Who updates the wp-admin/core file?

There is no ‘core’ file in WP core files.

So if there is such file, you don’t have access to it and it gets modified, then you should be really concerned.

My guess would be that it’s some malware/backdoor script. And since it’s created by server script, then there is a chance you can’t access it with FTP client.

The easiest approach would be to try to delete it using some script, or maybe with web FTP (if your hosting provides one).

PS. Security scans will always be clean in such case. Most of the time these scanners are scanning only the front of your site. They don’t have access to all files placed on your server. On the other hand – if you used a scanner that really has access to your server, then it will have the same access as you (so that scanner won’t be able to scan that file, if you can’t access it).