websites always have backdoor files generated with the suffix .php. Because no more .php files will be added to the site, think of using inotifywait to recursively monitor the entire site directory, find the newly created php file, and then delete it. In this way, as long as a backdoor file is created, it will be deleted immediately.
since I am not in operation and maintenance, I hope there is a boss who can help me. Currently, only newly created files are listed in one file.