The load in the past week on one of my servers seems to be a bit high. Here is the output of top:
As you can see something is running from perl. Here is the output of the ps command:Code:top - 15:58:09 up 2 days, 20:32, 1 user, load average: 2.03, 2.20, 2.46 Tasks: 132 total, 3 running, 127 sleeping, 1 stopped, 1 zombie Cpu(s): 0.2% us, 22.8% sy, 76.7% ni, 0.3% id, 0.0% wa, 0.0% hi, 0.0% si Mem: 969584k total, 930664k used, 38920k free, 59076k buffers Swap: 2064376k total, 144k used, 2064232k free, 404764k cached PID USER PR NI VIRT RES SHR S %CPU %MEM TIME+ COMMAND 3862 nobody 39 19 9188 3648 992 R 99 0.4 10:21.53 perl 3799 nobody 39 19 9420 3648 992 R 99 0.4 10:55.10 perl
Every time I kill these two perl commands right away the processes come back. I feel that this server may have been hacked. However I was wondering if there is any other commands I'm unaware of to find out what exactly the two "perl" processes are exactly running. Any help would be greatly appreciated.Code:nobody 3799 91.2 0.3 9420 3648 ? RN 15:46 14:05 /usr/sbin nobody 3859 0.0 0.0 0 0 ? Z 15:47 0:00 [sh] <defunct> nobody 3862 93.6 0.3 9188 3648 ? RN 15:47 13:31 /usr/sbin



LinkBack URL
About LinkBacks
Reply With Quote





