查看: 439|回复: 5
收起左侧

[可疑文件] centos7.9

[复制链接]
tom123123
发表于 2024-12-27 15:32:26 | 显示全部楼层 |阅读模式
zsbd

本帖子中包含更多资源

您需要 登录 才可以下载或查看,没有帐号?快速注册

x
202125
发表于 2024-12-27 17:08:23 | 显示全部楼层
looks fine
execve("./crond", ["./crond"], 0x7ffcc525b220 /* 12 vars */) = 0
brk(NULL)                               = 0x5fb3203dc000
mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x72a14683d000
access("/etc/ld.so.preload", R_OK)      = -1 ENOENT (No such file or directory)
open("/usr/lib/libxml2.so.2.9.2", O_RDONLY|O_CLOEXEC) = 3
read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\20\351\2\0\0\0\0\0"..., 832) = 832
fstat(3, {st_mode=S_IFREG|0755, st_size=1509600, ...}) = 0
mmap(NULL, 3575896, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x72a146200000
mprotect(0x72a14635e000, 2097152, PROT_NONE) = 0
mmap(0x72a14655e000, 40960, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x15e000) = 0x72a14655e000
mmap(0x72a146568000, 4184, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x72a146568000
close(3)                                = 0
open("/etc/ld.so.cache", O_RDONLY|O_CLOEXEC) = 3
fstat(3, {st_mode=S_IFREG|0644, st_size=15246, ...}) = 0
mmap(NULL, 15246, PROT_READ, MAP_PRIVATE, 3, 0) = 0x72a146839000
close(3)                                = 0
open("/lib64/libselinux.so.1", O_RDONLY|O_CLOEXEC) = 3
read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\220j\0\0\0\0\0\0"..., 832) = 832
fstat(3, {st_mode=S_IFREG|0755, st_size=155752, ...}) = 0
mmap(NULL, 2255216, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x72a145e00000
mprotect(0x72a145e24000, 2093056, PROT_NONE) = 0
mmap(0x72a146023000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x23000) = 0x72a146023000
mmap(0x72a146025000, 6512, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x72a146025000
close(3)                                = 0
mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x72a146838000
open("/lib64/libpam.so.0", O_RDONLY|O_CLOEXEC) = 3
read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0`&\0\0\0\0\0\0"..., 832) = 832
fstat(3, {st_mode=S_IFREG|0755, st_size=61680, ...}) = 0
mmap(NULL, 2155088, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x72a145a00000
mprotect(0x72a145a0d000, 2097152, PROT_NONE) = 0
mmap(0x72a145c0d000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0xd000) = 0x72a145c0d000
close(3)                                = 0
open("/lib64/libdl.so.2", O_RDONLY|O_CLOEXEC) = 3
read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0P\16\0\0\0\0\0\0"..., 832) = 832
fstat(3, {st_mode=S_IFREG|0755, st_size=19256, ...}) = 0
mmap(NULL, 2109744, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x72a145600000
mprotect(0x72a145602000, 2097152, PROT_NONE) = 0
mmap(0x72a145802000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x2000) = 0x72a145802000
close(3)                                = 0
open("/lib64/libaudit.so.1", O_RDONLY|O_CLOEXEC) = 3
read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0@2\0\0\0\0\0\0"..., 832) = 832
fstat(3, {st_mode=S_IFREG|0755, st_size=127192, ...}) = 0
mmap(NULL, 2261896, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x72a145200000
mprotect(0x72a14521e000, 2093056, PROT_NONE) = 0
mmap(0x72a14541d000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x1d000) = 0x72a14541d000
mmap(0x72a14541f000, 37768, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x72a14541f000
close(3)                                = 0
open("/lib64/libc.so.6", O_RDONLY|O_CLOEXEC) = 3
read(3, "\177ELF\2\1\1\3\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0`&\2\0\0\0\0\0"..., 832) = 832
fstat(3, {st_mode=S_IFREG|0755, st_size=2156664, ...}) = 0
mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x72a146837000
mmap(NULL, 3985920, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x72a144e00000
mprotect(0x72a144fc4000, 2093056, PROT_NONE) = 0
