You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Ubuntu 16.04.03虚拟机出现yam比特币挖矿进程致CPU满载求助

Alright, let's tackle this mining malware situation on your OpenVPN VM. Since only this specific Ubuntu 16.04.03 VM (which only runs OpenVPN) is affected, and your host machine and other VMs are safe, we can narrow down the fix and prevention steps pretty clearly. Here's what you need to do:

1. Immediately Kill the Mining Process

First things first, stop that "yam" process from hogging your CPU:

  • Find the process ID (PID) of yam:
    ps aux | grep yam
    
  • Force terminate the process using the PID you found:
    kill -9 <YAM_PID>
    
  • If it restarts automatically, use pkill -9 yam to wipe all instances, then check for auto-start scripts (we'll cover that later).
2. Remove the Mining Binary and Associated Files

Next, get rid of the malware entirely:

  • Locate where the yam binary is stored:
    which yam
    # Or search the entire filesystem if the above returns nothing
    find / -name yam -type f 2>/dev/null
    
  • Delete the binary file:
    rm -f <PATH_TO_YAM>
    
  • Check temporary directories for any suspicious scripts or binaries that might be spawning yam:
    ls -la /tmp /var/tmp
    rm -f /tmp/*suspicious* /var/tmp/*suspicious*  # Replace with actual suspicious filenames
    
3. Trace How the Malware Got In

Since this VM only runs OpenVPN, that's the most likely entry point. Let's investigate:

  • Check OpenVPN logs for unauthorized connections or weird activity:
    cat /var/log/openvpn.log
    # Or use journalctl if OpenVPN is managed by systemd
    journalctl -u openvpn
    
  • Look at SSH and authentication logs for brute-force attempts or unusual logins:
    cat /var/log/auth.log | grep -E 'Failed password|Accepted password'
    
  • Check for new, suspicious user accounts:
    cat /etc/passwd | grep -v 'root\|daemon\|nobody'  # Filter out default users
    
  • Inspect cron jobs for auto-starting malware:
    crontab -l  # Check current user's cron jobs
    ls -la /etc/crontab /etc/cron.d/ /etc/cron.hourly/ /etc/cron.daily/
    
  • Verify enabled systemd services for anything out of place:
    systemctl list-unit-files --state=enabled
    
4. Harden the VM to Prevent Future Infections

Now that we've cleaned up, let's lock down the system:

OpenVPN Specific Hardening

  • Switch to certificate-based authentication instead of (or in addition to) username/passwords to avoid weak credential breaches.
  • Update your OpenVPN config to use strong encryption (e.g., AES-256-GCM instead of older ciphers) and disable insecure protocols.
  • Restrict OpenVPN port (default 1194 UDP) access to only trusted IP addresses using UFW:
    ufw allow from <TRUSTED_IP> to any port 1194 proto udp
    ufw enable
    

System-Wide Hardening

  • Patch all system vulnerabilities by updating packages:
    apt update && apt upgrade -y
    
  • Disable any unnecessary services that aren't required for OpenVPN operation.
  • Install Fail2ban to block brute-force attempts on SSH and OpenVPN:
    apt install fail2ban -y
    systemctl enable fail2ban && systemctl start fail2ban
    
  • Limit SSH access to only trusted users and IP addresses, or disable it entirely if you don't need remote shell access (use VM console instead).
5. Set Up Ongoing Monitoring

To catch any future issues early:

  • Install htop for real-time CPU/process monitoring:
    apt install htop -y
    
  • Create a simple script to alert you if the "yam" process (or other suspicious high-CPU processes) reappears, and set it up as a cron job.
  • Regularly review system logs to spot unusual activity before it becomes a problem.

内容的提问来源于stack exchange,提问作者AlanObject

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 08:35:22