Hello everyone, I wanted to share the solution I found for dealing with a malware issue on my server. I used Imunify 360 to conduct server-level scans and scheduled them to run at 3 am.
Upon inspection, I discovered that a significant number of files were infected, making it challenging for the initial full scan to detect every compromised file. However, after running scheduled scans for a week, Imunify 360 effectively removed the malware.
One notable observation was the creation of a theme file during the infection. I recommend checking your WordPress themes folder for any suspiciously named directories.
I’m confident in the malware removal because the user responsible for repeated unsuccessful login attempts is now unable to access the system. My suspicion is that the malware inserted a code in certain files, triggering a function to create a user. This user would then attempt to sign in, spreading the infection to other files.