I have a website with Joomla and 404shSEF installed. The component logs all 404 requests and the log is really interesting. The site is getting requests on components and also a file called this: "7c334.php". Here an example:
wp-admin/admin-ajax.php
wp-content/plugins/contus-video-gallery/hdflvplayer/download.php
wp-content/plugins/document_manager/views/file_download.php
wp-content/themes/antioch/lib/scripts/download.php
wp-content/themes/epic/lib/scripts/download.php
wp-content/themes/trinity/lib/scripts/download.php
ftpchk3.php
image?format=raw&id=30&type=img&view=image
image?format=raw&id=31&type=img&view=image
image?format=raw&id=45&type=img&view=image
images/post.php
images/stories/explore.php
images/stories/petx.php
modules/7c334.php
modules/7c34.php
modules/mod_banners/sysm.php
modules/mod_search/tmpl/index.php
modules/mod_xsystemx/7c334.php
modules/mod_xsystemx/7c34.php
Is this "normal scanning" behaviour or should I be concerned? The passwords are safe, or at least should be strong enough on the site, and the scripts are always actual. Are these requests made to all websites? I have scanned the site on sucuri and everything looks normal.
 
     
     
    