Incident timeline
UTCA complete record of the incident, latest first. Search by event or filter by evidence source. All times are UTC; undated snapshots have no confirmed event time.
- Owner report
Malicious code reported; incident remains open
The site owner reports that the website is still infected with malicious code. Recovery is not confirmed. This owner report supersedes the earlier recovery-verification status; the code, entry point, and extent of infection have not been independently verified. The exact time of the finding was not supplied.
Link to this event ↗ - Live observation
Recovery verification update published
The initial status update records a fresh homepage check returning HTTP 200 with Elementor CSS, JavaScript, and page markup present. This differs from the earlier report. The check does not verify asset execution, all six pages, forms, videos, or email delivery.
Link to this event ↗ - Report timestamp
Original incident report prepared
The supplied HTML report carries an 11:00 UTC update stamp and describes the incident as active. That stamp establishes the report’s stated preparation time, not when a public status page became available.
Link to this event ↗ - Reported observation
Earlier verification reports degraded pages
Both supplied HTML files contain the same report: six published pages reportedly returned HTTP 200 with no plugin asset references, missing layouts, and degraded interactive elements. These are historical observations attributed to the report, not independently repeated checks at that time.
Link to this event ↗ - Time unconfirmed
No active plugins in the supplied snapshot
The active_plugins option is an empty serialized array. The exact export time and the time at which the list became empty are not established. This snapshot must not be read as the current live plugin state.
Link to this event ↗ - Database evidence
Recovery-mode email timestamp recorded
WordPress records its last recovery-mode email timestamp at this time. This is a recorded recovery signal, not a verified outage start or proof of email delivery. The precise fatal error and affected plugin or theme have not been identified.
Link to this event ↗ - Database evidence
Backup archive reference recorded
The export references a site archive whose filename encodes this timestamp. The archive itself was not supplied or restore-tested; its completeness and suitability for recovery remain unverified.
Link to this event ↗ - Report history
Recent page-builder editing reported
The supplied report describes edits to the Privacy Policy and Footer in Elementor. Editing records provide historical context but do not independently prove that all visitor-facing features worked at that time.
Link to this event ↗ - Database evidence
Migration extension deactivation recorded
The recorded entry is specifically All-in-One WP Migration Unlimited Extension. This timestamp should not be generalized to every migration plugin or every inactive plugin.
Link to this event ↗ - Database evidence
Perfmatters deactivation recorded
The same option records a separate timestamp for Perfmatters, 40 seconds after FluentSMTP. No causal connection to the September 6 incident has been established.
Link to this event ↗ - Database evidence
FluentSMTP deactivation recorded
The recently_activated option contains this deactivation timestamp for FluentSMTP. The export does not establish whether email delivery subsequently failed or whether the plugin was reactivated later.
Link to this event ↗ - Database evidence
Security scan action created
The exported Action Scheduler log records creation of the defender/async_scan action. It records a start at 15:10:20 and completion at 15:15:18. Completion of this action does not establish that the site was free of security issues.
Link to this event ↗ - Database evidence
Scheduler migration completes
The database export records the action_scheduler/migration_hook action as complete, with its last attempt at this time. This confirms the scheduler action completed, not that every part of the site migration succeeded.
Link to this event ↗ - Report history
Migration activity reported
The report describes migration to nea.cloud.mosiur.com using All-in-One WP Migration. The available evidence does not establish migration as the cause of the later incident.
Link to this event ↗ - Report history
Website content developed
The supplied report describes development of About, Platform, and Invitation pages, alongside media uploads. These activities predate the disruption.
Link to this event ↗ - Report history
Original site setup
The supplied report dates the original WordPress installation to this period. This is background context, not an incident trigger.
Link to this event ↗
No matching events. Try another search or source.
Evidence boundary. The exact infection start, entry point, and restoration time remain unknown. Historical HTTP 200 responses and plugin assets do not prove security recovery.
Latest update
UnresolvedInfection remains, according to the site owner
“site is still infected with malicious codes”
The owner’s latest report supersedes the earlier recovery-verification status. The previous appearance of Elementor assets does not establish that the site is clean.
The malicious code, entry point, and extent of infection have not been independently verified. No resolution ETA has been confirmed.
Visitor impact
Treat the affected website as untrusted while the reported infection remains unresolved. Avoid submitting sensitive information or downloading files from it until recovery is confirmed.
Earlier reports described broken layouts and interactive features on these pages. Their current individual status has not been reverified.