[ DIR ]
drwxr-x---
2026-06-18 01:35
xactsdiagnosticservices.com.ng
[ DIR ]
drwxr-x---
2026-06-13 00:33
yumenterprise.com
[ DIR ]
drwxr-x---
2026-06-13 00:33
ziccarddsspecialistclinic.com.ng
[ DIR ]
drwxr-x---
2026-06-13 00:52
.bash_history
1.14
KB
-rw-r--r--
2026-06-13 02:30
.bash_logout
18
B
-rw-r--r--
2019-12-23 13:21
.bash_profile
193
B
-rw-r--r--
2019-12-23 13:21
.bashrc
231
B
-rw-r--r--
2019-12-23 13:21
.clamavconnector.disinfection.log
74
B
-rw-r--r--
2026-06-13 00:55
.clamavconnector.status
199
B
-rw-r--r--
2026-06-13 01:56
.contactemail
22
B
-rw-r--r--
2019-12-23 13:21
.dns
24
B
-rw-r--r--
2023-12-18 10:30
.gemrc
139
B
-rw-r--r--
2020-07-24 00:43
.htaccess
197
B
-rw-r--r--
2026-06-12 07:42
.imunify_patch_id
106
B
-rw-r--r--
2025-04-16 10:44
.last.inodes
18.74
KB
-rw-r--r--
2026-06-17 10:15
.lastlogin
583
B
-rw-r--r--
2026-06-17 16:49
.myimunify_id
102
B
-rw-r--r--
2024-03-24 09:54
.spamassassinboxenable
0
B
-rw-r--r--
2019-12-23 13:21
.spamassassinenable
0
B
-rw-r--r--
2019-12-23 13:21
.zshrc
658
B
-rw-r--r--
2020-07-24 00:43
scan__report.txt
5.68
KB
-rw-r--r--
2020-07-24 01:04
scanreport-hyperdis-Jun_09_2026_09h48m.txt
23.23
KB
-rw-r--r--
2026-06-09 15:49
scanreport-hyperdis-Jun_17_2026_11h40m.txt
7.38
KB
-rw-r--r--
2026-06-17 16:48
Save
Rename
----------- SCAN REPORT ----------- TimeStamp: Tue, 9 Jun 2026 09:48:17 -0400 (/usr/sbin/cxs --background --clamdsock /var/clamd --dbreport --defapache nobody --doptions Mv --exploitscan --nofallback --filemax 50000 --noforce --html --ignore /etc/cxs/cxs.ignore.manual --options mMOLfSGchexdnwZDRru --noprobability --qoptions Mv --report /home/hyperdis/scanreport-hyperdis-Jun_09_2026_09h48m.txt --sizemax 1000000 --ssl --summary --sversionscan --timemax 30 --unofficial --user hyperdis --virusscan --vmrssmax 2000000 --waitscan 0 --xtra /etc/cxs/cxs.xtra.manual) Scanning /home/hyperdis: '/home/hyperdis/access-logs' # Symlink to [/etc/apache2/logs/domlogs/hyperdis] '/home/hyperdis/.nc_plugin/hidden' # World writeable directory '/home/hyperdis/465nafh.com.ng/cgi-bin/cgi-bin/cgi-bin/cgi-bin/cgi-bin/cgi-bin/YWq.tif' # Suspicious image file (hidden script file) '/home/hyperdis/abidencare.co.uk/wp-admin/css/RbtaK.php' # ClamAV detected virus = [TO-35550.WEBSHEL.nc_21_fCZfodQzer_notags_php.MD5-68eb58311c1ebd1acef987c4c8b6dc91.size-13796.UNOFFICIAL] '/home/hyperdis/abidencare.co.uk/wp-admin/images/media-button-music-2x.gif' # Suspicious image file (hidden script file) # Universal decode regex match = [universal decoder] '/home/hyperdis/abidencare.co.uk/wp-includes/images/smilies/icon_twisteds.png' # Suspicious image file (hidden script file) # Universal decode regex match = [universal decoder] '/home/hyperdis/abidencare.co.uk/wp-includes/js/dist/server-sied-renders.min.js' # Universal decode regex match = [universal decoder] '/home/hyperdis/abidencare.co.uk/wp-includes/js/wp/KLeMe.php' # ClamAV detected virus = [TO-35550.WEBSHEL.nc_21_fCZfodQzer_notags_php.MD5-68eb58311c1ebd1acef987c4c8b6dc91.size-13796.UNOFFICIAL] '/home/hyperdis/acehealth-caresolution.com/cgi-bin/cgi-bin/cgi-bin/cgi-bin/cgi-bin/cgi-bin/jpeg_6a1e59203126d.zip' # (compressed