Audit and Cleanup of Linux Server (IP blacklisted, suspected compromise)

Job ID: 39716359

Budget: €8 – €30 EUR

Details:
https://docs.google.com/document/d/1vmFu3sTakd8QWrXlxclu9SCfO3IFNWj8pG6UOPtFILI/edit?usp=sharing

We urgently need an experienced Linux system administrator / security specialist to investigate and fix issues with one of our servers.


We need a professional to:

Audit the server

Check for compromise (malware, trojans, rootkits, backdoors).

Analyze system and web logs for abnormal activity.

Identify the source of suspicious wp-login.php scanning activity.

Cleanup and fix

Remove any malicious files, processes, or cron jobs.

Update OS and all services to the latest secure versions.

Close/disable unnecessary ports and services.

Reconfigure firewall (iptables / ufw / CSF).

Harden security

Implement fail2ban (or equivalent) to block brute-force attacks.

Secure SSH (disable root login, use key-based authentication, non-standard port).

Reset all system and service passwords.

Set up basic monitoring of logs and system activity.

Report

Provide a short report of findings (evidence of compromise, actions taken).

Recommend best practices for preventing similar incidents in the future.

Draft a short summary for our Abuse Department to confirm remediation steps.