# Website shows default "Welcome to nginx!" page - account if0\_42062124

**URL:** https://forum.infinityfree.com/t/website-shows-default-welcome-to-nginx-page-account-if0-42062124/120998
**Category:** Hosting Support
**Created:** [October 1, 2026, 7:56am UTC](https://forum.infinityfree.com/t/website-shows-default-welcome-to-nginx-page-account-if0-42062124/120998 "2026-10-01T07:56:52Z")
**Posts on this page:** 2
**Page:** 1

<div class="post-metadata">

### Author: ![Simbakarate](https://forum.infinityfree.com/user_avatar/forum.infinityfree.com/simbakarate/32/67758_2.png) [@Simbakarate](https://forum.infinityfree.com/u/Simbakarate)
#### Post date: [October 1, 2026, 7:56am UTC](https://forum.infinityfree.com/t/website-shows-default-welcome-to-nginx-page-account-if0-42062124/120998/1 "2026-10-01T07:56:52Z")

</div>

### Website URL

[https://simbakarate.it/](https://simbakarate.it/)

### Error Message

Both simbakarate.it and [simbakarate.infinityfree.me](http://simbakarate.infinityfree.me) show the default “Welcome to nginx!” page instead of my WordPress site.

### Other Information

The site has been down for about a week. It worked until late September. I haven’t changed anything.

- Account: if0\_42062124
- Client area status: Active, both domains listed
- Website IP: 185.27.134.127 (DNS resolves correctly)
- Nameservers: [ns1-ns5.byet.org](http://ns1-ns5.byet.org) (unchanged)

Could this be related to the “Account stuck in processing” incident? Please check and restore my account on the server.

Thank you,  
Giuseppe

---

<div class="post-metadata">

### Author: ![Admin](https://forum.infinityfree.com/user_avatar/forum.infinityfree.com/admin/32/36437_2.png) [@Admin](https://forum.infinityfree.com/u/Admin)
#### Post date: [October 1, 2026, 11:27am UTC](https://forum.infinityfree.com/t/website-shows-default-welcome-to-nginx-page-account-if0-42062124/120998/3 "2026-10-01T11:27:14Z")

</div>

I checked your website, and I se the issue: your website has been hacked.

The “Welcome to nginx!” page resembles the page you’d see if you just installed the NGINX web server software and are seeing the default page. But that doesn’t make sense on our hosting, because that’s not a page you would see with us.

A quick look at your website code showed the issue. The `index.php` file in your htdocs folder does not look like a regular WordPress file at all. There is a lot of obfuscated code in there, code that has been deliberately garbled to make it hard to read and understand. That’s a classic sign of malware trying to hide its identity.

I wrote some steps for another case last week about another WordPress site that got infected. I recommend that you follow the same steps:

> [@Mobile browsers receive 403 from /aes.js browser-security challenge, desktop works](https://forum.infinityfree.com/t/mobile-browsers-receive-403-from-aes-js-browser-security-challenge-desktop-works/120876/2#p-422725-what-to-do-now-2):
>
> I spent more time than I should on this issue, but it was a strange case that piqued my curiosity. But I’m happy to say I found the issue: Your website is infected with malware. What’s going on It’s not a hosting problem. There is a hidden plugin in your website in the iframe-redirect folder that hijacks the page requests and shows a full screen iframe referring to another website. And that other website is returning the 403 error you see. It’s not from our hosting and not from Cloudflare (nei…
