Skip to content
Mohammad Emmon Mohammad Emmon.

Malware Removal & Security

Untraceable Banknotes

No live shell — but a nulled plugin with a remote-fetch channel in every request

Delivered by Mohammad Emmon
01

The problem

This WooCommerce store had no live web-shell and no injected database code — but it was running a pirated (“nulled”) copy of Elementor Pro whose licensing code had been swapped out for attacker-supplied code. That code forged a fake “Agency tier” licence and, more importantly, re-routed Elementor's template downloads to a non-official server over unencrypted HTTP — a built-in channel to fetch and run remote content whenever the operator chose. A cluster of eight automated bot customer accounts had also been created.

02

What I did

  • Isolated the root cause to the nulled Elementor Pro upload — confirmed by every file sharing a single install timestamp — and read the injected code that writes a fake licence and hooks every outbound HTTP request.
  • Documented the template-rerouting behaviour (downloads redirected to a third-party host with SSL verification disabled) as the latent backdoor channel.
  • Confirmed the genuinely clean areas honestly: uploads, core files, wp-config, htaccess, cron, must-use plugins, and database content all showed no live payload.
  • Identified the eight bot customer accounts and the lower-severity exposures (an exposed error log, leftover backup and fingerprinting files).
03

The result

I gave the client a calibrated High verdict that matched the evidence: not a running web-shell, but untrusted third-party code with a remote-fetch channel that has to be treated as a compromise of trust. The fix was concrete — remove the nulled plugin and replace it with a genuine licensed copy, rotate credentials and keys, and clear the spam accounts — with the reasoning for the rating spelled out.

No live shell — but a nulled plugin with a remote-fetch channel in every request
04

What it proves

Not every finding is Critical. Rating this High, and showing why, is what makes the Critical ratings on the other cases mean something.

Mohammad Emmon

Delivered by

Mohammad Emmon

WordPress Malware Removal, Security, Ongoing Security Monitoring And Website Development

I'm a WordPress malware removal and security specialist — I've cleaned and secured over 10,000 sites. Once a site is safe, I can also build, run and automate the whole thing. Based in Dhaka, working worldwide.

  • 15,000+ sites secured
  • 745+ businesses
  • 96% come back

Worried about your site?

Think your WordPress site is hacked? Let's check it.