Hi again,
I was hopping that the website wouldn't be infected anymore, as still today I see entries in the live traffic tab of Wordfence as
" Netherlands was blocked by firewall for Known malicious User-Agents at https://delasciencealassiette.fr/wqaofwbl.php?Fox=d3wL7
5/9/2022 11:39:38 AM (2 hours 9 mins ago)"
But... I also see entries in clicky.com analytics for yesterday as:
"`23:29 El Salvador flag 190.5.159.0 /ubpxwlwy.php?Fox=d3wL7"
the same thing from 3 different IP addresses, that are NOT blocked nor registered in Wordfence.
I wonder if, as it is registered in Clicky.com but not in Wordfence, it means that it got in?
I don't see any such files in the Public_html folder and no users nor email accounts created neither.
Greetings,
Rod
I was hopping that the website wouldn't be infected anymore, as still today I see entries in the live traffic tab of Wordfence as
" Netherlands was blocked by firewall for Known malicious User-Agents at https://delasciencealassiette.fr/wqaofwbl.php?Fox=d3wL7
5/9/2022 11:39:38 AM (2 hours 9 mins ago)"
But... I also see entries in clicky.com analytics for yesterday as:
"`23:29 El Salvador flag 190.5.159.0 /ubpxwlwy.php?Fox=d3wL7"
the same thing from 3 different IP addresses, that are NOT blocked nor registered in Wordfence.
I wonder if, as it is registered in Clicky.com but not in Wordfence, it means that it got in?
I don't see any such files in the Public_html folder and no users nor email accounts created neither.
Greetings,
Rod