
Closed
Posted
Paid on delivery
My corporate site runs on an Nginx + Node.js stack inside an Amazon Lightsail instance. It has suddenly gone offline and the behavior suggests a malware compromise rather than a simple configuration error. No security measures were put in place earlier, so I need an experienced engineer to step in quickly. After restoring access, I want the environment professionally disinfected, every backdoor closed, and the server hardened so this does not recur. Familiarity with AWS CLI, SSH hardening, malware scanners, log forensics, and typical Linux tools will be essential. Deliverables: • Bring the site back online with full functionality • Remove any malicious code or files and verify integrity of the Node.js application • Apply server-level hardening (firewall rules, service lockdowns, regular patching strategy) • Provide a concise report detailing findings, actions taken, and recommended ongoing maintenance Please outline your approach and estimated timeline so we can get moving right away.
Project ID: 40543623
106 proposals
Remote project
Active 3 days ago
Set your budget and timeframe
Get paid for your work
Outline your proposal
It's free to sign up and bid on jobs
106 freelancers are bidding on average $138 USD for this job

Being in the IT services field for over a decade, I have tackled numerous situations similar to yours, where a prompt and astute response was critical. My extensive background in AWS, Linux, and Network Security make me the perfect candidate to salvage your compromised system. I am well-versed with AWS CLI, SSH hardening techniques, and a range of malware scanning tools to ensure top-notch disinfection. Apart from addressing immediate issues, my past experience has instilled in me a proactive mindset when it comes to security. I don't just fix problems -- I provide long-term solutions. For this reason, securing your system through firewall rules and service lockdowns will be just as much a priority for me as resolving the present malware situation. Furthermore, my deep-rooted familiarity with typical Linux tools such as log forensics is an added advantage when it comes to ensuring a thorough job. After diligently cleaning out the malicious code or files and hardening your server, I will provide you with a detailed report on the findings and actions taken. Moving forward, I am more than willing to assist you remotely on an ongoing basis to keep your site safeguarded against future threats. In summary, you need someone with expertise in multiple facets of Network Security who is also quick on their feet: that's me. My 24-hour availability combined with an unwavering commitment to project delivery can be invaluable for your urgency. Let's set things right from hereon!
$200 USD in 3 days
7.1
7.1

A compromised Nginx + Node.js server on Lightsail with no prior security measures — I've handled this exact scenario multiple times and can start immediately. My approach: SSH in, analyze auth logs and system logs to identify the attack vector, scan the filesystem with rkhunter and ClamAV for malware, rootkits, and backdoors, then verify the integrity of your Node.js application code against your known-good source. Once disinfected, I'll harden the server — configure UFW firewall rules, lock down SSH with key-only auth and fail2ban, restrict Nginx to only necessary ports, set up unattended security patches, and review your Node.js process manager permissions. Your site comes back online clean, and you'll get a concise report detailing exactly what was found, what was fixed, and a recommended ongoing maintenance plan so this doesn't happen again.
$30 USD in 1 day
6.5
6.5

As soon as I saw this project, my extensive experience with AWS and Linux infrastructure had me compelled to apply. Over the years, I have mastered the art of system administration and security hardening. I know just how crucial it is to ensure the safety of your site—especially when devastating downtime due to malware compromises can put your business at stake. To combat your current situation effectively, let me outline my approach: firstly, I'll work swiftly to restore access and thoroughly scan every nook and cranny using reliable malware scanners. Then, using my proficiency in SSH hardening and AWS CLI, I'll safeguard your infrastructure against potential future threats with foolproof firewall rules and a meticulous patching strategy. Post disinfection and restoration process, I'll ensure that your Node.js application is thoroughly vetted for any irregularities, resulting in an all-encompassing solution that truly ensures the longevity of your site's security. Moreover, after diligently completing the project within an estimated timeframe of X-days (to be discussed), allow me to provide you with a comprehensive report outlining the findings along with recommended maintenance strategies for ongoing protection.
$140 USD in 7 days
6.6
6.6

