Time: Sat Oct 15 09:47:25 2016 -0700 PID: 10869 (Parent PID:8756) Account: mysite/ Uptime: 107 seconds Executable: /usr/bin/php Command Line (often faked in exploits): /usr/bin/php /home/mysite//public_html/oc-admin/index.php Network connections by the process (if any): tcp: my ip address:35509 -> 54.217.201.242:80 Files open by the process (if any): /tmp/sess_c1691135523fd07dda2f21a87b11a620 /home/mysite//public_html/oc-content/languages/en_US/core.mo /home/mysite//public_html/oc-content/languages/en_US/messages.mo /home/mysite//public_html/oc-content/themes/cartagena/languages/en_US/theme.mo /home/mysite//public_html/oc-content/plugins/moreedit/languages/en_US/messages.mo /home/mysite//public_html/oc-content/plugins/fb_page_plugin/languages/en_US/messages.mo /home/mysite//public_html/oc-content/plugins/location_required/languages/en_US/messages.mo /home/mysite//public_html/oc-content/plugins/paypal_advanced/languages/en_US/messages.mo /home/mysite//public_html/oc-content/plugins/republish_pro/languages/en_US/messages.mo /home/mysite//public_html/oc-content/plugins/requiredreg/languages/en_US/messages.mo /home/mysite/public_html/oc-content/plugins/seo_wiz/languages/en_US/messages.mo /home/mysite/public_html/oc-content/plugins/spam_solution/languages/en_US/messages.mo Memory maps by the process (if any): 00400000-00b28000 r-xp 00000000 08:03 134614007 /usr/bin/php 00d27000-00dae000 rw-p 00727000 08:03 134614007 /usr/bin/php 00dae000-00dcf000 rw-p 00000000 00:00 0 01108000-02437000 rw-p 00000000 00:00 0 [heap] 7f038eebc000-7f038f03f000 rw-p 00000000 00:00 0 7f038f03f000-7f038f04c000 r-xp 00000000 08:03 52428831 /lib64/libnss_files-2.12.so 7f038f04c000-7f038f24b000 ---p 0000d000 08:03 52428831 /lib64/libnss_files-2.12.so 7f038f24b000-7f038f24c000 r--p 0000c000 08:03 52428831 /lib64/libnss_files-2.12.so 7f038f24c000-7f038f24d000 rw-p 0000d000 08:03 52428831 /lib64/libnss_files-2.12.so 7f038f24d000-7f038f29f000 r-xp 00000000 08:03 137494755 /usr/local/lib/php/extensions/no-debug-non-zts-20090626/sqlite.so 7f038f29f000-7f038f49e000 ---p 00052000 08:03 137494755 /usr/local/lib/php/extensions/no-debug-non-zts-20090626/sqlite.so 7f038f49e000-7f038f4a4000 rw-p 00051000 08:03 137494755 /usr/local/lib/php/extensions/no-debug-non-zts-20090626/sqlite.so 7f038f4a4000-7f038f4ab000 r-xp 00000000 08:03 137494751 /usr/local/lib/php/extensions/no-debug-non-zts-20090626/pdo_mysql.so 7f038f4ab000-7f038f6ab000 ---p 00007000 08:03 137494751 /usr/local/lib/php/extensions/no-debug-non-zts-20090626/pdo_mysql.so 7f038f6ab000-7f038f6ac000 rw-p 00007000 08:03 137494751 /usr/local/lib/php/extensions/no-debug-non-zts-20090626/pdo_mysql.so 7f038f6ac000-7f038f744000 r-xp 00000000 08:03 137494754 /usr/local/lib/php/extensions/no-debug-non-zts-20090626/pdo_sqlite.so 7f038f744000-7f038f943000 ---p 00098000 08:03 137494754 /usr/local/lib/php/extensions/no-debug-non-zts-20090626/pdo_sqlite.so 7f038f943000-7f038f947000 rw-p 00097000 08:03 137494754 /usr/local/lib/php/extensions/no-debug-non-zts-20090626/pdo_sqlite.so 7f038f947000-7f038f95d000 r-xp 00000000 08:03 137494749 /usr/local/lib/php/extensions/no-debug-non-zts-20090626/pdo.so 7f038f95d000-7f038fb5d000 ---p 00016000 08:03 137494749 /usr/local/lib/php/extensions/no-debug-non-zts-20090626/pdo.so 7f038fb5d000-7f038fb60000 rw-p 00016000 08:03 137494749 /usr/local/lib/php/extensions/no-debug-non-zts-20090626/pdo.so 7f038fb60000-7f038fb7f000 r-xp 00000000 08:03 137494762 /usr/local/lib/php/extensions/no-debug-non-zts-20090626/suhosin.so 7f038fb7f000-7f038fd7e000 ---p 0001f000 08:03 137494762 /usr/local/lib/php/extensions/no-debug-non-zts-20090626/suhosin.so 7f038fd7e000-7f038fd84000 rw-p 0001e000 08:03 137494762 /usr/local/lib/php/extensions/no-debug-non-zts-20090626/suhosin.so
