forumNew topic

Unknown processes running on my server, hosting company said 'clean it up' — where do i start?

YYusuf E***Member
Job title
Gym owner
Organization type
workshop
Joined
Apr 2024
Message
66
#1

Checking my access logs this morning, there are 3-4 weird lines. Got an email from the hosting company saying 'we detected malicious code, clean it immediately' but i don't understand what's going on. Logged in via SSH, checked ps aux and saw some sketchy processes. There are weird .php files in the temp folder in the file manager.

Server is Linux running Apache. Wordpress is installed but i don't know if this happened because i haven't updated in the last 3-4 months. I wanted to check again but i don't even know what to look for. Hosting company said 'clean it urgently or we'll shut you down', writing this while stressed out.

Anyone have experience with this? How do you find where the attack started? Is deleting the files enough or do i need to do something else?

FFiliz U***Member
Job title
Social media manager
Sector
Consulting
Organization type
two-branch business
Joined
Sep 2025
Message
1
Most Helpful#2

If WordPress hasn't been updated, it's very likely they got in through a plugin exploit. Do these steps immediately: 1) Cut the server's internet connection (work in a backup environment), 2) Check /var/log/auth.log and /var/log/apache2/access.log — record login times and IPs, 3) Backup the found PHP files (as evidence), 4) Scan the web root for '.php' files with grep — check against upload dates, 5) Reinstall WordPress from scratch, only restore the database. There might be shell code remnants in the database too, so check that.

DDoruk A***Member
Job title
General coordinator
Sector
Automotive aftermarket
Organization type
20-person company
Joined
Oct 2022
Message
18

Doki · Penetration test · 2024

#3

had the same thing last year, they got in via a wordpress plugin exploit. i ran a query with wpdb back then, an admin account had been added to the wp_users table. i deleted that admin but there was still shell code in the file system, it was actually an executable disguised as a .jpg file. tbh the hosting company said they were done...

MMehmet M***Member
Job title
Digital marketing specialist
Sector
Education
Organization type
regional distributor
Joined
Nov 2025
Message
302
#4

To find the webshell, run this query with find: find /var/www -name '*.php' -newermt '3 months ago' | xargs file | grep 'PHP script'. Filter POST requests in the access logs, especially for file upload endpoints. You can run WPScan for vulnerability scanning, but isolating the network is critical first. Check the siteurl and home URLs in the wp_options table in the database, they might have been changed.

NNecati B***MemberCommunity member
Joined
Dec 2024
Message
86
#5

Wow thats a bad situation. Anyway, you seem pretty panicked. The first thing to do is really take a backup then disable plugins and themes one by one. Log into WP admin, check the users. They might have found a new admin account. Then install a security plugin, install WP updates. If you have problems again after a while, then contact the hosting company.

JJale P***MemberCommunity member
Joined
Mar 2024
Message
207
#6

Think of it as a cybersecurity review: step 1) Cut off network traffic, 2) Take a system snapshot, 3) Find vulnerabilities (web shell, database user, cron job), 4) Identify the entry mechanism (which plugin, which account, when), 5) Deletion and restoration. In WordPress, it's usually due to missing plugin updates or weak passwords. We had a similar situation on a site last week, the database password was hardcoded in wp-config.php, phpmyadmin was open...

JJülide A***MemberCommunity member
Joined
Aug 2024
Message
1
#7

It seemed a bit odd to me, does the hosting company immediately tell you if there's malicious code? They detected it on their own systems. If you could log into SSH, it means you still have access... Were you able to check the database too? So is the exploit still active, or did they just forget the shell? When was your last backup? If you want to go the restore route can you restore from an old backup?

EEmine K***MemberCommunity member
Joined
Jan 2026
Message
296
#8

oh no, wordpress hacking... that's really bad. but keep it simple: just go back to the latest backup. restore mysql and files. tbh then update wp everything... it'll be thoroughly cleaned up like that. also have the hosting company check it, pass it to them.

ZZafer Ö***Member
Job title
Production planning
Sector
Machinery manufacturing
Organization type
a company within a holding
Joined
Apr 2023
Message
247
#9

Thanks, that was the answer I was looking for. Forgotten test environments are more often the entry point than live systems.

Correct me if I'm wrong.

EEmre A***MemberCommunity member
Joined
Nov 2024
Message
1
#10

Just a heads-up. The biggest time-waster for us was not knowing who had the final say.

If you get three different answers on a topic, the question was asked wrong. Good luck with that.

RRıdvanMember
Job title
Dealer network manager
Organization type
regional distributor
Joined
Mar 2024
Message
92
#11

Saved.

DDamla P***MemberCommunity member
Joined
May 2024
Message
191
#12

I felt relieved reading this answer, so its not just me. Processes without records never improve because you dont know what to fix.

That's all, sorry if I went on too long.

ÖÖmer I***VeteranCommunity member
Joined
Jul 2024
Message
50
#13

You're right. If the notification path is long, notifications don't arrive; missing notifications mean delayed incident detection.

If I were you, I'd go this route.

LLevent B***MemberCommunity member
Joined
Aug 2025
Message
186
#14

The answer above hits the nail on the head. Trying to do this alone is the most expensive way.

Of course, it varies if your situation is different.

AAli D***Member
Job title
Social media manager
Sector
Tourism
Organization type
boutique agency
Joined
Jul 2024
Message
114
#15

My questions are cleared up, thanks.

EEfe G***New memberCommunity member
Joined
May 2026
Message
222
#16

I didn't know that.

DDamla C***Member
Job title
Customer Relations Manager
Sector
Printing
Organization type
300-person organization
Joined
Nov 2022
Message
229
#17

Exactly, and not many people know this. If you scold false alarms, nobody will report again.

HHüseyin T***MemberCommunity member
Joined
Jun 2025
Message
292
#18

You're right, I've been down that road too. If 2FA is on, a stolen password alone is useless.

If you have questions, write them; I'll answer as best I can.

IIrmak T***Veteran
Job title
System support specialist
Sector
Logistics
Organization type
120-person company
Joined
Nov 2023
Message
226
#19

I have no experience with virus on my server, so I'm asking. Payment information changes are never verified through the channel they came from.

I'm also curious if anyone does it differently.

ÜÜlkü K***Member
Job title
Board member
Sector
Agriculture
Organization type
cooperative
Joined
Jan 2025
Message
19

Doki · Infrastructure migration · 2025

#20

You're right. People defend habits, not processes. Resistance comes from there.

If you post the result here, it will help others too.

Reply