N
N
Nahs2017-05-24 08:34:13
linux
Nahs, 2017-05-24 08:34:13

Debian define process generator?

Good afternoon!
Faced a problem.
Everything related to Apache is deployed on the server under Debian.
Whether due to my clumsiness or a successful attack (a week ago we were severely ddosed)
, someone appeared on it who generates processes that hammer on various IPs with port 7000, which greatly upsets our tsiska and she goes to bed. Now the server is isolated from the outside world.
Please tell me how to identify and destroy this infection?
conclusionps -ela

1 S     0 11387     1 38  80   0 -  6745 -      ?        09:02:41 ewujhlglga
1 S  1000 11488     1  7  80   0 -  6661 -      ?        01:51:52 bfugpgmbtp
1 S  1000 11497     1  7  80   0 -  6659 -      ?        01:51:55 xdxbatlcft
1 S  1000 11677     1  0  80   0 -   364 -      ?        00:00:00 jqalrsffsj
1 S  1000 11679     1  0  80   0 -   364 -      ?        00:00:00 jqalrsffsj
1 S  1000 11682     1  0  80   0 -   364 -      ?        00:00:00 jqalrsffsj
1 S  1000 11683     1  0  80   0 -   364 -      ?        00:00:00 jqalrsffsj
1 S  1000 11685     1  0  80   0 -   364 -      ?        00:00:00 jqalrsffsj
1 S     0 11713     1  0  80   0 -   364 -      ?        00:00:00 epkghlkqlt
1 S     0 11718     1  0  80   0 -   364 -      ?        00:00:00 epkghlkqlt
1 S     0 11721     1  0  80   0 -   364 -      ?        00:00:00 epkghlkqlt
1 S     0 11723     1  0  80   0 -   364 -      ?        00:00:00 epkghlkqlt
1 S     0 11724     1  0  80   0 -   364 -      ?        00:00:00 epkghlkqlt
1 S  1000 11733     1  0  80   0 -   364 -      ?        00:00:00 aexrgivbcw
1 S  1000 11735     1  0  80   0 -   364 -      ?        00:00:00 aexrgivbcw
1 S  1000 11738     1  0  80   0 -   364 -      ?        00:00:00 aexrgivbcw
1 S  1000 11740     1  0  80   0 -   364 -      ?        00:00:00 aexrgivbcw
1 S  1000 11741     1  0  80   0 -   364 -      ?        00:00:00 aexrgivbcw

Answer the question

In order to leave comments, you need to log in

1 answer(s)
D
Dmitry, 2017-05-24
@Nahs

Please tell me how to identify and destroy this infection?

Complete reinstallation of the server.

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question