{"id":10550,"date":"2026-06-12T09:53:12","date_gmt":"2026-06-12T07:53:12","guid":{"rendered":"https:\/\/mybox.com\/help\/?post_type=manual_kb&#038;p=10550"},"modified":"2026-06-12T09:53:14","modified_gmt":"2026-06-12T07:53:14","slug":"how-to-investigate-and-clean-a-compromised-website-using-ssh","status":"publish","type":"manual_kb","link":"https:\/\/mybox.com\/help\/en\/knowledgebase\/how-to-investigate-and-clean-a-compromised-website-using-ssh\/","title":{"rendered":"How to Investigate and Clean a Compromised Website Using SSH"},"content":{"rendered":"\n<div class=\"translation-block translation-block-merged\">\n<p class=\"wp-block-paragraph\">Discovering that your website has been compromised can be stressful. You may notice unexpected redirects, security warnings in browsers, unusual files on the server, spam being sent from your account, or alerts from search engines and security tools.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">SSH access provides a powerful way to investigate suspicious activity, identify modified files, and restore a website to a healthy state. This guide explains common investigation techniques and best practices for cleaning an infected website.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_86 ez-toc-wrap-left counter-hierarchy ez-toc-counter ez-toc-custom ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Table of Contents<\/p>\n<span class=\"ez-toc-title-toggle\"><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/how-to-investigate-and-clean-a-compromised-website-using-ssh\/#Step_1_Secure_Access_to_Your_Account\" >Step 1: Secure Access to Your Account<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/how-to-investigate-and-clean-a-compromised-website-using-ssh\/#Step_2_Create_a_Backup\" >Step 2: Create a Backup<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/how-to-investigate-and-clean-a-compromised-website-using-ssh\/#Step_3_Look_for_Recently_Modified_Files\" >Step 3: Look for Recently Modified Files<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/how-to-investigate-and-clean-a-compromised-website-using-ssh\/#Step_4_Search_for_Suspicious_Code\" >Step 4: Search for Suspicious Code<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/how-to-investigate-and-clean-a-compromised-website-using-ssh\/#Step_5_Restore_Core_Application_Files\" >Step 5: Restore Core Application Files<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/how-to-investigate-and-clean-a-compromised-website-using-ssh\/#Step_6_Audit_Themes_Plugins_and_Extensions\" >Step 6: Audit Themes, Plugins, and Extensions<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-7\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/how-to-investigate-and-clean-a-compromised-website-using-ssh\/#Step_7_Review_the_Uploads_Directory\" >Step 7: Review the Uploads Directory<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-8\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/how-to-investigate-and-clean-a-compromised-website-using-ssh\/#Step_8_Check_Log_Files\" >Step 8: Check Log Files<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-9\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/how-to-investigate-and-clean-a-compromised-website-using-ssh\/#Step_9_Review_Database_Content\" >Step 9: Review Database Content<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-10\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/how-to-investigate-and-clean-a-compromised-website-using-ssh\/#Step_10_Update_and_Harden_the_Website\" >Step 10: Update and Harden the Website<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-11\" href=\"https:\/\/mybox.com\/help\/en\/knowledgebase\/how-to-investigate-and-clean-a-compromised-website-using-ssh\/#Summary\" >Summary<\/a><\/li><\/ul><\/nav><\/div>\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Step_1_Secure_Access_to_Your_Account\"><\/span>Step 1: Secure Access to Your Account<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<\/div>\n\n<div id=\"mybox-2671767582\" class=\"mybox-content mybox-entity-placement\"><div class=\"early-access-banner-inpost\">\r\n  <div class=\"banner-left-inpost\">\r\n    <div class=\"icon-box-inpost\">\r\n      <img decoding=\"async\" src=\"https:\/\/mybox.com\/help\/wp-content\/uploads\/2026\/02\/square-info-icon.svg\" alt=\"Info\">\r\n    <\/div>\r\n    <div class=\"text-box-inpost\">\r\n      <span class=\"label-inpost\"><span class=\"translation-block translation-block-banner-text\">Early access<\/span><\/span>\r\n      <h4><span class=\"translation-block translation-block-banner-text\">Still need help?<\/span><\/h4>\r\n      <p><span class=\"translation-block translation-block-banner-text\">Contact our customer service team.<\/span><\/p>\r\n    <\/div>\r\n  <\/div>\r\n\r\n  <div class=\"banner-right-inpost\">\r\n    <a href=\"https:\/\/panel.mybox.com\/helpdesk2\/v\/list\/\" class=\"banner-button-inpost\"><span class=\"translation-block translation-block-banner-text\">Message us<\/span><\/a>\r\n  <\/div>\r\n<\/div><\/div>\n\n<div class=\"translation-block translation-block-merged\"><p class=\"wp-block-paragraph\">Before making any changes, secure all account access points.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Consider updating:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Hosting account passwords<\/li>\n\n\n\n<li>FTP and SFTP passwords<\/li>\n\n\n\n<li>SSH credentials<\/li>\n\n\n\n<li>Database passwords<\/li>\n\n\n\n<li>CMS administrator accounts<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">If multiple users have access to the account, review and remove any accounts that are no longer required.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Step_2_Create_a_Backup\"><\/span>Step 2: Create a Backup<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Before removing files or making changes, create a backup of the current website.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Even if the website is infected, a backup can help recover important data if something is accidentally deleted during the cleanup process.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Example command:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>tar -czf emergency_backup.tar.gz public_html\/\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Store the backup in a safe location before proceeding.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Step_3_Look_for_Recently_Modified_Files\"><\/span>Step 3: Look for Recently Modified Files<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Many website compromises involve the creation or modification of files.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">You can identify recently changed files using:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>find . -type f -mtime -7\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">This command lists files modified during the last seven days.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">To focus on PHP files only:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>find . -type f -name \"*.php\" -mtime -2\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Pay particular attention to:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Upload directories<\/li>\n\n\n\n<li>Cache directories<\/li>\n\n\n\n<li>Temporary folders<\/li>\n\n\n\n<li>Unknown files with random names<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Executable files inside media upload directories often deserve additional investigation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Step_4_Search_for_Suspicious_Code\"><\/span>Step 4: Search for Suspicious Code<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Malicious scripts often contain functions that can execute hidden code or manipulate server processes.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">You can search for commonly abused functions:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>grep -rnw . --include=\\*.php -e 'base64_decode'\n<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>grep -rnw . --include=\\*.php -e 'eval('\n<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-code\"><code>grep -rnw . --include=\\*.php -e 'shell_exec'\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Finding these functions does not automatically mean a file is malicious. Some legitimate applications and plugins use them.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Always review the surrounding code before making decisions.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Step_5_Restore_Core_Application_Files\"><\/span>Step 5: Restore Core Application Files<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">If your website uses a popular content management system such as WordPress, Joomla, or PrestaShop, restoring the original application files is often safer than attempting to manually clean every modified file.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A common approach is:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Download a clean copy from the official vendor.<\/li>\n\n\n\n<li>Replace the application&#8217;s core files.<\/li>\n\n\n\n<li>Preserve configuration files and user-generated content.<\/li>\n\n\n\n<li>Verify functionality after replacement.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">Always follow the official upgrade and recovery procedures provided by the software vendor.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Step_6_Audit_Themes_Plugins_and_Extensions\"><\/span>Step 6: Audit Themes, Plugins, and Extensions<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Many compromises originate from outdated plugins, themes, or third-party extensions.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Review all installed components and:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Remove anything unused<\/li>\n\n\n\n<li>Update supported extensions<\/li>\n\n\n\n<li>Reinstall suspicious components from official sources<\/li>\n\n\n\n<li>Replace abandoned software with actively maintained alternatives<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">If you cannot verify the integrity of a plugin or theme, reinstalling it from the official source is often the safest option.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Step_7_Review_the_Uploads_Directory\"><\/span>Step 7: Review the Uploads Directory<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Media directories should normally contain files such as:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Images<\/li>\n\n\n\n<li>Documents<\/li>\n\n\n\n<li>Videos<\/li>\n\n\n\n<li>Audio files<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Search for executable scripts:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>find wp-content\/uploads\/ -type f -name \"*.php\"\n<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">The exact location will vary depending on your application.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Unexpected executable files in media directories should be investigated carefully.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Step_8_Check_Log_Files\"><\/span>Step 8: Check Log Files<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Server and application logs often provide valuable information about how the compromise occurred.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Look for:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Failed login attempts<\/li>\n\n\n\n<li>Unexpected administrative actions<\/li>\n\n\n\n<li>File uploads from unknown IP addresses<\/li>\n\n\n\n<li>Repeated requests to vulnerable scripts<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Large log files can also consume significant storage space.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Step_9_Review_Database_Content\"><\/span>Step 9: Review Database Content<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Website compromises do not always affect files. Attackers sometimes inject malicious content directly into the database.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Review:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Administrator accounts<\/li>\n\n\n\n<li>Website settings<\/li>\n\n\n\n<li>Redirect configurations<\/li>\n\n\n\n<li>Stored scripts or embedded code<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Remove any users, settings, or content that you cannot identify.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Step_10_Update_and_Harden_the_Website\"><\/span>Step 10: Update and Harden the Website<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Once the website has been cleaned:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Update the CMS to the latest version<\/li>\n\n\n\n<li>Update plugins and themes<\/li>\n\n\n\n<li>Enable two-factor authentication where available<\/li>\n\n\n\n<li>Remove unused software<\/li>\n\n\n\n<li>Use strong passwords<\/li>\n\n\n\n<li>Enable automatic updates when possible<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Regular maintenance significantly reduces the risk of future compromises.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Summary\"><\/span>Summary<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Cleaning a compromised website requires a methodical approach. Begin by securing access, creating backups, and identifying modified files. Restore trusted application files, review plugins and themes, inspect logs and databases, and ensure all software is fully updated.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If you are unable to determine the source of the compromise or suspect that the infection is still active, consider restoring from a known clean backup or consulting a security specialist for a full audit.<\/p>\n<\/div>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"template":"","format":"standard","manualknowledgebasecat":[10],"manual_kb_tag":[3354,4285,4286,4287,4288,4289,4290,889,1605,3344],"class_list":["post-10550","manual_kb","type-manual_kb","status-publish","format-standard","hentry","manualknowledgebasecat-safety","manual_kb_tag-compromised-website","manual_kb_tag-website-cleanup","manual_kb_tag-website-forensics","manual_kb_tag-incident-response","manual_kb_tag-file-integrity-monitoring","manual_kb_tag-suspicious-code-detection","manual_kb_tag-malicious-script-detection","manual_kb_tag-web-security","manual_kb_tag-malware-removal","manual_kb_tag-infected-website"],"_links":{"self":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb\/10550","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb"}],"about":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/types\/manual_kb"}],"author":[{"embeddable":true,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/users\/1"}],"version-history":[{"count":1,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb\/10550\/revisions"}],"predecessor-version":[{"id":10551,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb\/10550\/revisions\/10551"}],"wp:attachment":[{"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/media?parent=10550"}],"wp:term":[{"taxonomy":"manualknowledgebasecat","embeddable":true,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manualknowledgebasecat?post=10550"},{"taxonomy":"manual_kb_tag","embeddable":true,"href":"https:\/\/mybox.com\/help\/en\/wp-json\/wp\/v2\/manual_kb_tag?post=10550"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}