• Hi
    I’m receiving email from CSF firewall since I Setup the cron job as the instructions, everything looks ok so far except for emails but I’m afraid that could be something else.
    I had change XXXX for IP for security reasons.
    Please advise.
    Thanks.

    [email protected]
    To [email protected]
    Time: Wed Jun 10 21:47:21 2020 -0400
    PID: 11647 (Parent PID:11644)
    Account: XXXX
    Uptime: 12739 seconds

    Executable:

    /home/virtfs/XXXX/opt/cpanel/ea-php73/root/usr/bin/php-cgi

    Command Line (often faked in exploits):

    /opt/cpanel/ea-php73/root/usr/bin/php-cgi -q wp-cron.php

    Network connections by the process (if any):

    tcp: XXX.XXX.XXX.XXX:51342 -> 51.15.237.82:80

    Files open by the process (if any):

    /home/virtfs/XXXX/tmp/.ZendSem.OuG2Xa (deleted)
    /home/virtfs/XXXX/dev/urandom
    /home/virtfs/XXXX/home/ipadshowroom/public_html/wp-content/wflogs/ips.php
    /home/virtfs/XXXX/home/ipadshowroom/public_html/wp-content/wflogs/config.php
    /home/virtfs/XXXX/home/ipadshowroom/public_html/wp-content/wflogs/attack-data.php (deleted)
    /home/virtfs/XXXX/home/ipadshowroom/public_html/wp-content/wflogs/config-synced.php (deleted)
    /home/virtfs/XXXX/home/ipadshowroom/public_html/wp-content/wflogs/config-livewaf.php (deleted)
    /home/virtfs/XXXX/home/ipadshowroom/public_html/wp-content/wflogs/config-transient.php (deleted)
    /home/virtfs/XXXX/home/ipadshowroom/public_html/wp-content/wflogs/GeoLite2-Country.mmdb
    /home/virtfs/XXXX/dev/urandom

Viewing 1 replies (of 1 total)
Viewing 1 replies (of 1 total)
  • The topic ‘Suspicious process running under user:XXXX’ is closed to new replies.