1

I am really new to linux (Centos). I am monitoring of one of our servers and I found these processes and makes the server load very heavy. Is this an attack?? I tried to google it and due to my noobnies, I do not really understand.It appeared few weeks ago. I have read it is a mining protocol.Please enlighten me.I just kill the pid to stop these. Please help.

I attached a screenshot of the htop.

Thankyou!

enter image description here

Tushar Gupta - curioustushar
  • 58,085
  • 24
  • 103
  • 107
user2885500
  • 11
  • 1
  • 4
  • Have you figured out this. I am having similar issue. Mine is bash -a cryptonight -o stratum+tcp://xmr-eu1.nanopool.org:14444 -u 44TYbh84mGoMSiuDx8hbdJ6vkcc64MAS9LnaQ2qoJX6dAxvguq8ZAy2HJLLNL1LX6QLfiWsQH9Snbhyno3BjBWMk6B1nh35 -p x – Suracheth Chawla Nov 16 '17 at 16:02

1 Answers1

1

In the event you haven't already figured this out in the month and a half since posting your question, it appears that someone is mining Litecoins on your server. It looks like they're using a cpu miner which will max out your system cpu. It also appears that they're running it from the apache account which could mean someone has hacked your webserver and gained remote command line via a script - if I were you I'd stop your apache server and begin an immediate audit on whatever site(s) you're hosting on that server. If you're feeling particularly vindictive you may also want to get a hold of wemineltc.com and report user "judge" who was the account holder benefiting from the illicit use of your server.