Urgent WordPress malware cleanup needed for persistent PHP/auto_prepend infection
Budget: -
HOURLY / PART_TIME
⭐ 5.00 (3)
USA
wordpress-malware-removal
Qualifications préférées
- Expérience : Expert
I need an experienced WordPress malware/security specialist to clean a hacked WordPress site on Namecheap shared hosting.
This is not a simple plugin issue. Known symptoms/findings:
- Browser DevTools shows an injected request to https://forecast-chaos.com/x9i32md/w1/la02
- Malware injects obfuscated inline JavaScript into the homepage
- Malicious MU-plugin found at /wp-content/mu-plugins/vista-tracker-ops.php
- .user.ini and .htaccess were repeatedly rewritten with auto_prepend_file
- Payload files included /wp-content/ed34bae7.php, /wp-content/.ed34bae7.php, and /wp-content/81b7e91f.php
- Fake/suspicious plugin wordpesso was found and removed
- Imunify360 detected/cleaned backdoor-related files including /wp-content/.sc_15c1a847/core_d1ac14b9.php
- The infection has recreated files after WordPress/PHP was triggered
I need someone who can:
- Find and remove the persistence/backdoor source, not just delete visible malware files
- Inspect .user.ini, .htaccess, MU-plugins, wp-content, plugins/themes, uploads, and access logs
- Repair or replace infected WordPress core/plugin/theme files safely
- Keep the site working if possible
- Provide a clear list of files changed/removed and recommended next steps
- Advise on credential resets and hardening after cleanup
Please reply with:
1. Your experience with WordPress auto_prepend_file malware/backdoors
2. How you would approach this case
3. Whether you can start immediately
4. Estimated time to contain and clean
5. What access you need
Ouvrir sur Upwork
AI proposal draft
Generate a short cover letter for this job. Edit before sending.
Sign in to generate an AI proposal draft.
Connexion