This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Firewall CPU constantly at 100%

Hi folks,

We've got a couple of UTM firewalls running for several customers and we've noticed that some of those are running constantly at 100% CPU load.

These UTM firewalls all have different versions running, somewhere between 9.5 and 9.7. And after checking the running processes we've noticed the culprit seems to be the proces called 'xmrig'. I'm note familiar with this process but if you do a simple search on google, you'll get all kinds of crypto miner hits, suggesting this process is being used/abused to mine cryptos.

When we deployed a fresh UTM firewall, we noticed this process is available/running from the start. So I'm guessing this proces has been around on the UTM firewalls for some time. Does the UTM even use this process itself or is it just part of the Linux distro?

Anybody else encountered this behaviour before? Is it safe to assume these firewalls have been compromised, or are we way off base?

Cheers,

Frank



This thread was automatically locked due to age.
Parents
  • If you found a vulnerable version and webadmin is exposed to internet ... you have a crypto-miner. ... at least ... if you are lucky

    One option to place a malware is to replace a regular process. Middleware will load the malware wile trying to restart the stopped process.


    Dirk

    Systema Gesellschaft für angewandte Datentechnik mbH  // Sophos Platinum Partner
    Sophos Solution Partner since 2003
    If a post solves your question, click the 'Verify Answer' link at this post.

Reply
  • If you found a vulnerable version and webadmin is exposed to internet ... you have a crypto-miner. ... at least ... if you are lucky

    One option to place a malware is to replace a regular process. Middleware will load the malware wile trying to restart the stopped process.


    Dirk

    Systema Gesellschaft für angewandte Datentechnik mbH  // Sophos Platinum Partner
    Sophos Solution Partner since 2003
    If a post solves your question, click the 'Verify Answer' link at this post.

Children
No Data