Jan 5 14:01:39 ln02 lfd[4885]: *Suspicious Process* PID:3137 User:avahi Uptime:78887 secs EXE:/usr/sbin/avahi-daemon\00\00\00\00\00\00\00\00\a1\01\00\00\00\00\00\00h (deleted) CMD:avahi-daemon: running [ln02.local]
Jan 5 14:01:40 ln02 lfd[4885]: *Suspicious Process* PID:3144 User:avahi Uptime:78887 secs EXE:/usr/sbin/avahi-daemon\00\00\00\00\00\00\00\00\a1\01\00\00\00\00\00\00h (deleted) CMD:avahi-daemon: chroot helper
Jan 5 14:01:40 ln02 lfd[4885]: *User Processing* PID:3168 Kill:0 User:clamav Time:78880 EXE:/usr/local/bin/freshclam CMD:/usr/local/bin/freshclam -d -c 6
Jan 5 14:04:40 ln02 lfd[4913]: *Suspicious Process* PID:2344 User:haldaemon Uptime:79090 secs EXE:/usr/sbin/hald\00]\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00 (deleted) CMD:hald
Jan 5 14:04:40 ln02 lfd[4913]: *Suspicious Process* PID:2353 User:haldaemon Uptime:79089 secs EXE:/usr/libexec/hald-addon-acpi\00\00\00\00\00\04\00\00\00\00\00\00\00\90rL\0b (deleted) CMD:hald-addon-acpi: listening on acpid socket /var/run/acpid.socket
Jan 5 14:04:40 ln02 lfd[4913]: *Suspicious Process* PID:2687 User:mysql Uptime:79081 secs EXE:/usr/sbin/mysqld\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00 (deleted) CMD:/usr/sbin/mysqld --basedir=/ --datadir=/var/lib/mysql --user=mysql --log-error=/var/lib/mysql/ln02.bsg.vn.err --pid-file=/var/lib/mysql/ln02.bsg.vn.pid --socket=/var/lib/mysql/mysql.sock --port=3306
Jan 5 14:04:40 ln02 lfd[4913]: *Suspicious Process* PID:3072 User:ftp Uptime:79068 secs EXE:/usr/sbin/proftpd\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00 (deleted) CMD:proftpd: (accepting connections)
Jan 5 14:24:18 ln02 lfd[5188]: *SSH login* from 113.160.2.226 into the root account using password authentication
Jan 5 15:01:50 ln02 lfd[5741]: *Suspicious Process* PID:3137 User:avahi Uptime:82498 secs EXE:/usr/sbin/avahi-daemon\00\00\00\00\00\00\00\00\a1\01\00\00\00\00\00\00h (deleted) CMD:avahi-daemon: running [ln02.local]
Jan 5 15:01:51 ln02 lfd[5741]: *Suspicious Process* PID:3144 User:avahi Uptime:82497 secs EXE:/usr/sbin/avahi-daemon\00\00\00\00\00\00\00\00\a1\01\00\00\00\00\00\00h (deleted) CMD:avahi-daemon: chroot helper
Jan 5 15:01:51 ln02 lfd[5741]: *User Processing* PID:3168 Kill:0 User:clamav Time:82490 EXE:/usr/local/bin/freshclam CMD:/usr/local/bin/freshclam -d -c 6
Jan 5 15:04:51 ln02 lfd[5769]: *Suspicious Process* PID:2344 User:haldaemon Uptime:82701 secs EXE:/usr/sbin/hald\00]\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00 (deleted) CMD:hald
Jan 5 15:04:51 ln02 lfd[5769]: *Suspicious Process* PID:2353 User:haldaemon Uptime:82700 secs EXE:/usr/libexec/hald-addon-acpi\00\00\00\00\00\04\00\00\00\00\00\00\00\90rL\0b (deleted) CMD:hald-addon-acpi: listening on acpid socket /var/run/acpid.socket
Jan 5 15:04:51 ln02 lfd[5769]: *Suspicious Process* PID:2687 User:mysql Uptime:82692 secs EXE:/usr/sbin/mysqld\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00 (deleted) CMD:/usr/sbin/mysqld --basedir=/ --datadir=/var/lib/mysql --user=mysql --log-error=/var/lib/mysql/ln02.bsg.vn.err --pid-file=/var/lib/mysql/ln02.bsg.vn.pid --socket=/var/lib/mysql/mysql.sock --port=3306
Jan 5 15:04:51 ln02 lfd[5769]: *Suspicious Process* PID:3072 User:ftp Uptime:82679 secs EXE:/usr/sbin/proftpd\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00 (deleted) CMD:proftpd: (accepting connections)
