I have an Apache process running every 10 minutes.
It calls itself qmail and it is reaching to an English IP with http.
I ran lsof -p on the process and it turned out to be a perl script.
I don't know who's initiating it.
The website is not responding, so I can't get any data with tcpdump to see what it is doing...
Now I just want to find out who's calling it....
Anyone with clues how to better troubleshoot this?
66.143.14.60 is my own IP (well, not really) and 5.101.142.81 is the real IP it is targeting.
The owner is apache
There is no file called qmail anywhere in /var/www/vhosts/
It calls itself qmail and it is reaching to an English IP with http.
I ran lsof -p on the process and it turned out to be a perl script.
I don't know who's initiating it.
The website is not responding, so I can't get any data with tcpdump to see what it is doing...
Now I just want to find out who's calling it....
Anyone with clues how to better troubleshoot this?
66.143.14.60 is my own IP (well, not really) and 5.101.142.81 is the real IP it is targeting.
The owner is apache
There is no file called qmail anywhere in /var/www/vhosts/
Code:
2933 19:50 00:00:00 qmail
Code:
COMMAND PID USER FD TYPE DEVICE SIZE/OFF NODE NAME
qmail 2933 apache cwd DIR 253,0 4096 2 /
qmail 2933 apache rtd DIR 253,0 4096 2 /
qmail 2933 apache txt REG 253,0 1511826 33927562 /usr/local/bin/perl
qmail 2933 apache mem REG 253,0 144776 12812547 /lib64/ld-2.5.so
qmail 2933 apache mem REG 253,0 1726296 12812609 /lib64/libc-2.5.so
qmail 2933 apache mem REG 253,0 23360 12812615 /lib64/libdl-2.5.so
qmail 2933 apache mem REG 253,0 149968 12812610 /lib64/libpthread-2.5.so
qmail 2933 apache mem REG 253,0 18152 12812629 /lib64/libutil-2.5.so
qmail 2933 apache mem REG 253,0 614992 12812613 /lib64/libm-2.5.so
qmail 2933 apache mem REG 253,0 48600 12812625 /lib64/libcrypt-2.5.so
qmail 2933 apache mem REG 253,0 114352 12812642 /lib64/libnsl-2.5.so
qmail 2933 apache mem REG 253,0 21273 34899352 /usr/local/lib/perl5/5.14.2/x86_64-linux-thread-multi/auto/Fcntl/Fcntl.so
qmail 2933 apache mem REG 253,0 116787 34899399 /usr/local/lib/perl5/5.14.2/x86_64-linux-thread-multi/auto/POSIX/POSIX.so
qmail 2933 apache mem REG 253,0 19959 34899653 /usr/local/lib/perl5/5.14.2/x86_64-linux-thread-multi/auto/IO/IO.so
qmail 2933 apache mem REG 253,0 46086 36077988 /usr/local/lib/perl5/site_perl/5.14.2/x86_64-linux-thread-multi/auto/Socket/Socket.so
qmail 2933 apache 0r CHR 1,3 0t0 1026 /dev/null
qmail 2933 apache 1w CHR 1,3 0t0 1026 /dev/null
qmail 2933 apache 2w CHR 1,3 0t0 1026 /dev/null
qmail 2933 apache 3u IPv4 103078551 0t0 TCP 66.143.14.60:55132->5.101.142.81:http (SYN_SENT)
qmail 2933 apache 4w FIFO 0,6 0t0 103077634 pipe
qmail 2933 apache 5r FIFO 0,6 0t0 103077635 pipe