file: b_6a1e59203126d.tmp [depth: 1]) Known exploit = [Fingerprint Match (fp)] [PHP Exploit [P2195]] '/home/hyperdis/acehealth-caresolution.com/cgi-bin/cgi-bin/cgi-bin/cgi-bin/cgi-bin/cgi-bin/cgi-bin/RSjMBQVw.jpeg' # Suspicious image file (hidden script file) '/home/hyperdis/acehealth-caresolution.com/images/images/images/images/WbmwsLgAXYFGvUxMC.gif' # Suspicious image file (hidden script file) '/home/hyperdis/acehealth-caresolution.com/images/images/images/images/images/images/images/images/images/images/Gra.jpg' # Suspicious image file (hidden script file) '/home/hyperdis/acehealth-caresolution.com/images/images/images/images/images/images/images/images/images/images/images/ogm_6a2322bd4aa08.zip' # (compressed file: b_6a2322bd4aa08.tmp [depth: 1]) Known exploit = [Fingerprint Match (fp)] [PHP Exploit [P2195]] '/home/hyperdis/alphanursinghome.com.ng/cgi-bin/cgi-bin/cgi-bin/cgi-bin/cgi-bin/m3u8_6a0e566e75b47.zip' # (compressed file: b_6a0e566e75b47.tmp [depth: 1]) Known exploit = [Fingerprint Match (fp)] [PHP Shell Exploit [P2189]] '/home/hyperdis/alphanursinghome.com.ng/images/images/images/m3u8_6a0e566a3e420.zip' # (compressed file: b_6a0e566a3e420.tmp [depth: 1]) Known exploit = [Fingerprint Match (fp)] [PHP Shell Exploit [P2189]] '/home/hyperdis/azuahealthcare.ng/images/images/images/bvJctEVlT.tiff' # Suspicious image file (hidden script file) '/home/hyperdis/b-praisediagnostics.com.ng/cgi-bin/cgi-bin/qirHZvg.php' # ClamAV detected virus = [TO-35550.WEBSHEL.nc_21_fCZfodQzer_notags_php.MD5-68eb58311c1ebd1acef987c4c8b6dc91.size-13796.UNOFFICIAL] '/home/hyperdis/b-praisediagnostics.com.ng/cgi-bin/cgi-bin/cgi-bin/xbm_6a0d5c18a2cc9.zip' # (compressed file: b_6a0d5c18a2cc9.tmp [depth: 1]) Known exploit = [Fingerprint Match (fp)] [PHP Exploit [P2202]] '/home/hyperdis/b-praisediagnostics.com.ng/wp-admin/css/colors/coffee/coffee/YiZuUkWS.jpeg' # Suspicious image file (hidden script file) '/home/hyperdis/b-praisediagnostics.com.ng/wp-admin/images/media-button-music-3x.gif' # Suspicious image file (hidden script file) # Universal decode regex match = [universal decoder] '/home/hyperdis/b-praisediagnostics.com.ng/wp-content/plugins/akismet/_inc/img/logo-nqoppnpppoprnooqn.png' # Suspicious image file (hidden script file) # Universal decode regex match = [universal decoder] '/home/hyperdis/b-praisediagnostics.com.ng/wp-content/plugins/latepoint/lib/helpers/steps_helper.php' # Universal decode regex match = [universal decoder] '/home/hyperdis/b-praisediagnostics.com.ng/wp-content/plugins/surerank/inc/admin/dashboard.php' # Universal decode regex match = [universal decoder] '/home/hyperdis/b-praisediagnostics.com.ng/wp-content/plugins/surerank/inc/api/wp/nGCltKivhJ.php' # ClamAV detected virus = [TO-35550.WEBSHEL.nc_21_fCZfodQzer_notags_php.MD5-68eb58311c1ebd1acef987c4c8b6dc91.size-13796.UNOFFICIAL] '/home/hyperdis/b-praisediagnostics.com.ng/wp-content/plugins/surerank/inc/functions/helper.php' # Universal decode regex match = [universal decoder] '/home/hyperdis/b-praisediagnostics.com.ng/wp-content/plugins/ultimate-addons-for-gutenberg/admin-core/inc/admin-menu.php' # Universal