• Resolved nek007

    (@nek007)


    Hi Wordfence team.

    I have wordfence free version installed in all my websites. Today i received the Wordfence activity email for a few of the sites and i saw a lot of Recently Modified Files in the email.

    I scanned all my sites and wordfence didnt find any file changes.

    Let me give you a few examples so you know what kind of files i am writting about.

    1. One of the sites send me a list of recently modifies files like this one: wp-content/uploads/fusion-styles/bfe29e9afbdec22a091f0a7cf9d3c28b.min.css changing this part bfe29e9afbdec22a091f0a7cf9d3c28b

    2. Another site gave me a list modified files like this:

    August 22, 2022 11:48am	
    wp-content/uploads/2020/12/iatreio11.jpg2_-200x200.jpg
    August 22, 2022 11:48am	
    wp-content/uploads/2020/12/[email protected]
    August 16, 2022 3:59pm	
    .user.ini
    August 16, 2022 3:59pm	
    .htaccess
    August 16, 2022 3:59pm	
    wordfence-waf.php
    August 16, 2022 3:47pm	
    wp-content/plugins/wordfence/crypto/vendor/paragonie/sodium_compat/namespaced/Core/ChaCha20/IetfCtx.php
    August 16, 2022 3:47pm	
    wp-content/plugins/wordfence/crypto/vendor/paragonie/sodium_compat/namespaced/Core/ChaCha20.php
    August 16, 2022 3:47pm	
    wp-content/plugins/wordfence/crypto/vendor/paragonie/sodium_compat/namespaced/Core/Ed25519.php
    August 16, 2022 3:47pm	
    wp-content/plugins/wordfence/crypto/vendor/paragonie/sodium_compat/namespaced/Core/Poly1305.php
    August 16, 2022 3:47pm	
    wp-content/plugins/wordfence/crypto/vendor/paragonie/sodium_compat/namespaced/Core/HChaCha20.php

    I am concerned in both sites, but especially the 2nd looks suspicious. Its in wordfence directory and uses word like Crypto etc…

    I would like to read your opinion about these modified files. Is it something to worry or is it ok?

    Cant wait for your answer because it worries me a lot!

    THanks in Advance!

    Nek

Viewing 2 replies - 1 through 2 (of 2 total)
  • Plugin Support wfpeter

    (@wfpeter)

    Hi @nek007, thank-you for getting in touch!

    I don’t have reason to believe from the results above that there’s anything to worry about, especially if subsequent scans aren’t flagging any changed Wordfence core files.

    The crypto folder is indeed present in the Wordfence installation by default. It contains the cryptography libraries sodium_compat and random_compat which are required by Wordfence for safe implementation of certain PHP functions.

    Thanks,

    Peter.

    Thread Starter nek007

    (@nek007)

    That’s great Peter!

    Thanks a lot!!

    • This reply was modified 3 years, 10 months ago by nek007.
Viewing 2 replies - 1 through 2 (of 2 total)

The topic ‘Recently Modified Files’ is closed to new replies.