Suspicious process running under user:XXXX
-
Hi
I’m receiving email from CSF firewall since I Setup the cron job as the instructions, everything looks ok so far except for emails but I’m afraid that could be something else.
I had change XXXX for IP for security reasons.
Please advise.
Thanks.[email protected]
To [email protected]
Time: Wed Jun 10 21:47:21 2020 -0400
PID: 11647 (Parent PID:11644)
Account: XXXX
Uptime: 12739 secondsExecutable:
/home/virtfs/XXXX/opt/cpanel/ea-php73/root/usr/bin/php-cgi
Command Line (often faked in exploits):
/opt/cpanel/ea-php73/root/usr/bin/php-cgi -q wp-cron.php
Network connections by the process (if any):
tcp: XXX.XXX.XXX.XXX:51342 -> 51.15.237.82:80
Files open by the process (if any):
/home/virtfs/XXXX/tmp/.ZendSem.OuG2Xa (deleted)
/home/virtfs/XXXX/dev/urandom
/home/virtfs/XXXX/home/ipadshowroom/public_html/wp-content/wflogs/ips.php
/home/virtfs/XXXX/home/ipadshowroom/public_html/wp-content/wflogs/config.php
/home/virtfs/XXXX/home/ipadshowroom/public_html/wp-content/wflogs/attack-data.php (deleted)
/home/virtfs/XXXX/home/ipadshowroom/public_html/wp-content/wflogs/config-synced.php (deleted)
/home/virtfs/XXXX/home/ipadshowroom/public_html/wp-content/wflogs/config-livewaf.php (deleted)
/home/virtfs/XXXX/home/ipadshowroom/public_html/wp-content/wflogs/config-transient.php (deleted)
/home/virtfs/XXXX/home/ipadshowroom/public_html/wp-content/wflogs/GeoLite2-Country.mmdb
/home/virtfs/XXXX/dev/urandom
- The topic ‘Suspicious process running under user:XXXX’ is closed to new replies.