Getting Potential Threats Anti-Malware Security and Brute-Force Firewall

cteq1

Active member
Sep 18, 2018
246
94
28
On new install, no addon theme/plugins added, only added Anti-Malware Security and Brute-Force Firewall plugin.

Getting these Potential Threats, can I just ignore it?

Potential Threats

* NOTE: These are probably not malicious scripts (but it's a good place to start looking IF your site is infected and no Known Threats were found).
?.../xxxxxx.xxx/wp-admin/includes/class-pclzip.php
?.../xxxxxx.xxx/wp-includes/js/json2.js
?.../xxxxxx.xxx/wp-includes/js/json2.min.js
?.../xxxxxx.xxx/wp-includes/js/tw-sack.js
?.../xxxxxx.xxx/wp-includes/js/tw-sack.min.js
?.../xxxxxx.xxx/wp-includes/js/jquery/jquery.form.min.js
?.../xxxxxx.xxx/wp-includes/js/jquery/jquery.schedule.js
?.../xxxxxx.xxx/wp-includes/js/tinymce/tiny_mce_popup.js
 

KomissarMinsky

Active member
Nov 13, 2018
339
128
43
Hi @cteq1

remove the 'high sensitivity' from Wordfence and all should be fine..

But truly, you should try a different solution - globalsiteguard.com free; signup then let me know what site and I'll give you 6 mths Premium.
OK?
 
  • Like
Reactions: cteq1

TassieNZ

Premium Uploader and Sometimes Hacker!
Jan 17, 2019
9,017
19,812
120
New Zealand
On new install, no addon theme/plugins added, only added Anti-Malware Security and Brute-Force Firewall plugin.

Getting these Potential Threats, can I just ignore it?

Potential Threats

* NOTE: These are probably not malicious scripts (but it's a good place to start looking IF your site is infected and no Known Threats were found).
?.../xxxxxx.xxx/wp-admin/includes/class-pclzip.php
?.../xxxxxx.xxx/wp-includes/js/json2.js
?.../xxxxxx.xxx/wp-includes/js/json2.min.js
?.../xxxxxx.xxx/wp-includes/js/tw-sack.js
?.../xxxxxx.xxx/wp-includes/js/tw-sack.min.js
?.../xxxxxx.xxx/wp-includes/js/jquery/jquery.form.min.js
?.../xxxxxx.xxx/wp-includes/js/jquery/jquery.schedule.js
?.../xxxxxx.xxx/wp-includes/js/tinymce/tiny_mce_popup.js
NO, you probably have NOT been hacked!

Anti-Malware Security and Brute-Force Firewall is a great plugin. I use it on every site in conjunction with WordFence. It even states in your post ... NOTE: These are probably not malicious scripts (but it's a good place to start looking IF your site is infected and no Known Threats were found). This is quite a normal result. Ignore unless you can see you have an issue.

The plugin creator Eli is a great guy and very helpful. You can e-mail him if you are worried. He even totally cleaned a site for me a long time ago. All at no charge.

TassieNZ :)
 
  • Like
Reactions: cteq1 and guguk

guguk

Well-known member
Jul 19, 2019
1,150
828
113
Ottoman Empire
NO, you probably have NOT been hacked!

Anti-Malware Security and Brute-Force Firewall is a great plugin. I use it on every site in conjunction with WordFence. It even states in your post ... NOTE: These are probably not malicious scripts (but it's a good place to start looking IF your site is infected and no Known Threats were found). This is quite a normal result. Ignore unless you can see you have an issue.

I agree with you. Some security checkers plugins detect some JS files are threats.

my advice to you @cteq1 check these file via notepad++ and compare with original files.
And also check your mail server have any unknown sending or SPF values.
Check .htaccess file.
Check wp-config file
Check functions.php file
check wp-admin folder if there any unknown php files.

If all check are good dont be scare at all
 
  • Like
Reactions: cteq1

Rubixvi

Well-known member
Trusted Uploader
NO, you probably have NOT been hacked!

Anti-Malware Security and Brute-Force Firewall is a great plugin. I use it on every site in conjunction with WordFence. It even states in your post ... NOTE: These are probably not malicious scripts (but it's a good place to start looking IF your site is infected and no Known Threats were found). This is quite a normal result. Ignore unless you can see you have an issue.

The plugin creator Eli is a great guy and very helpful. You can e-mail him if you are worried. He even totally cleaned a site for me a long time ago. All at no charge.

TassieNZ :)

Maybe, I find wordfence better to find files that don't belong really.
 
  • Like
Reactions: cteq1

cteq1

Active member
Sep 18, 2018
246
94
28
I dont think I was hacked as this was fresh domain with fresh install. After installing wordpress I installed wordfence and I got these errors, someone has to be very quick to hack in to this, especially its one of those free domain to learn/practice on. Thank you all.
 

zippy

New member
Feb 27, 2020
7
3
3
On new install, no addon theme/plugins added, only added Anti-Malware Security and Brute-Force Firewall plugin.

Getting these Potential Threats, can I just ignore it?

Potential Threats

* NOTE: These are probably not malicious scripts (but it's a good place to start looking IF your site is infected and no Known Threats were found).
?.../xxxxxx.xxx/wp-admin/includes/class-pclzip.php
?.../xxxxxx.xxx/wp-includes/js/json2.js
?.../xxxxxx.xxx/wp-includes/js/json2.min.js
?.../xxxxxx.xxx/wp-includes/js/tw-sack.js
?.../xxxxxx.xxx/wp-includes/js/tw-sack.min.js
?.../xxxxxx.xxx/wp-includes/js/jquery/jquery.form.min.js
?.../xxxxxx.xxx/wp-includes/js/jquery/jquery.schedule.js
?.../xxxxxx.xxx/wp-includes/js/tinymce/tiny_mce_popup.js

I had exactly the same errors immediately after installing the 'Anti-Malware Security and Brute-Force Firewall' plugin as I believe the virus definitions had not yet been installed. However, after obtaining a free key (right hand menu) all was good.
 

About us

  • Our community has been around for many years and pride ourselves on offering unbiased, critical discussion among people of all different backgrounds. We are working every day to make sure our community is one of the best.

Quick Navigation

User Menu