Dear All,
Recently, the Microsoft Defender reported backdoor:
from:
file: C:\Program Files (x86)\Wowza Media Systems\Wowza Streaming Engine 4.2.0\manager\temp\webapps\enginemanager\img\wowza_kmEQx.jsp
file: C:\Program Files (x86)\Wowza Media Systems\Wowza Streaming Engine 4.2.0\manager\temp\webapps\enginemanager\img\wowza_UeLWx.jsp
file: C:\Program Files (x86)\Wowza Media Systems\Wowza Streaming Engine 4.2.0\manager\temp\work\Tomcat\localhost\enginemanager\org\apache\jsp\img\wowza_005fkmEQx_jsp.java
file: C:\Program Files (x86)\Wowza Media Systems\Wowza Streaming Engine 4.2.0\manager\temp\work\Tomcat\localhost\enginemanager\org\apache\jsp\img\wowza_005fUeLWx_jsp.java
Additionally the following files were found:
C:\Program Files (x86)\Wowza Media Systems\Wowza Streaming Engine 4.2.0\manager\temp\work\Tomcat\localhost\enginemanager\org\apache\jsp\img\wowza_005fkmEQx_jsp.class
C:\Program Files (x86)\Wowza Media Systems\Wowza Streaming Engine 4.2.0\manager\temp\work\Tomcat\localhost\enginemanager\org\apache\jsp\img\wowza_005fUeLWx_jsp.class
It is assumed, that this backdoor was used to install (detected by ESET AV):
which resulted in a bitcoin mining software. That software established a VPN link to an IP reported to be blacklisted on:
https://whatismyipaddress.com/blacklist-check
The PC was showing dllhost.exe (otherwise not used) to be using 3 and then 6 CPU cores before it was blocked.
This happened on Windows 2019 Server Standard with all updates installed and Wowza Streaming Engine Version
4.8.8.01
Which we cannot update due to excessive CPU usage of the Beamr video encoder used by Wowza in the newer releases.
Is it safe to delete the contents of the folder:
C:\Program Files (x86)\Wowza Media Systems\Wowza Streaming Engine 4.2.0\manager\temp
???
It has over 100MB and 4000+ files.
Thanks!
Atmapuri