Jan 5 16:02:01 ln02 lfd[6661]: *Suspicious Process* PID:3137 User:avahi Uptime:86109 secs EXE:/usr/sbin/avahi-daemon\00\00\00\00\00\00\00\00\a1\01\00\00\00\00\00\00h (deleted) CMD:avahi-daemon: running [ln02.local]
Jan 5 16:02:01 ln02 lfd[6661]: *Suspicious Process* PID:3144 User:avahi Uptime:86108 secs EXE:/usr/sbin/avahi-daemon\00\00\00\00\00\00\00\00\a1\01\00\00\00\00\00\00h (deleted) CMD:avahi-daemon: chroot helper
Jan 5 16:02:01 ln02 lfd[6661]: *User Processing* PID:3168 Kill:0 User:clamav Time:86101 EXE:/usr/local/bin/freshclam CMD:/usr/local/bin/freshclam -d -c 6
Jan 5 16:05:01 ln02 lfd[6695]: *Suspicious Process* PID:2344 User:haldaemon Uptime:86311 secs EXE:/usr/sbin/hald\00]\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00 (deleted) CMD:hald
Jan 5 16:05:01 ln02 lfd[6695]: *Suspicious Process* PID:2353 User:haldaemon Uptime:86310 secs EXE:/usr/libexec/hald-addon-acpi\00\00\00\00\00\04\00\00\00\00\00\00\00\90rL\0b (deleted) CMD:hald-addon-acpi: listening on acpid socket /var/run/acpid.socket
Jan 5 16:05:01 ln02 lfd[6695]: *Suspicious Process* PID:2687 User:mysql Uptime:86302 secs EXE:/usr/sbin/mysqld\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00 (deleted) CMD:/usr/sbin/mysqld --basedir=/ --datadir=/var/lib/mysql --user=mysql --log-error=/var/lib/mysql/ln02.bsg.vn.err --pid-file=/var/lib/mysql/ln02.bsg.vn.pid --socket=/var/lib/mysql/mysql.sock --port=3306
Jan 5 16:05:01 ln02 lfd[6695]: *Suspicious Process* PID:3072 User:ftp Uptime:86289 secs EXE:/usr/sbin/proftpd\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00 (deleted) CMD:proftpd: (accepting connections)
Jan 5 16:35:34 ln02 lfd[7110]: 5 (sshd) login failures from 58.61.149.213 in the last 300 secs - *Blocked in csf*
Jan 5 17:02:11 ln02 lfd[7546]: *Suspicious Process* PID:3137 User:avahi Uptime:89719 secs EXE:/usr/sbin/avahi-daemon\00\00\00\00\00\00\00\00\a1\01\00\00\00\00\00\00h (deleted) CMD:avahi-daemon: running [ln02.local]
Jan 5 17:02:11 ln02 lfd[7546]: *Suspicious Process* PID:3144 User:avahi Uptime:89718 secs EXE:/usr/sbin/avahi-daemon\00\00\00\00\00\00\00\00\a1\01\00\00\00\00\00\00h (deleted) CMD:avahi-daemon: chroot helper
Jan 5 17:02:11 ln02 lfd[7546]: *User Processing* PID:3168 Kill:0 User:clamav Time:89711 EXE:/usr/local/bin/freshclam CMD:/usr/local/bin/freshclam -d -c 6
Jan 5 17:05:11 ln02 lfd[7581]: *Suspicious Process* PID:2344 User:haldaemon Uptime:89921 secs EXE:/usr/sbin/hald\00]\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00 (deleted) CMD:hald
Jan 5 17:05:11 ln02 lfd[7581]: *Suspicious Process* PID:2353 User:haldaemon Uptime:89920 secs EXE:/usr/libexec/hald-addon-acpi\00\00\00\00\00\04\00\00\00\00\00\00\00\90rL\0b (deleted) CMD:hald-addon-acpi: listening on acpid socket /var/run/acpid.socket
Jan 5 17:05:11 ln02 lfd[7581]: *Suspicious Process* PID:2687 User:mysql Uptime:89912 secs EXE:/usr/sbin/mysqld\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00 (deleted) CMD:/usr/sbin/mysqld --basedir=/ --datadir=/var/lib/mysql --user=mysql --log-error=/var/lib/mysql/ln02.bsg.vn.err --pid-file=/var/lib/mysql/ln02.bsg.vn.pid --socket=/var/lib/mysql/mysql.sock --port=3306
Jan 5 17:05:11 ln02 lfd[7581]: *Suspicious Process* PID:3072 User:ftp Uptime:89899 secs EXE:/usr/sbin/proftpd\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00\00 (deleted) CMD:proftpd: (accepting connections)