
Closed
Posted
Paid on delivery
Yesterday our website was hit by a phishing attack that redirected some visitors to a fake login page and injected suspicious code into a few core files. I have already taken the site offline and backed up the current state; now I need an experienced security specialist to clean the infection, trace how the breach occurred, and put solid defenses in place so this does not happen again. The job starts with a full scan of the public-facing folders and the database to locate every malicious snippet or backdoor. Once the code is removed, I want a concise report that shows what was found, which vulnerabilities were exploited, and clear recommendations for closing them. Finally, please implement the agreed fixes—whether that means tightening headers, updating plugins, configuring a WAF, or hardening server permissions—before the site goes live again. I will be choosing someone whose past work demonstrates successful recovery from similar phishing incidents on websites. Please link directly to clean-up or security-hardening projects you have completed, noting any tools you prefer (e.g., OWASP ZAP, Burp Suite, ClamAV) and the turnaround times you achieved. Deliverables: • Clean, operational site with no malicious code • Post-remediation security report (PDF or Markdown) • List of preventive measures applied and any next steps I should schedule Once we’re back online safely, I’m open to arranging an ongoing maintenance agreement if your work proves reliable.
Project ID: 40560651
30 proposals
Remote project
Active 1 day ago
Set your budget and timeframe
Get paid for your work
Outline your proposal
It's free to sign up and bid on jobs
30 freelancers are bidding on average ₹6,936 INR for this job

hello sir, may I know your website name so that I can take a look? I will clean and secure your website guaranteed. I am ready to start right now. Thanks
₹8,000 INR in 3 days
7.2
7.2

With my extensive 9+ years of experience in web and mobile development, I have gained a deep understanding of PHP and website management. I've successfully developed ecommerce and CMS-based websites, honing my skills in detecting vulnerabilities and fortifying online platforms against security threats like the one your website encountered. In regards to cleanup, I use highly-effective tools like OWASP ZAP and ClamAV for scanning malicious code, ensuring that no backdoor or snippet is left undetected. Furthermore, I identify the root cause of such breaches and create concrete solutions to defend against such attacks in the future. Once remediation is complete, you can expect a comprehensive security report detailing all the findings, vulnerabilities exploited, and clear recommendations to fortify those areas of concern. Throughout the process, I prioritize transparency and effective communication for a seamless project experience. I also offer three months of free support post-delivery to ensure your maximum satisfaction with my work. Let me use my wealth of expertise to harden your platform, safety-proofing it from future threats.
₹17,000 INR in 7 days
5.4
5.4

I understand the urgency of securing your website after a phishing attack. I can deliver a comprehensive solution using a proven AI-assisted workflow. Step 1: Conduct a full scan of your public-facing folders and database using ClamAV and manual inspection to identify malicious code. Deliverable: Detailed list of infected files. Step 2: Remove all malicious code and backdoors, then document the vulnerabilities exploited. Deliverable: A concise security report highlighting the breach points. Step 3: Implement security measures such as updating PHP versions, configuring a Web Application Firewall (WAF), and tightening server permissions. Deliverable: Secure, operational website ready for relaunch. Step 4: Provide a handover session to explain the applied fixes and recommendations for ongoing security maintenance. Shall we discuss the details and next steps?
₹7,024 INR in 7 days
4.1
4.1

Hi , I’ve carefully checked your requirements and really interested in this job. I’m full time WordPress developer having 5+ years of experience. I’m offering best quality and highest performance at lowest price. I can complete your project on time and your will experience great satisfaction with me. I have rich experienced in Website Optimization, Web Security, Website Management, Security, PHP, Internet Security, Computer Security and Penetration Testing. Please message for further communication. Thanks
₹1,500 INR in 2 days
4.2
4.2

I can help restore your website safely by removing all malicious code, identifying the root cause of the attack, and hardening the site against future threats. I'll perform a complete file and database audit, clean infected files, verify the site is secure, and provide a detailed remediation report with recommendations for ongoing protection. Best regards, W3loop
₹7,000 INR in 7 days
3.4
3.4

Hello, I can help recover your website safely by removing the infection, identifying the compromise, and implementing security measures to prevent reinfection. With 6+ years of experience in WordPress security, malware removal, and server hardening, I focus on eliminating the root cause—not just the visible malicious code. Here's what I will deliver: • Complete scan of website files and database to identify malware, phishing code, and backdoors • Removal of all malicious code and restoration of a clean, fully functional website • Investigation of the likely attack vector and persistence mechanisms where possible • Security hardening including plugin/core updates, file permissions, security headers, WAF configuration, and other best practices • Thorough testing before bringing the site back online • Detailed remediation report with findings, fixes applied, and recommendations for ongoing protection I typically use tools such as **ClamAV**, **Wordfence**, manual code review, and server-level analysis to ensure nothing is overlooked. I can start immediately and provide regular progress updates throughout the cleanup process. Looking forward to helping you restore your website securely. Best regards, Subham
₹3,500 INR in 1 day
3.4
3.4

