=== VPS MAINTENANCE RAW LOG STARTED ON Thu Jun  4 11:41:11 UTC 2026 ===

[*] Phase 1: Running Pre-Checks & Environment Detection
[+] Detected OS: AlmaLinux (Version: 8.10)
[+] Detected cPanel/WHM: 134.0 (build 35)
[+] Created backup directory: /root/backup_maintenance_2026-06-04_114111
[+] Backed up critical configuration files and cron schedules.

[*] Phase 2: Gathering Performance and Resource Utilization Metrics
[+] CPU Load Average: 0.36, 0.52, 0.94 (Cores: 4)
[+] Memory Usage: 3590 MB / 5937 MB (60%)
[+] Disk space usage on all partitions is below critical threshold.
[+] Inode usage on all partitions is healthy.
Top CPU Consuming Processes:
    PID: 1577159 CPU: 80.0  MEM: 1.0   COMMAND: lsphp:/home/almashriq/public_html/wp-login.php
    PID: 1409002 CPU: 3.0   MEM: 11.6  COMMAND: /usr/sbin/mariadbd
    PID: 1577155 CPU: 2.0   MEM: 0.5   COMMAND: lsphp
    PID: 1577112 CPU: 1.5   MEM: 0.1   COMMAND: /usr/lib/systemd/systemd
    PID: 63     CPU: 0.7   MEM: 0.0   COMMAND: [kswapd0]

[*] Phase 3: Auditing SSH, Firewall, and Service Security Configurations
[!] SSH Default Port 22 is active.
[!] SSH PermitRootLogin is enabled.
[+] CSF (ConfigServer Security & Firewall) is active and running.
[+] Apache ModSecurity module is active.
[!] Imunify360 service is inactive.
[!] Insecure Services Listening: RPCBind (Port 111)
[+] Anonymous FTP access is disabled.

[*] Phase 4: Scanning for Malware, Suspicious PHP Files, and Permissive Permissions
[+] Scanning user public_html folders for suspicious files modified in the last 30 days...
[!] Found 44 suspicious PHP files. First 5 files:
[!] Found 2 world-writable files.
[+] All cron configurations and schedules appear clean.

[*] Phase 5: Auditing Service Health & cPanel License Status
[+] Service 'Apache' is active.
[+] Service 'MySQL/MariaDB' is active.
[+] Service 'Mail Server (Exim)' is active.
[+] Service 'IMAP/POP3 Server (Dovecot)' is active.
[-] Service 'DNS Server (Named)' (named) is INACTIVE!
[-] cPanel license validation failed: Updating cPanel license...Done. Update succeeded.

[*] Phase 6: Auditing System Updates & Security Patches
[!] There are 94 pending OS updates.
[!] A kernel upgrade is available.

[*] Phase 7: Compiling Findings & Report Summary
=== CRITICAL FINDINGS ===
 - Service 'DNS Server (Named)' (named) is stopped/failed!
 - cPanel License Check Failed: Updating cPanel license...Done. Update succeeded.
=== HIGH FINDINGS ===
 - SSH allows direct root logins (PermitRootLogin yes). Disabling and using a sudo user is recommended.
 - Insecure listening services detected: RPCBind (Port 111)
=== MEDIUM FINDINGS ===
 - Imunify360 is installed but inactive.
 - Found 44 suspicious PHP files containing shell indicators (e.g. obfuscated eval).
 - There are 94 pending package updates on the server.
 - A kernel upgrade is available. Applying it will require a system reboot.
=== LOW FINDINGS ===
 - SSH port is set to the default port 22. Changing to a non-standard port is recommended.
 - Found 2 world-writable files inside website document roots.
=== INFORMATIONAL FINDINGS ===
 - cPHulk control binary not found.
 - Skipped running cPanel repair tasks (Check-Only mode active).
 - Skipped interactive package updates (Check-Only mode active).
=== RECOMMENDED REMEDIATION ACTIONS ===

[!] Fix Failed Services:
    Restart service via cPanel script: /usr/local/cpanel/shared/helper_scripts/restartsrv_named

[!] Hardening SSH Daemon:
    1. Edit config: nano /etc/ssh/sshd_config
    2. Set: PermitRootLogin no
    3. Set: PasswordAuthentication no
    4. Verify configuration: sshd -t
    5. Reload SSH service: systemctl reload sshd
