This is my first post here so bear with me please.
For the past two days, I have been receiving 4 emails repetitively:
Mail 1:
Suspicious Process running under user exim
Code: Select all
Account: exim
Uptime: 610633 seconds
Executable:
/usr/sbin/exim
Command Line (often faked in exploits):
/usr/sbin/exim -bd -q1h
Network connections by the process (if any):
tcp: 127.0.0.1:25 -> 0.0.0.0:0
tcp: 127.0.0.1:465 -> 0.0.0.0:0
tcp: 127.0.0.1:587 -> 0.0.0.0:0
Files open by the process (if any):
/dev/null
/dev/null
/dev/null
Suspicious process running under user mysql
Code: Select all
Account: mysql
Uptime: 190691 seconds
Executable:
/usr/libexec/mysqld
Command Line (often faked in exploits):
/usr/libexec/mysqld --basedir=/usr --datadir=/var/lib/mysql --plugin-dir=/usr/lib64/mysql/plugin --user=mysql --log-error=/var/log/mysqld.log --pid-file=/var/run/mysqld/mysqld.pid --socket=/var/lib/mysql/mysql.sock
Network connections by the process (if any):
tcp: 0.0.0.0:3306 -> 0.0.0.0:0
Files open by the process (if any):
/dev/null
/var/log/mysqld.log
/var/log/mysqld.log
/var/lib/mysql/ibdata1
/tmp/ibPvy70e (deleted)
/tmp/ibaeef3h (deleted)
/tmp/ib7Zbn5k (deleted)
/tmp/ibBs4oAr (deleted)
/var/lib/mysql/ib_logfile0
/var/lib/mysql/ib_logfile1
/tmp/ibESBrjx (deleted)
/var/lib/mysql/mysql/host.MYI
/var/lib/mysql/mysql/host.MYD
/var/lib/mysql/mysql/user.MYI
/var/lib/mysql/mysql/user.MYD
/var/lib/mysql/mysql/db.MYI
/var/lib/mysql/mysql/db.MYD
/var/lib/mysql/mysql/proxies_priv.MYI
/var/lib/mysql/mysql/proxies_priv.MYD
/var/lib/mysql/mysql/tables_priv.MYI
/var/lib/mysql/mysql/tables_priv.MYD
/var/lib/mysql/mysql/columns_priv.MYI
/var/lib/mysql/mysql/columns_priv.MYD
/var/lib/mysql/mysql/procs_priv.MYI
/var/lib/mysql/mysql/procs_priv.MYD
/var/lib/mysql/mysql/servers.MYI
/var/lib/mysql/mysql/servers.MYD
/var/lib/mysql/mysql/event.MYI
/var/lib/mysql/mysql/event.MYD
Mail3:
Excessive resource usage: exim (1129 (Parent PID:1129))
Code: Select all
Account: exim
Resource: Process Time
Exceeded: 610633 > 1800 (seconds)
Executable: /usr/sbin/exim
Command Line: /usr/sbin/exim -bd -q1h
PID: 1129 (Parent PID:1129)
Killed: No
Excessive resource usage: mysql (469 (Parent PID:32716))
Code: Select all
Account: mysql
Resource: Process Time
Exceeded: 190691 > 1800 (seconds)
Executable: /usr/libexec/mysqld
Command Line: /usr/libexec/mysqld --basedir=/usr --datadir=/var/lib/mysql --plugin-dir=/usr/lib64/mysql/plugin --user=mysql --log-error=/var/log/mysqld.log --pid-file=/var/run/mysqld/mysqld.pid --socket=/var/lib/mysql/mysql.sock
PID: 469 (Parent PID:32716)
Killed: No