Comingz from a background highly proficient in Amazon Web Services, Linux and Web Security with over 15 years of experience, I am your go-to person for your AWS Lightsail malware cleanup and server hardening project. I understand the urgency and importance of the task at hand, and I warrante to not only restore full functionality to your site but to mitigate any future risks just as efficiently. My hands-on expertise in dealing with Linux systems will allow me to not only remove any existing malicious code but also apply a comprehensive series of firewall rules, service lockdowns, and patching strategies to secure your site from future threats. Using my strong familiarity with Linux tools, I will perform deep-rooted log forensics to gauge the extent of the breach to avoid potential backdoors. One thing I pride myself on is my commitment to maintaining promptness in system updates and security patches - a core strength that prevents vulnerabilities while minimizing downtime. Ultimately, my goal would be achieving an uncompromised system that can ensure smooth online experiences for users while keeping away malicious actors. Time is crucial for you here, which is exactly why you should hire me - I guarantee swift action without compromising efficacy.
$100 USD in 1 day
6.4
6.4

Hello, It's great to speak with you about your new project..!! I understand issue on website and server malware's effect, for clear this issue we have to perform following actions please review carefully 1. Changes all password (Website and server) 2. Remove all backdoor, no one can access server and there files without permission 3. Scan entire server/code files and database 4. effect files repair and update with system 5. unused php extn and any other content remove form server 6. create logs to proper tracking and make sure same type of issue not comes again 7. handover project to you back Ping us for more better discussion Best
$120 USD in 2 days
6.1
6.1

Hello, This appears to be an incident response task rather than a simple service recovery. Before making any changes, I'll perform a brief forensic assessment to identify the root cause and any Indicators of Compromise (IoCs). Bringing the site back online without eliminating the attack vector often results in the same issue returning. My approach follows industry best practices aligned with the NIST Cybersecurity Framework: identify, contain, eradicate, recover, and harden. I'll review system and authentication logs, running services, SSH access, startup services, scheduled tasks, open ports, user activity, and persistence mechanisms such as unauthorized SSH keys, rogue cron jobs, or systemd services. Once the environment is verified, I'll remove any malicious artifacts, validate the integrity of your Node.js application, restore the website to full operation, and harden the server by securing SSH, tightening firewall rules, applying security updates, and implementing additional protections to reduce future risk. You'll receive a concise technical report summarizing the findings, actions performed, and recommendations for ongoing maintenance. My goal is not only to restore your website, but to ensure it returns to production in a trusted and secure state. A couple of questions: • Do you still have SSH access to the Lightsail instance? • Do you have a recent snapshot or backup available? I can start immediately.
$140 USD in 7 days
5.8
5.8

With over 5 years of experience in AWS, backend development, and DevOps engineering, I am the perfect fit for your project. My expertise aligns precisely with your requirements - from shutting down backdoors and removing malware to hardening servers through firewall rules and service lockdowns. With my certifications in AWS including those on security and my knowledge of compliance frameworks (PCI-DSS, GDPR, ISO), I can guarantee a thorough disinfection of your environment. I understand the urgency of the situation. Hence, my approach will be diligently quick yet thorough. First, I'll restore your site’s functionality then initiate comprehensive malware scanning. After removing any malicious codes/files, I’ll proceed towards securing your server through various measures including regular patching strategies. Furthermore, I’ll provide you with a concise report detailed with all actions taken - so you have a transparent understanding of what transpired and recommended ongoing maintenance.I look forward to reviving your site to its robust state and safeguarding it for the future. Let's get started!
$250 USD in 7 days
5.4
5.4

Good morning. I'll restore your Lightsail instance immediately, run forensic log analysis to identify the intrusion vector, remove all malicious files, verify your Node.js application integrity, and harden the server with SSH lockdown, UFW firewall rules, and Fail2ban. You'll receive a clear written report covering findings, remediation steps, and an ongoing maintenance plan. Any specific Node.js services or ports I should prioritize when bringing the stack back online?
$100 USD in 1 day
5.4
5.4

My name is Craig, and I'm absolutely committed to delivering high-quality code, meeting deadlines, and exceeding client expectations - which I believe is exactly what you need for your AWS Lightsail Malware Cleanup & Hardening project. My strong background in full-stack web development with a focus on Node.js makes me the perfect fit for the task at hand. While it is unfortunate that your site has suffered a malware compromise, my extensive experience has prepared me to handle situations like these efficiently. I am well-versed in AWS CLI, SSH hardening, scanning for and cleaning out malware, and forensic analysis of logs. In action, my primary goal i
$140 USD in 2 days
4.9
4.9

