Hello,

anyone have experience with ConfigServer eXploit Scanner (cxs) ?

i think that Namecheap using something like this on their cpanel servers. Im receiving emails like:

Dear Hosting Account '*' Owner,

This is an automated alert to inform you that we have detected a malicious attempt to access your account
...
'[PHP Shell Exploit [P0297]]': /home/*/public_html/wp-content/themes/forex/stcchatcc.php
The ConfigServer eXploit Scanner page:
http://configserver.com/cp/cxs.html ($50 onetime / server)

There is also free & open source alternative (LMD):
https://www.rfxn.com/projects/linux-malware-detect/
https://github.com/rfxn/linux-malware-detect