Checking my access logs this morning, there are 3-4 weird lines. Got an email from the hosting company saying 'we detected malicious code, clean it immediately' but i don't understand what's going on. Logged in via SSH, checked ps aux and saw some sketchy processes. There are weird .php files in the temp folder in the file manager.
Server is Linux running Apache. Wordpress is installed but i don't know if this happened because i haven't updated in the last 3-4 months. I wanted to check again but i don't even know what to look for. Hosting company said 'clean it urgently or we'll shut you down', writing this while stressed out.
Anyone have experience with this? How do you find where the attack started? Is deleting the files enough or do i need to do something else?