Edit File by line
/home/barbar84/public_h.../wp-conte.../plugins/sujqvwi/AnonR/anonr.TX.../opt/sharedra...
File: check_darkmailer.py
#!/opt/imh-python/bin/python3
[0] Fix | Delete
import time
[1] Fix | Delete
[2] Fix | Delete
import psutil
[3] Fix | Delete
from rads import send_email
[4] Fix | Delete
from platform import node
[5] Fix | Delete
[6] Fix | Delete
[7] Fix | Delete
KNOWN_MALICIOUS_CMDLINE_STRINGS = [
[8] Fix | Delete
'httpd.pl',
[9] Fix | Delete
'bash',
[10] Fix | Delete
'exim',
[11] Fix | Delete
'proc',
[12] Fix | Delete
'./cache.sh',
[13] Fix | Delete
'./xmr',
[14] Fix | Delete
'xargsu',
[15] Fix | Delete
'perxg',
[16] Fix | Delete
'mdxfs',
[17] Fix | Delete
'./backupm',
[18] Fix | Delete
'./dirty',
[19] Fix | Delete
'./apache2',
[20] Fix | Delete
'/usr/bin/host',
[21] Fix | Delete
'/usr/sbin/acpid',
[22] Fix | Delete
'./cron.php',
[23] Fix | Delete
'./milemined',
[24] Fix | Delete
'./annizod',
[25] Fix | Delete
'./fpm-worker-main',
[26] Fix | Delete
'[stealth]',
[27] Fix | Delete
]
[28] Fix | Delete
KNOWN_NONMALICOUS_CMDLINE_STRINGS = [
[29] Fix | Delete
'usr/local/cpanel/bin/ftpput',
[30] Fix | Delete
'/usr/local/cpanel/3rdparty/bin/awstats.pl',
[31] Fix | Delete
'mail.cgi',
[32] Fix | Delete
]
[33] Fix | Delete
[34] Fix | Delete
[35] Fix | Delete
def get_system_processes():
[36] Fix | Delete
"""
[37] Fix | Delete
Use psutil to generate a list of all system processes
[38] Fix | Delete
:return: list of all system processes
[39] Fix | Delete
"""
[40] Fix | Delete
all_system_processes = []
[41] Fix | Delete
[42] Fix | Delete
for system_process in psutil.process_iter():
[43] Fix | Delete
try:
[44] Fix | Delete
process_info = system_process.as_dict(
[45] Fix | Delete
attrs=['username', 'pid', 'ppid', 'create_time', 'cmdline']
[46] Fix | Delete
)
[47] Fix | Delete
except psutil.NoSuchProcess:
[48] Fix | Delete
pass
[49] Fix | Delete
else:
[50] Fix | Delete
all_system_processes.append(process_info)
[51] Fix | Delete
[52] Fix | Delete
return all_system_processes
[53] Fix | Delete
[54] Fix | Delete
[55] Fix | Delete
def filter_processes(all_system_processes):
[56] Fix | Delete
"""
[57] Fix | Delete
Use some criteria to filter out the malicious processes and create a list
[58] Fix | Delete
of them
[59] Fix | Delete
- ppid is 1
[60] Fix | Delete
- username is not root (non-root)
[61] Fix | Delete
- process is older than 5 minutes
[62] Fix | Delete
- process 'cmdline' string matches known malicious cmdline string
[63] Fix | Delete
- process 'cmdline' string doesn't match known nonmalicious cmdline string
[64] Fix | Delete
:param list of all system processes
[65] Fix | Delete
:return: list of only malicious system processes
[66] Fix | Delete
"""
[67] Fix | Delete
now = time.time()
[68] Fix | Delete
darkmailer_processes = []
[69] Fix | Delete
for system_process in all_system_processes:
[70] Fix | Delete
seconds = now - system_process['create_time']
[71] Fix | Delete
if (
[72] Fix | Delete
system_process['ppid'] == 1
[73] Fix | Delete
and system_process['username'] != "root"
[74] Fix | Delete
and seconds > 300
[75] Fix | Delete
and system_process["cmdline"][0] in KNOWN_MALICIOUS_CMDLINE_STRINGS
[76] Fix | Delete
and system_process['cmdline'][0]
[77] Fix | Delete
not in KNOWN_NONMALICOUS_CMDLINE_STRINGS
[78] Fix | Delete
):
[79] Fix | Delete
darkmailer_processes.append(system_process)
[80] Fix | Delete
[81] Fix | Delete
return darkmailer_processes
[82] Fix | Delete
[83] Fix | Delete
[84] Fix | Delete
def main():
[85] Fix | Delete
"""
[86] Fix | Delete
Function that manages flow of nagios check
[87] Fix | Delete
- Find all system processes
[88] Fix | Delete
- Filter the malicious processes
[89] Fix | Delete
- Generate nagios exit status
[90] Fix | Delete
"""
[91] Fix | Delete
all_system_processes = get_system_processes()
[92] Fix | Delete
darkmailer_processes = filter_processes(all_system_processes)
[93] Fix | Delete
[94] Fix | Delete
if darkmailer_processes:
[95] Fix | Delete
# build email body message
[96] Fix | Delete
darkmailer_processes_crit_data = []
[97] Fix | Delete
for darkmailer_process in darkmailer_processes:
[98] Fix | Delete
darkmailer_processes_crit_data.append(
[99] Fix | Delete
(darkmailer_process['pid'], darkmailer_process['username'])
[100] Fix | Delete
)
[101] Fix | Delete
[102] Fix | Delete
body = "{} CRITICAL: {} malicious scripts: {}".format(
[103] Fix | Delete
node(),
[104] Fix | Delete
len(darkmailer_processes_crit_data),
[105] Fix | Delete
darkmailer_processes_crit_data,
[106] Fix | Delete
)
[107] Fix | Delete
[108] Fix | Delete
send_email(
[109] Fix | Delete
'str@imhadmin.net',
[110] Fix | Delete
"Darkmailer Processes",
[111] Fix | Delete
body,
[112] Fix | Delete
html=None,
[113] Fix | Delete
sender=None,
[114] Fix | Delete
ssl=False,
[115] Fix | Delete
server=('localhost', 0),
[116] Fix | Delete
login=None,
[117] Fix | Delete
)
[118] Fix | Delete
[119] Fix | Delete
[120] Fix | Delete
if __name__ == "__main__":
[121] Fix | Delete
main()
[122] Fix | Delete
[123] Fix | Delete
It is recommended that you Edit text format, this type of Fix handles quite a lot in one request
Function