decode regex match = [universal decoder] '/home/hyperdis/b-praisediagnostics.com.ng/wp-content/plugins/ultimate-addons-for-gutenberg/includes/blocks/forms/frontend.css.php' # Universal decode regex match = [universal decoder] '/home/hyperdis/b-praisediagnostics.com.ng/wp-content/plugins/wp-file-manager/lib/codemirror/mode/clike/index.html' # Suspicious file type [application/x-c] '/home/hyperdis/b-praisediagnostics.com.ng/wp-content/plugins/wp-live-chat-support/admin/class-wplc-plugin-settings.php' # Universal decode regex match = [universal decoder] '/home/hyperdis/b-praisediagnostics.com.ng/wp-content/themes/astra/admin/includes/class-astra-menu.php' # Universal decode regex match = [universal decoder] '/home/hyperdis/b-praisediagnostics.com.ng/wp-includes/images/smilies/icon_twistedd.png' # Suspicious image file (hidden script file) # Universal decode regex match = [universal decoder] '/home/hyperdis/b-praisediagnostics.com.ng/wp-includes/js/dist/server-sied-renderr.min.js' # Universal decode regex match = [universal decoder] '/home/hyperdis/bio-carelabs.com/temp/modules.php' # Known exploit = [Fingerprint Match (sha256)] '/home/hyperdis/cssakwaibom.com.ng/cgi-bin/cgi-bin/cgi-bin/cgi-bin/cgi-bin/cgi-bin/cgi-bin/UnYpGMLHl.png' # Suspicious image file (hidden script file) '/home/hyperdis/cssakwaibom.com.ng/images/images/images/BxeHPKtAFXRlrSbM.jpeg' # Suspicious image file (hidden script file) '/home/hyperdis/cssakwaibom.com.ng/images/images/images/GLNJywK.png' # Suspicious image file (hidden script file) '/home/hyperdis/cssakwaibom.com.ng/images/images/images/images/3gp_6a0e5683c9c1f.zip' # (compressed file: b_6a0e5683c9c1f.tmp [depth: 1]) Known exploit = [Fingerprint Match (fp)] [PHP Exploit [P2195]] '/home/hyperdis/cssakwaibom.com.ng/images/images/images/images/NusLalZbYzkjR.tiff' # Suspicious image file (hidden script file) '/home/hyperdis/cssakwaibom.com.ng/images/images/images/images/images/fla_6a1928fcc2124.zip' # (compressed file: b_6a1928fcc2124.tmp [depth: 1]) Known exploit = [Fingerprint Match (fp)] [PHP Exploit [P2202]] '/home/hyperdis/cssakwaibom.com.ng/images/images/images/images/images/images/images/UAmLWBEGpFxKzJjry.gif' # Suspicious image file (hidden script file) '/home/hyperdis/graceful-heritagecare.com/cgi-bin/cgi-bin/cgi-bin/UTPBxGMpafFKz.tiff' # Suspicious image file (hidden script file) '/home/hyperdis/graceful-heritagecare.com/cgi-bin/cgi-bin/cgi-bin/cgi-bin/MFNGfJy.gif' # Suspicious image file (hidden script file) '/home/hyperdis/graceful-heritagecare.com/cgi-bin/cgi-bin/cgi-bin/cgi-bin/cgi-bin/cgi-bin/cgi-bin/cgi-bin/cgi-bin/cgi-bin/cgi-bin/cgi-bin/hWwguzRGe.jpeg' # Suspicious image file (hidden script file) '/home/hyperdis/graceful-heritagecare.com/images/images/images/images/QyvjBWcUfIEnCP.png' # Suspicious image file (hidden script file) '/home/hyperdis/graceful-heritagecare.com/images/images/images/images/mp2_6a141a4129843.zip' # (compressed file: b_6a141a4129843.tmp [depth: 1]) Known exploit = [Fingerprint Match (fp)] [PHP Exploit [P2202]] '/home/hyperdis/graceful-heritagecare.com/images/images/images/images/images/NAzpfh.jpeg' # Suspicious