X7ROOT File Manager
Current Path:
/home/gfecatvj
home
/
gfecatvj
/
📁
..
📄
.bash_history
(37.51 KB)
📄
.bash_logout
(18 B)
📄
.bash_profile
(176 B)
📄
.bashrc
(124 B)
📁
.cache
📁
.cagefs
📁
.caldav
📁
.cl.selector
📁
.clwpos
📁
.composer
📁
.config
📄
.contactemail
(17 B)
📁
.cpanel
📁
.cphorde
📄
.dns
(10 B)
📁
.ftp-scan
📄
.ftpquota
(19 B)
📄
.gemrc
(140 B)
📁
.git
📄
.gitconfig
(48 B)
📁
.googleapps
📁
.htpasswds
📄
.imunify_patch_id
(106 B)
📄
.last.inodes
(7.2 KB)
📄
.lastlogin
(638 B)
📄
.myimunify_id
(102 B)
📁
.nc_plugin
📁
.pki
📁
.putty
📁
.razor
📁
.softaculous
📁
.spamassassin
📄
.spamassassinenable
(0 B)
📁
.sqmailattach
📁
.sqmaildata
📁
.ssh
📁
.subaccounts
📁
.trash
📄
.zshrc
(658 B)
📁
4abetter.us
📁
4abetter.us-old
📄
4abetterus
(602 B)
📄
WQA.html
(3.02 KB)
📁
_wildcard_.4abetter.us
📁
_wildcard_.gfects.com
📁
_wildcard_.qcoder.dev
📁
access-logs
📄
backup.zip
(428.54 MB)
📁
cache
📄
composer.json
(4 B)
📄
cpbackup-exclude.conf
(1 B)
📁
data
📁
etc
📁
gfects.com
📁
laravel-blog
📁
logs
📁
lscache
📁
mail
📁
perl5
📁
public
📁
public_ftp
📁
public_html
📄
public_html-v1.zip
(414.19 MB)
📄
public_html.zip
(831.98 MB)
📄
public_htmlbradly.zip
(436.81 MB)
📁
repositories
📄
scan_report-2025-07-04_03-25
(7.02 KB)
📁
site_publisher
📁
sites
📁
softaculous_backups
📁
softaculous_templates
📁
ssl
📁
tmp
📁
www
Editing: scan_report-2025-07-04_03-25
----------- SCAN REPORT ----------- TimeStamp: Thu, 3 Jul 2025 20:26:01 -0400 (/usr/sbin/cxs --background --clamdsock /var/clamd --dbreport --defapache nobody --doptions Mv --exploitscan --nofallback --filemax 100000 --noforce --html --ignore /etc/cxs/cxs.ignore.manual --options mMOLfSGchexdnwZDRru --noprobability --qoptions Mvh --quarantine /opt/cxs/quarantine --report /home/gfecatvj/scan_report-2025-07-04_03-25 --sizemax 1000000 --ssl --summary --sversionscan --timemax 30 --unofficial --user gfecatvj --virusscan --vmrssmax 2000000 --waitscan 0 --xtra /etc/cxs/cxs.xtra.manual) Scanning /home/gfecatvj: '/home/gfecatvj/access-logs' # Symlink to [/etc/apache2/logs/domlogs/gfecatvj] '/home/gfecatvj/.composer/vendor/symfony/console/Resources/bin/hiddeninput.exe' # MS Windows Binary/Executable [application/x-winexec] '/home/gfecatvj/.nc_plugin/hidden' # World writeable directory '/home/gfecatvj/.softaculous/installations.php' # Universal decode regex match = [universal decoder] '/home/gfecatvj/4abetter.us/wp-access.php' # Universal decode regex match = [universal decoder] '/home/gfecatvj/4abetter.us/wp-content/plugins/woocommerce/includes/admin/class-wc-admin-menus.php' # Universal decode regex match = [universal decoder] '/home/gfecatvj/4abetter.us/wp-content/plugins/woocommerce/src/Internal/Admin/Settings/PaymentsController.php' # Universal decode regex match = [universal decoder] '/home/gfecatvj/4abetter.us/wp-content/plugins/woocommerce/vendor/maxmind-db/reader/ext/maxminddb.c' # Suspicious file type [application/x-c] '/home/gfecatvj/public_ftp/incoming' # World writeable directory '/home/gfecatvj/public_html/rotexmailer-new.php' # Universal decode regex match = [universal decoder] # (quarantined to /opt/cxs/quarantine/cxsuser/gfecatvj/rotexmailer-new.php.1751590155_1) (decoded file [advanced decoder: 14 (depth: 1)]) ClamAV detected virus = [TO-37027.WEBSHEL.nc_l0gin_decoded_part_php.MD5-fa882bdafbc39ee6cf85573a91214b31.size-166204.UNOFFICIAL] '/home/gfecatvj/public_html/sites/gfine/item.php' # (quarantined to /opt/cxs/quarantine/cxsuser/gfecatvj/item.php.1751590260_1) (decoded file [depth: 1]) Known exploit = [Fingerprint Match (fp)] [RFI Exploit [P1419]] '/home/gfecatvj/public_html/sites/gfine/vendor/symfony/console/Resources/bin/hiddeninput.exe' # MS Windows Binary/Executable [application/x-winexec] '/home/gfecatvj/public_html/sites/qcoder/vendor/amphp/process/bin/windows/ProcessWrapper.exe' # MS Windows Binary/Executable [application/x-winexec] '/home/gfecatvj/public_html/sites/qcoder/vendor/amphp/process/bin/windows/ProcessWrapper64.exe' # MS Windows Binary/Executable [application/x-winexec] '/home/gfecatvj/public_html/sites/qcoder/vendor/symfony/console/Resources/bin/hiddeninput.exe' # MS Windows Binary/Executable [application/x-winexec] '/home/gfecatvj/public_html/sites/scus/vendor/lukasyelle/dusk-prodsafe/bin/chromedriver-linux' # Linux Binary/Executable [application/x-sharedlib] '/home/gfecatvj/public_html/sites/scus/vendor/lukasyelle/dusk-prodsafe/bin/chromedriver-win.exe' # MS Windows Binary/Executable [application/x-winexec] '/home/gfecatvj/public_html/sites/scus/vendor/php-ai/php-ml/bin/libsvm/svm-predict' # Linux Binary/Executable [application/x-executable] '/home/gfecatvj/public_html/sites/scus/vendor/php-ai/php-ml/bin/libsvm/svm-predict.exe' # MS Windows Binary/Executable [application/x-winexec] '/home/gfecatvj/public_html/sites/scus/vendor/php-ai/php-ml/bin/libsvm/svm-scale' # Linux Binary/Executable [application/x-executable] '/home/gfecatvj/public_html/sites/scus/vendor/php-ai/php-ml/bin/libsvm/svm-scale.exe' # MS Windows Binary/Executable [application/x-winexec] '/home/gfecatvj/public_html/sites/scus/vendor/php-ai/php-ml/bin/libsvm/svm-train' # Linux Binary/Executable [application/x-executable] '/home/gfecatvj/public_html/sites/scus/vendor/php-ai/php-ml/bin/libsvm/svm-train.exe' # MS Windows Binary/Executable [application/x-winexec] '/home/gfecatvj/public_html/sites/scus/vendor/symfony/console/Resources/bin/hiddeninput.exe' # MS Windows Binary/Executable [application/x-winexec] '/home/gfecatvj/public_html/sites/vendor/amphp/process/bin/windows/ProcessWrapper.exe' # MS Windows Binary/Executable [application/x-winexec] '/home/gfecatvj/public_html/sites/vendor/amphp/process/bin/windows/ProcessWrapper64.exe' # MS Windows Binary/Executable [application/x-winexec] '/home/gfecatvj/public_html/vendor/symfony/console/Resources/bin/hiddeninput.exe' # MS Windows Binary/Executable [application/x-winexec] '/home/gfecatvj/sites/radon/wp-content/plugins/akismet/akismet.php' # Script version check [OLD] [Akismet Anti-Spam v4.2.2 < v5.3.7] '/home/gfecatvj/sites/radon/wp-content/plugins/contact-form-7/wp-contact-form-7.php' # Script version check [OLD] [Contact Form 7 v5.5.6 < v6.0.6] '/home/gfecatvj/sites/radon/wp-content/plugins/google-analytics-for-wordpress/googleanalytics.php' # Script version check [OLD] [Google Analytics for WordPress by MonsterInsights v8.4.0 < v9.4.1] '/home/gfecatvj/sites/radon/wp-content/plugins/litespeed-cache/litespeed-cache.php' # Script version check [OLD] [LiteSpeed Cache v4.5.0.1 < v7.0.1] '/home/gfecatvj/sites/radon/wp-content/plugins/loginizer/loginizer.php' # Script version check [OLD] [Loginizer v1.7.0 < v2.0.0] '/home/gfecatvj/sites/radon/wp-content/plugins/w3-total-cache/CdnEngine_Ftp.php' # Regular expression match = [\n(?!\s*(//|\#|\*)).*\.ssh/] '/home/gfecatvj/sites/radon/wp-content/plugins/w3-total-cache/w3-total-cache.php' # Script version check [OLD] [W3 Total Cache v2.2.1 < v2.8.8] '/home/gfecatvj/sites/radon/wp-content/plugins/wordpress-seo/wp-seo.php' # Script version check [OLD] [Yoast SEO v18.4.1 < v24.9] '/home/gfecatvj/sites/radon/wp-includes/version.php' # Script version check [OLD] [Wordpress v5.6.2 < v6.8.1] '/home/gfecatvj/sites/realesbar/vendor/scrivo/highlight.php/test/detect/cpp/default.txt' # Suspicious file type [application/x-c] '/home/gfecatvj/sites/realesbar/vendor/scrivo/highlight.php/test/markup/cpp/function-title.txt' # Suspicious file type [application/x-c] '/home/gfecatvj/sites/realesbar/vendor/symfony/console/Resources/bin/hiddeninput.exe' # MS Windows Binary/Executable [application/x-winexec] '/home/gfecatvj/sites/realesbar-X/vendor/scrivo/highlight.php/test/detect/cpp/default.txt' # Suspicious file type [application/x-c] '/home/gfecatvj/sites/realesbar-X/vendor/scrivo/highlight.php/test/markup/cpp/function-title.txt' # Suspicious file type [application/x-c] '/home/gfecatvj/sites/realesbar-X/vendor/symfony/console/Resources/bin/hiddeninput.exe' # MS Windows Binary/Executable [application/x-winexec] '/home/gfecatvj/sites/restate/vendor/symfony/console/Resources/bin/hiddeninput.exe' # MS Windows Binary/Executable [application/x-winexec] '/home/gfecatvj/sites/vendor/symfony/console/Resources/bin/hiddeninput.exe' # MS Windows Binary/Executable [application/x-winexec] ----------- SCAN SUMMARY ----------- Scanned directories: 27469 Scanned files: 160712 Ignored items: 629 Suspicious matches: 45 Viruses found: 1 Fingerprint matches: 1 Data scanned: 9475.85 MB Scan peak memory: 455348 kB Scan time/item: 0.030 sec Scan time: 5682.900 sec
Upload File
Create Folder