Hello, I’ve carefully reviewed your project requirements and they align very well with work I’ve completed successfully in the past. I’m confident I can deliver this exactly the way you expect — clean, reliable, and scalable. If you’d like, I can quickly walk you through a similar project I completed and explain how I’d approach yours step-by-step. I’m also happy to jump on a quick audio or video call to clarify anything. 410+ verified 5★ reviews, 538+ completed projects, Full-stack expert: CMS (WordPress, Shopify, Wix, Framer, Squarespace, Magento 2, OpenCart) Python, PHP, Laravel, React.js , node.js n8n, Zapier, AI agents. Always on time, within budget, Free 1-month post-delivery support you can check my skills and reviews here - https://www.freelancer.com/u/zahi9 Looking forward to your response. Best regards, Zahidul
$140 USD in 4 days
4.7
4.7

As an experienced and integrally skilled full-stack developer with a speciality in Node.js, I am more than equipped to tackle your AWS Lightsail malware cleanup and hardening project. My extensive 12+ years of experience offering scalable applications, automation systems, and crucially cloud infrastructure align exactly with your project needs. This depth of experience also resonates within the immediate action requirements of your project. I understand the urgency of your situation and that your site must be back online with foolproof security measures as soon as possible. My familiarity with AWS CLI, SSH hardening, malware scanners, Linux tools and most critically in this case - security measures and server-level hardening for the Linux environment - will prove advantageous in delivering the robust solutions you require. Furthermore, my capability extends beyond cleanups; I excel in providing thorough concise reports detailing all findings, actions taken along with recommended ongoing maintenance protocols. Client satisfaction is our utmost priority and our adherence to enterprise-grade standards guarantees the craftsmanship that goes into each project we undertake. Choosing me would not only ensure speedy recovery of your site but also serve as an investment for its durability on the longer run. Let's discuss further how I can bring my expertise to bear on your project now!
$30 USD in 7 days
4.7
4.7

With a decade of experience in web engineering and a specialization in Web Security, I am confident that I can provide the meticulous cleanup and hardening your AWS Lightsail instance requires. My proficiency with AWS CLI, SSH hardening, malware scanners, log forensics, and Linux tools will ensure every nook and cranny of your system is thoroughly inspected and sanitized for any malicious presence. My approach would include promptly restoring your site to full functionality before conducting a comprehensive malware sweep. Once this is accomplished, I will fortify your server with an airtight security framework comprising firewall rules, service lockdowns and a regular patching strategy, reducing future vulnerability risks significantly. Realizing the importance of transparency, I promise to deliver a concise report detailing all the actions taken as well as any issues identified along with recommended ongoing maintenance. Don't let this malware compromise be a recurring nightmare. Collaborate with me and let's safeguard all your digital assets with fortified vigilance.
$30 USD in 1 day
4.7
4.7

Hi, I understand the urgency of restoring your Lightsail server and securing it against future threats. My approach begins with regaining access and performing a thorough malware scan using trusted tools to identify compromised files. I will then clean the server, verify the integrity of your Node.js application, and ensure all malicious code is removed. Next, I will implement robust hardening measures such as configuring firewall rules, disabling unnecessary services, and applying SSH best practices. I will also set up routine patching and monitoring strategies to prevent recurrence. After completing these steps, I will provide a detailed report outlining the vulnerabilities found, actions taken, and recommended ongoing maintenance to keep your environment secure. I estimate this process will take approximately 1 to 2 days depending on the server's condition and complexity. Best, Justin
$500 USD in 7 days
4.7
4.7

Hello dear, I’m Md. Toriqul Islam, an experienced DevOps and backend engineer with 10+ years of expertise in AWS, Linux security, Node.js deployments, and server hardening. I understand your Amazon Lightsail instance has gone offline and may have been compromised. I’ve handled similar incidents involving malware analysis, log forensics, application recovery, integrity verification, and server hardening to restore services quickly and securely. I have rich experience in AWS CLI, Lightsail, Nginx, Node.js, Linux administration, SSH hardening, malware scanning, firewall configuration, and security best practices. I’m ready to start immediately and can quickly audit, restore, disinfect, and secure your environment with a detailed remediation report. Looking forward to hearing from you. Best regards, Md. Toriqul Islam
$60 USD in 4 days
4.5
4.5

