Server Files Encrypted with .sorry Extension and WHM Internal Error
Hello,
I am facing a critical security and operational issue on my server. All of my user files and system data have been renamed with the .sorry extension, which indicates a ransomware attack.
Additionally, I can no longer access the WHM interface. When I attempt to log in or navigate through WHM, I receive the following internal error:
undef error - Cannot open “/var/cpanel/plugins/components/homebanner.json”: No such file or directory at /usr/local/cpanel/Cpanel/JSON.pm line 656. Cpanel::JSON::_LoadFile("/var/cpanel/plugins/components/homebanner.json", 0, 0, undef, 0) called at /usr/local/cpanel/Cpanel/JSON.pm line 571 Cpanel::JSON::LoadFile("/var/cpanel/plugins/components/homebanner.json") called at /usr/local/cpanel/Cpanel/Plugins/Components/Rules.pm line 124 Cpanel::Plugins::Components::Rules::load_config(Cpanel::Plugins::Components::Rules=HASH(0x6144d00), HASH(0x616e028)) called at /usr/local/cpanel/Cpanel/Plugins/Components/Rules.pm line 112 Cpanel::Plugins::Components::Rules::BUILD(Cpanel::Plugins::Components::Rules=HASH(0x6144d00), HASH(0x616e028)) called at (eval 202) line 22 Cpanel::Plugins::Components::Rules::BUILDALL(Cpanel::Plugins::Components::Rules=HASH(0x6144d00), HASH(0x616e028)) called at /usr/local/cpanel/3rdparty/perl/542/cpanel-lib/Moo/Object.pm line 26 Moo::Object::new("Cpanel::Plugins::Components::Rules", "config_file", "/var/cpanel/plugins/components/homebanner.json") called at /usr/local/cpanel/Cpanel/Plugins/Components/whostmgr/home/homebanner.pm line 73 Cpanel::Plugins::Components::whostmgr::home::homebanner::__ANON__(Cpanel::Plugins::Components::whostmgr::home::homebanner=HASH(0x6115600)) called at (eval 811) line 21 Cpanel::Plugins::Components::whostmgr::home::homebanner::is_enabled(Cpanel::Plugins::Components::whostmgr::home::homebanner=HASH(0x6115600)) called at /usr/local/cpanel/Cpanel/Plugins/Components.pm line 60 Cpanel::Plugins::Components::get_components("whostmgr", "home") called at /usr/local/cpanel/Cpanel/Template/Plugin/Components.pm line 64 Cpanel::Template::Plugin::Components::get_components(Cpanel::Template::Plugin::Components=HASH(0x53f25a8), "whostmgr", "home") called at /usr/local/cpanel/Cpanel/Template/Plugin/Components.pm line 83 Cpanel::Template::Plugin::Components::has_components_for(Cpanel::Template::Plugin::Components=HASH(0x53f25a8), "whostmgr", "home", "menu-top") called at (eval 433) line 323 eval {...} called at (eval 433) line 323 eval {...} called at (eval 433) line 1 Cpanel::Template::Shared::__ANON__(Template::Context=HASH(0x52f3498)) called at /usr/local/cpanel/3rdparty/perl/542/cpanel-lib/x86_64-linux/Template/Document.pm line 166 eval {...} called at /usr/local/cpanel/3rdparty/perl/542/cpanel-lib/x86_64-linux/Template/Document.pm line 164 Template::Document::process(Template::Document=HASH(0x53f1a98), Template::Context=HASH(0x52f3498)) called at /usr/local/cpanel/3rdparty/perl/542/cpanel-lib/x86_64-linux/Template/Context.pm line 354 eval {...} called at /usr/local/cpanel/3rdparty/perl/542/cpanel-lib/x86_64-linux/Template/Context.pm line 324 Template::Context::process(Template::Context=HASH(0x52f3498), Template::Document=HASH(0x53f1a98)) called at /usr/local/cpanel/3rdparty/perl/542/cpanel-lib/x86_64-linux/Template/Service.pm line 96 eval {...} called at /usr/local/cpanel/3rdparty/perl/542/cpanel-lib/x86_64-linux/Template/Service.pm line 93 Template::Service::process(Template::Service=HASH(0x52f3018), "menu/main.tmpl", HASH(0x52f2700)) called at /usr/local/cpanel/3rdparty/perl/542/cpanel-lib/x86_64-linux/Template.pm line 66 Template::process(Template=HASH(0x52f2c10), "menu/main.tmpl", HASH(0x52f2700)) called at /usr/local/cpanel/Cpanel/Template.pm line 529 Cpanel::Template::process_template("whostmgr", HASH(0x52f2700)) called at whostmgr/bin/whostmgr10.pl line 532 main::themecommand_tmpl("main") called at whostmgr/bin/whostmgr10.pl line 435 main::roothtml(__CPANEL_HIDDEN__) called at /usr/local/cpanel/Whostmgr/Dispatch.pm line 428 Whostmgr::Dispatch::_do_call(__CPANEL_HIDDEN__, HASH(0x3945aa8), HASH(0x3971558)) called at /usr/local/cpanel/Whostmgr/Dispatch.pm line 183 Whostmgr::Dispatch::dispatch(__CPANEL_HIDDEN__, 1, ARRAY(0x3971528)) called at whostmgr/bin/whostmgr10.pl line 276