my ip address - - [21/Oct/2016:13:55:05 -0700] "POST / HTTP/1.1" 200 - "Osclass (v.361)" "-"
my ip address - - [21/Oct/2016:14:06:06 -0700] "POST / HTTP/1.1" 200 - "Osclass (v.361)" "-"
my ip address - - [21/Oct/2016:14:06:34 -0700] "POST / HTTP/1.1" 200 - "Osclass (v.361)" "-"
my ip address - - [21/Oct/2016:14:07:01 -0700] "POST / HTTP/1.1" 200 - "Osclass (v.361)" "-"
my ip address - - [21/Oct/2016:14:09:14 -0700] "POST / HTTP/1.1" 200 - "Osclass (v.361)" "-"
my ip address - - [21/Oct/2016:14:09:36 -0700] "POST / HTTP/1.1" 200 - "Osclass (v.361)" "-"
my ip address - - [21/Oct/2016:14:09:45 -0700] "POST / HTTP/1.1" 200 - "Osclass (v.361)" "-"
my ip address - - [21/Oct/2016:14:13:35 -0700] "POST / HTTP/1.1" 200 - "Osclass (v.361)" "-"
my ip address - - [21/Oct/2016:14:16:03 -0700] "POST / HTTP/1.1" 200 - "Osclass (v.361)" "-"
my ip address - - [21/Oct/2016:14:26:42 -0700] "POST / HTTP/1.1" 200 - "Osclass (v.361)" "-"
my ip address - - [21/Oct/2016:14:26:42 -0700] "POST / HTTP/1.1" 200 - "Osclass (v.361)" "-"
my ip address - - [21/Oct/2016:14:26:59 -0700] "POST / HTTP/1.1" 200 - "Osclass (v.361)" "-"
my ip address - - [21/Oct/2016:14:43:44 -0700] "POST / HTTP/1.1" 200 - "Osclass (v.361)" "-"
my ip address - - [21/Oct/2016:14:48:12 -0700] "POST / HTTP/1.1" 200 - "Osclass (v.361)" "-"
my ip address - - [21/Oct/2016:14:48:15 -0700] "POST / HTTP/1.1" 200 - "Osclass (v.361)" "-"
my ip address - - [21/Oct/2016:14:49:54 -0700] "POST / HTTP/1.1" 200 - "Osclass (v.361)" "-"
my ip address - - [21/Oct/2016:14:50:27 -0700] "POST / HTTP/1.1" 200 - "Osclass (v.361)" "-"
my ip address - - [21/Oct/2016:14:52:35 -0700] "POST / HTTP/1.1" 200 - "Osclass (v.361)" "-"
my ip address - - [21/Oct/2016:14:52:39 -0700] "POST / HTTP/1.1" 200 - "Osclass (v.361)" "-"
my ip address - - [21/Oct/2016:14:53:46 -0700] "POST / HTTP/1.1" 200 - "Osclass (v.361)" "-"
my ip address - - [21/Oct/2016:14:53:47 -0700] "POST / HTTP/1.1" 200 - "Osclass (v.361)" "-"
my ip address - - [21/Oct/2016:14:54:49 -0700] "POST / HTTP/1.1" 200 - "Osclass (v.361)" "-"
my ip address - - [21/Oct/2016:14:56:59 -0700] "POST / HTTP/1.1" 200 - "Osclass (v.361)" "-"
my ip address - - [21/Oct/2016:14:57:24 -0700] "POST / HTTP/1.1" 200 - "Osclass (v.361)" "-"
my ip address - - [21/Oct/2016:14:58:12 -0700] "POST / HTTP/1.1" 200 - "Osclass (v.361)" "-"
Time: Wed Nov 16 02:17:11 2016 -0800
PID: 32434 (Parent PID:28965)
Account: mysite
Uptime: 125 seconds
Executable:
/usr/bin/php
Command Line (often faked in exploits):
/usr/bin/php /home/mysite/public_html/index.php
Network connections by the process (if any):
tcp: 71.19.244.97:40201 -> 91.134.29.33:80
Files open by the process (if any):
/tmp/sess_0186e010f86c76ad2c5acdbf43e85208
/home/mysite/public_html/oc-content/languages/en_US/core.mo
/home/mysite/public_html/oc-content/languages/en_US/messages.mo
/home/mysite/public_html/oc-content/themes/ctg_classifieds_cvclassifieds/languages/en_US/theme.mo
/home/mysite/public_html/oc-content/plugins/ads4osc/languages/en_US/messages.mo
/home/mysite/public_html/oc-content/plugins/products_attributes/languages/en_US/messages.mo
