High resource usage
CPU stays busy with an unknown process, the server becomes unusually slow or the load suddenly rises.
Linux · VPS · cPanel · aaPanel · Plesk
I investigate compromised Linux servers, VPS and hosting environments for suspicious processes, miners, outbound spam, phishing files, web shells, cron jobs, systemd services, users and SSH keys. The goal is to identify the entry path and persistence, not merely delete one detected file.
A single symptom is not proof of compromise, but several signs together call for prompt investigation.
CPU stays busy with an unknown process, the server becomes unusually slow or the load suddenly rises.
The IP sends mail, abuse notices arrive, SMTP is blocked or domains appear on blacklists.
Websites become infected again after a file cleanup or backup restoration.
New cron jobs, systemd services, users, SSH keys or executables in temporary directories appear.
Foreign pages, casino redirects, doorway pages or malicious downloads are hosted on the server.
The provider restricts the server due to abuse, outbound traffic or infected files.
Record symptoms, back up available data and retain relevant logs.
Review processes, connections, users, SSH, cron, systemd, web roots, databases and recent changes.
Check vulnerable CMS components and panels, stolen credentials, exposed services and exploit traces.
Stop malicious processes, isolate files, remove persistence and restore required components.
Rotate compromised credentials, update software and apply the necessary hardening.
Test sites and services, outbound connections, resource use and whether indicators return.
If an attacker obtained root access or system-file integrity cannot be established, promising a reliable manual cleanup would be misleading. In that case I recommend provisioning a clean server, migrating verified data and switching traffic only after validation.
Website cleanup focuses on CMS files and the database. A server incident also requires reviewing processes, users, SSH keys, cron, systemd, network connections and other sites in the same environment.
Sometimes, when the compromise is limited to a site or one user. With root compromise, a clean rebuild and verified data migration is safer.
Usually SSH with sufficient permissions, the control panel and hosting information. Access is shared privately and rotated after the work.
I provide scope and timing after the initial review. A limited incident may take several hours; multiple infected sites or system-level persistence takes longer.
No one can honestly guarantee that. I remove identified persistence, close the discovered entry path and provide concrete monitoring and hardening steps.
Incident review
Include the Linux distribution or panel, symptoms, number of sites and any hosting warning. Do not send passwords in the form.