当前位置:网站首页>Record a time when the server was taken to mine
Record a time when the server was taken to mine
2022-06-26 09:28:00 【gdky005】
The server was swiped ?
Recently, Alibaba cloud has always warned about various risks , It's just a simple process , I don't care .
Today, I want to read a of the server Static files , Always fail , Succeed once or twice , Alicloud servers are always connected , Once suspected the problem of the company network , Then I hung up once when I packed it remotely , That means there must be something wrong with the server .
When I came home, I found that Yapi A loophole in the will lead to mining , So I quickly banned Yapi Services related to .
It is suspected that there may be residual files , Then you have to check carefully . First, check the file path in the Alibaba cloud alarm information , Delete the deleted .
1. One case was found :

According to this address, we can find , This is the cat pool , And get the address of his stolen wallet .
Cat pool address :https://c3pool.com/cn/

** Unexpectedly 277 Miners for a period of service , And made hundreds of money .**
** 0.0444 = 55 RMB , 0.067/0.00455 + 55 == 976 RMB . near 1 Thousand pieces , Using someone else's server , Transfer your own money . *
The wallet address is :43sEd48rjD2TpXjv7ptYWq1XWLGfpRKw25w1XtNd7rQDFpxrtcvu6KrNnmiX2Ui3Zb2rqEmdbGcg4gdW1ptApHGjAc6mqww
You can monitor it later , How much can he make .
2. Then follow it down , Discover the second miner program :


There is no quantity at present .
Found another problem :


Someone from alicloud server in Shanghai .
3. Found the same record as the first one :
43sEd48rjD2TpXjv7ptYWq1XWLGfpRKw25w1XtNd7rQDFpxrtcvu6KrNnmiX2Ui3Zb2rqEmdbGcg4gdW1ptApHGjAc6mqww


3.1 A third case was found :


4. Special cases are found :


5. Another case was found :
46n4YeKAjUp2FcJnx8SFEb5CMK3kMRJ9o9MEuCzWtv2VEF5LYeq6TJKSWV3h4sEj4CQiUmsb2dNMEQcKJZJM8zCYFp7wFoy



Found the above malicious program , The file is also saved locally , The process has been deleted .
Further discovery
All domain names are from https://jhx15.zzlxrj.com/Uploads/image/goods/2021-06-07/mysql.tar.gz Download data , Before that , It must be the user operation of the server .


It was you !!!
Zhengzhou continuous Software Technology Co., Ltd , It looks like a deep dig .

Associated with so many domain names , At first glance, it is not a serious company .

Now that we have found the company , It would be QQ Contact me .

The full mailbox is :[email protected]

Many new domain names have been registered .
thus , The investigation has been completed . We'll see how to play later .

Another cloud of doubt arises ?
The next morning, I found that Alibaba cloud had another alarm , I traced it to Vietnam , Shanghai ip In heavy use of memory , Reset the system .
Upgrade now YApi The version of the to 1.9.5.
Since you are through YApi Hold my , Then I have to check what you have done ?
These tables can be found through the existing database :


That's how he attacked me
Feeling adv_mock and adv_mock_case I little interesting , Go in and have a look :


drink , Dynamically execute scripts , Um. , I little interesting .
This article by the blog one article many sends the platform OpenWrite Release !
边栏推荐
- 《一周搞定数电》——组合逻辑电路
- A Style-Based Generator Architecture for Generative Adversarial Networks
- "One week's work on Analog Electronics" - power amplifier
- [open5gs] open5gs installation configuration
- 《一周搞定模电》—负反馈
- Error importerror: numpy core. multiarray failed to import
- js---获取对象数组中key值相同的数据,得到一个新的数组
- Course paper: Copula modeling code of portfolio risk VaR
- Bug encountered in training detectron2: the test set cannot be evaluated during training
- 2021年全国职业院校技能大赛(中职组)网络安全竞赛试题(2)详解
猜你喜欢

jz2440---使用uboot烧录程序

"One week's work on Analog Electronics" - optocoupler and other components
![Li Kou 399 [division evaluation] [joint query]](/img/25/ea7d526c0628f11277141f51d4ccae.png)
Li Kou 399 [division evaluation] [joint query]

Comprehensive interpretation! Use of generics in golang

【CVPR 2021】Joint Generative and Contrastive Learning for Unsupervised Person Re-identification

《一周搞定数电》——组合逻辑电路

Solutions for safety management and control at the operation site

Understanding of swing transformer

Principe et application du micro - ordinateur à puce unique - Aperçu

"One week to solve the model electricity" - negative feedback
随机推荐
OpenCV depthframe -> pointcloud 导致 segmentation fault!
jz2440---使用uboot燒錄程序
Self taught neural network series - 3. First knowledge of neural network
使用递归或while循环获取父/子层级结构的名称
Self taught neural network series - 1 Basic programming knowledge
"One week to finish the model electricity" - 55 timer
"One week's work on digital power" -- encoder and decoder
Analysis of ROS calculation diagram level
51 single chip microcomputer ROM and ram
Is it safe to dig up money and make new debts
【CVPR 2021】 Lifelong Person Re-Identification via Adaptive Knowledge Accumulation
MySQL单表500万条数据增、删、改、查速度测试
Badge collection 6:api\_ Use of level
Creation and use of XSync synchronization script (taking debian10 cluster as an example)
The first techo day Tencent technology open day, 628
【CVPR 2021】Unsupervised Pre-training for Person Re-identification(UPT)
点击遮罩层关闭弹窗
Cancellation and unbinding of qiniu cloud account
2021年全国职业院校技能大赛(中职组)网络安全竞赛试题(2)详解
There is a strong demand for enterprise level data integration services. How to find a breakthrough for optimization?