All DirectAdmin servers have root login with SSH keys. I found that many virus files are spreading to all DirectAdmin accounts and all vps & servers.
An undead malicious file that will rebuild itself when deleted.
-rw-r--r-- 1 xxxx xxxx 374 Sep 12 12:10 accesson.php
-rw-rw-rw- 1 root root 10676 Sep 3 03:23 c5eXWE9oxH.php
Whenever I delete a lot of virus files, the deleted files will be undeleted in a few seconds or minutes.
The virus files are created and spread to all users very quickly, and the worst are all user accounts, even the "Admin".
If the Directadmin staff want to investigate, I can send all ssh passcode key details privately.
This is an extremely urgent case; please help.
An undead malicious file that will rebuild itself when deleted.
-rw-r--r-- 1 xxxx xxxx 374 Sep 12 12:10 accesson.php
-rw-rw-rw- 1 root root 10676 Sep 3 03:23 c5eXWE9oxH.php
Whenever I delete a lot of virus files, the deleted files will be undeleted in a few seconds or minutes.
The virus files are created and spread to all users very quickly, and the worst are all user accounts, even the "Admin".
If the Directadmin staff want to investigate, I can send all ssh passcode key details privately.
This is an extremely urgent case; please help.