当前位置:网站首页>There is a mining virus in the server

There is a mining virus in the server

2022-04-23 14:02:00 Rookie cat meow meow

use top Command view , These two mining viruses , Really .
The two of us have the same solution , For example .

Find out PID

ps -ef | grep kdevtmpfsi

Delete process

sudo kill -9 [PID]

Can pass sudo crontab -l See if there are any suspicious planned tasks .

The virus will restart soon , Look at its daemon

systemctl status [ Viruses PID]

[ Failed to transfer the external chain picture , The origin station may have anti-theft chain mechanism , It is suggested to save the pictures and upload them directly (img-ujJmM3q4-1650554012207)(C:\Users\14470\Desktop\ newly build   Text document .assets\image-20220421222135428.png)]

Delete virus daemon

sudo kill -9 30409 30985

Delete Suspicious documents ’

It's usually in tmp Under the table of contents

[ Failed to transfer the external chain picture , The origin station may have anti-theft chain mechanism , It is suggested to save the pictures and upload them directly (img-WOjXqpyF-1650554012208)(C:\Users\14470\Desktop\ newly build   Text document .assets\image-20220421222539667.png)]

You can see kdevtmpfsi, These two virus files

Decisive deletion :

sudo rm kdevtmpfsi

stay /tmp Look under the directory to see :

 Insert picture description here

These are all deleted

[ Failed to transfer the external chain picture , The origin station may have anti-theft chain mechanism , It is suggested to save the pictures and upload them directly (img-BMTkVjlR-1650554012210)(C:\Users\14470\Desktop\ newly build   Text document .assets\image-20220421223641155.png)]

Delete !

  • adopt find / -name "*kdevtmpfsi*" Does the command search have kdevtmpfsi file

No, just
Now? cpu It's down .

 Insert picture description here
 Insert picture description here

After the fact check

  • adopt find / -name "*kdevtmpfsi*" Does the command search have kdevtmpfsi file
  • see Linux ssh Log in to the audit log .Centos And RedHat The audit log path is /var/log/secure,Ubuntu And Debian The audit log path is /var/log/auth.log.
  • Check crontab Is there any suspicious task in the planned task

Later protection

  • Enable ssh Public key login , Disable password login .
  • Virtual machine : Perfect security strategy , Inlet flow , Generally only open 80 443 Just port , The outlet flow can be unlimited by default , If there is a need to limit according to demand . The physical machine : Can pass Hardware firewall perhaps On the machine iptables To open the flow rules at the entrance and exit .
  • This machine does not directly need to provide external services , You can reject all traffic at the entrance of the external network card , adopt jumper Machine intranet login service machine .
  • Prohibition ip

版权声明
本文为[Rookie cat meow meow]所创,转载请带上原文链接,感谢
https://yzsam.com/2022/04/202204231342343007.html