当前位置:网站首页>服务器中挖矿病毒了,屮
服务器中挖矿病毒了,屮
2022-04-23 13:42:00 【菜鸟猫喵喵】
用top命令查看 , 这俩挖矿病毒,真屮了。
这俩我解决途径一样,举一个例子说吧。
查出PID
ps -ef | grep kdevtmpfsi
删除 进程
sudo kill -9 [PID]
可以通过 sudo crontab -l 查看是否有可疑的计划任务。
病毒一会就重启了,看它的守护进程
systemctl status [病毒PID]
[外链图片转存失败,源站可能有防盗链机制,建议将图片保存下来直接上传![(img-ujJmM3q4-1650554012207)(C:\Users\14470\Desktop\新建 文本文档.assets\image-20220421222135428.png)]](/img/f1/45124e181116c9af6857090dc9f441.png)
删除病毒守护进程
sudo kill -9 30409 30985
删除 可疑文件’
一般都是在tmp目录下
![[外链图片转存失败,源站可能有防盗链机制,建议将图片保存下来直接上传(img-WOjXqpyF-1650554012208)(C:\Users\14470\Desktop\新建 文本文档.assets\image-20220421222539667.png)]](/img/1a/2b92e2ffe0987def48f71b3c80eb85.png)
可以看到kdevtmpfsi,这俩病毒文件
果断删除:
sudo rm kdevtmpfsi
在 /tmp目录下看以看到:

这些也全部删除
![[外链图片转存失败,源站可能有防盗链机制,建议将图片保存下来直接上传(img-BMTkVjlR-1650554012210)(C:\Users\14470\Desktop\新建 文本文档.assets\image-20220421223641155.png)]](/img/f8/e5f081aa2663d0e0f781ccd019577f.png)
删除!
- 通过
find / -name "*kdevtmpfsi*"命令搜索是否还有 kdevtmpfsi 文件
没有就可以了
现在cpu已经降下去了。


事后检查
- 通过
find / -name "*kdevtmpfsi*"命令搜索是否还有 kdevtmpfsi 文件 - 查看 Linux ssh 登陆审计日志。
Centos与RedHat审计日志路径为/var/log/secure,Ubuntu与Debian审计日志路径为/var/log/auth.log。 - 检查 crontab 计划任务是否有可疑任务
后期防护
- 启用
ssh公钥登陆,禁用密码登陆。 云主机:完善安全策略,入口流量,一般只开放 80 443 端口就行,出口流量默认可以不限制,如果有需要根据需求来限制。物理机:可以通过硬件防火墙或者机器上iptables来开放出入口流量规则。- 本机不是直接需要对外提供服务,可以拒绝外网卡入口所有流量,通过
jumper机器内网登陆业务机器。
- 封禁ip
版权声明
本文为[菜鸟猫喵喵]所创,转载请带上原文链接,感谢
https://blog.csdn.net/qq_45802080/article/details/124334437
边栏推荐
- Set Jianyun x Feishu Shennuo to help the enterprise operation Department realize office automation
- Oracle and MySQL batch query all table names and table name comments under users
- 初探 Lambda Powertools TypeScript
- Parameter comparison of several e-book readers
- Reading notes: Secure federated matrix factorization
- 剑南春把文字游戏玩明白了
- Troubleshooting of expdp export error when Oracle table has logical bad blocks
- Analysis of unused index columns caused by implicit conversion of timestamp
- Resolution: argument 'radius' is required to be an integer
- JUC interview questions about synchronized, ThreadLocal, thread pool and atomic atomic classes
猜你喜欢

Why do you need to learn container technology to engage in cloud native development

校园外卖系统 - 「农职邦」微信原生云开发小程序

On the bug of JS regular test method

Building MySQL environment under Ubuntu & getting to know SQL
![MySQL [read / write lock + table lock + row lock + mvcc]](/img/a9/ace85899a01a7d4fd80b2e631e44d6.png)
MySQL [read / write lock + table lock + row lock + mvcc]

Lenovo Savior y9000x 2020

Double pointer instrument panel reading (I)

Oracle job scheduled task usage details

AI21 Labs | Standing on the Shoulders of Giant Frozen Language Models(站在巨大的冷冻语言模型的肩膀上)
![MySQL [SQL performance analysis + SQL tuning]](/img/71/2ca1a5799a2c7a822158d8b73bd539.png)
MySQL [SQL performance analysis + SQL tuning]
随机推荐
Oracle job scheduled task usage details
TIA博途中基於高速計數器觸發中斷OB40實現定點加工動作的具體方法示例
SAP ui5 application development tutorial 72 - trial version of animation effect setting of SAP ui5 page routing
Innobackupex incremental backup
PG library to view the distribution keys of a table in a certain mode
Analysis of the problem that the cluster component GIPC in RAC environment cannot correctly identify the heartbeat network state
Utilisation de GDB
Oracle index status query and index reconstruction
Ora-600 encountered in Oracle environment [qkacon: fjswrwo]
Use future and countdownlatch to realize multithreading to execute multiple asynchronous tasks, and return results after all tasks are completed
Oracle lock table query and unlocking method
JUC interview questions about synchronized, ThreadLocal, thread pool and atomic atomic classes
Cross carbon market and Web3 to achieve renewable transformation
[machine learning] Note 4. KNN + cross validation
Operations related to Oracle partition
Apache Atlas Compilation and installation records
切线空间(tangent space)
Modification of table fields by Oracle
SAP UI5 应用开发教程之七十二 - SAP UI5 页面路由的动画效果设置
[barycentric coordinate interpolation, perspective correction interpolation] principle and usage opinions