Gotta say those ‘guys’ in the Netherlands/Iceland/CountryCode7 did a very quick , very clever and very nasty opportunistic compromise in a very short time span.
They are well organized, well distributed, very skillful and likely well funded.
The script touches large parts of a compromised system.
I suggest anyone with a tendency to ‘paranoid’ or ‘wise virgin’ to check the existence , timestamp and content of all of
Properly installing and configuring a ‘root kit’ detector can help detect future compromises. I use
Also DROP in your firewall
whois -h ’ -v -f’
and related networks belonging to AS213371