MOSHGI.DEV
← Selected work

Incident Response

Client
Live breach, production website
Role
Forensics lead
Year
2026

The problem

A production marketing site was found compromised. The scope was unknown: how the attackers got in, how long they had been there, what they could still reach, and whether anything had been taken.

The approach

A full forensic investigation from server logs upward. Six distinct malicious components were identified, including a command-and-control implant that took its instructions from Ethereum smart contracts, a data-theft plugin exfiltrating site secrets on a schedule, a permanent admin backdoor, and a theme-level backdoor enabling passwordless account takeover. Unauthorised access was traced across hundreds of source addresses to reconstruct the timeline.

6
malware components
353
attacking IPs traced
24h
to full restoration

The outcome

Containment and restoration inside 24 hours of discovery: every malicious component removed, backdoors closed, two-factor enforced on all admin accounts, and login exposure cut by IP restriction. A structured report documented the timeline and indicators of compromise in enough detail to refer onward.

Built with

  • Digital forensics
  • Server log analysis
  • Linux
  • WordPress
  • MySQL