Identifying if Revive has been compromised/hacked

Hi all,

Started working with a company who has Revive v3 currently installed.
Started several weeks back, we began experiencing traffic spikes originating from some suspicious domains:

Reading up on these traffic sources, it appears they are adware/malware.

My question - could this all be happening because of an outdated version of Revive that has been compromised?


Thanks for your time and help Andrew.
We're talking a Revive implementaiton that is 7+ years old and has never been updated..... yah.. I was thrown into this mess.

Andrew - could you direct me to any resources where I can find the necessary talent to diagnose/fix/secure our Revive implementaiton?


^correction, 4+ years old

Ech. Outside of the advice on that link above, it's a pretty thankless task trying to clean up a hacked server. You can try the usual places (here on the forums, UpWork, etc.) but I don't often see people wanting to pick up those kinds of jobs.

Best thing I would do is start with a fresh server, and a fresh install, and create the campaigns etc. you need from scratch. It's a lot of boring work, but it's not really any less boring that trying to clean out a hacked instance, and will probably be faster and give a safer, more reliable result.

