URGENT: WordPress Malware and Server Security Expert Needed for Persistent Reinfection
Budżet: -
HOURLY / PART_TIME
⭐ 4.95 (298)
United States
wordpress, vulnerability-assessment, network-security, security-analysis, wordpress-malware-removal
Preferowane kwalifikacje
- Doświadczenie: Ekspert
We are looking for an experienced WordPress malware removal and server security specialist to investigate and permanently resolve a recurring malware issue affecting a WordPress environment.
This is not a basic malware cleanup. We need someone who can identify the root entry point, persistence mechanism, and source of reinfection, then secure the environment to prevent the issue from returning.
Issue Summary
A WordPress website was compromised with casino/iGaming spam and unauthorized administrative activity.
A fake cloudflare/recaptcha/ Clickfix showing on windows users
- 1. ClickFix JavaScript injection Source found: wp-content/mu-plugins/index.php
- 2. Casino/iGaming spam posts Source found: published WordPress posts
During the incident:
- Legitimate pages, including the homepage, were moved to the trash.
- Installing unwanted plugins.
- Adding zip file in media library
- Media files deleted
- Created hidden a admin account
- The WordPress front-page setting was changed to display the blog roll.
- Casino and iGaming spam posts were created and published.
- Some spam posts appeared to have been scheduled in advance.
- Activity was recorded under legitimate WordPress usernames, but the associated IP addresses were unfamiliar and changed between actions.
- Suspicious administrator accounts have previously been created through injected code.
- Malicious code has appeared in different locations during separate incidents.
- The activity returned within hours of an initial cleanup, password change, and WordPress salt reset.
Work Already Completed
Our internal team has already:
- Inspected and cleaned suspicious WordPress files.
- Removed identified injected code.
- Replaced the wp-admin and wp-includes directories with clean WordPress copies.
- Updated WordPress core, PHP, plugins, and available components.
- Reset WordPress salts to invalidate active sessions.
- Changed passwords for available WordPress accounts.
- Changed database username and password.
- Reviewed themes, plugins, cache folders, core files, and functions.php.
- Reviewed WordPress activity logs, usernames, and IP addresses.
- Ran Wordfence using high-sensitivity scan settings.
- Requested a server-level scan from the hosting provider.
- Wordfence and hosting support reported that no malware was detected after the cleanup. However, the unauthorized activity returned afterward, indicating that the persistence mechanism may not be detectable through standard malware scans.
What We Need Investigated
We need the selected specialist to investigate possible sources including:
- Hidden or obfuscated PHP backdoors.
- Rogue cron jobs or scheduled server processes.
- WordPress cron events and scheduled posts.
- Must-use plugins or hidden plugins.
- Malicious theme or plugin code.
- Modified WordPress core files.
- Database-level injections or unauthorized options.
- Hidden or automatically recreated administrator accounts.
- Compromised WordPress credentials.
- Stolen cookies or hijacked WordPress sessions.
- Compromised API keys, application passwords, or authentication tokens.
- Vulnerable, outdated, nulled, or abandoned plugins and themes.
- Compromised hosting, server, SFTP, SSH, control panel, or database credentials.
- Infected local devices or browser sessions used to access WordPress.
- Cross-site or cross-account contamination within the hosting environment.
- The specialist should not rely only on Wordfence or automated malware scans.
Required Deliverables
The project must include:
- A full WordPress and server-level security audit.
- Identification of the original entry point, where technically possible.
- Identification and removal of all persistence mechanisms.
- Review of server cron jobs, WordPress cron events, database records, users, plugins, themes, and core files.
- Review of authentication logs, access logs, IP activity, sessions, and account usage.
- Removal of malicious files, accounts, scripts, database entries, and scheduled processes.
- Credential and session security recommendations.
- Hardening of WordPress and the server environment.
- Verification that clean files come from trusted and official sources.
- A monitoring plan to confirm that the malware does not return.
A written report explaining:
What was found
- How the attacker likely gained access
- How persistence was maintained
- What was removed or changed
- What was done to close the entry point
- What preventive controls should be implemented
- We do not want a final report that only says the files were cleaned. We need a clear explanation of the root cause and how it was addressed.
Required Experience
Please apply only if you have proven experience with:
- Persistent or recurring WordPress malware.
- PHP malware analysis and deobfuscation.
- WordPress and Linux server security.
- Cron jobs and scheduled-task investigation.
- WordPress database security.
- Session hijacking and compromised account investigations.
- Hosting and web-server log analysis.
- WordPress hardening after a breach.
- Incidents where automated scanners reported a site as clean despite continued unauthorized activity.
- Experience with managed WordPress hosting, VPS environments, Cloudflare, Nginx, Apache, SSH, SFTP, WP-CLI, and MySQL is highly preferred.
Access and Confidentiality
- No credentials or confidential client information will be included in the public job post.
- The selected freelancer may be provided with restricted and temporary access to the relevant systems after appropriate confidentiality and access-control measures are agreed upon.
- All findings, client information, credentials, files, and security details must remain confidential.
Application Questions
Please answer the following when applying:
- Have you handled a WordPress infection that returned after a full cleanup?
- How do you investigate malware when Wordfence and hosting scans report the site as clean?
- How would you check for rogue cron jobs, hidden plugins, database persistence, and session hijacking?
- What logs and access would you require?
- How would you determine whether the issue originated from WordPress, the hosting environment, credentials, or a compromised device?
- Can you provide a written root-cause and remediation report?
Please share examples of similar investigations, without exposing confidential client information.
We are looking for someone who can begin with the investigation promptly and provide clear updates throughout the process.
Otwórz na Upwork
AI proposal draft
Generate a short cover letter for this job. Edit before sending.
Sign in to generate an AI proposal draft.
Zaloguj