当前位置:网站首页>Early in the morning, pay Bora SMS to say that you won the "prize"? Dealing with server mining virus - kthreaddi
Early in the morning, pay Bora SMS to say that you won the "prize"? Dealing with server mining virus - kthreaddi
2022-07-28 16:27:00 【Sun Fendou】
Deal with server mining virus - kthreaddi
- When your server has the following symptoms , Congratulations on winning the prize


I opened the server early this morning and found that the card was not good , So using top The order was checked , Sure enough , The server has been mined , Here is a complete solution !

Due to the soaring of bitcoin , It may drive the production of other mining viruses , This virus can not only occupy crazily cpu Resources can also attack other servers through the port of the server , It can be said that it is harmful to others but not beneficial to oneself , Very vicious !!!
Have a look first kthreaddi Ugly face
Use ll /proc/3436 have a look Where does it run 
When you see it, it appears in www The following documents are and [kthreaddi] The process user is www That may be through web Way to inject , Excluded my first idea through Redis Port entry , Then switch to this file 
It doesn't show its original shape !
There is a link to open such an advertisement of a foreign man !
【 kthreaddi 】 It's a mining virus Constantly write scheduled tasks Perform the operation
Do you think it will be solved when you find it ?
First, top Command to check the occupied process PID 3436 Kill directly But after a period of time, it will automatically establish the process , Think about it, it's someone else who came in with his ability. How can he say to leave
This kind of immortality is not tenacious , But there is a task that keeps running
Use the view scheduled task command crontab -e Sure enough, there is a scheduled task , What's more annoying is that I can't find this file
Then only Delete all scheduled tasks , That's easy to say , Would rather kill a thousand by mistake , We can't let one go ( Too reckless , It is recommended to back up the files of scheduled tasks first )
So the world is quiet !
边栏推荐
- Numpy ndarray learning < II > miscellaneous records
- Common problems and precautions of remote serial port server (adapter) uart/i2c/1-wire/spi PS304
- 李宏毅《机器学习》丨4. Deep Learning(深度学习)
- KubeEdge发布云原生边缘计算威胁模型及安全防护技术白皮书
- 深入理解Istio流量管理的熔断配置
- LwIP development | socket | TCP | client
- 食品安全 | 这两类瓜果宜改善便秘 孕妇人群尤其建议
- 头条文章_signature
- The video Number finds the golden key, and Tiktok imitates the latecomers
- Notes on October 22, 2021
猜你喜欢

Abaqus GUI界面解决中文乱码问题(插件中文乱码也适用)

一小时内学会Abaqus脚本编程秘籍

我在上海偶遇数字凤凰#坐标徐汇美罗城

CoDeSys realizes bubble sorting

疫情红利消失,「居家健身」泡沫消散

The video Number finds the golden key, and Tiktok imitates the latecomers

Zhengda cup hacker marathon data analysis competition

LwIP development | realize TCP server through socket

ANSA二次开发 - 抽中面的两种方法

HyperMesh自动保存(增强版)插件使用说明
随机推荐
百度编辑器ueditor,编辑内容过多时,工具栏不可见,不方便编辑或上传问题
LabVIEW LINX Toolkit控制Arduino设备(拓展篇—1)
The video Number finds the golden key, and Tiktok imitates the latecomers
Wechat official account to obtain material list
Common problems and precautions of remote serial port server (adapter) uart/i2c/1-wire/spi PS304
Practical development tutorial of software problem repair tracking system (Part 1)
Wei Jianjun couldn't catch up with Li Shufu by riding a BMW
Notes on October 22, 2021
后台弹出layer提示
Qt学习之信号和槽机制
Zhaoqi science and technology innovation and entrepreneurship competition talent introduction platform, mass entrepreneurship and entrepreneurship competition high-level talent introduction
PHP计算坐标距离
关于标准IO缓冲区的问题
ANSA二次开发 - 抽中面的两种方法
PHP mb_ Substr Chinese garbled code
1. Simple command line connection to database
flashfxp 530 User cannot log in. ftp
Application of optical rain gauge to rainfall detection
mysql查询 limit 1000,10 和limit 10 速度一样快吗?如果我要分页,我该怎么办?
Redis系列4:高可用之Sentinel(哨兵模式)