当前位置:网站首页>Early in the morning, pay Bora SMS to say that you won the "prize"? Dealing with server mining virus - kthreaddi
Early in the morning, pay Bora SMS to say that you won the "prize"? Dealing with server mining virus - kthreaddi
2022-07-28 16:27:00 【Sun Fendou】
Deal with server mining virus - kthreaddi
- When your server has the following symptoms , Congratulations on winning the prize


I opened the server early this morning and found that the card was not good , So using top The order was checked , Sure enough , The server has been mined , Here is a complete solution !

Due to the soaring of bitcoin , It may drive the production of other mining viruses , This virus can not only occupy crazily cpu Resources can also attack other servers through the port of the server , It can be said that it is harmful to others but not beneficial to oneself , Very vicious !!!
Have a look first kthreaddi Ugly face
Use ll /proc/3436 have a look Where does it run 
When you see it, it appears in www The following documents are and [kthreaddi] The process user is www That may be through web Way to inject , Excluded my first idea through Redis Port entry , Then switch to this file 
It doesn't show its original shape !
There is a link to open such an advertisement of a foreign man !
【 kthreaddi 】 It's a mining virus Constantly write scheduled tasks Perform the operation
Do you think it will be solved when you find it ?
First, top Command to check the occupied process PID 3436 Kill directly But after a period of time, it will automatically establish the process , Think about it, it's someone else who came in with his ability. How can he say to leave
This kind of immortality is not tenacious , But there is a task that keeps running
Use the view scheduled task command crontab -e Sure enough, there is a scheduled task , What's more annoying is that I can't find this file
Then only Delete all scheduled tasks , That's easy to say , Would rather kill a thousand by mistake , We can't let one go ( Too reckless , It is recommended to back up the files of scheduled tasks first )
So the world is quiet !
边栏推荐
猜你喜欢

500million users, four years earlier than wechat... This app, which has been in operation for 15 years, will be permanently discontinued

The video Number finds the golden key, and Tiktok imitates the latecomers

Food safety | these two kinds of melons and fruits should be improved, especially for pregnant women with constipation

头条文章_signature

How to measure the vibrating wire sensor by vibrating wire acquisition module?

Abaqus GUI界面解决中文乱码问题(插件中文乱码也适用)

正大杯黑客马拉松数据解析竞赛

IT远程运维是什么意思?远程运维软件哪个好?

小程序中的分页查询

资本「断供」两年,我只能把公司卖了
随机推荐
500million users, four years earlier than wechat... This app, which has been in operation for 15 years, will be permanently discontinued
Telecommuting can be easily realized in only three steps
Sudden! MSI CEO Jiang Shengchang fell to death
R language uses file of FS package_ Delete function deletes the specified file under the specified folder, draw inferences from one instance, dir_ Delete function, link_ The delete function can be use
Laser rangefinder non-contact surface crack monitor
laravel
QT packaging
Thoughts on solving the pop-up of malicious computer advertisements
Leetcode topic
Deeply understand the fusing configuration of istio traffic management
SCI scientific paper writing Growth Camp (full version)
flashfxp 530 User cannot log in. ftp
flashfxp 530 User cannot log in. ftp
解决uniapp等富文本图片宽度溢出
I'll show you a little chat! Summary of single merchant function modules
JS linked list 01
QT QString详解
The little red book of accelerating investment, "rush to medical treatment"?
一小时内学会Abaqus脚本编程秘籍
laravel