Also, I received an email from the host for this site (WP Engine):
“This email was generated from the WP Engine ‘TimThumb Scanner’ application. We’ve updated the version of the TimThumb script in account ‘[xxxx]’.
— Found version 2.8.14 ../wp content/plugins/connections/vendor/timthumb/timthumb.php
– Replaced with 220.127.116.11
It has been updated to the most recent stable version, for your security, and ours. Learn more about it here, http://wpengine.com/2011/11/timthumb-script-scanner/.”