I'll thoroughly clean the infected website, remove all malicious code and backdoors, identify the attack vector, and harden your server to prevent future compromises. With 12+ years of experience in PHP, WordPress, Laravel, and Linux server security, I've handled malware cleanup, phishing recovery, WAF configuration, permission hardening, and vulnerability remediation. You'll receive a fully cleaned website, a detailed security report (Markdown/PDF), and recommendations to keep your site protected. I use tools such as OWASP ZAP, ClamAV, malware scanners, and manual code review to ensure nothing is missed. I can begin immediately and complete the work with minimal downtime while maintaining complete transparency throughout the process.
₹2,500 INR in 1 day
2.8
2.8

**"Hackers only need one mistake. My job is to make sure they don't get a second chance."** Hi, I've worked extensively with full-stack web applications and understand how critical it is to restore a compromised website without leaving behind hidden backdoors or vulnerabilities. Here's how I'd approach your project: * ? Perform a complete scan of the website files and database to identify malicious code, redirects, and potential backdoors. * ?️ Remove infected code while preserving legitimate functionality. * ? Investigate the attack vector to determine how the compromise occurred. * ? Apply security hardening, including permission reviews, security headers, dependency updates, plugin audits, and WAF recommendations/configuration where applicable. * ? Deliver a clear remediation report detailing findings, actions taken, and recommendations for ongoing protection. * ✅ Assist with final testing before the website is brought back online. **Preferred stack & tools** * OWASP security best practices * Burp Suite (verification) * OWASP ZAP * ClamAV (where applicable) * Server log analysis * Manual code review I'm comfortable working with PHP-based websites, Linux servers, and modern web stacks, and I prioritize restoring functionality without compromising security. If you're looking for someone who treats security as a process—not just a cleanup—I'd be glad to help restore your site safely and leave it significantly more resilient than before.
₹15,800 INR in 2 days
2.5
2.5

Hello, I'm sorry to hear about the security incident. I can help you identify the source of the compromise, clean the infected website, and harden it against future attacks. With 8+ years of experience in PHP, Laravel, WordPress, MySQL, and website maintenance, I have worked on recovering compromised websites by removing malicious code, fixing vulnerabilities, and restoring secure operation. **My approach includes:** * Complete scan of website files and database to identify malware, backdoors, and injected code. * Remove all malicious files and verify core application integrity. * Investigate the likely entry point, such as outdated software, vulnerable plugins, weak permissions, or compromised credentials. * Update the application and dependencies to the latest secure versions where applicable. * Strengthen file permissions, server configuration, and security headers. * Configure firewall/security measures and implement best practices to reduce future risks. * Perform security testing to verify the website is clean and functioning correctly. **Deliverables:** * Fully cleaned and operational website * Security report detailing findings, remediation steps, and recommendations * Documentation of all security hardening measures applied * Support after deployment to address any issues related to the cleanup I can begin immediately and will keep you updated throughout the remediation process. Thank you, and I look forward to helping restore your website securely.
₹3,000 INR in 1 day
2.4
2.4

A phishing injection that redirects visitors and modifies core files almost always leaves at least one backdoor beyond the obvious payload — cleaning the visible redirect without finding the backdoor just means round two a few weeks later, so the scan has to cover uploads, theme/plugin files, and database options tables, not just the flagged pages. I've worked extensively in WordPress/PHP codebases (Astra/GeneratePress, ACF, WooCommerce) doing security-adjacent cleanup and hardening — reviewing core file integrity, tightening security headers, updating vulnerable plugins, and locking down file permissions on production sites. My approach: full diff scan of core/plugin/theme files against known-clean versions plus a database sweep for injected redirects or rogue admin accounts, document exactly what was found and how the breach likely occurred, then apply hardening (headers, permission tightening, plugin updates, WAF rule if you're on Cloudflare/similar) before bringing the site back online. Do you know which CMS/stack the site runs on (WordPress or custom PHP), and do you have the backup timestamped from before the infection so I can diff against a clean baseline?
₹7,000 INR in 2 days
0.6
0.6

