CMD.war found in Insight IDR

Hi guys,

We got a notification from S1 that there is a malicious file cmd.war and it is being created and used by the ir_agent. Please see the screenshots

I wonder if this is expected behavior?

image
image


Also,I’ve been having this issue when trying to open the support portal:

image

If anyone from the R7 team see this please help me to fix it. Thank you guys