/home/mysite/public_html/oc-content/plugins/realestate_attributes/languages/en_US/messages.mo
/home/mysite/public_html/oc-content/plugins/location_required/languages/en_US/messages.mo
/home/mysite/public_html/oc-content/plugins/spam_solution/languages/en_US/messages.mo
/home/mysite/public_html/oc-content/plugins/fb_page_plugin/languages/en_US/messages.mo
/home/mysite/public_html/oc-content/plugins/seo_wiz/languages/en_US/messages.mo
/home/mysite/public_html/oc-content/plugins/paypal_advanced/languages/en_US/messages.mo
/home/mysite/public_html/oc-content/plugins/requiredreg/languages/en_US/messages.mo
/home/mysite/public_html/oc-content/plugins/republish_pro/languages/en_US/messages.mo
/home/mysite/public_html/oc-content/plugins/moreedit/languages/en_US/messages.mo
/home/mysite/public_html/oc-content/plugins/ghost_fix/languages/en_US/messages.mo
Memory maps by the process (if any):
00400000-00b28000 r-xp 00000000 08:03 134614007 /usr/bin/php
00d27000-00dae000 rw-p 00727000 08:03 134614007 /usr/bin/php
00dae000-00dcf000 rw-p 00000000 00:00 0
023da000-03784000 rw-p 00000000 00:00 0 [heap]
7f2356ad8000-7f2356c5b000 rw-p 00000000 00:00 0
7f2356c5b000-7f2356c68000 r-xp 00000000 08:03 52428831 /lib64/libnss_files-2.12.so
7f2356c68000-7f2356e67000 ---p 0000d000 08:03 52428831 /lib64/libnss_files-2.12.so
7f2356e67000-7f2356e68000 r--p 0000c000 08:03 52428831 /lib64/libnss_files-2.12.so
7f2356e68000-7f2356e69000 rw-p 0000d000 08:03 52428831 /lib64/libnss_files-2.12.so
7f2356e69000-7f2356ebb000 r-xp 00000000 08:03 137494755 /usr/local/lib/php/extensions/no-debug-non-zts-20090626/sqlite.so
7f2356ebb000-7f23570ba000 ---p 00052000 08:03 137494755 /usr/local/lib/php/extensions/no-debug-non-zts-20090626/sqlite.so
7f23570ba000-7f23570c0000 rw-p 00051000 08:03 137494755 /usr/local/lib/php/extensions/no-debug-non-zts-20090626/sqlite.so
7f23570c0000-7f23570c7000 r-xp 00000000 08:03 137494751 /usr/local/lib/php/extensions/no-debug-non-zts-20090626/pdo_mysql.so
7f23570c7000-7f23572c7000 ---p 00007000 08:03 137494751 /usr/local/lib/php/extensions/no-debug-non-zts-20090626/pdo_mysql.so
7f23572c7000-7f23572c8000 rw-p 00007000 08:03 137494751 /usr/local/lib/php/extensions/no-debug-non-zts-20090626/pdo_mysql.so
7f23572c8000-7f2357360000 r-xp 00000000 08:03 137494754 /usr/local/lib/php/extensions/no-debug-non-zts-20090626/pdo_sqlite.so
7f2357360000-7f235755f000 ---p 00098000 08:03 137494754 /usr/local/lib/php/extensions/no-debug-non-zts-20090626/pdo_sqlite.so
7f235755f000-7f2357563000 rw-p 00097000 08:03 137494754 /usr/local/lib/php/extensions/no-debug-non-zts-20090626/pdo_sqlite.so
7f2357563000-7f2357579000 r-xp 00000000 08:03 137494749 /usr/local/lib/php/extensions/no-debug-non-zts-20090626/pdo.so
7f2357579000-7f2357779000 ---p 00016000 08:03 137494749 /usr/local/lib/php/extensions/no-debug-non-zts-20090626/pdo.so
7f2357779000-7f235777c000 rw-p 00016000 08:03 137494749 /usr/local/lib/php/extensions/no-debug-non-zts-20090626/pdo.so
7f235777c000-7f235779b000 r-xp 00000000 08:03 137494762 /usr/local/lib/php/extensions/no-debug-non-zts-20090626/suhosin.so
7f235779b000-7f235799a000 ---p 0001f000 08:03 137494762 /usr/local/lib/php/extensions/no-debug-non-zts-20090626/suhosin.so
7f235799a000-7f23579a0000 rw-p 0001e000 08:03 137494762 /usr/local/lib/php/extensions/no-debug-non-zts-20090626/suhosin.so
wget https://www.website.com/index.php?page=cron -O /dev/null