image file (hidden script file) '/home/hyperdis/graceful-heritagecare.com/images/images/images/images/images/images/mov_6a2599c65ae4d.zip' # (compressed file: b_6a2599c65ae4d.tmp [depth: 1]) Known exploit = [Fingerprint Match (fp)] [PHP Exploit [P2195]] '/home/hyperdis/manorhealthcare.org.uk/cgi-bin/cgi-bin/cgi-bin/ZqheEBNaUsYzHRPnQc.png' # Suspicious image file (hidden script file) '/home/hyperdis/manorhealthcare.org.uk/cgi-bin/cgi-bin/cgi-bin/cgi-bin/ex.tiff' # Suspicious image file (hidden script file) '/home/hyperdis/manorhealthcare.org.uk/cgi-bin/cgi-bin/cgi-bin/cgi-bin/yrqxmUeXGhuNWYk.gif' # Suspicious image file (hidden script file) '/home/hyperdis/manorhealthcare.org.uk/images/images/images/images/ATLWVnItJeMcB.tif' # Suspicious image file (hidden script file) '/home/hyperdis/manorhealthcare.org.uk/images/images/images/images/ZwWANSbuYXcR.jpg' # Suspicious image file (hidden script file) '/home/hyperdis/manorhealthcare.org.uk/images/images/images/images/images/images/NA.gif' # Suspicious image file (hidden script file) '/home/hyperdis/masccarehome.com.ng/cgi-bin/cgi-bin/cgi-bin/fWBQ.tiff' # Suspicious image file (hidden script file) '/home/hyperdis/masccarehome.com.ng/cgi-bin/cgi-bin/cgi-bin/kWnmypTqtSQVGlufUjg.jpeg' # Suspicious image file (hidden script file) '/home/hyperdis/masccarehome.com.ng/cgi-bin/cgi-bin/cgi-bin/kipnRjybg.jpg' # Suspicious image file (hidden script file) '/home/hyperdis/masccarehome.com.ng/cgi-bin/cgi-bin/cgi-bin/m4a_6a14a718b7f79.zip' # (compressed file: b_6a14a718b7f79.tmp [depth: 1]) Known exploit = [Fingerprint Match (fp)] [PHP Exploit [P2202]] '/home/hyperdis/masccarehome.com.ng/cgi-bin/cgi-bin/cgi-bin/cgi-bin/FqWiVRZvthbLJn.jpeg' # Suspicious image file (hidden script file) '/home/hyperdis/masccarehome.com.ng/cgi-bin/cgi-bin/cgi-bin/cgi-bin/cxbusQrTvniKZEB.tif' # Suspicious image file (hidden script file) '/home/hyperdis/masccarehome.com.ng/images/images/images/gPuJnBxhC.png' # Suspicious image file (hidden script file) '/home/hyperdis/masccarehome.com.ng/images/images/images/images/iAjeauH.gif' # Suspicious image file (hidden script file) '/home/hyperdis/pejehealthcare.co.uk/cgi-bin/cgi-bin/cgi-bin/WGmgwXuSJ.gif' # Suspicious image file (hidden script file) '/home/hyperdis/pejehealthcare.co.uk/cgi-bin/cgi-bin/cgi-bin/gTLP.jpeg' # Suspicious image file (hidden script file) '/home/hyperdis/pejehealthcare.co.uk/cgi-bin/cgi-bin/cgi-bin/cgi-bin/jpx_6a11125d8cc82.zip' # (compressed file: b_6a11125d8cc82.tmp [depth: 1]) Known exploit = [Fingerprint Match (fp)] [PHP Shell Exploit [P2189]] '/home/hyperdis/pejehealthcare.co.uk/cgi-bin/cgi-bin/cgi-bin/cgi-bin/ljSCiLsaYhR.jpg' # Suspicious image file (hidden script file) '/home/hyperdis/pejehealthcare.co.uk/images/images/images/images/images/images/images/images/xbm_6a1ce439e286e.zip' # (compressed file: b_6a1ce439e286e.tmp [depth: 1]) Known exploit = [Fingerprint Match (fp)] [PHP Exploit [P2195]] '/home/hyperdis/pepper-staffing.co.uk/index.php' # Universal decode regex match = [universal decoder] '/home/hyperdis/pepper-staffing.co.uk/wper.php' # Universal