Did you see the
Courtesy Reminder that FreePBX v15 is EOL Starting 1 October 2025 ?
From your nice write-up
it looks pretty nasty, so checking that you hold on to back-ups saved externally from before the infection is probably wise.
why wait ?
No, please don’t, but good question, as this is currently not explicitly covered in the FAQ, although there is a clause about posting stuff that is not your own that includes some legalese on not breaking laws, etc. Generally, it does seem reasonable that the forums should not be used to distribute malware. To aid users in scanning their systems for infection, it is sufficient to post the hashes of the sick files. (As an aside, we offer a pastebin.freepbx.org as well, in case you have curious logs to share.)