Potential malicious activity question

RPmentor

Member
Jun 20, 2020
5
0
1
SALISBURY, UK
cPanel Access Level
Reseller Owner
I joined this forum in June 2020 and now that I have an issue, I'm hoping its resolution will be of some help to others...

My hosting provider has alerted me to ' malicious activity detected on my account'... I do have access to the file manager and I have found a number of .htaccess file with recent creation dates... is it possible that these files have somehow been added by an automatic cPanel routine..??

I'm appending a screenprint of an .htaccess file which does not appear to be malicious and will be grateful for any suggestions about what may have transpired... thank you...
 

Attachments

Last edited by a moderator:

cPRex

Jurassic Moderator
Staff member
Oct 19, 2014
16,525
2,607
363
cPanel Access Level
Root Administrator
Hey there! I have a couple thoughts on this.

The top section isn't something we would control, as that would be added by the site admin or software installed on the domain.

The bottom section, as mentioned in the comments, is controlled by cPanel, so it's normal for us to automatically update that file on the system from time to time.

Is your site using PHP 5.4? If so, if that server using alt-php through CloudLinux? PHP 5.4 has been End of Life since September 2015, so I wouldn't recommend using that on any production site, and having that old version could be the source of the compromise.
 
  • Like
Reactions: RPmentor

RPmentor

Member
Jun 20, 2020
5
0
1
SALISBURY, UK
cPanel Access Level
Reseller Owner
Is your site using PHP 5.4?
All domains are using PHP 8.0 (ea-php80), except for the two main domains which are using PHP 7.4 (ea-php74)...

Some of the domains were using PHP 5.4 (ea-php54) before I was alerted to malicious activity and I have updated these to PHP 8.0 (ea-php80) since I received the 'malicious activity detected on my account' message... is this likely to have resolved my issue..??
 

quietFinn

Well-Known Member
Feb 4, 2006
2,034
546
493
Finland
cPanel Access Level
Root Administrator
Some of the domains were using PHP 5.4 (ea-php54) before I was alerted to malicious activity and I have updated these to PHP 8.0 (ea-php80) since I received the 'malicious activity detected on my account' message... is this likely to have resolved my issue..??
Most likely not, it might stop future hacks, but unless you find all the malicious code you are still in danger.
 
  • Like
Reactions: RPmentor and cPRex

ResellerWiz

Well-Known Member
Mar 24, 2023
150
66
103
USA
cPanel Access Level
Root Administrator
Twitter
The htaccess file you showed does not appear to have anything "mailicious" in it.

I think your host needs to be more specific as to what malicious activity is occurring to give you a better idea of what you should be looking for.
 
  • Like
Reactions: RPmentor and cPRex

RPmentor

Member
Jun 20, 2020
5
0
1
SALISBURY, UK
cPanel Access Level
Reseller Owner
I think your host needs to be more specific as to what malicious activity is occurring to give you a better idea of what you should be looking for.
I'll need to sign up for their security offering because I can see no other way that they'll remove the block on the website... as @quietFinn says (above), maybe there is some malicious code somewhere...!!!!!!!
 

ResellerWiz

Well-Known Member
Mar 24, 2023
150
66
103
USA
cPanel Access Level
Root Administrator
Twitter
I'll need to sign up for their security offering because I can see no other way that they'll remove the block on the website... as @quietFinn says (above), maybe there is some malicious code somewhere...!!!!!!!
You shouldn't have to pay extra for a "security offering".

Hosting providers that nickel and dime you for security/backups/SSL by referring to them as "addon services/products" should be avoided like the plague.
 
  • Like
Reactions: RPmentor

RPmentor

Member
Jun 20, 2020
5
0
1
SALISBURY, UK
cPanel Access Level
Reseller Owner
They should at least be able to tell you how they found the issue and point you in the right direction, such as to a specific webpage or file.
This is certainly what I had hoped for, however, the support people probably do not have enough specialist knowledge to do more than recommend their security add-on which is provided by Sucuri at £5.99 pcm...
 

ResellerWiz

Well-Known Member
Mar 24, 2023
150
66
103
USA
cPanel Access Level
Root Administrator
Twitter
What about the appended text file generated yesterday... is there anything suspicious in it, please...?
That appears to be nothing more than a session token and not malicious.
 

ITHKBO

Active Member
Jun 23, 2020
41
39
18
Netherlands
cPanel Access Level
Root Administrator
Have you tried running the domain through ImunifyAV or is that not a option in your cPanel account?
You can do a quickscan online at Sucuri from Sucuri Security These scans do not cost anything.

That should give a indication if there is a url hijack going on. It can't find more obscure stuff without access to the site itself but if there are malicious redirects going on that is the first spot we always check for our clients. Make sure to scan per page.