How to find malicious files on your website

Practical ways to spot injected and backdoor files: PHP where it shouldn’t be, recently modified files, obfuscated code and comparisons with clean copies.

How-to guideAdvanced2 min readUpdated

1. PHP files where they don’t belong

Uploads folders should contain images and documents only. Any .php file in wp-content/uploads or similar folders is suspicious. Also look for .php files disguised as images, such as logo.png.php or .ico files included from PHP.

2. Recently modified files

In System Info & Files then File Manager, sort folders by modification date. Files changed on a date you didn’t update anything — especially core files — deserve a look. Attackers sometimes fake dates, so this finds many but not all.

3. Obfuscated code

Open suspicious PHP files and look for:

  • eval(, assert( or create_function( with dynamic input
  • base64_decode, gzinflate, str_rot13 chains
  • Long lines of random-looking characters
  • $_POST, $_REQUEST or $_COOKIE values being executed
  • preg_replace with the /e modifier

Legitimate plugins use some of these functions occasionally; context matters. Random-looking blobs at the very top of a file are almost always malicious.

4. Unfamiliar files with plausible names

wp-configs.php, class-wp-cache-x.php, admin-ajax1.php next to real files.

5. Compare with a clean copy

Download the same version of your CMS, plugins and themes from their official sources and compare. Core files should match exactly. This is why rebuilding from fresh copies is more reliable than hunting file by file.

6. Check outside the website folder

Cron jobs you didn’t create, and unfamiliar files in your home folder.

After finding them

Don’t just delete them and carry on; follow My website has been hacked: what to do so the entry point is closed.

Popular

Tip: press / to search from any pageSee all results