Thanks for the help, All!
Back online for now, and at least know where to start should this happen again.
Time to back-up and change credentials!
Truly appreciate the insight.
So I need to delete everything in the root directory except the wp-config.php and the /wp-content? folder, but couldn’t those files include malicious code from the initial hack as well?
Will the core file restore alter the look and feel of the website once completed?
Is there also a way to prevent this from occurring in the future?
I appreciate the help on this.