Discovering that your website has been compromised can be stressful. You may notice unexpected redirects, security warnings in browsers, unusual files on the server, spam being sent from your account, or alerts from search engines and security tools.
SSH access provides a powerful way to investigate suspicious activity, identify modified files, and restore a website to a healthy state. This guide explains common investigation techniques and best practices for cleaning an infected website.
Table of Contents
Step 1: Secure Access to Your Account
Before making any changes, secure all account access points.
Consider updating:
- Hosting account passwords
- FTP and SFTP passwords
- SSH credentials
- Database passwords
- CMS administrator accounts
If multiple users have access to the account, review and remove any accounts that are no longer required.
Step 2: Create a Backup
Before removing files or making changes, create a backup of the current website.
Even if the website is infected, a backup can help recover important data if something is accidentally deleted during the cleanup process.
Example command:
tar -czf emergency_backup.tar.gz public_html/
Store the backup in a safe location before proceeding.
Step 3: Look for Recently Modified Files
Many website compromises involve the creation or modification of files.
You can identify recently changed files using:
find . -type f -mtime -7
This command lists files modified during the last seven days.
To focus on PHP files only:
find . -type f -name "*.php" -mtime -2
Pay particular attention to:
- Upload directories
- Cache directories
- Temporary folders
- Unknown files with random names
Executable files inside media upload directories often deserve additional investigation.
Step 4: Search for Suspicious Code
Malicious scripts often contain functions that can execute hidden code or manipulate server processes.
You can search for commonly abused functions:
grep -rnw . --include=\*.php -e 'base64_decode'
grep -rnw . --include=\*.php -e 'eval('
grep -rnw . --include=\*.php -e 'shell_exec'
Finding these functions does not automatically mean a file is malicious. Some legitimate applications and plugins use them.
Always review the surrounding code before making decisions.
Step 5: Restore Core Application Files
If your website uses a popular content management system such as WordPress, Joomla, or PrestaShop, restoring the original application files is often safer than attempting to manually clean every modified file.
A common approach is:
- Download a clean copy from the official vendor.
- Replace the application’s core files.
- Preserve configuration files and user-generated content.
- Verify functionality after replacement.
Always follow the official upgrade and recovery procedures provided by the software vendor.
Step 6: Audit Themes, Plugins, and Extensions
Many compromises originate from outdated plugins, themes, or third-party extensions.
Review all installed components and:
- Remove anything unused
- Update supported extensions
- Reinstall suspicious components from official sources
- Replace abandoned software with actively maintained alternatives
If you cannot verify the integrity of a plugin or theme, reinstalling it from the official source is often the safest option.
Step 7: Review the Uploads Directory
Media directories should normally contain files such as:
- Images
- Documents
- Videos
- Audio files
Search for executable scripts:
find wp-content/uploads/ -type f -name "*.php"
The exact location will vary depending on your application.
Unexpected executable files in media directories should be investigated carefully.
Step 8: Check Log Files
Server and application logs often provide valuable information about how the compromise occurred.
Look for:
- Failed login attempts
- Unexpected administrative actions
- File uploads from unknown IP addresses
- Repeated requests to vulnerable scripts
Large log files can also consume significant storage space.
Step 9: Review Database Content
Website compromises do not always affect files. Attackers sometimes inject malicious content directly into the database.
Review:
- Administrator accounts
- Website settings
- Redirect configurations
- Stored scripts or embedded code
Remove any users, settings, or content that you cannot identify.
Step 10: Update and Harden the Website
Once the website has been cleaned:
- Update the CMS to the latest version
- Update plugins and themes
- Enable two-factor authentication where available
- Remove unused software
- Use strong passwords
- Enable automatic updates when possible
Regular maintenance significantly reduces the risk of future compromises.
Summary
Cleaning a compromised website requires a methodical approach. Begin by securing access, creating backups, and identifying modified files. Restore trusted application files, review plugins and themes, inspect logs and databases, and ensure all software is fully updated.
If you are unable to determine the source of the compromise or suspect that the infection is still active, consider restoring from a known clean backup or consulting a security specialist for a full audit.