decode regex match = [universal decoder] # Scan Timeout (30 secs) while processing: '/home/hyperdis/pepper-staffing.co.uk/wp-admin/blockt/maint/SgASelgFas.php' '/home/hyperdis/pepper-staffing.co.uk/wp-admin/css/ljcYIixSbS.php' # ClamAV detected virus = [TO-35550.WEBSHEL.nc_21_fCZfodQzer_notags_php.MD5-68eb58311c1ebd1acef987c4c8b6dc91.size-13796.UNOFFICIAL] '/home/hyperdis/pepper-staffing.co.uk/wp-admin/css/colors/KJCwEO.php' # Universal decode regex match = [universal decoder] '/home/hyperdis/pepper-staffing.co.uk/wp-admin/images/media-button-music-2x.gif' # Suspicious image file (hidden script file) # Universal decode regex match = [universal decoder] '/home/hyperdis/pepper-staffing.co.uk/wp-content/themes/twentytwenty/wp/YJmiRa.php' # Universal decode regex match = [universal decoder] '/home/hyperdis/pepper-staffing.co.uk/wp-includes/oqtxtj.php' # ClamAV detected virus = [{HEX}php.generic.globals.500.UNOFFICIAL] '/home/hyperdis/pepper-staffing.co.uk/wp-includes/revisson.php' # Universal decode regex match = [universal decoder] '/home/hyperdis/pepper-staffing.co.uk/wp-includes/images/smilies/icon_twisteds.png' # Suspicious image file (hidden script file) # Universal decode regex match = [universal decoder] '/home/hyperdis/pepper-staffing.co.uk/wp-includes/js/dist/server-sied-renders.min.js' # Universal decode regex match = [universal decoder] '/home/hyperdis/pepper-staffing.co.uk/wp-includes/js/wp/iSnDfbhBKr.php' # ClamAV detected virus = [TO-35550.WEBSHEL.nc_21_fCZfodQzer_notags_php.MD5-68eb58311c1ebd1acef987c4c8b6dc91.size-13796.UNOFFICIAL] '/home/hyperdis/prestigediagnostica.com/wp-includes/images/wpspin-1x.gif' # Suspicious image file (hidden script file) '/home/hyperdis/prestigediagnostica.com/wp-includes/images/xit-3x.gif' # Suspicious image file (hidden script file) '/home/hyperdis/public_html/wp-content/plugins/akismet/akismet.php' # Script version check [OLD] [Akismet Anti-Spam v4.2.4 < v5.3.7] '/home/hyperdis/public_html/wp-content/plugins/classic-editor/classic-editor.php' # Script version check [OLD] [Classic Editor v1.6.2 < v1.6.7] '/home/hyperdis/public_html/wp-content/plugins/contact-form-7/wp-contact-form-7.php' # Script version check [OLD] [Contact Form 7 v5.5.6.1 < v6.0.6] '/home/hyperdis/public_html/wp-content/plugins/elementor/elementor.php' # Script version check [OLD] [Elementor v3.6.5 < v3.28.4] '/home/hyperdis/public_html/wp-content/plugins/mega-elements-addons-for-elementor/includes/meafe-helpers.php' # Universal decode regex match = [universal decoder] '/home/hyperdis/public_html/wp-content/plugins/really-simple-ssl/rlrsssl-really-simple-ssl.php' # Script version check [OLD] [Really Simple SSL v5.3.2 < v9.3.3] '/home/hyperdis/public_html/wp-content/plugins/wpforms-lite/wpforms.php' # Script version check [OLD] [WPForms Lite v1.7.4.2 < v1.9.4.2] # Scan Timeout (30 secs) while processing: '/home/hyperdis/public_html/wp-content/plugins/wpforms-lite/assets/css/builder/builder-fields-types.css' '/home/hyperdis/public_html/wp-includes/version.php' # Script version check [OLD] [Wordpress v6.0 < v6.8.2] '/home/hyperdis/pulchritudebynana.com/wp-load.php' # Universal decode regex match = [universal decoder] '/home/hyperdis/pulchritudebynana.com/wp-admin/js/js/js/f4v_6a1ce43a1b411.zip' # (compressed file: b_6a1ce43a1b411.tmp [depth: 1]) Known exploit = [Fingerprint Match (fp)] [PHP Exploit [P2195]] '/home/hyperdis/pulchritudebynana.com/wp-content/plugins/bdthemes-prime-slider-lite/admin/admin-settings.php' # Universal decode regex match = [universal decoder] '/home/hyperdis/pulchritudebynana.com/wp-content/plugins/google-listings-and-ads/vendor/phpseclib/phpseclib/phpseclib/Crypt/EC/Curves/sect571k1.php' # Universal decode regex match = [universal decoder] '/home/hyperdis/pulchritudebynana.com/wp-content/plugins/google-listings-and-ads/vendor/phpseclib/phpseclib/phpseclib/Crypt/EC/Curves/sect571r1.php' # Universal decode regex match = [universal decoder] '/home/hyperdis/pulchritudebynana.com/wp-content/plugins/unlimited-elements-for-elementor/vendor/twig/twig/src/Loader/Loader/ALsWHitrFbwyVQhjT.gif' # Suspicious image file (hidden script file) '/home/hyperdis/pulchritudebynana.com/wp-content/plugins/woocommerce/includes/admin/class-wc-admin-menus.php' # Universal decode regex match = [universal decoder] '/home/hyperdis/pulchritudebynana.com/wp-content/plugins/woocommerce/src/Internal/Admin/Settings/PaymentsController.php' # Universal decode regex match = [universal decoder] '/home/hyperdis/pulchritudebynana.com/wp-content/plugins/woocommerce/vendor/maxmind-db/reader/ext/maxminddb.c' # Suspicious file type [application/x-c] '/home/hyperdis/pulchritudebynana.com/wp-content/themes/astra/admin/includes/class-astra-menu.php' # Universal decode regex match = [universal decoder] '/home/hyperdis/pulchritudebynana.com/wp-includes/template-loader.php' # Universal decode regex match = [universal decoder] '/home/hyperdis/pulchritudebynana.com/wp-includes/Text/Diff/Engine/orqoqporsnrsornprop.ttf' # Universal decode regex match = [universal decoder] '/home/hyperdis/pulchritudebynana.com/wp-includes/blocks/cover/style-rel.css' # Universal decode regex match = [universal decoder] '/home/hyperdis/pulchritudebynana.com/wp-includes/images/w-bedbdcbefaefbeacebc.gif' # Suspicious image file (hidden script file) # Universal decode regex match = [universal decoder] '/home/hyperdis/pulchritudebynana.com/wp-includes/images/wpspin-1x.gif' # Suspicious image file (hidden script file) '/home/hyperdis/pulchritudebynana.com/wp-includes/images/xit-3x.gif' # Suspicious image file (hidden script file) '/home/hyperdis/pulchritudebynana.com/wp-includes/images/media/bedbdcbefaefbeacebc.png' # Suspicious image file (hidden script file) # Universal decode regex match = [universal decoder] '/home/hyperdis/seven-resourcingnursing.com/index.php' # Universal decode regex match = [universal decoder] '/home/hyperdis/seven-resourcingnursing.com/wper.php' # Universal decode regex match = [universal decoder] # Scan Timeout (30 secs) while processing: '/home/hyperdis/seven-resourcingnursing.com/wp-admin/ID3/plugins/certificates/eSNuGC.php' '/home/hyperdis/seven-resourcingnursing.com/wp-admin/ID3/plugins/certificates/fonts/zStQnvuR.php' # Universal