=== VPS MAINTENANCE RAW LOG STARTED ON Thu Jun  4 11:47:18 UTC 2026 ===

[*] Phase 1: Running Pre-Checks & Environment Detection
[+] Detected OS: AlmaLinux (Version: 8.10)
[+] Detected cPanel/WHM: 134.0 (build 35)
[+] Created backup directory: /root/backup_maintenance_2026-06-04_114718
[+] Backed up critical configuration files and cron schedules.

[*] Phase 2: Gathering Performance and Resource Utilization Metrics
[+] CPU Load Average: 0.58, 0.94, 1.01 (Cores: 4)
[+] Memory Usage: 3627 MB / 5937 MB (61%)
[+] Disk space usage on all partitions is below critical threshold.
[+] Inode usage on all partitions is healthy.
Top CPU Consuming Processes:
    PID: 1409002 CPU: 3.0   MEM: 11.6  COMMAND: /usr/sbin/mariadbd
    PID: 63     CPU: 0.7   MEM: 0.0   COMMAND: [kswapd0]
    PID: 258146 CPU: 0.5   MEM: 11.8  COMMAND: /usr/lib/jvm/jre-11/bin/java
    PID: 1      CPU: 0.4   MEM: 0.1   COMMAND: /usr/lib/systemd/systemd
    PID: 3130   CPU: 0.3   MEM: 0.3   COMMAND: tailwatchd

[*] Phase 3: Auditing SSH, Firewall, and Service Security Configurations
[!] SSH Default Port 22 is active.
[!] SSH PermitRootLogin is enabled.
[+] CSF (ConfigServer Security & Firewall) is active and running.
[+] Apache ModSecurity module is active.
[!] Imunify360 service is inactive.
[!] Insecure Services Listening: RPCBind (Port 111)
[+] Anonymous FTP access is disabled.

[*] Phase 4: Scanning for Malware, Suspicious PHP Files, and Permissive Permissions
[+] Scanning user public_html folders for suspicious files modified in the last 30 days...
[!] Found 44 suspicious PHP files. First 5 files:
[!] Found 2 world-writable files.
[+] All cron configurations and schedules appear clean.

[*] Phase 5: Auditing Service Health & cPanel License Status
[+] Service 'Apache' is active.
[+] Service 'MySQL/MariaDB' is active.
[+] Service 'Mail Server (Exim)' is active.
[+] Service 'IMAP/POP3 Server (Dovecot)' is active.
[-] Service 'DNS Server (Named)' (named) is INACTIVE!
[-] cPanel license validation failed: Updating cPanel license...Done. Update succeeded.

[*] Running safe cPanel self-repair routines...
[+] Cleaned user php.ini overrides.
[!] cPanel RPM audit reported issues. We will note this in the report for manual resolution.

[*] Phase 6: Auditing System Updates & Security Patches
[!] There are 94 pending OS updates.
[!] A kernel upgrade is available.

[*] Applying system upgrades, please wait...
[+] System package upgrades applied successfully.

[*] Phase 7: Compiling Findings & Report Summary
=== CRITICAL FINDINGS ===
 - Service 'DNS Server (Named)' (named) is stopped/failed!
 - cPanel License Check Failed: Updating cPanel license...Done. Update succeeded.
=== HIGH FINDINGS ===
 - SSH allows direct root logins (PermitRootLogin yes). Disabling and using a sudo user is recommended.
 - Insecure listening services detected: RPCBind (Port 111)
=== MEDIUM FINDINGS ===
 - Imunify360 is installed but inactive.
 - Found 44 suspicious PHP files containing shell indicators (e.g. obfuscated eval).
 - cPanel RPM database audit reported issues: /root/vps_maintenance_suite.sh: line 538: /scripts/check_cpanel_rpms: No such file or directory
error
 - There are 94 pending package updates on the server.
 - A kernel upgrade is available. Applying it will require a system reboot.
=== LOW FINDINGS ===
 - SSH port is set to the default port 22. Changing to a non-standard port is recommended.
 - Found 2 world-writable files inside website document roots.
=== INFORMATIONAL FINDINGS ===
 - cPHulk control binary not found.
=== RECOMMENDED REMEDIATION ACTIONS ===

[!] Fix Failed Services:
    Restart service via cPanel script: /usr/local/cpanel/shared/helper_scripts/restartsrv_named

[!] Hardening SSH Daemon:
    1. Edit config: nano /etc/ssh/sshd_config
    2. Set: PermitRootLogin no
    3. Set: PasswordAuthentication no
    4. Verify configuration: sshd -t
    5. Reload SSH service: systemctl reload sshd
