Since this morning, I have received security alerts from OVHcloud for several Joomla websites hosted on OVH shared hosting.
OVHcloud reports a malicious file and temporarily blocks outbound requests and PHP mail sending on the hosting account.
The file reported is always:
/administrator/components/com_akeebabackup/installers/kickstart.txt
Akeeba Backup is up to date on these websites.
I compared the reported file from two different affected websites. The files are strictly identical
The file appears to be Akeeba Kickstart included with Akeeba Backup, not a modified or injected file.
Could you please confirm whether this file is expected to be present in this location, and whether it is safe/normal?
Also, do you know if OVHcloud may be falsely detecting this file as malware? If so, is there a recommended action: delete/rename this file, ignore the warning, or ask OVHcloud to whitelist it?
Thank you for your help.
Best regards,
Nicolas