Available for projects & agency overflow · Quick reply, from the person who does the work

A file I don't recognise has appeared on the server

A PHP file with a strange name, or one that mimics a core CMS file, sitting in a folder that should only hold images or exports: it's one of the most direct signs of an intrusion, and one of the most often misread.

Describe my issue Send a message

What should raise a flag in a file manager

  • A .php extension inside a folder that should only hold images (wp-content/uploads, img/, an export or cache folder)
  • A filename close to a legitimate one but not quite identical, say with a swapped letter or an added suffix
  • A recent modification date on a file you never touched, while the rest of the folder hasn't changed in months
  • A script file that's oddly small (a few hundred bytes), or conversely unreadable, compressed-looking content when opened
  • A file sitting inside a theme folder you no longer use or never activated
  • Several near-identical filenames scattered across different folders, as if the same script had been dropped in more than one place

The SoakSoak case: what a backdoor looks like in practice

In December 2014, a campaign known as SoakSoak affected more than 100,000 WordPress sites by exploiting a flaw in the widely used Slider Revolution plugin, so common that it was bundled directly into many premium themes, often without the theme buyer even knowing it was there. Over 11,000 domains ended up blacklisted by Google as a result of that campaign, according to the analyses published at the time by Sucuri and by Graham Cluley.

The mechanism Sucuri documented shows what a suspicious file can look like in practice, without needing to go into the technical detail of the exploit itself: once access was gained through the plugin flaw, attackers dropped a hidden file called "Filesman", a backdoor giving permanent access to the site's files. It was typically hidden inside a theme or media folder, exactly the kind of place an administrator rarely inspects closely. With that access in place, a legitimate JavaScript file on the site, swfobject.js, was then modified to redirect some visitors to a malicious domain.

The lesson from this case, a decade on: a backdoor doesn't need to be sophisticated to stay invisible for a long time. It simply relies on nobody looking closely at a media folder or an inactive theme. The name "Filesman" itself isn't especially subtle once you know it, but you still need to know where to look.

How to confirm a file doesn't belong on the site

  1. Compare against a clean archive

    A file from the CMS core, a theme or an official plugin can be checked against the archive downloaded from the official source, for the exact same version.

  2. Check the date against your own history

    A modification date that matches no update, no deployment and no known action on your part is a strong signal, especially when it sits alone among files that haven't changed in a long time.

  3. Look for the file elsewhere on the site

    A backdoor is rarely dropped in just one place: finding the same file, or a close variant, in several folders strengthens the suspicion.

  4. Don't delete it before understanding how it got there

    Deleting the file without identifying the entry point leaves the door open for the same kind of file to reappear within hours.

Related pages

Describe your need in one minute

A few targeted questions so I can reply with an estimate rather than another questionnaire.

symptomes
depuis-quand
sauvegarde
acces-admin (facultatif)
Please provide an email or a phone number so I can get back to you.

Please provide an email or a phone number so I can get back to you.

Frequently asked questions

Can I just delete the suspicious file?
You can, but that only fixes the visible part of the problem. If the flaw that let it in is still open, an identical or different file usually reappears very quickly.
The filename looks like a core file — does that mean it's malicious?
Not necessarily, but that's exactly the most common technique for staying unnoticed. The only way to be sure is to compare it against an official archive of the exact same version.
Should I worry if the file is in a theme I no longer use?
Yes — that's actually one of the most common places for this kind of file, precisely because an inactive theme is almost never checked.
How does this kind of file end up on the server?
Usually through an outdated plugin or theme with a known flaw, or through a compromised access point such as FTP or the admin panel. The file itself is a consequence, not the cause.
Would a regular antivirus on my computer catch this kind of file?
No, a desktop antivirus doesn't scan the hosting server's contents. You need either a dedicated server-side tool or a manual check of the files and their dates.