Hello Rising Security Team,
I am reaching out to submit https://nationalgroupmgt.com for reclassification. The initial security event occurred on this website on August 6th and was fully remediated by August 13th.
Rising currently classifies this domain as Malicious according to VirusTotal.
Remediation:
- All 3 malicious files identified (Wordfence) and removed
- Both rogue admin accounts deleted
- All admin passwords rotated; WordPress auth salts regenerated (invalidated all sessions); MySQL database password rotated (wp-config.php is world-readable + webshell had RCE, so DB creds treated as exposed)
- Core files checksum-verified clean
- WooCommerce API keys/webhooks confirmed absent; checkout templates scanned for skimmer code — none found
- Cron and filesystem searched for additional persistence (secondary .woff2.php background pattern referenced in webshell code) — none found
- Residual malicious DB options purged; DISALLOW_FILE_EDIT enabled
Verification: Site load tested post-remediation, confirmed no longer serving malicious redirect; log integrity confirmed intact (anti-forensics routine present in webshell was never triggered). Post-incident hardening in progress: 2FA on all admin accounts, WAF deployment, PHP-execution blocking in uploads/, extended log retention, quarterly credential/plugin audits
If you have any questions, concerns, or require any additional details, please let me know and I will assist you as soon as possible.
|