当前位置:网站首页>There is a mining virus in the server
There is a mining virus in the server
2022-04-23 14:02:00 【Rookie cat meow meow】
use top Command view , These two mining viruses , Really .
The two of us have the same solution , For example .
Find out PID
ps -ef | grep kdevtmpfsi
Delete process
sudo kill -9 [PID]
Can pass sudo crontab -l See if there are any suspicious planned tasks .
The virus will restart soon , Look at its daemon
systemctl status [ Viruses PID]
[ Failed to transfer the external chain picture , The origin station may have anti-theft chain mechanism , It is suggested to save the pictures and upload them directly ![(img-ujJmM3q4-1650554012207)(C:\Users\14470\Desktop\ newly build Text document .assets\image-20220421222135428.png)]](/img/f1/45124e181116c9af6857090dc9f441.png)
Delete virus daemon
sudo kill -9 30409 30985
Delete Suspicious documents ’
It's usually in tmp Under the table of contents
![[ Failed to transfer the external chain picture , The origin station may have anti-theft chain mechanism , It is suggested to save the pictures and upload them directly (img-WOjXqpyF-1650554012208)(C:\Users\14470\Desktop\ newly build Text document .assets\image-20220421222539667.png)]](/img/1a/2b92e2ffe0987def48f71b3c80eb85.png)
You can see kdevtmpfsi, These two virus files
Decisive deletion :
sudo rm kdevtmpfsi
stay /tmp Look under the directory to see :

These are all deleted
![[ Failed to transfer the external chain picture , The origin station may have anti-theft chain mechanism , It is suggested to save the pictures and upload them directly (img-BMTkVjlR-1650554012210)(C:\Users\14470\Desktop\ newly build Text document .assets\image-20220421223641155.png)]](/img/f8/e5f081aa2663d0e0f781ccd019577f.png)
Delete !
- adopt
find / -name "*kdevtmpfsi*"Does the command search have kdevtmpfsi file
No, just
Now? cpu It's down .


After the fact check
- adopt
find / -name "*kdevtmpfsi*"Does the command search have kdevtmpfsi file - see Linux ssh Log in to the audit log .
CentosAndRedHatThe audit log path is/var/log/secure,UbuntuAndDebianThe audit log path is/var/log/auth.log. - Check crontab Is there any suspicious task in the planned task
Later protection
- Enable
ssh Public key login, Disable password login . Virtual machine: Perfect security strategy , Inlet flow , Generally only open 80 443 Just port , The outlet flow can be unlimited by default , If there is a need to limit according to demand .The physical machine: Can passHardware firewallperhapsOn the machine iptablesTo open the flow rules at the entrance and exit .- This machine does not directly need to provide external services , You can reject all traffic at the entrance of the external network card , adopt
jumperMachine intranet login service machine .
- Prohibition ip
版权声明
本文为[Rookie cat meow meow]所创,转载请带上原文链接,感谢
https://yzsam.com/2022/04/202204231342343007.html
边栏推荐
- Crontab timing task output generates a large number of mail and runs out of file system inode problem processing
- Ptorch classical convolutional neural network lenet
- 联想产品经理林林:天津当地网络运营商网络故障 ZUI系统后台服务器暂时无法正常工作
- Programming travel function
- 记录一个奇怪的bug:缓存组件跳转之后出现组件复制
- 【项目】小帽外卖(八)
- 2021年秋招,薪资排行NO
- How does redis solve the problems of cache avalanche, cache breakdown and cache penetration
- What is the difference between blue-green publishing, rolling publishing and gray publishing?
- 微信小程序进行蓝牙初始化、搜索附近蓝牙设备及连接指定蓝牙(一)
猜你喜欢

elmo(BiLSTM-CRF+elmo)(Conll-2003 命名实体识别NER)
![[VMware] address of VMware Tools](/img/0e/13f263bd69c8224f7c755258d94777.png)
[VMware] address of VMware Tools

烟雾传感器(mq-2)使用详细教程(基于树莓派3b+实现)

Quartus prime hardware experimental development (de2-115 board) experiment 1 CPU instruction calculator design

The latest development of fed digital currency

Nacos+AspnetCore+Ocelot实战编码

Quartus Prime硬件实验开发(DE2-115板)实验一CPU指令运算器设计

Question bank and answer analysis of the 2022 simulated examination of the latest eight members of Jiangxi construction (quality control)

STM32学习记录0007——新建工程(基于寄存器版)

程序编译调试学习记录
随机推荐
网站_收藏
快捷键(多行)
elmo(BiLSTM-CRF+elmo)(Conll-2003 命名实体识别NER)
JMeter pressure test tool
Question bank and answer analysis of the 2022 simulated examination of the latest eight members of Jiangxi construction (quality control)
Elmo (bilstm-crf + Elmo) (conll-2003 named entity recognition NER)
Expression「Func「TSource, object」」 转Expression「Func「TSource, object」」[]
9月8日,临去松山湖的前夜
Business case | how to promote the activity of sports and health app users? It is enough to do these points well
Nodejs安装及环境配置
Oracle alarm log alert Chinese trace and trace files
freeCodeCamp----arithmetic_ Arranger exercise
crontab定时任务输出产生大量邮件耗尽文件系统inode问题处理
[code analysis (7)] communication efficient learning of deep networks from decentralized data
全局变量能否放在头文件中定义
Basic knowledge learning record
Analysis and understanding of atomicintegerarray source code
力扣刷题 101. 对称二叉树
Universal template for scikit learn model construction
项目中遇到的问题(五)操作Excel接口Poi的理解