As a Senior Full Stack Developer with over 6 years of extensive experience, I have honed an expertise in Linux and Ubuntu, making me exceptionally equipped to decipher complicated server malfunctions that may plague dynamic frameworks like Nginx and Node.js. Additionally, my profound knowledge in Web Security enables me to confront abruptly triggered malware and provide pre-emptive measures for maintaining a futureproof environment. Most significantly, my past engagements with Amazon Web Services (AWS) gives me hands-on experience with its products - including AWS CLI which will be central to this task. My strategy is a two-faced sword in tackling the problem at hand. I will first combat the existing malware sincerely, making certain that your website's functionality returns to its peak performance by sniffing out every malignant element and reinforcing the Node.js application. Secondly, I'll conduct a sturdy post-mortem investigation - employing log forensics and malware scanners - to unearth vulnerable areas within your system that allowed it to make way for the intrusion.
$40 USD in 1 day
4.6
4.6

Hi, I'm Muhammad Idrees from Global IT Vision. We manage and harden production Linux/Nginx/Node.js stacks daily — this is squarely in our wheelhouse, and I can step in fast given your site is currently offline. My approach: 1) Regain access to the Lightsail instance over SSH and triage — confirm whether it's a compromise vs config, snapshot the instance first so we have a clean rollback point. 2) Bring the site back online with full functionality. 3) Disinfect — scan with malware/rootkit tools (rkhunter, chkrootkit, ClamAV), review crontab/systemd/authorized_keys for persistence, audit Nginx + Node for injected code, and verify integrity of the Node.js app. 4) Harden: firewall rules, SSH lockdown (key-only, no root), service minimisation, fail2ban, and a patching strategy. 5) A concise report of findings, actions, and ongoing maintenance. Ready to start immediately — send SSH access and I'll begin triage. — Muhammad Idrees / Global IT Vision Pvt. Ltd
$230 USD in 3 days
4.8
4.8

I can quickly restore your Nginx + Node.js site on AWS Lightsail, investigate and remove any malware, and verify application integrity. I’ll secure SSH access, audit logs, harden the server with firewall and patching practices, and ensure no backdoors remain. A concise incident report and recovery steps will be provided. Regards, Shawana
$100 USD in 6 days
4.2
4.2

Interesting project, We will restore your Lightsail instance, remove all malicious code, and harden the server so it stays protected. Our first step is pulling logs (auth, access, syslog) to trace the entry point. From there we will scan the filesystem, verify your Node.js app integrity against your repo, and lock down SSH, Nginx, and firewall rules. A couple of quick things to confirm: 1) Do you have a recent snapshot or backup of the instance? 2) Is your Node.js source in a Git repo we can compare against? The number quoted here is a starting estimate. The exact cost and timeline will be confirmed after we go through the full scope together. Send me a message and we can go over the details. Best regards, Faizan
$90 USD in 5 days
3.8
3.8

Hi, There, I can quickly restore your AWS Lightsail server, identify and remove any malware or backdoors, verify your Node.js application integrity, and harden the entire Ubuntu/Nginx environment against future attacks. With 4+ years of experience in Linux server administration, AWS, web security, and Node.js deployments, I'll provide a complete cleanup, firewall and SSH hardening, security patches, log forensics, and a detailed report of findings and preventive recommendations. I can start immediately and typically complete the entire process within 6–12 hours, depending on the severity of the compromise. Waqas,
$140 USD in 7 days
4.0
4.0

Hi A suspected compromise needs more than just getting the site back online—it needs the root cause identified and the server secured so it doesn't happen again. I'll investigate the Lightsail instance, review Nginx, Node.js, and system logs, identify any malicious files or unauthorized changes, and restore the application to a clean, working state. Once the site is operational, I'll harden the server by securing SSH access, updating packages, configuring firewall rules, reviewing running services, and closing any security gaps that allowed the compromise. You'll receive: • Fully restored Node.js application • Malware and backdoor removal with integrity verification • Server hardening and security best practices applied • Concise report covering findings, actions taken, and maintenance recommendations I've handled similar server recovery and security projects, though many are protected by NDAs and can't be shared publicly. I'm available to begin immediately and can prioritize getting your site back online before moving on to hardening and cleanup. Best, Chand
$120 USD in 5 days
4.0
4.0

abu dhabi, United Arab Emirates
Member since Mar 7, 2015
$250-750 USD
₹12500-37500 INR
€1500-3000 EUR
$250-750 USD
$250-750 USD
$10-30 USD
₹600-1500 INR
₹1500-12500 INR
$250-750 USD
₹12500-37500 INR
$250-750 USD
$750-1500 USD
₹1500-12500 INR
₹1500-12500 INR
$750-1500 USD
$10-30 USD
$30-250 USD
$10-30 AUD
$5000-10000 USD
₹12500-37500 INR
$30-250 USD