Re: Hacked
Peter Hickman <[email protected]>
| Newsgroups | gmane.comp.lang.ruby.general |
|---|---|
| Message-ID | <CALxYQy7_eFsx2bczpjgaw71eDzwwevGGUg0qPoVfLTVx6ibxfA@mail.gmail.com> |
The temp folder is the /tmp folder on a Linux system. Not really something you can just drop Should have said that these are Linux boxes On Wed, 13 Feb 2019 at 13:41, Gamal Aly <[email protected]> wrote: > Sounds like that temp folder's being created by a reg file or being > autorun by some startup process. I bet if you spike that process and/or > startup value you'd be able to stop that temp folder from being created. > > All in all, I'm not entirely sure that's what's happening but personally > I'd assume as much > > https://blog.minerva-labs.com/waterminer-a-new-evasive-crypto-miner > > On Wed, Feb 13, 2019 at 8:37 AM Peter Hickman < > [email protected]> wrote: > >> Some of my servers have been hacked and running a monero(?) coin miner. >> It creates a directory >> called /tmp/systemd-private-60ffef34724f43b19fa2d3962b83687e-systemd-timesyncd.service-sPMHHT >> (or similar) >> >> Also at the same time a /tmp/bundle directory is created >> >> Do these seem related? Does anyone have an idea on this? >> >> >> Unsubscribe: <mailto:[email protected]?subject=unsubscribe> >> <http://lists.ruby-lang.org/cgi-bin/mailman/options/ruby-talk> >> > > > -- > > > *Gamal Aly* > *Senior Business Developer, Technology* > > > > > *Access Staffing, LLC*360 Lexington Avenue, 8th floor > New York, NY 10017 > > *P:* 212-687-5440 ext. 2301 > *D:* 646-307-8908 > *F: *212-818-9251 <(212)%20818-9251> > [email protected] > http://www.accessstaffing.com > > Unsubscribe: <mailto:[email protected]?subject=unsubscribe> > <http://lists.ruby-lang.org/cgi-bin/mailman/options/ruby-talk> > Unsubscribe: <mailto:[email protected]?subject=unsubscribe> <http://lists.ruby-lang.org/cgi-bin/mailman/options/ruby-talk>