Search found 1 match
- Sat Apr 14, 2018 3:13 am
- Forum: General Discussion
- Topic: Got 10 VestaCP servers exploited
- Replies: 548
- Views: 1073119
Procedure to remove exploited
Locate the file / process lsof -i |grep smtp ersjbxirbj 5461 root 3u IPv4 107136 0t0 TCP host.dom.br:35112->192.126.118.127:smtp Scan with clamscan -r -i /usr /usr/bin/ersjbxirbj: Unix.Trojan.DDoS_XOR-1 FOUND Change the FILE variable to the file/process name. Copy and paste running at one time FILE...