Hi — sorry about the breach. You did the two key things already: took it offline and backed up. That makes a clean recovery straightforward. I run and harden my own production sites, including a WordPress/WooCommerce store with a custom PHP theme. So I work daily in exactly the environment your attack hit — injected PHP, redirect scripts, and backdoors in core files. My approach, 3–4 days: Scan & isolate — full sweep of public folders + database vs. a clean reference; checksums on core files; hunt for injection markers (base64/eval blobs, rogue admins, altered .htaccess, odd cron jobs). Clean & verify — remove every snippet and backdoor, then re-scan so nothing respawns. Tools: ClamAV, manual diff vs. clean core, OWASP ZAP for a post-clean pass. Report — concise remediation report (MD/PDF): what was found, likely entry point, prioritized fixes. Harden — security headers, plugin/core updates, tightened permissions, WAF config, before going live. Bid: ₹7,500 for the full scope, 3–4 day turnaround. Open to an ongoing maintenance arrangement afterward if the work earns it. Two quick questions: is the site WordPress/PHP, and how large is the codebase? I can start as soon as you share the backup. — Vipul
₹7,500 INR in 3 days
0.0
0.0

Hello, I have experience investigating and remediating compromised websites, including malware injections, phishing redirects, hidden backdoors, and post-attack security hardening. My process begins with a complete scan of the web root, uploads, themes/plugins, and database to identify malicious code, persistence mechanisms, and unauthorized changes. I then compare core files against official versions, remove injected code, eliminate backdoors, verify scheduled tasks, and ensure the site is clean before restoring service. After cleanup, I perform a root-cause analysis to determine how the compromise occurred (outdated software, vulnerable plugins, weak permissions, exposed credentials, etc.) and provide a concise remediation report with evidence, findings, and recommendations. Security hardening includes applying updates, tightening file permissions, reviewing server configuration, strengthening security headers, enabling WAF protection where appropriate, securing admin access, and implementing ongoing monitoring. I commonly use tools such as OWASP ZAP, Burp Suite, ClamAV, and manual code review during investigations. Deliverables: * Fully cleaned and operational website * Post-remediation security report (PDF or Markdown) * List of security improvements applied and recommended maintenance tasks I'm also available for ongoing monitoring and preventive maintenance to help keep the site secure after it goes back online.
₹1,500 INR in 7 days
0.0
0.0

Hi! I can clean this up and lock it down properly. My approach: 1. Full scan of every public-facing folder and the database to find each injected snippet, backdoor and the malicious redirect - I'll diff against a clean copy so nothing hides, not just the obvious files. 2. Remove the infection cleanly, then trace HOW they got in (vulnerable plugin/version, weak file permissions, exposed admin, etc.) so it's actually fixed, not papered over. 3. A concise report: what was found, which vulnerability was exploited, and clear next steps. 4. Implement the hardening we agree on - security headers, plugin/core updates, WAF rules, tightened server/file permissions and closing the redirect vector - before it goes live. Since you've already backed up and taken it offline, we're in good shape. What's the stack (WordPress, other CMS, or custom PHP), and do you have hosting/SFTP + DB access ready? I can start right away and get you safely back online.
₹6,000 INR in 4 days
0.0
0.0

Full scan — Check all public folders and database for malicious code, backdoors, and phishing pages with both automated scanning and manual code review. Cleanup — Remove all malicious code thoroughly with no shortcuts. Root cause analysis — Find the entry point (old plugin vulnerability? weak password? vulnerable code?) so it won't happen again. Hardening — Fix file permissions, configure WAF rules, security headers, disable unused services, update outdated plugins. Report — Deliver a clear security report (PDF or Markdown): what was found, how they got in, what was fixed, and what to watch for. Timeline: 24-48 hours after getting access Budget: ₹5,000 INR (fixed price) I've managed multiple production PHP servers and handled malware removal for live e-commerce and SaaS platforms. I have real-world experience in server security. Give me server access and I'll start right away. If the work goes well, happy to discuss long-term maintenance.
₹5,000 INR in 7 days
0.0
0.0

Hello, I can help you fully recover your website from this phishing attack and ensure it is secure before it goes live again. I have experience with website malware removal, security hardening, vulnerability assessment, and server security. My approach includes: - Complete scan of website files and database to identify malicious code, backdoors, and injected scripts. - Removal of all malware while preserving website functionality. - Investigation of the attack vector to determine how the breach occurred. - Security hardening by updating vulnerable components, fixing file permissions, improving security headers, and configuring firewall/WAF protections where applicable. - Final verification to ensure the website is clean and functioning properly. - A detailed remediation report (PDF or Markdown) explaining the findings, vulnerabilities, fixes applied, and recommendations for future protection. Tools I commonly use: - OWASP ZAP - Burp Suite - ClamAV - Linux security tools - Manual PHP code review Estimated Turnaround: Initial assessment within a few hours, with complete cleanup and hardening typically completed within 24–48 hours, depending on the size of the website and the severity of the infection. I focus on delivering a secure, clean, and stable website while minimizing downtime. I would also be happy to provide ongoing security monitoring and maintenance after the recovery is complete.
₹1,500 INR in 1 day
0.0
0.0

