Yes… you are right Lisa, apparently a few days a go, another user from this webhost experienced the same issue. His images folder has been breached too… Here’s his comment:
Anyway. I have logged onto said account via FTP, and there is something really suss. There is a directory in /images/ called “RBC_files” with what appears to have no permissions set. I change permissions to 777 via FTP, but the permissions dont actually change.
The attributes on this directory say that the “RBC_files” directory was added at 9:33am this morning. I can honestly tell you that this directory was NOT added by anyone who should have.
When I try to delete this said directory, it boots me off the server and i have to reconnect via FTP.
A google search of “RBC_files” does not look promising.
it appears your server is under some sort of phishing attack!!!! Especially considering the other accounts.
EDIT: confirmed!
if i visit - mydomain.com.au/images it takes me to a fake internet banking site called - RBC financial group.!!! I definitely did not put this here.
There are several sus files. -
/images/
login.php
index.html
update.html
and heaps of .gif’s
I have now removed all files from /images/ from said account. EXCEPT the directory “RBC_files” which i am unable to remove….
I suggest others who are on the Aussie server to check their /images/ directory for the above files and folders.