Hacker News new | ask | show | jobs
by deefour 4613 days ago
My money is so far on Darkleech apache module[1] as the cause. As far as I know it's still unclear how the attacker gains root access to the server to do the install.

[1]http://malwaremustdie.blogspot.com/2013/03/the-evil-came-bac...

1 comments

It says it's a Linux malware, but the server in question run FreeBSD. Of course, FreeBSD version might as well be out there too.