0

I have a WordPress site sitting on a Docker container and which was infected by a malware. I noticed that when I try to remove the malware, it gets back again after a few seconds. When I run a process list, I can see a process 'sleep 3s' and which I am suspecting it checks if a malware file is present, and if not, downloads it again.

However I cannot find/kill the process which is calling this process because this container is not showing me the parent process. Additionally, the process changes its PID quickly.

What approach do you suggest to trace the parent malware doing the checks?

James
  • 123
  • 1
    I suggest you delete the container and start again with a focus on security & installing the latest versions since you do not seem to understand where or what the problem is. – Bib Nov 28 '23 at 12:26

0 Answers0