MadsDK
Regular Member
- Aug 16, 2022
- 383
- 191
Hi
I have been fighting a tough battle for the past week against a hacker who keeps injecting malware into my file manager and I have no idea how this is possible and how to fix it once and for all.
I have since I discovered the malware files:
And the hacker continues to be able to inject malware into my websites. I have also not been able to find out which website(s) are being accessed through.
The same files are constantly being changed (wp-config, wp-settings, index.php) and the same files, with the same names, are being uploaded.
WordFence allows me to see which suspicious pages people are visiting. Here's a screenshot of some of them for one of my websites:

These seem very suspicious to me, but they could also just be bots trying to find weaknesses and not the actual hacker.
I hired someone a few days ago to remove backdoors, malicious files, etc. from a scan report, but these files just come right back again, and BlueHost is not very helpful. I am therefore writing in here, hoping that there is someone who has been in the same situation and found the solution.
I have been fighting a tough battle for the past week against a hacker who keeps injecting malware into my file manager and I have no idea how this is possible and how to fix it once and for all.
I have since I discovered the malware files:
- Changed all passwords
- Updated all my plugins and themes
- Installed WordFence, and through Festinger got the premium version.
- Activated 2FA
- Of course, removed all malware that WordFence finds and also what the scan report from BlueHost shows.
- Blocked most of the world from accessing my websites, so only my top geographies can access my sites.
And the hacker continues to be able to inject malware into my websites. I have also not been able to find out which website(s) are being accessed through.
The same files are constantly being changed (wp-config, wp-settings, index.php) and the same files, with the same names, are being uploaded.
WordFence allows me to see which suspicious pages people are visiting. Here's a screenshot of some of them for one of my websites:

These seem very suspicious to me, but they could also just be bots trying to find weaknesses and not the actual hacker.
I hired someone a few days ago to remove backdoors, malicious files, etc. from a scan report, but these files just come right back again, and BlueHost is not very helpful. I am therefore writing in here, hoping that there is someone who has been in the same situation and found the solution.