How to clean the server? I think I have the same issue
Hi. Before deleting anything, I would recommend checking whether your compromise is actually the same one.
We found several different indicators on the affected server, including OMRIG/XMRig-related persistence and later a suspicious root process running from a deleted memfd, so preserving evidence before cleaning is important.
If possible, please do not reinstall, reboot or delete suspicious files yet.
Could you first post the output of:
ps auxf
ss -plant
ss -lntp
find /proc/[0-9]*/exe -lname '*deleted*' -ls 2>/dev/null
systemctl list-unit-files --type=service | grep -Ei \
'systemd-logind-helpers|polkitd-helpers|dbus-monitor-srv|auth-policykit'
ls -la /usr/sbin/netd /usr/bin/systemd-logind-helpers \
/usr/bin/polkitd-helpers /usr/bin/dbus-monitor-srv 2>/dev/nullAlso, if you use the CWP External API, please check whether port 2304 is publicly accessible and preserve these logs before doing anything else:
/usr/local/cwpsrv/logs/2304_access_log
/usr/local/cwpsrv/logs/2304_error_log
/var/log/cwp/cwp_api.logIn our case we found malicious requests to CWP API endpoints such as /v1/backup, /v1/endtransf/ and /v1/addemail/, followed by commands executed as root.
Please redact passwords, API keys/tokens and other credentials before posting any logs here.
Once we know whether the indicators match, I can explain what we removed and how we checked the server afterwards. But I would preserve the evidence first, because it may also help determine exactly how the CWP API was exploited.