Hi,
I'm posting this because I've had a security incident on one of my CWP servers and, after seeing some of the recent security reports here, I thought it might be useful to share what I found and see if anyone else has seen the same thing.
The server is running AlmaLinux 8 with CWP.
I found what appears to be an OMRIG crypto miner, together with these suspicious services/binaries:
dbus-monitor-srv
polkitd-helpers
systemd-logind-helpersThere were also signs of persistence through systemd.
During the investigation I found these two IP addresses, which I have now blocked:
146.103.45.130
184.107.106.86146.103.45.130 was related to the miner activity.
184.107.106.86 appeared during the investigation of suspicious outbound activity.
Another thing that caught my attention was port 2304, used by the CWP External API. It was publicly exposed on this server. I have now removed it from the allowed ports in CSF and confirmed that it is no longer accessible.
I have restored the server from a backup taken before the incident, removed/checked the suspicious services and files, blocked both IP addresses and closed port 2304.
I want to make clear that I cannot confirm that port 2304 or the CWP API was the entry point. I'm mentioning it because it was exposed at the time of the incident and because I've seen other recent reports of CWP servers being compromised with root access and crypto miners.
Has anyone else seen these same services/binaries or IP addresses on an affected CWP server?
And does anyone know if this could be related to one of the recent CWP security/API issues?
I still have information and logs from the incident, so I can provide more details if they are useful.
Thanks.