mmap(0x72a1451c3000, 24576, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x1c3000) = 0x72a1451c3000
mmap(0x72a1451c9000, 16896, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x72a1451c9000
close(3)                                = 0
open("/lib64/libz.so.1", O_RDONLY|O_CLOEXEC) = 3
read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0P!\0\0\0\0\0\0"..., 832) = 832
fstat(3, {st_mode=S_IFREG|0755, st_size=90160, ...}) = 0
mmap(NULL, 2183272, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x72a144a00000
mprotect(0x72a144a15000, 2093056, PROT_NONE) = 0
mmap(0x72a144c14000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x14000) = 0x72a144c14000
close(3)                                = 0
open("/lib64/liblzma.so.5", O_RDONLY|O_CLOEXEC) = 3
read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0`0\0\0\0\0\0\0"..., 832) = 832
fstat(3, {st_mode=S_IFREG|0755, st_size=157432, ...}) = 0
mmap(NULL, 2249352, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x72a144600000
mprotect(0x72a144625000, 2093056, PROT_NONE) = 0
mmap(0x72a144824000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x24000) = 0x72a144824000
close(3)                                = 0
open("/lib64/libm.so.6", O_RDONLY|O_CLOEXEC) = 3
read(3, "\177ELF\2\1\1\3\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0PS\0\0\0\0\0\0"..., 832) = 832
fstat(3, {st_mode=S_IFREG|0755, st_size=1136952, ...}) = 0
mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x72a146836000
mmap(NULL, 3150136, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x72a144200000
mprotect(0x72a144301000, 2093056, PROT_NONE) = 0
mmap(0x72a144500000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x100000) = 0x72a144500000
close(3)                                = 0
open("/lib64/libpcre.so.1", O_RDONLY|O_CLOEXEC) = 3
read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\360\25\0\0\0\0\0\0"..., 832) = 832
fstat(3, {st_mode=S_IFREG|0755, st_size=402384, ...}) = 0
mmap(NULL, 2494984, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x72a143e00000
mprotect(0x72a143e60000, 2097152, PROT_NONE) = 0
mmap(0x72a144060000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x60000) = 0x72a144060000
close(3)                                = 0
open("/lib64/libcap-ng.so.0", O_RDONLY|O_CLOEXEC) = 3
read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0\200\25\0\0\0\0\0\0"..., 832) = 832
fstat(3, {st_mode=S_IFREG|0755, st_size=23968, ...}) = 0
mmap(NULL, 2118016, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x72a143a00000
mprotect(0x72a143a04000, 2097152, PROT_NONE) = 0
mmap(0x72a143c04000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x4000) = 0x72a143c04000
close(3)                                = 0
mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x72a146835000
open("/lib64/libpthread.so.0", O_RDONLY|O_CLOEXEC) = 3
read(3, "\177ELF\2\1\1\0\0\0\0\0\0\0\0\0\3\0>\0\1\0\0\0Pn\0\0\0\0\0\0"..., 832) = 832
fstat(3, {st_mode=S_IFREG|0755, st_size=142504, ...}) = 0
mmap(NULL, 2208968, PROT_READ|PROT_EXEC, MAP_PRIVATE|MAP_DENYWRITE, 3, 0) = 0x72a143600000
mprotect(0x72a143617000, 2093056, PROT_NONE) = 0
mmap(0x72a143816000, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_DENYWRITE, 3, 0x16000) = 0x72a143816000
mmap(0x72a143818000, 13512, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_FIXED|MAP_ANONYMOUS, -1, 0) = 0x72a143818000
close(3)                                = 0
mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x72a146834000
mmap(NULL, 8192, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x72a146832000
arch_prctl(ARCH_SET_FS, 0x72a146832840) = 0
access("/etc/sysconfig/strcasecmp-nonascii", F_OK) = -1 ENOENT (No such file or directory)
access("/etc/sysconfig/strcasecmp-nonascii", F_OK) = -1 ENOENT (No such file or directory)
mprotect(0x72a1451c3000, 16384, PROT_READ) = 0