It seems that the ransomware has corrupted or deleted essential cPanel system files, such as /var/cpanel/plugins/components/homebanner.json, causing the JSON loader to fail.
I need urgent guidance on the following:
-
Is there a known recovery path for the .sorry extension ransomware on cPanel environments?
-
How can I restore the integrity of the cPanel/WHM binary files and plugins to at least regain access to the interface?
-
What are the recommended steps to investigate the entry point of this breach?
Any assistance or advice from the community or the cPanel team would be greatly appreciated.
Thank you.
-
This is unfortunately the biggest cPanel security breach in history. Two of our servers were compromised in the same way. First, we reverted to a snapshot taken two days prior and tried to update cPanel to patch the vulnerability, but as many people have written on this platform, unfortunately, the cPanel update failed (I believe this problem is cPanel-related) and the vulnerability persisted.
We closed the WHM/cPanel ports on the compromised server and transferred website backups via SSH to another clean server (a server not using cPanel). Because we had installed the snapshot, the sites were in their state before the server was hacked. We formatted the compromised server, reinstalled the operating system and cPanel, and then restored the backups we transferred to the other server.
NOTE: Be aware that if you are installing the operating system and cPanel from your datacenter images, the cPanel version included in those images may still be an older version containing security vulnerabilities. In this situation, the moment you reinstall your server, you get hacked again. The bots are so numerous and work so fast that you get hacked again before you can even update cPanel after the fresh installation.
In conclusion, cPanel truly failed miserably in this serious hacking attempt. Furthermore, it shows that this vulnerability has been exploited since February, but instead of damaging the servers, the hackers seized and backed up the data on them. After the security vulnerability was revealed, the hackers started encrypting the data on the servers and demanding a ransom in cryptocurrency (.sorry extension).
0 -
sercandemir - as you've likely seen, this was caused by the following exploit:
I'll go through and answer your questions individually to ensure nothing is missed:
Q1 - Is there a known recover path for the .sorry extension ransomware on cPanel environment?
A1 - As with any root compromise, the only safe action is to create a new server and restore the data from backups.Q2 - How can I restore the integrity of the cPanel/WHM binary files and plugins to at least regain access to the interface?
A2 - There is likely not going to be a way to do this with the server in its current state.Q3 - What are the recommended steps to investigate the entry point of this breach?
A3 - There is little point in investigating as the source is well known by now. Also, since the server's disk is already encrypted with the .sorry malware, the actual entry point would be hidden.I'm sorry I don't have better news but if you'd like to create a support ticket with our team, assuming root access to the SSH service still works, we can take a look at the server and confirm these things for you.
0
Please sign in to leave a comment.
Comments
2 comments