全球主机交流论坛

 找回密码
 注册

QQ登录

只需一步,快速开始

CeraNetworks网络延迟测速工具IP归属甄别会员请立即修改密码
查看: 585|回复: 9

乌龟壳说我挖矿,怎么破?

[复制链接]
发表于 2025-7-2 17:22:07 | 显示全部楼层 |阅读模式

Oracle Cloud Infrastructure Customer,

Oracle Cloud Infrastructure (OCI) has received notice of or detected unusual and potentially harmful activity originating from your tenancy.

Abuse Details: Crypto or Cyber-Currency Coin-Mining Activity

Action Required: Under your agreement with Oracle, you are responsible for the maintenance and security of this resource. You may wish to inspect the resource(s) for compromise or misconfiguration and mitigate the indicated issues. If the activity continues beyond the Disable By date provided in the details column, or Oracle determines that there is a significant threat to the functionality, security, integrity, or availability of our services, your resource(s) may be disabled.

我系统都重新安装了,过了几天就又收到邮件
发表于 2025-7-2 19:59:39 | 显示全部楼层
你不装探针看鸡鸡占用情况的吗
发表于 2025-7-2 17:25:27 | 显示全部楼层
Under your agreement with Oracle, you are responsible for the maintenance and security of this resource.
发表于 2025-7-2 17:32:01 | 显示全部楼层
实际情况是啥
 楼主| 发表于 2025-7-2 17:42:13 | 显示全部楼层

只用于FQ,里面啥也没装
发表于 2025-7-2 17:43:25 | 显示全部楼层
别用一键脚本
 楼主| 发表于 2025-7-2 17:48:04 | 显示全部楼层
pstree -a 的结果:

systemd
  |-accounts-daemon
  |   `-2*[{accounts-daemon}]
  |-agent
  |   |-gomon
  |   |   `-8*[{gomon}]
  |   |-oci-wlp
  |   |   `-8*[{oci-wlp}]
  |   `-7*[{agent}]
  |-agetty -o -p -- \\u --keep-baud 115200,38400,9600 ttyS0 vt220
  |-agetty -o -p -- \\u --noclear tty1 linux
  |-atd -f
  |-cron -f
  |-dbus-daemon --system --address=systemd: --nofork --nopidfile --systemd-activation --syslog-only
  |-irqbalance --foreground
  |   `-{irqbalance}
  |-lvmetad -f
  |-lxcfs /var/lib/lxcfs/
  |   `-6*[{lxcfs}]
  |-networkd-dispat /usr/bin/networkd-dispatcher --run-startup-triggers
  |   `-{networkd-dispat}
  |-polkitd --no-debug
  |   `-2*[{polkitd}]
  |-rpcbind -f -w
  |-rsyslogd -n
  |   `-3*[{rsyslogd}]
  |-screen -R trojan
  |   `-bash
  |       `-trojan-go
  |           `-8*[{trojan-go}]
  |-screen -R mihomo
  |   `-bash
  |       `-mihomo -d ./
  |           `-8*[{mihomo}]
  |-snapd
  |   `-9*[{snapd}]
  |-sshd -D
  |   `-sshd
  |       `-sshd  
  |           `-bash
  |               `-sudo -i
  |                   `-bash
  |                       `-pstree -a
  |-systemd --user
  |   `-(sd-pam)
  |-systemd-journal
  |-systemd-logind
  |-systemd-network
  |-systemd-resolve
  |-systemd-timesyn
  |   `-{systemd-timesyn}
  |-systemd-udevd
  |-unattended-upgr /usr/share/unattended-upgrades/unattended-upgrade-shutdown --wait-for-signal
  |   `-{unattended-upgr}
  `-updater
      `-8*[{updater}]
发表于 2025-7-2 18:20:27 来自手机 | 显示全部楼层
你的脚本有问题 或许是dd脚本出问题
发表于 2025-7-2 19:49:26 | 显示全部楼层
那还不重装系统等ban号吗
发表于 2025-7-2 19:51:17 | 显示全部楼层
不用查,直接去控制台后台看占用率,包准
您需要登录后才可以回帖 登录 | 注册

本版积分规则

Archiver|手机版|小黑屋|全球主机交流论坛

GMT+8, 2025-9-11 07:33 , Processed in 0.061867 second(s), 10 queries , Gzip On, MemCache On.

Powered by Discuz! X3.4

© 2001-2023 Discuz! Team.

快速回复 返回顶部 返回列表