Something is done via perl on webserver - how can i find the causing script ?

Hi,

on a webserver there is something wrong (in my opinion). Perl is using much CPU. If i use lsof on its PID, i get this:

COMMAND PID    USER   FD   TYPE DEVICE SIZE/OFF     NODE NAME
perl    693 uvftpzg  cwd    DIR    8,1     4096        2 /
perl    693 uvftpzg  rtd    DIR    8,1     4096        2 /
perl    693 uvftpzg  txt    REG    8,5  1648400 17983266 /usr/bin/perl
perl    693 uvftpzg  mem    REG    8,5    31512 17796254 /usr/lib/perl5/5.10.0/x86_64-linux-thread-multi/auto/Socket/Socket.so
perl    693 account6663  mem    REG    8,5    27464 51082960 /usr/lib/perl5/5.10.0/x86_64-linux-thread-multi/auto/IO/IO.so
perl    693 account6663  mem    REG    8,1  1495120   783548 /lib64/libc-2.8.so
perl    693 account6663  mem    REG    8,1   142867   783542 /lib64/libpthread-2.8.so
perl    693 account6663  mem    REG    8,1    61240   783534 /lib64/libcrypt-2.8.so
perl    693 account6663  mem    REG    8,1    16040   783530 /lib64/libdl-2.8.so
perl    693 account6663  mem    REG    8,1   380776   783535 /lib64/libm-2.8.so
perl    693 account6663  mem    REG    8,1   131240   783549 /lib64/ld-2.8.so
perl    693 account6663  0r  FIFO    0,5      0t0    84033 pipe
perl    693 account6663  1w  FIFO    0,5      0t0    84034 pipe
perl    693 account6663  2w  FIFO    0,5      0t0    84035 pipe
perl    693 account6663  3u  IPv4 146573      0t0      TCP domainname.com:56158->ns1.openhost.lv:arcp (ESTABLISHED)
perl    693 account6663  187r  FIFO    0,5      0t0     8206 pipe
perl    693 account6663  188w  FIFO    0,5      0t0     8206 pipe
perl    693 account6663  189r  FIFO    0,5      0t0     8207 pipe
perl    693 account6663  190w  FIFO    0,5      0t0     8207 pipe



What exactly does this mean ? I dont know "ns1.openhost.lv:arcp" ...
How can i find out which script is used for this ?


Thanks
loosainAsked:
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

x
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Jan SpringerCommented:
run a quick check of tmp "ls -al /tmp" for programs/files that don't belong

"ls -alR /etc/cron*" for any install cron jobs

"find / -user account6663" to first find the files owned by this account

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
arnoldCommented:
Look for its PPID.

Grep arcp /etc/services.

This looks like a socket app, but there is no way to say what it is doing, using strace -f -p PID may show what it is doing.

But using ps, and track down up to the parent.

Look in crons, services chkconfig --list.

....
arnoldCommented:
Searching for port arcp to which your system is connected, suggests it might be a Trojan/compromise.

Do you know what should be running on your system?
loosainAuthor Commented:
Thanks. I found a script that should not be there which is causing all this. I moved it away and now no ports are open or perl-scripts a running so far.
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Apache Web Server

From novice to tech pro — start learning today.