linux - Check which script create a file in /tmp -




i got malware or hack in debian. see process in top took 300% of processor load. how can check script or user creating file on , on again, can kill process in next 30 min process renew.

this process is: /tmp/phpmne0ib_jhikt717dscrcw6b -c 2 -m stratum+tcp://4ae9fi43498hg 938hg....3o4ijf3ioei0:x@monerohash.com:3333/xmr

and user of process apache (www-data).

there no sure or easy way find causing this. worse still, if find keeps running script, , rid of immediate problem, still can't sure 1) "hole" got in through has been plugged , 2) haven't installed rootkit or backdoor can in @ later date.

the best advice is:

  • shutdown compromised system
  • snapshot / preserve file system.
  • use known secure system forensically examine compromised file system. should looking evidence identify vulnerability (or bad security practice!!) lead compromise.
  • once have positively cause of problem:
    • build new version of system known clean base image (e.g. installation discs) , up-to-date copies of of software, obtained known clean sources.
    • restore files , database state backup known clean; i.e. taken prior compromise.

it unwise attempt "clean out" compromised system. unless extremely skilled in forensic security , extremely diligeny, can never sure have gotten rid of hidden backdoors, etc bad guys might have left. expert hackers @ hiding tracks ... , leading false trails / false clues make think have figured out.





wiki

Comments

Popular posts from this blog

Asterisk AGI Python Script to Dialplan does not work -

kotlin - Out-projected type in generic interface prohibits the use of metod with generic parameter -

python - Read npy file directly from S3 StreamingBody -