Treatment of VPS from the virus
A viral file was uploaded to the VPS
All files were deleted and the database was uploaded before the virus infection, but index.php with malicious code is still being created
сайту наразі немає, в файлах тільки index та htaccess, треба подивитись що їх створює та видалити
логи створення файлу:
[2024-09-06T20:28:46+03:00] INFO Start handle upload file 'index.php' EVENT_NAME=filemanager.upload SUBJECT=index.php TASK_ID=dbcc24e1-0610-42d3-ba78-ea5ea9f774a4
[2024-09-06T20:28:46+03:00] INFO Move '/var/upload/0000000222' to '/var/www/fastuser/data/www/index.php' EVENT_NAME=filemanager.upload SUBJECT=index.php TASK_ID=dbcc24e1-0610-42d3-ba78-ea5ea9f774a4
[2024-09-06T20:28:46+03:00] INFO exec: "/usr/bin/mv /var/upload/0000000222 /var/www/fastuser/data/www/index.php" EVENT_NAME=filemanager.upload SUBJECT=index.php TASK_ID=dbcc24e1-0610-42d3-ba78-ea5ea9f774a4
[2024-09-06T20:28:46+03:00] INFO File 'index.php' have been uploaded successfully EVENT_NAME=filemanager.upload SUBJECT=index.php TASK_ID=dbcc24e1-0610-42d3-ba78-ea5ea9f774a4
31.202.92.109 - - [06/Sep/2024:20:28:46 +0300] "POST /api/files/upload?file=index.php&site=2&path=/var/www/fastuser/data/www/&encoding=utf-8 HTTP/2.0" 200 2 "vhosts/2/files" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36 OPR/113.0.0.0" rt="0.006" uct="0.004" uht="0.004" urt="0.004"
Applications 1
-
2198 11 0 Ready to do it, I am in the top 10 freelancers in security and antivirus. Write to me - I will be glad to cooperate! I see that the site is on WordPress - I have colossal experience, as I have been in web development for over 15 years!
-
Доброго дня.
Така проблема не тільки у вас, а у всіх у кого сайт працює на https://fastpanel.direct/
Сама панель десь має вразливість. Вам треба закрити доступ до панелі по IP. Так як у одного знайомого сайт не ломанули бо там взагалі зайти навіть по FTP без додавання IP в список неможливо.
-
І ще. У вас випадково на хостингу не було сайту на prestashop?
-
Current freelance projects in the category Cybersecurity & Data Protection
Diagnosis and elimination of recurring WhatsApp Business blocksTask Description A specialist is required with experience in WhatsApp Business and Meta Business to analyze and resolve the reasons for the constant blocking of the WhatsApp Business account. Problem: When logging into the WhatsApp Business account, it is almost immediately… Cybersecurity & Data Protection, Software & Server Configuration ∙ 2 days 19 hours back ∙ 5 proposals |
