Source Of The Suspicious Files Identified - Question | JoomShaper

Source Of The Suspicious Files Identified

Kostas Konstantinidis

Kostas Konstantinidis

Helix Framework 3 days ago

Following my previous message, the access log shows that the suspicious files were created through repeated POST requests to:

/index.php?option=com_ajax&plugin=helix3&format=json

The requests came from IP 169.58.30.114 on 26 August 2026 at 18:55–18:58. Immediately afterwards, the same IP successfully accessed the newly created nxproof files.

The site runs Joomla 6.1.3 and JCE 2.9.99.10. Please forward this to your security team and let us know whether a Helix3 patch or temporary protection is available.

Thank you.

0
7 Answers
Paul Frankowski
Paul Frankowski
Accepted Answer
Senior Staff 2 days ago #232593

Helix3 update is planned for today, it should help. By now use tips that I shared so far.


AT Pro - good :) I like all Akeeba products a lot.

0
Paul Frankowski
Paul Frankowski
Accepted Answer
Senior Staff 3 days ago #232566

Hi Kostas,

  1. I guess you don't have any firewall installed. Also that's why Joomla cannot handle attacts alone.
  2. What is full template name, or you do have "raw" helix3 template? And what version of Helix3 plugin.
  3. Where those files were uploaded, what folder ?
  4. Extra tips in "Hidden Content"
0
Kostas Konstantinidis
Kostas Konstantinidis
Accepted Answer
3 days ago #232569

Hi Paul,

Admin Tools 7.8.0 is installed and active. The template is JoomShaper Moview 3.0.2, using Helix3 Framework plugin 3.1.3. The files were created in:

/templates/ /templates/shaper_moview/ /templates/shaper_moview/layout/

The access log links their creation directly to repeated POST requests to the Helix3 Ajax endpoint mentioned above.

Thank you.

0
Paul Frankowski
Paul Frankowski
Accepted Answer
Senior Staff 3 days ago #232573

extra tip

Please from my documenation guide take code for .htaccess file and put that file inside folder/templates/shaper_moview/layout/ it my also help by now.


do you have Akeeba Tools Free/Core or PRO, becuase only PRO can really protect the site.

0
Paul Frankowski
Paul Frankowski
Accepted Answer
Senior Staff 3 days ago #232575

and yes,

0
Kostas Konstantinidis
Kostas Konstantinidis
Accepted Answer
3 days ago #232582

Admin Tools Professional 7.9.2 is now installed and UploadShield is fully enabled.

0
Kostas Konstantinidis
Kostas Konstantinidis
Accepted Answer
2 days ago #232594

Great, Thank you Paul

0