1 |
One of the servers I manage has a strange problem. |
2 |
|
3 |
Every 24h, someone starts a process shows up as perl in the list, but |
4 |
launching command is /usr/sbin/httpd. |
5 |
It shows just one process, but when I run something like this: |
6 |
|
7 |
ps -C perl -o cmd,pid |
8 |
|
9 |
I get some 5-6 processes alternatively with cmd as /usr/sbin/httpd or |
10 |
/usr/bin/perl. |
11 |
|
12 |
The even more interesting thing is, /usr/sbin/httpd does not exist. |
13 |
I suspect a rootkit, but chkrootkit & rkhunter reported nothing. |
14 |
|
15 |
Also, I found a mysterious file: /tmp/ips.txt with following content: |
16 |
xxx.xxx.xxx.xxx |
17 |
127.0.0.1 |
18 |
addr:xxx.xxx.xxx.xxx |
19 |
addr: |
20 |
addr:127.0.0.1 |
21 |
addr: |
22 |
|
23 |
Somebody is aware of a malware/rootkit which creates such files? |
24 |
|
25 |
-- |
26 |
Nilesh Govindarajan |
27 |
http://nileshgr.com |