MultiCmsManager

Suspicious files in uploads

PHP malware hidden in the uploads folder: how to catch it at once

The uploads folder should hold images and documents. A PHP file in there is almost always a backdoor.

The problem

The most writable folder is also the most attacked.

Vulnerable plugins, upload forms and nulled themes let attackers drop files into the uploads folder. From there a PHP backdoor can take the site back even after a clean-up.

The file often has an innocent name or a double extension, like cache.php or logo.php.jpg.

How it works

A scan that knows where to look.

  1. 1

    First scan

    The agent records the state of the site’s files, skipping caches and noisy folders.

  2. 2

    Later scans

    Every hour it looks for new or changed files, in short steps.

  3. 3

    Report

    A PHP file in uploads or a suspicious double extension triggers a critical alert, and you can view its content from the dashboard.

In detail

What gets flagged.

  • PHP files in wp-content/uploads and in Joomla media folders
  • Double extensions such as .php.jpg or .phtml
  • New or changed files elsewhere, compared with the previous scan
  • .htaccess, .user.ini and auto_prepend_file: where malware loads before the CMS
  • File content viewable from the dashboard, so you can decide without FTP

FAQ

Frequently asked questions

Why is a PHP file in uploads so suspicious?

Because WordPress and Joomla never put executable code there: that folder should only hold media and documents.

Does scanning slow the site down?

No, it runs in steps of a few seconds and skips caches and other plugins’ backups.

Try it on your clients’ sites.

During the beta we welcome agencies in small groups and set up the first sites together.