Malicious files keeps coming back over and over again
-
So I’ve been having issues with malicious files over the period of last month or so. It started off initially with the host completely locking my account due to malicious/dangerous files being on the site. It happens, sure I’ve pretty much deleted the whole site and the database, so starter again completely from scratch. It is a relatively simple site, with 5 pages, no comments, no search, no users.
Since the initial incident took extra measures, on the site itself and the host, changed the host password to random generated one, all WordPress logins to random generated 20 character passwords, all FTP passwords etc.Approximately every 3 days, a malicious file gets uploaded, which is an obfuscated .ico file that is then linked normally via wp-config, wp-settings, index.php each time I revert any changes and remove the malicious files (literally for them to come back within days).
With regards to WordPress, it is up to date on version 5.2.2, plugin wise all up to date, only uses a handful of plugins, most used by 100k+ installations:
Coming Soon Page & Maintenance Mode by SeedProd
Easy Facebook Likebox
Elementor
Loginizer
UpdraftPlus – Backup/Restore
WebDefender Security – only installed this one very recently
Wordfence Security
WP Security Audit Log
WPForms LiteTheme wise, again out of the box, only 1 theme installed on the site being Twenty Nineteen and all up to date.
I’ve had a look through Hardening WordPress, secured wp-includes folder, completely disabled file editing via WordPress, scanned all the machines which are used to access the site (there are only 2). The site is set-up through CloudFlare as well.
From a host perspective, the site is hosted on the standard shared hosting. Support are relatively useless, as each time they just lock the site until the files are removed rather than helping with any kind of logs. The most I managed to get out of them is that the malicious files were not uploaded via FTP as there were no logs of them.At this stage, I think I’m stuck just pulling my hair out, as tried everything I could, but it’s hitting my head against the wall. Any tips or ideas?
- The topic ‘Malicious files keeps coming back over and over again’ is closed to new replies.