Anyone seen this weird directory after a hack?

4 replies
Last night my sites were hacked. Looks like a bunch of .php files were all modified within wordpress directories.

It also affected my folder where DLG (Sam Stephens download guard software) resides. That was the major problem because now I have to manually add customers who couldn't get their product.

Bluehost fixed it for me by restoring files in my public_html. I opted to leave the databases unchanged because as far as I can tell they were not compromised. But if they were I can go back and restore them too.

Anyway, I was looking through my files via FTP and I noticed a weird folder in my public_html called "scopbin".

It seems to be related to some way to execute encrypted PHP code. There is a single php file inside the directory with a bunch of stuff I don't understand.

Anyone ever seen this? I have done a bunch of Googling and can't tell is this is part of the attack or not. I've renamed the file to .xphp in the mean time so that it won't function, but I'm curious what this sucker is.

While we're on the subject, I'm at the point where I think I need better backup and protection versus what Bluehost offers.

What do YOU recommend as an ultimate solution to automate backups of all your sites?



I am not a develoer and I have no need for such a directory
#directory #hack #weird
  • Profile picture of the author rosetrees
    Originally Posted by Chris Thompson View Post

    While we're on the subject, I'm at the point where I think I need better backup and protection versus what Bluehost offers.
    This probably isn't the answer you want - I use a UK webhost who offers weekly or daily offsite backups. If anything happens to a site or to one of their servers, they can restore instantly from their off site backups. www.betterwebspace.com
    {{ DiscussionBoard.errors[5457160].message }}
  • Profile picture of the author sbucciarel
    Banned
    {{ DiscussionBoard.errors[5457641].message }}
  • Profile picture of the author Chris Thompson
    Hi sbucciarel,

    Yeah, I found the same thing too. And Sourcecop looks like something that developers use to obfuscate their code. Since I'm not a dev, I should need it right? So I assume someone had to put it there perhaps to obfuscate their own hacks on my site?
    {{ DiscussionBoard.errors[5457722].message }}
    • Profile picture of the author sbucciarel
      Banned
      Originally Posted by Chris Thompson View Post

      Hi sbucciarel,

      Yeah, I found the same thing too. And Sourcecop looks like something that developers use to obfuscate their code. Since I'm not a dev, I should need it right? So I assume someone had to put it there perhaps to obfuscate their own hacks on my site?
      Yep ... I would remove it entirely if you didn't install it.
      {{ DiscussionBoard.errors[5457777].message }}

Trending Topics