Urgent WordPress malware cleanup needed for persistent PHP/auto_prepend infection
Бюджет: -
HOURLY / PART_TIME
⭐ 5.00 (3)
USA
wordpress-malware-removal
Предпочтительная квалификация
- Опыт: Эксперт
I need an experienced WordPress malware/security specialist to clean a hacked WordPress site on Namecheap shared hosting.
This is not a simple plugin issue. Known symptoms/findings:
- Browser DevTools shows an injected request to https://forecast-chaos.com/x9i32md/w1/la02
- Malware injects obfuscated inline JavaScript into the homepage
- Malicious MU-plugin found at /wp-content/mu-plugins/vista-tracker-ops.php
- .user.ini and .htaccess were repeatedly rewritten with auto_prepend_file
- Payload files included /wp-content/ed34bae7.php, /wp-content/.ed34bae7.php, and /wp-content/81b7e91f.php
- Fake/suspicious plugin wordpesso was found and removed
- Imunify360 detected/cleaned backdoor-related files including /wp-content/.sc_15c1a847/core_d1ac14b9.php
- The infection has recreated files after WordPress/PHP was triggered
I need someone who can:
- Find and remove the persistence/backdoor source, not just delete visible malware files
- Inspect .user.ini, .htaccess, MU-plugins, wp-content, plugins/themes, uploads, and access logs
- Repair or replace infected WordPress core/plugin/theme files safely
- Keep the site working if possible
- Provide a clear list of files changed/removed and recommended next steps
- Advise on credential resets and hardening after cleanup
Please reply with:
1. Your experience with WordPress auto_prepend_file malware/backdoors
2. How you would approach this case
3. Whether you can start immediately
4. Estimated time to contain and clean
5. What access you need
Открыть заказ
AI-черновик отклика
Короткий текст отклика для копирования в оффер: интерес + готовность работать.
Войдите, чтобы сгенерировать AI-черновик.
Войти