mprotect(0x72a143816000, 4096, PROT_READ) = 0
mprotect(0x72a143c04000, 4096, PROT_READ) = 0
mprotect(0x72a144060000, 4096, PROT_READ) = 0
mprotect(0x72a144500000, 4096, PROT_READ) = 0
mprotect(0x72a144824000, 4096, PROT_READ) = 0
mprotect(0x72a144c14000, 4096, PROT_READ) = 0
mprotect(0x72a14541d000, 4096, PROT_READ) = 0
mprotect(0x72a145802000, 4096, PROT_READ) = 0
mprotect(0x72a145c0d000, 4096, PROT_READ) = 0
mprotect(0x72a146023000, 4096, PROT_READ) = 0
mprotect(0x72a14655e000, 32768, PROT_READ) = 0
access("/etc/sysconfig/strcasecmp-nonascii", F_OK) = -1 ENOENT (No such file or directory)
mprotect(0x5fb31e40f000, 4096, PROT_READ) = 0
mprotect(0x72a146821000, 4096, PROT_READ) = 0
munmap(0x72a146839000, 15246)           = 0
set_tid_address(0x72a146832b10)         = 130
set_robust_list(0x72a146832b20, 24)     = 0
rt_sigaction(SIGRTMIN, {sa_handler=0x72a143606920, sa_mask=[], sa_flags=SA_RESTORER|SA_SIGINFO, sa_restorer=0x72a14360f8c0}, NULL, 8) = 0
rt_sigaction(SIGRT_1, {sa_handler=0x72a1436069b0, sa_mask=[], sa_flags=SA_RESTORER|SA_RESTART|SA_SIGINFO, sa_restorer=0x72a14360f8c0}, NULL, 8) = 0
rt_sigprocmask(SIG_UNBLOCK, [RTMIN RT_1], NULL, 8) = 0
getrlimit(RLIMIT_STACK, {rlim_cur=8192*1024, rlim_max=RLIM64_INFINITY}) = 0
statfs("/sys/fs/selinux", {f_type=TMPFS_MAGIC, f_bsize=4096, f_blocks=4108617, f_bfree=4108617, f_bavail=4108617, f_files=4108617, f_ffree=4108616, f_fsid={val=[1302929075, 1342907661]}, f_namelen=255, f_frsize=4096, f_flags=ST_VALID|ST_RDONLY|ST_RELATIME}) = 0
statfs("/selinux", 0x7ffc6aaa4f30)      = -1 ENOENT (No such file or directory)
brk(NULL)                               = 0x5fb3203dc000
brk(0x5fb3203fd000)                     = 0x5fb3203fd000
open("/proc/filesystems", O_RDONLY)     = 3
fstat(3, {st_mode=S_IFREG|0444, st_size=0, ...}) = 0
mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x72a14683c000
read(3, "nodev\tsysfs\nnodev\ttmpfs\nnodev\tbd"..., 1024) = 470
stat("/etc/sysconfig/64bit_strstr_via_64bit_strstr_sse2_unaligned", {st_mode=S_IFREG|0644, st_size=0, ...}) = 0
close(3)                                = 0
munmap(0x72a14683c000, 4096)            = 0
open("/proc/mounts", O_RDONLY)          = 3
fstat(3, {st_mode=S_IFREG|0444, st_size=0, ...}) = 0
mmap(NULL, 4096, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x72a14683c000
read(3, "/dev/sde1 / btrfs rw,nodev,relat"..., 1024) = 1024
read(3, "100 0 0\ncgroup /sys/fs/cgroup cg"..., 1024) = 1024
read(3, "16k,nr_inodes=4107254,mode=755 0"..., 1024) = 556
read(3, "", 1024)                       = 0
close(3)                                = 0
munmap(0x72a14683c000, 4096)            = 0
access("/etc/selinux/config", F_OK)     = -1 ENOENT (No such file or directory)
rt_sigaction(SIGCHLD, {sa_handler=0x5fb31e204500, sa_mask=[], sa_flags=SA_RESTORER|SA_RESTART, sa_restorer=0x72a144e36400}, NULL, 8) = 0
rt_sigaction(SIGHUP, {sa_handler=0x5fb31e2044f0, sa_mask=[], sa_flags=SA_RESTORER|SA_RESTART, sa_restorer=0x72a144e36400}, NULL, 8) = 0
rt_sigaction(SIGINT, {sa_handler=0x5fb31e204510, sa_mask=[], sa_flags=SA_RESTORER|SA_RESTART, sa_restorer=0x72a144e36400}, NULL, 8) = 0
rt_sigaction(SIGTERM, {sa_handler=0x5fb31e204510, sa_mask=[], sa_flags=SA_RESTORER|SA_RESTART, sa_restorer=0x72a144e36400}, NULL, 8) = 0
open("/var/run/crond.pid", O_RDWR|O_CREAT, 0600) = 3
flock(3, LOCK_EX|LOCK_NB)               = 0
fchmod(3, 0644)                         = 0
fcntl(3, F_SETFD, FD_CLOEXEC)           = 0
lseek(3, 0, SEEK_SET)                   = 0
write(3, "130\n", 4)                    = 4
ftruncate(3, 4)                         = 0
setuid(0)                               = 0
stat("/var/spool/cron", {st_mode=S_IFDIR|0700, st_size=0, ...}) = 0
clone(child_stack=NULL, flags=CLONE_CHILD_CLEARTID|CLONE_CHILD_SETTID|SIGCHLD, child_tidptr=0x72a146832b10) = 131
exit_group(0)                           = ?
+++ exited with 0 +++

strace: Process 1589114 attached
restart_syscall(<... resuming interrupted read ...>
) = 0
stat("/etc/localtime", {st_mode=S_IFREG|0644, st_size=118, ...}) = 0
select(5, [4], NULL, NULL, {tv_sec=0, tv_usec=0}) = 0 (Timeout)
rt_sigprocmask(SIG_BLOCK, [CHLD], [], 8) = 0
rt_sigaction(SIGCHLD, NULL, {sa_handler=0x5d8006004500, sa_mask=[], sa_flags=SA_RESTORER|SA_RESTART, sa_restorer=0x7c3db4236400}, 8) = 0
rt_sigprocmask(SIG_SETMASK, [], NULL, 8) = 0
nanosleep({tv_sec=60, tv_nsec=0}, 0x7ffc48f921f0) = 0
tom123123
 楼主| 发表于 2024-12-27 17:15:53 | 显示全部楼层
202125 发表于 2024-12-27 17:08
looks fine
execve("./crond", ["./crond"], 0x7ffcc525b220 /* 12 vars */) = 0
brk(NULL)              ...

没看懂。。。。
求详解。
心醉咖啡
发表于 2024-12-27 20:10:58 | 显示全部楼层
火绒扫描miss
biue
发表于 2024-12-28 00:17:13 | 显示全部楼层
腾讯电脑管家 不报
GDHJDSYDH
发表于 2024-12-28 01:24:25 | 显示全部楼层
EIS扫描miss
您需要登录后才可以回帖 登录 | 快速注册

本版积分规则

手机版|杀毒软件|软件论坛| 卡饭论坛

Copyright © KaFan  KaFan.cn All Rights Reserved.

Powered by Discuz! X3.4( 沪ICP备2020031077号-2 ) GMT+8, 2025-1-5 13:09 , Processed in 0.119790 second(s), 17 queries .

卡饭网所发布的一切软件、样本、工具、文章等仅限用于学习和研究,不得将上述内容用于商业或者其他非法用途,否则产生的一切后果自负,本站信息来自网络,版权争议问题与本站无关,您必须在下载后的24小时之内从您的电脑中彻底删除上述信息,如有问题请通过邮件与我们联系。

快速回复 客服 返回顶部 返回列表