clamAV
yum install -y clamav*service clamd restartfreshclamclamscan -r /etc --max-dir-recursion=5 -l /root/etcclamav.logclamscan -r /bin --max-dir-recursion=5 -l /root/binclamav.logclamscan -r /usr --max-dir-recursion=5 -l /root/usrclamav.log/usr/bin/.sshd: Linux.Trojan.Agent FOUND/usr/sbin/ss: Linux.Trojan.Agent FOUND/usr/sbin/lsof: Linux.Trojan.Agent FOUNDwholastgrep "sshd" /var/log/secure
Failed password for root from 222.186.56.168 port 4080 ssh2grep "Accepted" /var/log/secure,可以看到:pop3, ssh, telnet, ftp 类型topps auxlast | morehistory >> /opt/test.txtcat /etc/passwd |awk -F \: '{print $1}'
cat /etc/passwdnetstat -lnplsof -i :18954chkconfigcat /etc/crontabcrontab -l
vim /var/spool/cron/crontabs/rootvim /var/spool/cron/rootcat /etc/rc.localcd /etc/init.d;llfind / -uid 0 –perm -4000 –printfind / -size +10000k –printfind / -name "…" –printfind / -name ".. " –printfind / -name ". " –printfind / -name " " –printyum install -y flex byacc libpcap ncurses ncurses-devel libpcap-develwget http://www.ex-parrot.com/pdw/iftop/download/iftop-0.17.tar.gztar zxf iftop-0.17.tar.gzcd iftop-0.17/./configuremake && make installyum install -y iftopiftop
iftop -nP中间部分:外部连接列表,即记录了哪些ip正在和本机的网络连接
右边部分:实时参数分别是该访问 ip 连接到本机 2 秒,10 秒和 40 秒的平均流量
=> 代表发送数据,<= 代表接收数据
底部会显示一些全局的统计数据,peek 是指峰值情况,cumm 是从 iftop 运行至今的累计情况,而 rates 表示最近 2 秒、10 秒、40 秒内总共接收或者发送的平均网络流量。
TX:(发送流量) cumm: 143MB peak: 10.5Mb rates: 1.03Mb 1.54Mb 2.10Mb
RX:(接收流量) 12.7GB 228Mb 189Mb 191Mb 183Mb
TOTAL:(总的流量) 12.9GB 229Mb 190Mb 193Mb 185MbW
vim /etc/ssh/sshd_config
vim /etc/ssh/sshd_config
vim /var/spool/cron/rootvim /var/spool/cron/crontabs/rootsystemctl stop crond127.0.0.1 prax0zma.ru
cd /proc/22935 && ll,发现程序目录是:/root/.tmp00/bash64chmod -R -x /root/.tmp00/,然后再 kill 掉该程序rm -rf /tmp/.ha /boot/.b /boot/.0 /root/.tmp00
cd ~/.ssh/ && cat authorized_keys