Dear potential client, We recently helped a client achieve enhanced website security post-phishing attack recovery—and judging by your post, it sounds like we could do the same for you. We've worked on websites for service-based businesses and would love to bring that experience to your project. From your post, it sounds like you're looking for something secure and robust, specifically around website phishing cleanup and hardening. We specialize in cybersecurity and website security, and we have 75+ 5-star reviews on similar projects and rank in the top 1% among 75 million users! I would love to help you with your project! The worst that can happen is you walk away with free consultation. Regards, Shannonkb21.
₹6,250 INR in 7 days
0.0
0.0

Hello, I have experience in website security, malware analysis, and web application hardening. I can perform a complete scan of your website and database to identify malicious code, phishing redirects, backdoors, and compromised files. I'll clean the infection, investigate the attack vector, validate the integrity of the application, and provide a detailed remediation report with recommendations. I use security tools such as OWASP ZAP, Burp Suite, ClamAV, and manual code review where appropriate. I'll also implement preventive measures including server hardening, WAF configuration, secure headers, permission reviews, and ongoing monitoring to help prevent future attacks.
₹6,000 INR in 5 days
0.0
0.0

"Hi there, I read your project details regarding the phishing attack and malicious code injection on your website. I understand how critical it is to clean this up immediately to protect your users and prevent your domain from being blacklisted. As a Vulnerability Researcher specializing in security hardening, I can clean and secure your web infrastructure. Here is my action plan for your website: Malware & Shell Cleanup: Thoroughly scanning and removing the injected malicious code and phishing pages from your core files. Vulnerability Patching: Identifying how the attacker gained entry (outdated plugins, weak credentials, or configuration flaws) and patching it. Security Hardening: Implementing defensive measures like security headers, strong file permissions, and monitoring to prevent future attacks. I am ready to start right away to get your site safely back online. Let's connect in the chat to discuss the details. Best regards, Yashpal"
₹7,000 INR in 7 days
0.0
0.0

I can help you fully recover your website after the phishing incident and ensure it is secure before going live again. My process includes: Performing a complete security audit of the website and server. Identifying and removing all malicious code, backdoors, and injected files. Investigating how the compromise occurred and documenting the attack path. Scanning the database and public-facing files for hidden malware. Hardening the server by updating vulnerable components, improving file permissions, configuring security headers, and deploying appropriate WAF rules. Delivering a detailed remediation report with findings, actions taken, and recommendations to prevent future attacks. I have practical experience in web application security and penetration testing, using tools such as Burp Suite, OWASP ZAP, Nuclei, and other security assessment tools. My background in vulnerability research helps me identify not only the malware but also the root cause that allowed the compromise. I am available to start immediately and will keep you updated throughout the cleanup process until the website is safe to bring back online. Looking forward to working with you.
₹7,000 INR in 7 days
0.0
0.0

Hi, Security cleanup + hardening is work I can handle fully. Here's my exact approach: Step 1 — Full infection scan: - Scan all PHP/HTML/JS files for obfuscated code (base64, eval, chr() chains), injected iframes, redirects - Check .htaccess for unauthorized rewrites - Scan DB for injected scripts in content fields - Identify all backdoor files (web shells, fake image files with PHP) Step 2 — Clean and restore: - Remove every malicious snippet, restore clean versions from backup where needed - Verify against known-good files after removal - Commit clean state to Git so you have a recovery point Step 3 — Hardening: - Patch the exploitation vector (most likely outdated plugin, weak credentials, or file upload bypass) - Implement CSP headers, X-Frame-Options, disable directory listing - Set correct file permissions (644 files, 755 dirs) - Add login brute-force protection if applicable Step 4 — Report: - What was found, which files, how the attack likely entered, what was changed Please share your backup ZIP or server access and I can start within the hour.
₹8,000 INR in 3 days
0.0
0.0

Indore, India
Payment method verified
Member since Jul 5, 2026
$30-250 USD
$250-750 USD
₹600-1500 INR
₹1500-12500 INR
₹1500-12500 INR
₹1500-12500 INR
$10-30 USD
$15-25 USD / hour
$10-30 USD
₹1500-12500 INR
₹14300-19100 INR
₹1500-12500 INR
$10-30 USD
$1500-3000 USD
$15-25 AUD / hour
₹1250-2500 INR / hour
$10-30 CAD
₹600-1500 INR
₹600-3000 INR
₹600-1500 INR