decode regex match = [universal decoder] '/home/hyperdis/seven-resourcingnursing.com/wp-admin/css/DEcXyablA.php' # ClamAV detected virus = [TO-35550.WEBSHEL.nc_21_fCZfodQzer_notags_php.MD5-68eb58311c1ebd1acef987c4c8b6dc91.size-13796.UNOFFICIAL] '/home/hyperdis/seven-resourcingnursing.com/wp-admin/images/media-button-music-2x.gif' # Suspicious image file (hidden script file) # Universal decode regex match = [universal decoder] '/home/hyperdis/seven-resourcingnursing.com/wp-includes/revisson.php' # Universal decode regex match = [universal decoder] '/home/hyperdis/seven-resourcingnursing.com/wp-includes/xycvdu.php' # ClamAV detected virus = [{HEX}php.generic.globals.500.UNOFFICIAL] '/home/hyperdis/seven-resourcingnursing.com/wp-includes/images/smilies/icon_twisteds.png' # Suspicious image file (hidden script file) # Universal decode regex match = [universal decoder] '/home/hyperdis/seven-resourcingnursing.com/wp-includes/images/style-engine/ID3/php-compat/wp/enIOPKc.php' # Universal decode regex match = [universal decoder] '/home/hyperdis/seven-resourcingnursing.com/wp-includes/js/dist/server-sied-renders.min.js' # Universal decode regex match = [universal decoder] '/home/hyperdis/seven-resourcingnursing.com/wp-includes/js/wp/lmYBIjIa.php' # ClamAV detected virus = [TO-35550.WEBSHEL.nc_21_fCZfodQzer_notags_php.MD5-68eb58311c1ebd1acef987c4c8b6dc91.size-13796.UNOFFICIAL] '/home/hyperdis/telstatech.com.ng/wp-admin/css/colors/blue/blue/FSEhUjGmvLetRJw.tiff' # Suspicious image file (hidden script file) '/home/hyperdis/telstatech.com.ng/wp-content/plugins/akismet/_inc/img/logo-qnpqopnqp.png' # Suspicious image file (hidden script file) # Universal decode regex match = [universal decoder] '/home/hyperdis/telstatech.com.ng/wp-content/plugins/all-in-one-seo-pack/app/Common/Views/admin/settings-page.php' # Universal decode regex match = [universal decoder] '/home/hyperdis/telstatech.com.ng/wp-content/plugins/google-analytics-for-wordpress/includes/helpers.php' # Universal decode regex match = [universal decoder] '/home/hyperdis/telstatech.com.ng/wp-includes/IXR/IXR/AsxTtNVuYPZMf.tiff' # Suspicious image file (hidden script file) '/home/hyperdis/telstatech.com.ng/wp-includes/Text/Diff/Engine/qnpqopnqp.ttf' # Universal decode regex match = [universal decoder] '/home/hyperdis/telstatech.com.ng/wp-includes/blocks/cover/style-rel.css' # Universal decode regex match = [universal decoder] '/home/hyperdis/telstatech.com.ng/wp-includes/images/w-dacdbcadc.gif' # Suspicious image file (hidden script file) # Universal decode regex match = [universal decoder] '/home/hyperdis/telstatech.com.ng/wp-includes/images/wpspin-1x.gif' # Suspicious image file (hidden script file) '/home/hyperdis/telstatech.com.ng/wp-includes/images/xit-3x.gif' # Suspicious image file (hidden script file) '/home/hyperdis/telstatech.com.ng/wp-includes/images/media/dacdbcadc.png' # Suspicious image file (hidden script file) # Universal decode regex match = [universal decoder] '/home/hyperdis/urbansignaturehomes.com/wp-content/ewww/cwebp' # Linux Binary/Executable [application/x-executable] '/home/hyperdis/urbansignaturehomes.com/wp-content/ewww/gifsicle' # Linux Binary/Executable [application/x-executable] '/home/hyperdis/urbansignaturehomes.com/wp-content/ewww/jpegtran' # Linux Binary/Executable [application/x-executable] '/home/hyperdis/urbansignaturehomes.com/wp-content/ewww/optipng' # Linux Binary/Executable [application/x-executable] '/home/hyperdis/urbansignaturehomes.com/wp-content/ewww/pngquant' # Linux Binary/Executable [application/x-sharedlib] '/home/hyperdis/urbansignaturehomes.com/wp-content/plugins/ewww-image-optimizer/binaries/cwebp-fbsd' # Linux Binary/Executable [application/x-executable] '/home/hyperdis/urbansignaturehomes.com/wp-content/plugins/ewww-image-optimizer/binaries/cwebp-linux' # Linux Binary/Executable [application/x-executable] '/home/hyperdis/urbansignaturehomes.com/wp-content/plugins/ewww-image-optimizer/binaries/cwebp.exe' # MS Windows Binary/Executable [application/x-winexec] '/home/hyperdis/urbansignaturehomes.com/wp-content/plugins/ewww-image-optimizer/binaries/gifsicle-fbsd' # Linux Binary/Executable [application/x-executable] '/home/hyperdis/urbansignaturehomes.com/wp-content/plugins/ewww-image-optimizer/binaries/gifsicle-linux' # Linux Binary/Executable [application/x-executable] '/home/hyperdis/urbansignaturehomes.com/wp-content/plugins/ewww-image-optimizer/binaries/gifsicle.exe' # MS Windows Binary/Executable [application/x-winexec] '/home/hyperdis/urbansignaturehomes.com/wp-content/plugins/ewww-image-optimizer/binaries/jpegtran-fbsd' # Linux Binary/Executable [application/x-executable] '/home/hyperdis/urbansignaturehomes.com/wp-content/plugins/ewww-image-optimizer/binaries/jpegtran-linux' # Linux Binary/Executable [application/x-executable] '/home/hyperdis/urbansignaturehomes.com/wp-content/plugins/ewww-image-optimizer/binaries/jpegtran.exe' # MS Windows Binary/Executable [application/x-winexec] '/home/hyperdis/urbansignaturehomes.com/wp-content/plugins/ewww-image-optimizer/binaries/optipng-fbsd' # Linux Binary/Executable [application/x-executable] '/home/hyperdis/urbansignaturehomes.com/wp-content/plugins/ewww-image-optimizer/binaries/optipng-linux' # Linux Binary/Executable [application/x-executable] '/home/hyperdis/urbansignaturehomes.com/wp-content/plugins/ewww-image-optimizer/binaries/optipng.exe' # MS Windows Binary/Executable [application/x-winexec] '/home/hyperdis/urbansignaturehomes.com/wp-content/plugins/ewww-image-optimizer/binaries/pngquant-fbsd' # Linux Binary/Executable [application/x-executable] '/home/hyperdis/urbansignaturehomes.com/wp-content/plugins/ewww-image-optimizer/binaries/pngquant-linux' # Linux Binary/Executable [application/x-sharedlib] '/home/hyperdis/urbansignaturehomes.com/wp-content/plugins/ewww-image-optimizer/binaries/pngquant.exe' # MS Windows Binary/Executable [application/x-winexec] ----------- SCAN SUMMARY ----------- Scanned directories: 23006 Scanned files: 132654 Ignored items: 1080 Suspicious matches: 160 Viruses found: 10 Fingerprint matches: 14 Data scanned: 3837.95 MB Scan peak memory: 368784 kB Scan time/item: 0.047 sec Scan time: 7284.822 sec