Your IP : 216.73.216.246


Current Path : /proc/self/root/opt/sharedrads/__pycache__/
Upload File :
Current File : //proc/self/root/opt/sharedrads/__pycache__/check_darkmailer.cpython-313.pyc

�

��}j����SSKJr SSKJr SSKJr SSKJr SSKrSSKrSSK	r	SSK
r
SSKJr SSK
r
SSKrSSKr/SQr/SQr\"S	S
55rS\\4SjrS
\S\4SjrSr\S:Xa\R0"\"55 gg)�)�ArgumentParser)�	dataclass)�fnmatch)�PathN)�	Generator)zhttpd.pl�bash�exim�procz
./cache.shz./xmr�xargsu�perxg�mdxfsz	./backupmz./dirtyz	./apache2z
/usr/bin/hostz/usr/sbin/acpidz
./cron.phpz./mileminedz	./annizodz./fpm-worker-mainz	[stealth])zusr/local/cpanel/bin/ftpputz)/usr/local/cpanel/3rdparty/bin/awstats.plzmail.cgic�b�\rSrSr%\\\S'\\S'\\S'\\S'\\S'\\S'\\S'S	r	g
)�Proc�+�cmdline�pid�create_time�age_secs�username�ppid�cmd_str�N)
�__name__�
__module__�__qualname__�__firstlineno__�list�str�__annotations__�int�float�__static_attributes__r��#/opt/sharedrads/check_darkmailer.pyrr+s+��
�#�Y��	�H����O��M�

�I�
�Lr#r�returnc	#�8# �[R"5n[R"5HMnUR/SQS9nUS(dM![SXS-
[R"US5S.UD6v� MO g![Ra Mif=f7f)zDIterate all system processes which match check_proc, as Proc objects)rrrrr)�attrsrr)rrNr)�time�psutil�process_iter�as_dict�
NoSuchProcessr�shlex�join)�now�psutil_proc�	proc_dicts   r$�
iter_procsr26s����
�)�)�+�C��*�*�,��	�#�+�+�K�,��I�
��#���
��]�3�3��J�J�y��3�4�
��
�	
�-��
�#�#�	��	�s(�.B�A?�=B�?B�B�B�Br
c�4�URS:Xd URS:XdURS:agURS[;dURS[
;ag[
[R"UR5R5nUS-S-nUR5R5H9nUR5nU(dM[URU5(dM9 g g![a gf=f![ a gf=f)	z7Use some criteria to filter to only malicious processes��rooti,FrTz.imhz.check_darkmailer.ignore)rrrr�BAD_CMDS�	OKAY_CMDSr�pwd�getpwnam�pw_dir�KeyError�	read_text�
splitlines�striprr�OSError)r
�home�ignore_file�line�globs     r$�
check_procrDIs����y�y�A�~����&�0�D�M�M�C�4G���|�|�A��h�&�$�,�,�q�/�Y�*F����C�L�L����/�6�6�7����-�"<�<�K�
��)�)�+�6�6�8�D��:�:�<�D��t�����d�3�3��9���������
���
�s6�"3C:�6D
�D
�5D
�7D
�:
D�D�

D�Dc��[5nURSSSS9 UR5Rn[	[
[
55nU(dg/nUH:nURURSURSUR35 M< [USS06 U(dg	S[R"5S
[U5S[S[S
SR!U5S3n["R"SSUS9 g	!["R$a%n[SU3[&R(S9 SnAgSnAff=f)z*Locates possible running malicious scriptsz
--make-ticket�
store_truezaThis is used by the cron; it creates an STR ticket if any potentially malicious scripts are found)�action�helpr� �sep�
�z found z! potentially malicious scripts.

a~ found these processes by filtering to any non-root processes
older than 5 minutes and not with a parent PID of 1, then checking their names
for anything that looks like it might be malicious.

If there's any false positives, you can mark them in the user's home dir in
~/.imh/.check_darkmailer.ignore - each line in the file is a glob.
You can test that your glob works by running zT again
without --make-ticket and seeing if it still lists the process.

Processes:

zstr@imhadmin.netzDarkmailer Processes)�dest�subject�bodyzFailed to create STR ticket - )�fileN�)r�add_argument�
parse_args�make_ticket�filterrDr2�appendrrr�print�platform�node�len�__file__r.�rads�TicketError�sys�stderr)�parserrT�	bad_procs�	proc_infor
rO�excs       r$�mainrd^sG��
�
�F�
�����2����)�)�+�7�7�K��z�:�<�0�I����I������D�H�H�:�Q�t�}�}�o�Q�t�|�|�n�E�F��
�9��$�����	�������Y��(�)�	�
�.�/7�Z�8�
���9�����D� ����#�*��	
�
������
�.�s�e�4�3�:�:�F����s�1D�E�D<�<E�__main__)�argparser�dataclassesrr�pathlibrr-r^r(rX�collections.abcrr8r)r\r6r7rr2�boolrDrdr�exitrr#r$�<module>rls���#�!����
���%�
�
����*
�	������
�I�d�O�
�&�T��d��*.
�b�z���H�H�T�V��r#