🚀 go-pugleaf

RetroBBS NetNews Server

Inspired by RockSolid Light RIP Retro Guy

3 total messages Started by "Android8675" Tue, 15 Nov 2022 00:51
Ubuntu, Crypto Malware
#10
Author: "Android8675"
Date: Tue, 15 Nov 2022 00:51
10 lines
793 bytes
Hey all, anyone have any experience with crypto infected Linux systems? My box that I use has mxrig running, and I've no idea how it got there, where it's hiding, or how to get it off my system. Speculating that it could be some rootkit bologna, and there's vague suggestions on the googles as to how to get it off my system without "nuking it from orbit".

So, before I do that I thought I might see if there's anyone who's had experience with this sort of thing who might be willing to take a peek? Drop me a note at andyob [at] gmail.com if you've had some experience. I got the thing backed up, so I'm ok with letting you pop-on and see if you can work some magic.

Thanks in advance,
-A @ shodanscore.com

---
 þ Synchronet þ Vertrauen þ Home of Synchronet þ [vert/cvs/bbs].synchro.net
.
Ubuntu, Crypto Malware
#11
Author: "Digital Man"
Date: Tue, 15 Nov 2022 04:51
25 lines
1771 bytes
  Re: Ubuntu, Crypto Malware
  By: Android8675 to All on Tue Nov 15 2022 07:51 am

 > Hey all, anyone have any experience with crypto infected Linux systems? My
 > box that I use has mxrig running, and I've no idea how it got there, where
 > it's hiding, or how to get it off my system. Speculating that it could be
 > some rootkit bologna, and there's vague suggestions on the googles as to how
 > to get it off my system without "nuking it from orbit".
 >
 > So, before I do that I thought I might see if there's anyone who's had
 > experience with this sort of thing who might be willing to take a peek? Drop
 > me a note at andyob [at] gmail.com if you've had some experience. I got the
 > thing backed up, so I'm ok with letting you pop-on and see if you can work
 > some magic.

I was running a version of GitLab (a year ago?) that had an exploit published and I was vulnerable for about 24 hours before upgrading to a fixed GitLab version. During that 24 hours, a crypto miner (I forget the name) was installed and it was pretty obvious from the impact on CPU utilization. I found and killed the process manually and deleted the maliciously-installed files (in the /tmp dir, iirc). Tools like ps, top, netstat should help you find the culperate process(es) and get rid of them, but it is important that you find and remove (or update/patch) the software with the original vulnerability that was used to install the crypto miner in the first place.
--
                                            digital man (rob)

Rush quote #57:
He picks up scraps of information, he's adept at adaptation .. Digital Man
Norco, CA WX: 68.5øF, 21.0% humidity, 0 mph NE wind, 0.00 inches rain/24hrs
---
 þ Synchronet þ Vertrauen þ Home of Synchronet þ [vert/cvs/bbs].synchro.net
.
Ubuntu, Crypto Malware
#12
Author: "MRO"
Date: Tue, 15 Nov 2022 09:33
27 lines
1078 bytes
  Re: Ubuntu, Crypto Malware
  By: Android8675 to All on Tue Nov 15 2022 07:51 am

 > Hey all, anyone have any experience with crypto infected Linux systems? My
 > box that I use has mxrig running, and I've no idea how it got there, where
 > it's hiding, or how to get it off my system. Speculating that it could be
 > some rootkit bologna, and there's vague suggestions on the googles as to how
 > to get it off my system without "nuking it from orbit".
 >
 > So, before I do that I thought I might see if there's anyone who's had
 > experience with this sort of thing who might be willing to take a peek? Drop
 > me a note at andyob [at] gmail.com if you've had some experience. I got the
 > thing backed up, so I'm ok with letting you pop-on and see if you can work
 > some magic.


if you have it backed up, and your backups are clean, just 'nuke it from orbit'.

why do you want to waste time going on a search for it?
if your files are encrypted you aren't getting them back and you might lose
more anyways.



---
 þ Synchronet þ ::: BBSES.info - free BBS services :::
.
Thread Navigation

This is a paginated view of messages in the thread with full content displayed inline.

Messages are displayed in chronological order, with the original post highlighted in green.

Use pagination controls to navigate through all messages in large threads.

Back to All Threads