My server is compromised, and when I ssh to it, i get " WARNING: REMOTE HOST IDENTIFICATION HAS CHANGED!"
, I know it is because the SHA256 fingerprint is changed, and you can see the new one by an openssl command but I don't know from where I can check when it has changed? and Also I don't know how you(or the hacker) can change it?or what has happened that it is changed.
Please do not recommend me to unplug it from the network and etc, as I've already did that , and I just want to know when and how it has happened.