Hello,
I have been receiving CRON emails for some time now that first looked like that:
Date: Thu, 8 Oct 2009 11:00:01 -0400 (EDT)
From: Cron Daemon <root@################>
To: root@##############
Subject: Cron <root@##########> /usr/share/ixscEYMlmLxu.p2/.p-2.4c i &> /dev/null
(_- phalanx 2.4d -_)
; mmap failed..bypassing /dev/mem restrictions
; locating sys_call_table..
; sys_call_table_phys = 0x6a88e0
; phys_base = 0x0
; sys_call_table = 0xffffffff806a88e0
; hooking.. ################
; locating &tcp4_seq_show..
; &tcp4_seq_show not found
>>injected
I was kind of worried, and I removed the /usr/share/ixscEYMlmLxu.p2/.p-2.4c file (I know this is a somewhat brutal approach...). Since then, I now receive, every minute, emails that look like that:
Date: Mon, 2 Nov 2009 14:08:01 -0500 (EST)
From: Cron Daemon <root@############>
To: root@####################
Subject: Cron <root@##########> /usr/share/ixscEYMlmLxu.p2/.p-2.4c i &> /dev/null
/bin/sh: /usr/share/ixscEYMlmLxu.p2/.p-2.4c: not found
I tried rkhunter and chkrootkit, but found nothing wrong. I also looked into cron and crontab to see what was scheduled every minute, but found nothing... Except these emails, the computer seems to behave normally. Any idea? Should I worry? Thanks.
--Tristan
Bookmarks