• WordPress.com
  • Forums
  • Plans & Pricing
  • Log In
  • Get Started
  • WordPress Hosting
  • Domain Names
  • Website Builder
  • Create a Blog
  • Newsletter
  • Professional Email
  • Website Design Services
  • Commerce
  • Enterprise
  • Overview
  • WordPress Themes
  • WordPress Plugins
  • WordPress Patterns
  • Google Apps
  • WordPress.com Support
  • News
  • Website Building Tips
  • Business Name Generator
  • Logo Maker
  • Popular Topics
  • Daily Webinars
  • Learn WordPress
Get Started
  • Sign Up
  • Log In
About
  • Plans & Pricing
Products
  • WordPress Hosting
  • Domain Names
  • Website Builder
  • Create a Blog
  • Newsletter
  • Professional Email
  • Website Design Services
  • Commerce
  • Enterprise
Features
  • Overview
  • WordPress Themes
  • WordPress Plugins
  • WordPress Patterns
  • Google Apps
Resources
  • WordPress.com Support
  • News
  • Website Building Tips
  • Business Name Generator
  • Logo Maker
  • Popular Topics
  • Daily Webinars
  • Learn WordPress
en WordPress.com Forums I keep getting hacked

I keep getting hacked

  • viralinnature · Member · Jan 15, 2025 at 3:01 pm
    • Copy link Copy link
    • Add topic to favorites Add topic to favorites

    I have a reseller package with Bluehost for the past 11 years. They stopped selling reseller packages about a decade ago so I know the server I am on is from 2009. Very outdated. On Dec 9, several sites in my WHM got hacked. I’ve gone through a long checklist of all the things to do such as change passwords, 2FA, even changed computers.
    This one site in particular I recently did the following:

    1. Deleted all ftp accounts, MySQL databases, all files, everything so basically starting from scratch.

    2. Installed a fresh copy of WordPress and a maintenance mode plugin.

    Sure enough, it took about 48 hours for it to be hacked again. The files they are adding are as follows:
    robots.txt
    simple.php
    chosen.php
    .htaccess (modified)
    groupon.php
    sample.php
    .user.ini
    index.php (modified)
    network.php

    I could really use some help or even a point in the right direction if you know the name of this hack. One person told me it might be the Japanese Keyword Hack.

    The blog I need help with is: (visible only to logged in users)

  • staartmees · Member · Jan 15, 2025 at 3:27 pm
    • Copy link Copy link

    We can’t help as the wordpress.com platform has nothing to do with any other hosting platform. Only Bluehost support can help.

  • magefix · Member · Jan 16, 2025 at 1:20 pm
    • Copy link Copy link

    Hello, I recently fixed a server with the same issue & wrote about it. Most likely, the server setup is not properly configured. If the “chosen.php” file keeps coming back, the attackers may’ve triggered PHP scripts in the background.

    More info:

    • https://wordpress.org/support/topic/i-keep-getting-hacked-even-on-fresh-install/#post-18247530
Reply to I keep getting hacked
Log in or get started with WordPress.com to reply Login Sign Up

Tags

  • .org
  • account
  • design

About this topic

  • In: Support
  • 3 participants
  • 2 replies
  • Last activity 1 week
  • Latest reply from viralinnature
Advertisment

WordPress.com

WordPress.com WordPress.com Logo

Products

  • WordPress Hosting
  • Domain Names
  • Website Builder
  • Create a Blog
  • Professional Email
  • P2: WordPress for Teams
  • Website Design Services
  • Enterprise Solutions

Features

  • Overview
  • WordPress Themes
  • WordPress Plugins
  • WordPress Patterns
  • Google Apps

Resources

  • WordPress.com Support
  • WordPress Forums
  • WordPress News
  • Website Building Tips
  • Business Name Generator
  • Logo Maker
  • Discover New Posts
  • Popular Tags
  • Blog Search
  • Daily Webinars
  • Learn WordPress
  • Developer Resources

Company

  • About
  • Partners
  • Press
  • Terms of Service
  • Privacy Policy
  • Do Not Sell or Share My Personal Information
  • Privacy Notice for California Users

Language

Mobile Apps

  • Download on the App Store
  • Get it on Google Play

Social Media

  • WordPress.com on Twitter Twitter Icon
  • WordPress.com on Facebook Facebook Icon
  • WordPress.com on Instagram Instagram Icon
  • WordPress.com on YouTube Youtube Icon
An Automattic experiment
Work With Us
    • WordPress.com Forums
    • Sign up
    • Log in
    • Copy shortlink
    • Report this content
    • Manage subscriptions