=== INVESTIGATION COMPLÈTE FAILLE AVADA === lundi 10 novembre 2025, 12:51:00 (UTC+0000) --- 1. VERSION AVADA/FUSION --- * Version: 3.11.6 Version: 7.11.6 --- 2. FICHIERS PHP DANS UPLOADS --- 5306066 5 -rw----r-- 1 senova users 29 juin 2 2022 /homez.863/senova/www/wp-content/uploads/wp-migrate-db/index.php 5306064 5 -rw-r--r-- 1 senova users 27 oct. 6 12:27 /homez.863/senova/www/wp-content/uploads/ithemes-security/logs/index.php --- 3. FICHIERS MODIFIÉS DEPUIS LE 4 NOV --- 10176275 41 -rw------- 1 senova users 40083 nov. 10 11:32 /homez.863/senova/www/wp-content/wflogs/attack-data.php 10176296 5 -rw------- 1 senova users 51 nov. 10 11:32 /homez.863/senova/www/wp-content/wflogs/template.php 10176272 5 -rw------- 1 senova users 51 nov. 10 11:32 /homez.863/senova/www/wp-content/wflogs/ips.php 10789910 905 -rw-r--r-- 1 senova users 828527 nov. 10 11:43 /homez.863/senova/www/wp-content/wflogs/rules.php 10789914 5 -rw------- 1 senova users 618 nov. 10 11:43 /homez.863/senova/www/wp-content/wflogs/config-livewaf.php 10789913 1673 -rw------- 1 senova users 1694519 nov. 10 11:43 /homez.863/senova/www/wp-content/wflogs/config-transient.php 12062505 25 -rw------- 1 senova users 21639 nov. 10 12:11 /homez.863/senova/www/wp-content/wflogs/config-synced.php 10176287 5 -rw------- 1 senova users 611 nov. 10 11:32 /homez.863/senova/www/wp-content/wflogs/config.php 10811891 5 -rw-r--r-- 1 senova users 1128 nov. 10 11:53 /homez.863/senova/www/wp-content/plugins/wp-super-cache/advanced-cache.php 10811968 5 -rw-r--r-- 1 senova users 1033 nov. 10 11:53 /homez.863/senova/www/wp-content/plugins/wp-super-cache/partials/rejected_user_agents.php 10811958 9 -rw-r--r-- 1 senova users 5980 nov. 10 11:53 /homez.863/senova/www/wp-content/plugins/wp-super-cache/partials/debug.php 10811957 37 -rw-r--r-- 1 senova users 33859 nov. 10 11:53 /homez.863/senova/www/wp-content/plugins/wp-super-cache/partials/advanced.php 10811969 5 -rw-r--r-- 1 senova users 586 nov. 10 11:53 /homez.863/senova/www/wp-content/plugins/wp-super-cache/partials/restore.php 10811971 5 -rw-r--r-- 1 senova users 1393 nov. 10 11:53 /homez.863/senova/www/wp-content/plugins/wp-super-cache/partials/tracking_parameters.php 10811966 9 -rw-r--r-- 1 senova users 5835 nov. 10 11:53 /homez.863/senova/www/wp-content/plugins/wp-super-cache/partials/preload.php 10811964 9 -rw-r--r-- 1 senova users 5093 nov. 10 11:53 /homez.863/senova/www/wp-content/plugins/wp-super-cache/partials/lockdown.php 10811960 13 -rw-r--r-- 1 senova users 12027 nov. 10 11:53 /homez.863/senova/www/wp-content/plugins/wp-super-cache/partials/easy.php 10811995 17 -rw-r--r-- 1 senova users 16154 nov. 10 11:53 /homez.863/senova/www/wp-content/plugins/wp-super-cache/rest/class.wp-super-cache-rest-update-settings.php 10811997 9 -rw-r--r-- 1 senova users 6990 nov. 10 11:53 /homez.863/senova/www/wp-content/plugins/wp-super-cache/rest/class.wp-super-cache-settings-map.php 10811990 5 -rw-r--r-- 1 senova users 421 nov. 10 11:53 /homez.863/senova/www/wp-content/plugins/wp-super-cache/rest/class.wp-super-cache-rest-get-stats.php 10811993 5 -rw-r--r-- 1 senova users 2813 nov. 10 11:53 /homez.863/senova/www/wp-content/plugins/wp-super-cache/rest/class.wp-super-cache-rest-test-cache.php 10811991 5 -rw-r--r-- 1 senova users 3092 nov. 10 11:53 /homez.863/senova/www/wp-content/plugins/wp-super-cache/rest/class.wp-super-cache-rest-get-status.php 10811985 5 -rw-r--r-- 1 senova users 926 nov. 10 11:53 /homez.863/senova/www/wp-content/plugins/wp-super-cache/rest/class.wp-super-cache-rest-delete-cache.php 10811999 9 -rw-r--r-- 1 senova users 6002 nov. 10 11:53 /homez.863/senova/www/wp-content/plugins/wp-super-cache/rest/load.php 10811988 5 -rw-r--r-- 1 senova users 369 nov. 10 11:53 /homez.863/senova/www/wp-content/plugins/wp-super-cache/rest/class.wp-super-cache-rest-get-plugins.php 10811986 5 -rw-r--r-- 1 senova users 1183 nov. 10 11:53 /homez.863/senova/www/wp-content/plugins/wp-super-cache/rest/class.wp-super-cache-rest-get-cache.php 10811989 9 -rw-r--r-- 1 senova users 4920 nov. 10 11:53 /homez.863/senova/www/wp-content/plugins/wp-super-cache/rest/class.wp-super-cache-rest-get-settings.php 10811994 5 -rw-r--r-- 1 