Skip to main content

Account contact info change to hackerish address

Comments

5 comments

  • cPRex Jurassic Moderator
    Hey there! The most likely explanation would be SSH if that user had SSH access enabled on their account. A user compromised the cPanel password through a keylogger tool (or something similar), then accessed SSH, then manually updated the contact details to get the password reset email sent to them. This could also happen through File Manager, but that would show up in the cPanel access_log file. Did you check /var/log/secure for any entries related to that cPanel username?
    0
  • AGY
    Hey there! The most likely explanation would be SSH if that user had SSH access enabled on their account. A user compromised the cPanel password through a keylogger tool (or something similar), then accessed SSH, then manually updated the contact details to get the password reset email sent to them. This could also happen through File Manager, but that would show up in the cPanel access_log file. Did you check /var/log/secure for any entries related to that cPanel username?

    That account does not have a shell configured and I found nothing in the mail logs indicating mail to that account other than the contact change notification. Nothing in secure indicating access to that account other than the periodic wp-toolkit messages.
    0
  • cPRex Jurassic Moderator
    Those were the best guesses off the top of my head. You're always welcome to submit a ticket to our team so we can check things on our end, but our assistance with security is very limited, usually to root compromises. It might be best to work with a third-party administrator if you aren't able to track this down on your end.
    0
  • AGY
    Thanks, I was more interested to see if anyone else had seen something like this as no files appear to have been changed and no other evidence of any malicious behavior has been found.
    0
  • cPRex Jurassic Moderator
    It's relatively common for that to happen, but it seems odd for that to be the only change. Usually the whole point of that type of change is to get access to the cPanel account to upload files, send email, or use the web space, but it's odd that nothing else has been changed.
    0

Please sign in to leave a comment.