Wouldn’t any malware incidents be listed in the actual Imunfy360 panel already
The CLI command provided is an analogue for Malicious tab highlights the same data:
Useful to check if any infected files remain not cleaned/deleted on a server but no content differences.
If there is nothing on the Dashboard, this means the detected attack was an attempt to access a non-existing backdoor on the VPS. In general access to dot files is an attempted reconnaissance, while a request for a shell like "wso112233.php" (Web Shell by oRb) doesn't necessarily mean the server has been compromised but an attacker/bot to discover a known web shell by path.
I hope this clarifies the ModSec incident nature and provides some comfort )
Thank you for staying vigilant!
Leave a comment: