Back to work
WordPressSiteGroundSSHClient project

Hacked WordPress subdomains cleanup

Malware removal

Diagram of the cleanup in three stages, find, clean and lock down, repeated for every subdomain

The problem

A client’s domain, hosted on SiteGround, had many WordPress sites on subdomains. Most of them were hacked. When we checked the files, we found backdoors: hidden code that lets an attacker get back in after a normal cleanup.

What we did

Abner worked through the sites one by one, about 20 subdomains in total.

  1. Access. He got SSH access to the hosting, so every file could be checked directly on the server, not only through the WordPress dashboard.
  2. Backup first. Every site was backed up before anything was changed.
  3. Find. He rechecked all files for malware and traced the backdoor code.
  4. Clean. He removed the infected files, the injected code and the backdoors, and cleaned the database.
  5. Lock down. He removed unknown users, revoked auto-login, created new database users with new passwords, and improved the security settings.

Why the backdoors matter

A hacked site that is only partly cleaned often gets reinfected within days, because the attacker still has a way in. Removing the backdoors and changing every database user and password closes those ways in, so the cleanup lasts.

The honest note

This was real client work, so the client and the domain are not named, and we have no screenshots of it. The diagram on this page shows the steps, not the client’s site.