Skip to content
Mohammad Emmon Mohammad Emmon.

Malware Removal & Security

Solace Boats

WordPress security forensics across 146,000 log events — entry vector proven, not guessed

Delivered by Mohammad Emmon
01

The problem

Solace Boats was serving “fake popups” to visitors and couldn't shake the infection even after installing security tooling. Underneath were two malicious files: a fake “page-ftp-sitemap” plugin that hid itself from the plugin list and exposed an unauthenticated remote-code-execution dispatcher with a magic-key admin backdoor, and a 116KB must-use plugin that injected heavily-obfuscated JavaScript to non-logged-in visitors only — the source of the popups.

02

What I did

  • Completed a file-level forensic pass and decoded both malicious files — the AES-encrypted RCE dispatcher and magic-key backdoor in the fake plugin, and the visitor-only obfuscated JS injector in the must-use plugin.
  • Analysed the database and, crucially, the WordPress Activity Log's 146,000 events to prove the entry vector: the fake plugin was installed under a legitimate but compromised admin account from an anomalous foreign IP — credential theft, not an exploit-install.
  • Corrected the patient-zero date using the activity log rather than the (later, re-touched) file timestamp, and identified a second suspicious admin account and the attacker's ongoing control after security tooling was added.
  • Documented the outstanding vulnerable components (file-manager, Ultimate Member, WooCommerce Payments, an exposed hardcoded API key) for rotation and patching.
03

The result

Unlike a database-only case, here I could prove rather than infer the entry vector: stolen admin credentials used to install a self-hiding backdoor that persisted even after Wordfence went in. That moved the recommendation decisively to server-level investigation, full credential rotation, and isolated hosting — and gave the client a defensible, timeline-backed account of exactly how their site was taken and why a surface clean would not hold.

WordPress security forensics across 146,000 log events — entry vector proven, not guessed
04

What it proves

This is what WordPress security forensics is for. A guess about the way in is not a finding. The activity log made it a fact. It named the account. It gave the IP. It gave the date and the time. That is a case, not a theory. The log did the work here. It is the one place a hacked WordPress site keeps a plain record of who did what. Most sites never turn it on. This one had.

Mohammad Emmon

Delivered by

Mohammad Emmon

WordPress Malware Removal, Security, Ongoing Security Monitoring And Website Development

I'm a WordPress malware removal and security specialist — I've cleaned and secured over 10,000 sites. Once a site is safe, I can also build, run and automate the whole thing. Based in Dhaka, working worldwide.

  • 15,000+ sites secured
  • 745+ businesses
  • 96% come back

Worried about your site?

Think your WordPress site is hacked? Let's check it.