Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- U 17 root@mail.myappname.o Tue Aug 8 20:14 28/1278 lfd on myappname.org: blocked 104.168.235.239 (US/United States/client-104-168-245-239.hostwindsdns.com)
- U 18 root@mail.myappname.o Tue Aug 8 20:49 506/51125 lfd on myappname.org: Suspicious process running under user www-data
- U 19 root@mail.myappname.o Tue Aug 8 21:00 188/16048 lfd on myappname.org: Suspicious process running under user git-auto-deploy
- U 20 root@mail.myappname.o Tue Aug 8 21:48 521/51860 lfd on myappname.org: Suspicious process running under user www-data
- U 21 root@mail.myappname.o Tue Aug 8 21:49 511/51370 lfd on myappname.org: Suspicious process running under user www-data
- U 22 root@mail.myappname.o Tue Aug 8 22:00 188/16048 lfd on myappname.org: Suspicious process running under user git-auto-deploy
- U 23 root@mail.myappname.o Tue Aug 8 22:25 28/1213 lfd on myappname.org: blocked 176.10.171.216 (SE/Sweden/h-171-216.A173.priv.bahnhof.se)
- U 24 root@mail.myappname.o Tue Aug 8 22:37 512/51498 lfd on myappname.org: Suspicious process running under user www-data
- From root@mail.myappname.org Thu Sep 7 11:58:17 2017
- Return-Path: <root@mail.myappname.org>
- X-Original-To: root
- Delivered-To: root@mail.myappname.org
- From: root@mail.myappname.org
- To: root@mail.myappname.org
- Subject: lfd on myappname.org: Suspicious process running under user www-data
- Date: Thu, 7 Sep 2017 11:58:17 -0500 (COT)
- Status: RO
- Time: Thu Sep 7 11:58:17 2017 -0500
- PID: 16349 (Parent PID:28471)
- Account: www-data
- Uptime: 176473 seconds
- Executable:
- /usr/sbin/php-fpm7.0
- Command Line (often faked in exploits):
- php-fpm: pool www
- Network connections by the process (if any):
- [I removed them, 2 tcp connections, 2 udp connections]
- Files open by the process (if any):
- /dev/null
- /dev/null
- /tmp/.ZendSem.dAvy4O (deleted)
- /dev/urandom
- /var/www/blog.myappname.org/public_html/wp-content/plugins/tracking-code-manager/includes/classes/domain
- Memory maps by the process (if any):
- 7f19b0000000-7f19b0021000 rw-p 00000000 00:00 0
- 7f19b0021000-7f19b4000000 ---p 00000000 00:00 0
- 7f19b4000000-7f19b4021000 rw-p 00000000 00:00 0
- 7f19b4021000-7f19b8000000 ---p 00000000 00:00 0
- 7f19b8000000-7f19b8021000 rw-p 00000000 00:00 0
- 7f19b8021000-7f19bc000000 ---p 00000000 00:00 0
- 7f19bc000000-7f19bc021000 rw-p 00000000 00:00 0
Add Comment
Please, Sign In to add comment