LittleDemon WebShell


Linux webm007.cluster106.gra.hosting.ovh.net 5.15.167-ovh-vps-grsec-zfs-classid #1 SMP Tue Sep 17 08:14:20 UTC 2024 x86_64
Path : /home/eglisebaa/www/wp-includes/js/imgareaselect/mu-plugins/
File Upload :
Command :
Current File : /home/eglisebaa/www/wp-includes/js/imgareaselect/mu-plugins/scan-report.txt.tar

home/eglisebaa/www/wp-scan-complet-20260111-154905/scan-report.txt000064400000013362151723111060017704 0ustar00
==========================================
1. Scan des Patterns Malveillants
==========================================

[15:49:05] ℹ️  Recherche de patterns de backdoor dans tous les fichiers PHP...
[15:53:38] ⚠️  2076 fichier(s) avec patterns suspects détectés

==========================================
2. Fichiers Récemment Modifiés (30 derniers jours)
==========================================

[15:53:38] ℹ️  Recherche des fichiers modifiés récemment...
[15:53:45] ℹ️  79 fichier(s) modifié(s) récemment

==========================================
3. Fichiers PHP dans wp-content/uploads
==========================================

[15:53:45] ℹ️  Recherche de fichiers PHP dans uploads (très suspect)...
[15:53:45] 🔴 2 fichier(s) PHP trouvé(s) dans uploads!
wp-content/uploads/2024/07/assets/index.php
wp-content/uploads/fileaway-custom-css/index.php

==========================================
4. Vérification des Fichiers Core WordPress
==========================================

[15:53:45] ✅ index.php semble propre
[15:53:45] ✅ wp-config.php semble propre
[15:53:45] ✅ wp-blog-header.php semble propre
[15:53:45] ✅ wp-load.php semble propre
[15:53:45] ✅ wp-settings.php semble propre
[15:53:45] 🔴 Pattern suspect dans .htaccess

==========================================
5. Scan des Thèmes
==========================================

[15:53:45] ℹ️  Scan des fichiers de thème...
[15:53:47] ⚠️  Thème suspect: wp-content/themes/twentytwentyfour/parts/07/index.php

==========================================
6. Scan des Plugins
==========================================

[15:53:48] ℹ️  Scan des fichiers de plugins...
[15:54:06] ⚠️  Plugin suspect: wp-content/plugins/contact-form-7/includes/form-tag.php
[15:54:06] ⚠️  Plugin suspect: wp-content/plugins/contact-form-7/includes/contact-form.php
[15:54:10] ⚠️  Plugin suspect: wp-content/plugins/advanced-custom-fields/includes/api/api-helpers.php
[15:54:10] ⚠️  Plugin suspect: wp-content/plugins/wp-fastest-cache/wpFastestCache.php
[15:54:10] ⚠️  Plugin suspect: wp-content/plugins/wp-fastest-cache/inc/admin.php
[15:54:10] ⚠️  Plugin suspect: wp-content/plugins/wp-fastest-cache/inc/css-utilities.php
[15:54:10] ⚠️  Plugin suspect: wp-content/plugins/wp-crontrol/src/bootstrap.php
[15:54:10] ⚠️  Plugin suspect: wp-content/plugins/wp-crontrol/src/event.php
[15:54:11] ⚠️  Plugin suspect: wp-content/plugins/elementor/core/page-assets/data-managers/base.php
[15:54:11] ⚠️  Plugin suspect: wp-content/plugins/elementor/core/dynamic-tags/manager.php
[15:54:11] ⚠️  Plugin suspect: wp-content/plugins/elementor/core/files/uploads-manager.php
[15:54:11] ⚠️  Plugin suspect: wp-content/plugins/elementor/core/base/elements-iteration-actions/assets.php
[15:54:11] ⚠️  Plugin suspect: wp-content/plugins/elementor/includes/api.php
[15:54:11] ⚠️  Plugin suspect: wp-content/plugins/elementor/includes/template-library/sources/local.php
[15:54:11] ⚠️  Plugin suspect: wp-content/plugins/elementor/includes/fonts.php
[15:54:12] ⚠️  Plugin suspect: wp-content/plugins/elementor/includes/libraries/bfi-thumb/bfi-thumb.php
[15:54:12] ⚠️  Plugin suspect: wp-content/plugins/search-filter-pro/public/includes/class-search-filter-cache.php
[15:54:12] ⚠️  Plugin suspect: wp-content/plugins/search-filter-pro/includes/class-search-filter-third-party.php
[15:54:13] ⚠️  Plugin suspect: wp-content/plugins/code-snippets/php/class-plugin.php
[15:54:13] ⚠️  Plugin suspect: wp-content/plugins/code-snippets/php/snippet-ops.php
[15:54:13] ⚠️  Plugin suspect: wp-content/plugins/code-snippets/php/front-end/class-front-end.php
[15:54:13] ⚠️  Plugin suspect: wp-content/plugins/code-snippets/php/evaluation/class-evaluate-content.php
[15:54:13] ⚠️  Plugin suspect: wp-content/plugins/code-snippets/php/evaluation/class-evaluate-functions.php

==========================================
7. Vérification des Permissions
==========================================

[15:54:13] ℹ️  Analyse des permissions des fichiers critiques...

==========================================
8. Fichiers avec Noms Suspects
==========================================

[15:54:15] ℹ️  Recherche de fichiers avec noms suspects...

==========================================
RÉSUMÉ DU SCAN
==========================================

✓ Fichiers suspects détectés: 2076
✓ Fichiers PHP dans uploads: 2
✓ Fichiers récemment modifiés: 79
📁 Rapports générés dans: /home/eglisebaa/www/wp-scan-complet-20260111-154905
  • /home/eglisebaa/www/wp-scan-complet-20260111-154905/scan-report.txt (rapport principal)
  • /home/eglisebaa/www/wp-scan-complet-20260111-154905/fichiers-suspects.txt (fichiers suspects)
  • /home/eglisebaa/www/wp-scan-complet-20260111-154905/patterns-malware.txt (patterns détectés)
  • /home/eglisebaa/www/wp-scan-complet-20260111-154905/fichiers-recents.txt (fichiers récents)
  • /home/eglisebaa/www/wp-scan-complet-20260111-154905/php-dans-uploads.txt (PHP dans uploads)
  • /home/eglisebaa/www/wp-scan-complet-20260111-154905/permissions.txt (permissions)

==========================================
SCAN TERMINÉ
==========================================


LittleDemon - FACEBOOK
[ KELUAR ]