CPU 100% - Is it a virus?


Soberg

Recommended Posts

On 1/29/2022 at 2:23 PM, Soberg said:

Sorry I missed your reply

 

The hezb process is coming from your unifi docker app

root     11227  0.0  0.0 112036  6364 ?        Sl   20:00   0:00 /usr/bin/containerd-shim-runc-v2 -namespace moby -id 759460c22cf3d809b0564a2a0c1cc5490b1d149cbe2763eb4d3ccf90750d7a22 -address /var/run/docker/containerd/containerd.sock
root     11252  0.0  0.0    204     4 ?        Ss   20:00   0:00  \_ s6-svscan -t0 /var/run/s6/services
nobody   25600  197 14.7 2821392 2404568 ?     Ssl  20:09  24:56      \_ hezb -o 142.93.8.2:80 -u 759460c22cf3 -k -B
nobody   22263  9.6  0.0   4632  1748 ?        S    20:08   1:13      \_ /bin/sh ./6beb05a
root     11352  0.0  0.0    204     4 ?        S    20:00   0:00      \_ s6-supervise s6-fdholderd
root     11686  0.0  0.0    204     4 ?        S    20:00   0:00      \_ s6-supervise unifi
nobody   11689  4.4  4.2 4698128 685620 ?      Ssl  20:00   0:55          \_ java -Xmx1024M -jar /usr/lib/unifi/lib/ace.jar start
nobody   12542  0.5  0.6 959408 108160 ?       Sl   20:00   0:06              \_ bin/mongod --dbpath /usr/lib/unifi/data/db --port 27117 --unixSocketPrefix /usr/lib/unifi/run --logRotate reopen --logappend --logpath /usr/lib/unifi/logs/mongod.log --pidfilepath /usr/lib/unifi/run/mongod.pid --bind_ip 127.0.0.1

 

I would suggest you hit up linuxserver and @Roxedus on LSIO's discord (hit the icon and then hit support or discord) and they can properly help you diagnose if this should be here (the IP address implies that it shouldn't)  Old versions of the unifi app were susceptible to Log4J, but whether that's the case here they would know 

  • Like 1
Link to comment

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.

Guest
Reply to this topic...

×   Pasted as rich text.   Restore formatting

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.