Further, here is the email I received from 1&1 when I returned home, can you please look at this :
A few minutes ago, our security systems detected unusual e-mail activity on your webspace.
Dispatch of the e-mails was initiated by the following files on your webspace:
~/SCCMAD/index.php
Details about the incident:
Sender: info@sccmad.org
Date sent: 2019-07-17 05:55:05 UTC
Number of e-mails: 35
Number of delivery attempts: 35
Country of originating IP: 103.73.x.x (HK), 103.73.x.x (HK), 2001:19f0x
x
x (US), 2001:19f0
x
x
x (US), 212.227.x.x (DE)
Recipient domain: sccmad.org, qq.com, outlook.comTo stop the sending of e-mails and prevent further misuse of your contract, we have locked the files listed above.