Ubuntu 16.04.03虚拟机出现yam比特币挖矿进程致CPU满载求助
Alright, let's tackle this mining malware situation on your OpenVPN VM. Since only this specific Ubuntu 16.04.03 VM (which only runs OpenVPN) is affected, and your host machine and other VMs are safe, we can narrow down the fix and prevention steps pretty clearly. Here's what you need to do:
1. Immediately Kill the Mining Process
First things first, stop that "yam" process from hogging your CPU:
- Find the process ID (PID) of yam:
ps aux | grep yam - Force terminate the process using the PID you found:
kill -9 <YAM_PID> - If it restarts automatically, use
pkill -9 yamto wipe all instances, then check for auto-start scripts (we'll cover that later).
2. Remove the Mining Binary and Associated Files
Next, get rid of the malware entirely:
- Locate where the yam binary is stored:
which yam # Or search the entire filesystem if the above returns nothing find / -name yam -type f 2>/dev/null - Delete the binary file:
rm -f <PATH_TO_YAM> - Check temporary directories for any suspicious scripts or binaries that might be spawning yam:
ls -la /tmp /var/tmp rm -f /tmp/*suspicious* /var/tmp/*suspicious* # Replace with actual suspicious filenames
3. Trace How the Malware Got In
Since this VM only runs OpenVPN, that's the most likely entry point. Let's investigate:
- Check OpenVPN logs for unauthorized connections or weird activity:
cat /var/log/openvpn.log # Or use journalctl if OpenVPN is managed by systemd journalctl -u openvpn - Look at SSH and authentication logs for brute-force attempts or unusual logins:
cat /var/log/auth.log | grep -E 'Failed password|Accepted password' - Check for new, suspicious user accounts:
cat /etc/passwd | grep -v 'root\|daemon\|nobody' # Filter out default users - Inspect cron jobs for auto-starting malware:
crontab -l # Check current user's cron jobs ls -la /etc/crontab /etc/cron.d/ /etc/cron.hourly/ /etc/cron.daily/ - Verify enabled systemd services for anything out of place:
systemctl list-unit-files --state=enabled
4. Harden the VM to Prevent Future Infections
Now that we've cleaned up, let's lock down the system:
OpenVPN Specific Hardening
- Switch to certificate-based authentication instead of (or in addition to) username/passwords to avoid weak credential breaches.
- Update your OpenVPN config to use strong encryption (e.g., AES-256-GCM instead of older ciphers) and disable insecure protocols.
- Restrict OpenVPN port (default 1194 UDP) access to only trusted IP addresses using UFW:
ufw allow from <TRUSTED_IP> to any port 1194 proto udp ufw enable
System-Wide Hardening
- Patch all system vulnerabilities by updating packages:
apt update && apt upgrade -y - Disable any unnecessary services that aren't required for OpenVPN operation.
- Install Fail2ban to block brute-force attempts on SSH and OpenVPN:
apt install fail2ban -y systemctl enable fail2ban && systemctl start fail2ban - Limit SSH access to only trusted users and IP addresses, or disable it entirely if you don't need remote shell access (use VM console instead).
5. Set Up Ongoing Monitoring
To catch any future issues early:
- Install
htopfor real-time CPU/process monitoring:apt install htop -y - Create a simple script to alert you if the "yam" process (or other suspicious high-CPU processes) reappears, and set it up as a cron job.
- Regularly review system logs to spot unusual activity before it becomes a problem.
内容的提问来源于stack exchange,提问作者AlanObject
相关产品推荐
相关产品推荐

