Details of malware below - this email was sent from the host who supplies the VPS. I will supply Plesk login and wordpress.
this is the website: [login to view URL]
----------------------------------------------------
I’m writing to inform you that we have detected malicious requests from the IP [login to view URL] directed at our clients’ servers.
As a result of these attacks, we have added your IP to our greylist to prevent it from attacking our clients’ servers.
Servers are increasingly exposed as the targets of botnet attacks and you might not be aware that your server is being used as a “bot” to send malicious attacks over the Internet.
I've collected the 3 earliest logs below, and you can find the freshest 100, that may help you disinfect your server, under the link. The timezone is UTC +2:00.
[login to view URL]
2020-04-13 11:57:35
BL_WEB_HONEYPOT_DELIST_BADURL
Url: [###.ma###[login to view URL]]
Remote connection: [[login to view URL]]
Headers: [array (
'Host' => '###.ma###[login to view URL]',
'Accept' => '*/*',
'BN-Frontend' => 'captcha-https',
'X-Forwarded-Port' => '443',
'X-Forwarded-Proto' => 'https',
'X-Forwarded-For' => '[login to view URL]',
)]
Get data: [Array
(
[y] => 2002
[m] => 1" and "x"="y
)
]
2020-04-13 11:57:35
BL_WEB_HONEYPOT_DELIST_BADURL
Url: [###.ma###[login to view URL]"%20and%20"x"%3D"x]
Remote connection: [[login to view URL]]
Headers: [array (
'Host' => '###.ma###[login to view URL]',
'Accept' => '*/*',
'BN-Frontend' => 'captcha-https',
'X-Forwarded-Port' => '443',
'X-Forwarded-Proto' => 'https',
'X-Forwarded-For' => '[login to view URL]',
)]
Get data: [Array
(
[y] => 2002
[m] => 1" and "x"="x
)
]
2020-04-13 11:57:35
More info about this type of incident: [login to view URL]
BL_WEB_HONEYPOT_DELIST_BADURL
Url: [###.ma###[login to view URL]]
Remote connection: [[login to view URL]]
Headers: [array (
'Host' => '###.ma###[login to view URL]',
'Accept' => '*/*',
'BN-Frontend' => 'captcha-https',
'X-Forwarded-Port' => '443',
'X-Forwarded-Proto' => 'https',
'X-Forwarded-For' => '[login to view URL]',
)]
Get data: [Array
(
[y] => 2002
[m] => 1' and 'x'='y
)
]
Please keep in mind that after the first intrusion we log all traffic between your server and the BitNinja-protected servers until the IP is removed from the greylist. This means you may see valid logs beside the malicious actions in the link above. If you need help finding the malicious logs, please don’t hesitate to contact our incident experts by replying to this e-mail.
For more information on analyzing and understanding outbound traffic, check out this:
[login to view URL]
Hi There,
Thanks for your project. First sorry for the attack that your website has been exposed to. I have great experience in wordpress Security and can quickly cleanup your website and strengthen security to thwart any future attacks.
Regards
$50 USD in 1 day
5.0 (160 reviews)
6.5
6.5
7 freelancers are bidding on average $54 USD for this job
Hello Sir, I need to go through your whole server and check each file and folder manually.I also need to check Database. I am ready to start right now. Thanks
Hello
Hope you are doing well.
I have 7 years of experience in wordpress and web security.
I can remove malware and make your website secure.
Regards
VishnuLal*
Hi there,
I will be able to clean your site and make it secure by today evening only.
Please share the website details so I can check the things and move ahead with the work to make the site secure.
I can provide the maximum security of your site. I will take a complex security audit + install security plugins + setup files/folders permissions + setup .htaccess rules + my private trick = unbreakable site.
Please award me the project so I can move ahead with the work now.
Looking forward to your positive response and a great working relationship.
Thank You..!!!
Hi!
i understand your requirement . I have good expertise on php, wordpress,html,css, Javascript. I can Remove malware from Wordpress site.
Please ping me for quality work on time
waiting for your positive response
Thanks.
Warmest Regards,
Ramakrishna Panigrahi