thomasdk81
Verified User
Hi,
I am pretty new to csf and lfd.
Lfd is sending me alerts several times a minute.
The log looks like this:
I just moved away from a server which were hacked, so I am not liking this.
Is it Suspicious or do I have to white list something?
Ps. I have installed mod_ruid2 today, but I dont see any difference in the behavior above.
I am pretty new to csf and lfd.
Lfd is sending me alerts several times a minute.
The log looks like this:
Code:
Mar 16 16:46:31 server5 lfd[12228]: *Suspicious Process* PID:10894 User:apache Uptime:187 secs EXE:/usr/sbin/httpd CMD:/usr/sbin/httpd -k start -DSSL
Mar 16 16:46:31 server5 lfd[12228]: *Suspicious Process* PID:10895 User:apache Uptime:187 secs EXE:/usr/sbin/httpd CMD:/usr/sbin/httpd -k start -DSSL
Mar 16 16:46:31 server5 lfd[12228]: *Suspicious Process* PID:11029 User:nobody Uptime:139 secs EXE:/usr/local/directadmin/directadmin CMD:/usr/local/directadmin/directadmin d
Mar 16 16:46:31 server5 lfd[12228]: *Suspicious Process* PID:12126 User:nobody Uptime:124 secs EXE:/usr/local/directadmin/directadmin CMD:/usr/local/directadmin/directadmin d
Mar 16 16:46:31 server5 lfd[12228]: *Suspicious Process* PID:12129 User:nobody Uptime:117 secs EXE:/usr/local/directadmin/directadmin CMD:/usr/local/directadmin/directadmin d
Mar 16 16:46:31 server5 lfd[12228]: *Suspicious Process* PID:12134 User:nobody Uptime:115 secs EXE:/usr/local/directadmin/directadmin CMD:/usr/local/directadmin/directadmin d
Mar 16 16:46:31 server5 lfd[12228]: *Suspicious Process* PID:12138 User:nobody Uptime:106 secs EXE:/usr/local/directadmin/directadmin CMD:/usr/local/directadmin/directadmin d
Mar 16 16:46:31 server5 lfd[12228]: *Suspicious Process* PID:13447 User:mysql Uptime:522942 secs EXE:/usr/sbin/mysqld (deleted) CMD:/usr/sbin/mysqld --basedir=/ --datadir=/var/lib/mysql --user=mysql --log-error=/var/lib/mysql/server5.infoland.dk.err --pid-file=/var/lib/mysql/server5.infoland.dk.pid --socket=/var/lib/mysql/mysql.sock --port=3306
Mar 16 16:46:31 server5 lfd[12228]: *Suspicious Process* PID:20099 User:nobody Uptime:95787 secs EXE:/usr/local/directadmin/directadmin CMD:/usr/local/directadmin/directadmin d
Mar 16 16:46:31 server5 lfd[12228]: *Excessive Processes* User:apache Kill:0 Process Count:19
Mar 16 16:46:31 server5 lfd[12228]: *User Processing* PID:8866 Kill:0 User:apache Time:3902 EXE:/usr/sbin/httpd CMD:/usr/sbin/httpd -k start -DSSL
Mar 16 16:46:31 server5 lfd[12228]: *User Processing* PID:8872 Kill:0 User:apache Time:3880 EXE:/usr/sbin/httpd CMD:/usr/sbin/httpd -k start -DSSL
Mar 16 16:46:31 server5 lfd[12228]: *User Processing* PID:10396 Kill:0 User:apache VM:201(MB) EXE:/usr/sbin/httpd CMD:/usr/sbin/httpd -k start -DSSL
Mar 16 16:46:31 server5 lfd[12228]: *User Processing* PID:5661 Kill:0 User:apache Time:5227 EXE:/usr/sbin/httpd CMD:/usr/sbin/httpd -k start -DSSL
Mar 16 16:46:31 server5 lfd[12228]: *User Processing* PID:9159 Kill:0 User:dovecot Time:3513 EXE:/usr/libexec/dovecot/anvil CMD:dovecot/anvil [35 connections]
Mar 16 16:46:31 server5 lfd[12228]: *User Processing* PID:5642 Kill:0 User:apache VM:201(MB) EXE:/usr/sbin/httpd CMD:/usr/sbin/httpd -k start -DSSL
Mar 16 16:46:31 server5 lfd[12228]: *User Processing* PID:5642 Kill:0 User:apache Time:5236 EXE:/usr/sbin/httpd CMD:/usr/sbin/httpd -k start -DSSL
Mar 16 16:46:32 server5 lfd[12228]: *User Processing* PID:5868 Kill:0 User:apache Time:4961 EXE:/usr/sbin/httpd CMD:/usr/sbin/httpd -k start -DSSL
Mar 16 16:46:32 server5 lfd[12228]: *User Processing* PID:9822 Kill:0 User:apache VM:202(MB) EXE:/usr/sbin/httpd CMD:/usr/sbin/httpd -k start -DSSL
Mar 16 16:46:32 server5 lfd[12228]: *User Processing* PID:9822 Kill:0 User:apache Time:2952 EXE:/usr/sbin/httpd CMD:/usr/sbin/httpd -k start -DSSL
Mar 16 16:46:32 server5 lfd[12228]: *User Processing* PID:8867 Kill:0 User:apache Time:3901 EXE:/usr/sbin/httpd CMD:/usr/sbin/httpd -k start -DSSL
Mar 16 16:46:32 server5 lfd[12228]: *User Processing* PID:10573 Kill:0 User:apache VM:200(MB) EXE:/usr/sbin/httpd CMD:/usr/sbin/httpd -k start -DSSL
Mar 16 16:46:32 server5 lfd[12228]: *User Processing* PID:6208 Kill:0 User:apache VM:202(MB) EXE:/usr/sbin/httpd CMD:/usr/sbin/httpd -k start -DSSL
Mar 16 16:46:32 server5 lfd[12228]: *User Processing* PID:6208 Kill:0 User:apache Time:4706 EXE:/usr/sbin/httpd CMD:/usr/sbin/httpd -k start -DSSL
Mar 16 16:46:32 server5 lfd[12228]: *User Processing* PID:10400 Kill:0 User:apache VM:200(MB) EXE:/usr/sbin/httpd CMD:/usr/sbin/httpd -k start -DSSL
Mar 16 16:46:32 server5 lfd[12228]: *User Processing* PID:2596 Kill:0 User:ntp Time:709498 EXE:/usr/sbin/ntpd CMD:ntpd -u ntp:ntp -p /var/run/ntpd.pid
Mar 16 16:46:32 server5 lfd[12228]: *User Processing* PID:6214 Kill:0 User:apache VM:202(MB) EXE:/usr/sbin/httpd CMD:/usr/sbin/httpd -k start -DSSL
Mar 16 16:46:32 server5 lfd[12228]: *User Processing* PID:6214 Kill:0 User:apache Time:4661 EXE:/usr/sbin/httpd CMD:/usr/sbin/httpd -k start -DSSL
Mar 16 16:46:32 server5 lfd[12228]: *User Processing* PID:6045 Kill:0 User:apache Time:4855 EXE:/usr/sbin/httpd CMD:/usr/sbin/httpd -k start -DSSL
Mar 16 16:46:32 server5 lfd[12228]: *User Processing* PID:8868 Kill:0 User:apache Time:3901 EXE:/usr/sbin/httpd CMD:/usr/sbin/httpd -k start -DSSL
I just moved away from a server which were hacked, so I am not liking this.
Is it Suspicious or do I have to white list something?
Ps. I have installed mod_ruid2 today, but I dont see any difference in the behavior above.
Last edited: