Sunday, May 5, 2024
 Popular · Latest · Hot · Upcoming
6
rated 0 times [  6] [ 0]  / answers: 1 / hits: 2748  / 2 Years ago, thu, december 2, 2021, 4:29:39

Does anyone know what sapd, skysapd, sksapd, ksapd do? Are they viruses? I tried clamav it didn't recognized them as viruses.



my htop



I also realized that my /etc/rc.local has multiple copies of this:



nohup /etc/cupsdd > /dev/null 2>&1&
cd /etc;./ksapd
cd /etc;./kysapd
cd /etc;./atdd

More From » security

 Answers
3

It's a backdoor / DDoS trojan. Check your /etc/crontab and /etc/cron.* files for multiple cronjobs that download and execute those files. (see https://isc.sans.edu/forums/diary//17282)


[#27747] Friday, December 3, 2021, 2 Years  [reply] [flag answer]
Only authorized users can answer the question. Please sign in first, or register a free account.
brellked

Total Points: 63
Total Questions: 107
Total Answers: 104

Location: Morocco
Member since Fri, May 22, 2020
4 Years ago
;