Magento Malware Cleanup & Report
Budget: $30 – $50 AUD
My Magento store is currently flagged by Nexcess for possible malware. I have their scan report and need a hands-on specialist to manually confirm every alert, and clean the installation without breaking live sales.
Work required
• Perform a fresh, manual malware scan that follows the exact paths and hashes Nexcess identified.
• Quarantine, repair, or safely remove every malicious or suspicious file, keeping clear records of each action.
• Apply any missing Magento security patches and extension updates once the site is clean.
• Verify front-end, admin panel, checkout, and cron jobs all run normally after remediation.
• Produce a detailed PDF/Markdown report summarising findings, actions taken, and recommendations to keep the site secure.
Acceptance criteria
– No malware flagged by a repeat Nexcess scan and common tools such as maldet or clamscan.
– Store functions (browse, add to cart, checkout, admin login) operate exactly as before or better.
– Detailed report delivered within the agreed timeframe.
SSH/SFTP and Magento admin credentials will be provided after project award.
Nexcess Report
During the routine scans of our systems, we found malicious files in one or more of your web sites.
Don't worry, we've already quarantined this malware for you!
Here's what you should do next:
PLEASE CHECK YOUR SITE
Is your site still up? Does everything look normal?
MY SITE IS UP AND EVERYTHING SEEMS FINE
That's great! It's possible the vulnerability that allowed the attack is still there, however, and there may be additional malware present.
OH NO, MY SITE IS BROKEN!
The malware may have affected a core file in your site. You can use the technical information below to identify the file or files that need to be cleaned or restored.
In either case, we recommend that you do a thorough inspection of your site for any additional malware, and a thorough review and audit of your site to ensure that security updates are being applied and good security practices are being followed. You can do the work yourself, with a developer, or hire a malware-remediation service provider.
For our customers with WordPress sites, Nexcess offers malware remediation for /usr/local/maldetect/sess/session.260209-2236.1263400 per incident. If you'd like to take advantage of that service, open a ticket with Support and include the malware details information below.
Once your site is cleaned up and returned to normal, be sure to secure your site to guard against future infections. Here's our guide to how to do that:
https://www.nexcess.net/help/secure-your-compromised-site/
MALWARE DETAILS
Below are details of the affected files:
________________________________________
TOTAL HITS: 7
FILE HIT LIST:
/chroot/home/a779e1cc/901e4459aa.nxcli.net/pub/media/customer_address/s/e/sess_m7ik6nh1vdfgjozszop4xx8hv56y48tu
/chroot/home/a779e1cc/901e4459aa.nxcli.net/pub/media/customer_address/s/e/sess_jieptfz2a9se13vitpu3c7hu94g8tg6j
/chroot/home/a779e1cc/901e4459aa.nxcli.net/pub/media/customer_address/s/e/sess_v80266wqibb6ilqnfl5t4ihqdl8523nm
/chroot/home/a779e1cc/901e4459aa.nxcli.net/pub/media/customer_address/s/e/sess_7sdutkrtwwn2cx70k9cr4xsb8jpggwod
/chroot/home/a779e1cc/901e4459aa.nxcli.net/pub/media/customer_address/s/e/sess_6bdgu7g60j13ayic2mi5ibbwkx098hfo
/chroot/home/a779e1cc/901e4459aa.nxcli.net/pub/media/customer_address/s/e/sess_ado60kr9ws4bha7sorahxeehenha38o7
/chroot/home/a779e1cc/901e4459aa.nxcli.net/pub/media/customer_address/s/e/sess_xdc1iet50eepsuk9z69243ppm5vrtcwy
Work required
• Perform a fresh, manual malware scan that follows the exact paths and hashes Nexcess identified.
• Quarantine, repair, or safely remove every malicious or suspicious file, keeping clear records of each action.
• Apply any missing Magento security patches and extension updates once the site is clean.
• Verify front-end, admin panel, checkout, and cron jobs all run normally after remediation.
• Produce a detailed PDF/Markdown report summarising findings, actions taken, and recommendations to keep the site secure.
Acceptance criteria
– No malware flagged by a repeat Nexcess scan and common tools such as maldet or clamscan.
– Store functions (browse, add to cart, checkout, admin login) operate exactly as before or better.
– Detailed report delivered within the agreed timeframe.
SSH/SFTP and Magento admin credentials will be provided after project award.
Nexcess Report
During the routine scans of our systems, we found malicious files in one or more of your web sites.
Don't worry, we've already quarantined this malware for you!
Here's what you should do next:
PLEASE CHECK YOUR SITE
Is your site still up? Does everything look normal?
MY SITE IS UP AND EVERYTHING SEEMS FINE
That's great! It's possible the vulnerability that allowed the attack is still there, however, and there may be additional malware present.
OH NO, MY SITE IS BROKEN!
The malware may have affected a core file in your site. You can use the technical information below to identify the file or files that need to be cleaned or restored.
In either case, we recommend that you do a thorough inspection of your site for any additional malware, and a thorough review and audit of your site to ensure that security updates are being applied and good security practices are being followed. You can do the work yourself, with a developer, or hire a malware-remediation service provider.
For our customers with WordPress sites, Nexcess offers malware remediation for /usr/local/maldetect/sess/session.260209-2236.1263400 per incident. If you'd like to take advantage of that service, open a ticket with Support and include the malware details information below.
Once your site is cleaned up and returned to normal, be sure to secure your site to guard against future infections. Here's our guide to how to do that:
https://www.nexcess.net/help/secure-your-compromised-site/
MALWARE DETAILS
Below are details of the affected files:
________________________________________
TOTAL HITS: 7
FILE HIT LIST:
/chroot/home/a779e1cc/901e4459aa.nxcli.net/pub/media/customer_address/s/e/sess_m7ik6nh1vdfgjozszop4xx8hv56y48tu
/chroot/home/a779e1cc/901e4459aa.nxcli.net/pub/media/customer_address/s/e/sess_jieptfz2a9se13vitpu3c7hu94g8tg6j
/chroot/home/a779e1cc/901e4459aa.nxcli.net/pub/media/customer_address/s/e/sess_v80266wqibb6ilqnfl5t4ihqdl8523nm
/chroot/home/a779e1cc/901e4459aa.nxcli.net/pub/media/customer_address/s/e/sess_7sdutkrtwwn2cx70k9cr4xsb8jpggwod
/chroot/home/a779e1cc/901e4459aa.nxcli.net/pub/media/customer_address/s/e/sess_6bdgu7g60j13ayic2mi5ibbwkx098hfo
/chroot/home/a779e1cc/901e4459aa.nxcli.net/pub/media/customer_address/s/e/sess_ado60kr9ws4bha7sorahxeehenha38o7
/chroot/home/a779e1cc/901e4459aa.nxcli.net/pub/media/customer_address/s/e/sess_xdc1iet50eepsuk9z69243ppm5vrtcwy