Thanks Charlie for your insight. I searched everywhere to find a cfhttp request that was causing the issue, but couldn't find it. I did find some unusual files that were loaded though that I know we didn't put there. I did a search and found this link that shows the code. Coldfusion CFIDE bitcoin mining exploit – PHP involved… | code-complete.com and that you mention in your article too. I don't see any of the executables running or files that were mentioned though. I found that code in 8 different spots though and removed them. Maybe our old server had the executables and hacked files on them. Hard to know as it won't boot up anymore! I think I did possibly isolate the HTTP request {URL='http://zzen1wbudopwg.nchyt.com/encfm/en0024-ssj5iway6wvg/cbeim94a1s2kebu.php?do=218', method='get'} in the http.log file to a certain site in IIS though. And it wasn't our main site. I turn off this website in IIS and it appears the weird request goes away. I turn the site back on and it starts to re-appear. It doesn't always load constantly so it's a little hard to tell. This site is pretty small. I went through each file on the site and did find one file that did appear to be hacked. It wasn't coldfusion code though. Just some html links. I removed it. That's all I could find. No cfhttp calls or anything else. We re-installed Coldfusion 11 on Friday as well and upgraded to Update 3. It doesn't stay locked at 100% as much right now, but it being over the weekend we don't get much traffic. Monday will be the real test. I think I will leave that smaller site turned off for now and see how things perform. I'm doing a full virus scan for the heck of it overnight too. Don't really expect it to find anything though. I also turned on advanced logging in IIS 7.5 and don't see anything out of the ordinary. I made sure client variables weren't in the registry either. Here's a part of the http.log file when I turn the IIS site on. I turn the site off and it stops popping up in the logs. "Information","ajp-bio-8014-exec-57","12/13/14","22:33:14",,"Starting HTTP request {URL='http://zzen1wbudopwg.nchyt.com/encfm/en0024-ssj5iway6wvg/cbeim94a1s2kebu.php?do=233', method='get'}" "Information","ajp-bio-8014-exec-57","12/13/14","22:36:17",,"Starting HTTP request {URL='http://zzen1wbudopwg.nchyt.com/encfm/en0024-ssj5iway6wvg/cbeim94a1s2kebu.php?do=601', method='get'}" "Information","ajp-bio-8014-exec-57","12/13/14","22:38:31",,"Starting HTTP request {URL='http://zzen1wbudopwg.nchyt.com/encfm/en0024-ssj5iway6wvg/cbeim94a1s2kebu.php?do=459', method='get'}" "Information","ajp-bio-8014-exec-57","12/13/14","22:38:54",,"Starting HTTP request {URL='http://zzen1wbudopwg.nchyt.com/encfm/en0024-ssj5iway6wvg/cbeim94a1s2kebu.php?do=108', method='get'}" "Information","ajp-bio-8014-exec-57","12/13/14","22:39:55",,"Starting HTTP request {URL='http://zzen1wbudopwg.nchyt.com/encfm/en0024-ssj5iway6wvg/cbeim94a1s2kebu.php?do=218', method='get'}" "Information","ajp-bio-8014-exec-63","12/13/14","22:52:03",,"Starting HTTP request {URL='http://zzen1wbudopwg.nchyt.com/encfm/en0024-ssj5iway6wvg/cbeim94a1s2kebu.php?do=54', method='get'}" "Information","ajp-bio-8014-exec-64","12/13/14","22:57:32",,"Starting HTTP request {URL='http://zzen1wbudopwg.nchyt.com/encfm/en0024-ssj5iway6wvg/cbeim94a1s2kebu.php?do=40', method='get'}" "Information","ajp-bio-8014-exec-64","12/13/14","22:58:37",,"Starting HTTP request {URL='http://zzen1wbudopwg.nchyt.com/encfm/en0024-ssj5iway6wvg/cbeim94a1s2kebu.php?do=702', method='get'}"
... View more