senova users 507 nov. 10 11:53 /homez.863/senova/www/wp-content/plugins/wp-super-cache/rest/class.wp-super-cache-rest-update-plugins.php 10811992 5 -rw-r--r-- 1 senova users 947 nov. 10 11:53 /homez.863/senova/www/wp-content/plugins/wp-super-cache/rest/class.wp-super-cache-rest-preload.php 10812047 5 -rw-r--r-- 1 senova users 121 nov. 10 11:53 /homez.863/senova/www/wp-content/plugins/wp-super-cache/src/example.php 10811901 9 -rw-r--r-- 1 senova users 8119 nov. 10 11:53 /homez.863/senova/www/wp-content/plugins/wp-super-cache/inc/boost.php 10811904 9 -rw-r--r-- 1 senova users 6294 nov. 10 11:53 /homez.863/senova/www/wp-content/plugins/wp-super-cache/inc/delete-cache-button.php 10811906 5 -rw-r--r-- 1 senova users 701 nov. 10 11:53 /homez.863/senova/www/wp-content/plugins/wp-super-cache/inc/preload-notification.php 10812143 125 -rw-r--r-- 1 senova users 124819 nov. 10 11:53 /homez.863/senova/www/wp-content/plugins/wp-super-cache/wp-cache-phase2.php 10812142 9 -rw-r--r-- 1 senova users 6706 nov. 10 11:53 /homez.863/senova/www/wp-content/plugins/wp-super-cache/wp-cache-phase1.php 10811978 5 -rw-r--r-- 1 senova users 2398 nov. 10 11:53 /homez.863/senova/www/wp-content/plugins/wp-super-cache/plugins/multisite.php 10811976 13 -rw-r--r-- 1 senova users 8265 nov. 10 11:53 /homez.863/senova/www/wp-content/plugins/wp-super-cache/plugins/dynamic-cache-test.php 10811977 5 -rw-r--r-- 1 senova users 4086 nov. 10 11:53 /homez.863/senova/www/wp-content/plugins/wp-super-cache/plugins/jetpack.php 10811974 5 -rw-r--r-- 1 senova users 3969 nov. 10 11:53 /homez.863/senova/www/wp-content/plugins/wp-super-cache/plugins/badbehaviour.php 10811979 9 -rw-r--r-- 1 senova users 5171 nov. 10 11:53 /homez.863/senova/www/wp-content/plugins/wp-super-cache/plugins/wptouch.php 10811973 5 -rw-r--r-- 1 senova users 2889 nov. 10 11:53 /homez.863/senova/www/wp-content/plugins/wp-super-cache/plugins/awaitingmoderation.php 10811975 9 -rw-r--r-- 1 senova users 4570 nov. 10 11:53 /homez.863/senova/www/wp-content/plugins/wp-super-cache/plugins/domain-mapping.php 10811955 21 -rw-r--r-- 1 senova users 16492 nov. 10 11:53 /homez.863/senova/www/wp-content/plugins/wp-super-cache/ossdl-cdn.php 10812127 5 -rw-r--r-- 1 senova users 139 nov. 10 11:53 /homez.863/senova/www/wp-content/plugins/wp-super-cache/vendor/composer/autoload_namespaces.php 10812139 5 -rw-r--r-- 1 senova users 925 nov. 10 11:53 /homez.863/senova/www/wp-content/plugins/wp-super-cache/vendor/composer/platform_check.php 10812129 5 -rw-r--r-- 1 senova users 1266 nov. 10 11:53 /homez.863/senova/www/wp-content/plugins/wp-super-cache/vendor/composer/autoload_real.php 10812131 17 -rw-r--r-- 1 senova users 16378 nov. 10 11:53 /homez.863/senova/www/wp-content/plugins/wp-super-cache/vendor/composer/ClassLoader.php 10812130 5 -rw-r--r-- 1 senova users 888 nov. 10 11:53 /homez.863/senova/www/wp-content/plugins/wp-super-cache/vendor/composer/autoload_static.php 10812135 17 -rw-r--r-- 1 senova users 16143 nov. 10 11:53 /homez.863/senova/www/wp-content/plugins/wp-super-cache/vendor/composer/InstalledVersions.php 10812126 5 -rw-r--r-- 1 senova users 500 nov. 10 11:53 /homez.863/senova/www/wp-content/plugins/wp-super-cache/vendor/composer/autoload_classmap.php --- 4. FICHIERS CACHÉS PHP --- --- 5. VÉRIFICATION wp-config.php --- Dernières 30 lignes: define('LOGGED_IN_SALT', '%RZ+3jVO;J$$.=9;q[-|7{nJUYbEJP7K4P{YicLgFk-@'); /**#@-*/ /** * WordPress Database Table prefix. * * You can have multiple installations in one database if you give each a unique * prefix. Only numbers, letters, and underscores please! */ $table_prefix = 'wpSenova_'; /** * For developers: WordPress debugging mode. * * Change this to true to enable the display of notices during development. * It is strongly recommended that plugin and theme developers use WP_DEBUG * in their development environments. */ define('WP_DEBUG', false); /* That's all, stop editing! Happy blogging. */ /** Absolute path to the WordPress directory. */ if ( !defined('ABSPATH') ) define('ABSPATH', dirname(__FILE__) . '/'); /** Sets up WordPress vars and included files. */ require_once(ABSPATH . 'wp-settings.php'); --- 6. CODE SUSPECT DANS wp-config.php ---