I’m looking for an experienced Linux incident response / sysadmin to help with a server issue.
A Linux server previously had an xmrig miner infection. Most artefacts have been removed, but something on the system is still intermittently attempting to download a miner script via wget.
The application code has been thoroughly checked and appears clean. This looks like a system-level persistence issue (cron, systemd service/timer, user-level service, SSH abuse, etc.).
What I’m looking for: • Identify and remove the persistence mechanism • Confirm whether there is any evidence of data access/exfiltration • Advise whether the server is safe to keep or if a rebuild is recommended
Context: • Ubuntu server • Node.js / Next.js app • PM2 • auditd already enabled • Sensitive app secrets will be rotated after the work
Credentials WILL be checked prior to work commencing
Spanish Procurement PDF Data Extraction -- 2 Category: API Integration, Data Analysis, Data Extraction, Data Processing, Excel, Google Search, JSON, Natural Language Processing, Python, Web Scraping Budget: $10 - $100 USD
25-Jan-2026 11:01 GMT
Forex Facebook Page Management India Category: Content Creation, Content Writing, Graphic Design, Hindi Translator, Social Media Management, Social Media Marketing, Video Editing, Voice Talent Budget: ₹600 - ₹1500 INR
Friendship Matchmaking Service Development Category: App Development, Backend Development, Graphic Design, IPhone, Mobile App Development, Project Management, UI / User Interface, User Experience Research, Web Development, Web Design Budget: £20 - £250 GBP