We got notices by our vps provider that our vps have maybe problems:
They point to this report: http://firewall.sigsiu.net/index.php?ip=85.17.149.15&force=1
On the server we notice there is a large amount of perl processes.
When we check the command by one of those processes in /proc is said:
/usr/sbin/apache2 -k start
We also did enable server-status in http to find out more information about the proces, but these processes were not displayed.
Then we run rkhunter, it didnt detcect any malware.
My question is how can we be sure this vps isnt hack, how can we find out more information about the perl processes?
Thanks a lot.
They point to this report: http://firewall.sigsiu.net/index.php?ip=85.17.149.15&force=1
On the server we notice there is a large amount of perl processes.
When we check the command by one of those processes in /proc is said:
/usr/sbin/apache2 -k start
We also did enable server-status in http to find out more information about the proces, but these processes were not displayed.
Then we run rkhunter, it didnt detcect any malware.
My question is how can we be sure this vps isnt hack, how can we find out more information about the perl processes?
Thanks a lot.