Exact work depends on compromise depth, number of affected accounts, server access, source of infection, application condition, mail abuse, and whether the operating system can still be trusted.
Hacked cPanel and Linux server incident assessment
Suspicious files, web shells, injected code, and malicious redirects
Phishing-page and compromised website cleanup
Spam scripts, outbound mail abuse, and Exim-related investigation
Compromised users, cPanel accounts, passwords, and access review
Cron jobs, processes, persistence indicators, and suspicious paths
Blacklist-cause review and remediation guidance
Post-cleanup website, mail, service, and symptom validation
Hardening, monitoring, backup, rebuild, and management recommendations