# A file I don't recognise has appeared on the server

> A PHP file with a strange name, or one that mimics a core CMS file, sitting in a folder that should only hold images or exports: it's one of the most direct signs of an intrusion, and one of the most often misread.

- Source canonique : [https://allaux.fr/en/securite/fichier-inconnu-sur-le-serveur](https://allaux.fr/en/securite/fichier-inconnu-sur-le-serveur)
- Langue : EN
- Dernière mise à jour : 2026-09-30

## Direct answer

> Never open the file by typing its address in a browser — that alone can run it. Record its full path and modification date, then sort the folder by date over FTP or SSH to list everything written the same day. A .php file inside wp-content/uploads or an images folder has no legitimate reason to exist.

## What should raise a flag in a file manager

- A .php extension inside a folder that should only hold images (wp-content/uploads, img/, an export or cache folder)
- A filename close to a legitimate one but not quite identical, say with a swapped letter or an added suffix
- A recent modification date on a file you never touched, while the rest of the folder hasn't changed in months
- A script file that's oddly small (a few hundred bytes), or conversely unreadable, compressed-looking content when opened
- A file sitting inside a theme folder you no longer use or never activated
- Several near-identical filenames scattered across different folders, as if the same script had been dropped in more than one place

## The SoakSoak case: what a backdoor looks like in practice

In December 2014, a campaign known as SoakSoak affected more than 100,000 WordPress sites by exploiting a flaw in the widely used Slider Revolution plugin, so common that it was bundled directly into many premium themes, often without the theme buyer even knowing it was there. Over 11,000 domains ended up blacklisted by Google as a result of that campaign, according to the analyses published at the time by Sucuri and by Graham Cluley.

The mechanism Sucuri documented shows what a suspicious file can look like in practice, without needing to go into the technical detail of the exploit itself: once access was gained through the plugin flaw, attackers dropped a hidden file called "Filesman", a backdoor giving permanent access to the site's files. It was typically hidden inside a theme or media folder, exactly the kind of place an administrator rarely inspects closely. With that access in place, a legitimate JavaScript file on the site, swfobject.js, was then modified to redirect some visitors to a malicious domain.

The lesson from this case, a decade on: a backdoor doesn't need to be sophisticated to stay invisible for a long time. It simply relies on nobody looking closely at a media folder or an inactive theme. The name "Filesman" itself isn't especially subtle once you know it, but you still need to know where to look.

## Don't open it in a browser

> Never access a suspicious file by typing its address into a browser: if it's an active script, that alone can be enough to run it. Only view its contents through your host's file manager or an FTP client, read-only, without executing it.

## How to confirm a file doesn't belong on the site

1. **Compare against a clean archive** — A file from the CMS core, a theme or an official plugin can be checked against the archive downloaded from the official source, for the exact same version.
2. **Check the date against your own history** — A modification date that matches no update, no deployment and no known action on your part is a strong signal, especially when it sits alone among files that haven't changed in a long time.
3. **Look for the file elsewhere on the site** — A backdoor is rarely dropped in just one place: finding the same file, or a close variant, in several folders strengthens the suspicion.
4. **Don't delete it before understanding how it got there** — Deleting the file without identifying the entry point leaves the door open for the same kind of file to reappear within hours.

## Related pages

- **Hacked WordPress or WooCommerce site** — The full cleanup method and how to close the flaw, beyond the single file you've spotted. ([/wordpress-woocommerce/site-pirate](/wordpress-woocommerce/site-pirate))
- **E-commerce security and hacked site cleanup** — How a cleanup engagement runs, step by step, regardless of the CMS. ([/services/securite](/services/securite))

## FAQ

### Can I just delete the suspicious file?

You can, but that only fixes the visible part of the problem. If the flaw that let it in is still open, an identical or different file usually reappears very quickly.

### The filename looks like a core file — does that mean it's malicious?

Not necessarily, but that's exactly the most common technique for staying unnoticed. The only way to be sure is to compare it against an official archive of the exact same version.

### Should I worry if the file is in a theme I no longer use?

Yes — that's actually one of the most common places for this kind of file, precisely because an inactive theme is almost never checked.

### How does this kind of file end up on the server?

Usually through an outdated plugin or theme with a known flaw, or through a compromised access point such as FTP or the admin panel. The file itself is a consequence, not the cause.

### Would a regular antivirus on my computer catch this kind of file?

No, a desktop antivirus doesn't scan the hosting server's contents. You need either a dedicated server-side tool or a manual check of the files and their dates.
