☠️ KILL MALICIOUS PROCESS
[👤] DETECTED WEBSITE USERNAME:
oeodv
Kill commands will use: pgrep -U oeodv | xargs kill -9
⚠️ INFO:
• Kills PHP, Socket, Netcat, Reverse Shell, Backdoor processes
• Target User: oeodv (Auto-detected from website)
• Commands: pkill php, kill -9 [PID], pgrep -U oeodv | xargs kill -9
• shell_exec() is available - Kill feature enabled
[📋] ACTIVE PROCESSES:
root 961 0.0 0.0 242908 31700 ? Ss 2024 119:56 php-fpm: master process (/opt/plesk/php/7.4/etc/php-fpm.conf)
root 962 0.0 0.0 242604 4004 ? Ss 2024 15:25 php-fpm: master process (/var/www/vhosts/system/ehrenpreis.jugendmeisterschaft.at/etc/php-fpm.conf)
root 963 0.0 0.0 242320 29572 ? Ss 2024 93:51 php-fpm: master process (/opt/plesk/php/8.0/etc/php-fpm.conf)
root 964 0.0 0.0 241904 13032 ? Ss 2024 15:24 php-fpm: master process (/var/www/vhosts/system/old.murtal-storage.at/etc/php-fpm.conf)
oeodv 558970 0.4 0.0 338216 25204 ? S 08:03 0:53 php-fpm: pool bo.optimistsegeln.at
izaquie+ 560197 0.0 0.0 2892 0 ? Ss 2025 0:00 /bin/sh -c /opt/plesk/php/8.2/bin/php -f 'cockpit.izaquiel.at/index.php' -- 'cron/index'
izaquie+ 560207 0.0 0.0 137056 9196 ? S 2025 0:00 /opt/plesk/php/8.2/bin/php -f cockpit.izaquiel.at/index.php -- cron/index
nginx 576195 1.8 0.2 199284 164860 ? S 08:23 3:44 nginx: worker process
nginx 576196 0.0 0.2 196272 155108 ? S 08:23 0:00 nginx: cache manager process
www-data 576486 0.0 0.0 272044 40488 ? S 08:23 0:00 /usr/sbin/apache2 -k start
www-data 576487 0.0 0.0 273220 40232 ? S 08:23 0:00 /usr/sbin/apache2 -k start
oeodv 625948 0.3 0.0 338216 25156 ? S 09:17 0:35 php-fpm: pool bo.optimistsegeln.at
oeodv 626716 0.4 0.0 338216 25160 ? S 09:18 0:35 php-fpm: pool bo.optimistsegeln.at
www-data 653404 0.4 0.0 2140408 63372 ? Sl 09:50 0:32 /usr/sbin/apache2 -k start
oeodv 712577 0.4 0.0 338220 25040 ? S 10:51 0:13 php-fpm: pool bo.optimistsegeln.at
www-data 713234 0.6 0.0 2204392 62064 ? Sl 10:52 0:20 /usr/sbin/apache2 -k start
www-data 752913 0.9 0.0 2139512 62484 ? Sl 11:19 0:15 /usr/sbin/apache2 -k start
starcla+ 753364 4.4 0.1 296752 78224 ? S 11:19 1:12 php-fpm: pool starclass.at
dev.hat+ 772563 33.9 0.4 459948 277200 ? S 11:41 1:42 php-fpm: pool zuhoerakademie.at
dev.hat+ 772582 32.6 0.4 465136 281480 ? S 11:41 1:38 php-fpm: pool zuhoerakademie.at
dev.hat+ 773324 33.9 0.4 444868 263636 ? R 11:42 1:24 php-fpm: pool zuhoerakademie.at
dev.hat+ 773958 32.1 0.4 465160 281504 ? S 11:43 1:06 php-fpm: pool zuhoerakademie.at
dev.hat+ 773973 29.3 0.4 457088 273568 ? S 11:43 1:00 php-fpm: pool zuhoerakademie.at
tedxvie+ 774064 4.1 0.0 244476 27156 ? S 11:43 0:08 php-fpm: pool browse.tedxvienna.at
scatt 775358 33.1 0.2 461088 164616 ? S 11:45 0:34 php-fpm: pool scatt.at
scatt 775367 32.7 0.2 387156 163280 ? R 11:45 0:34 php-fpm: pool scatt.at
gymnasi+ 776780 0.4 0.0 241848 43848 ? S 11:46 0:00 /opt/plesk/php/7.4/bin/php-cgi -c /var/www/vhosts/system/essen.gymnasium-saalfelden.at/etc/php.ini
krunksu+ 777014 2.8 0.1 338156 79360 ? S 11:46 0:00 php-fpm: pool krunk.me
krunksu+ 777031 2.2 0.1 263236 76468 ? S 11:46 0:00 php-fpm: pool krunk.me
tfk-des+ 777041 11.1 0.2 416388 148036 ? S 11:46 0:01 php-fpm: pool kitt-experience.com
tfk-des+ 777045 6.8 0.1 313228 116808 ? S 11:46 0:00 php-fpm: pool kitt-experience.com
starcla+ 777046 7.2 0.1 295192 71344 ? S 11:46 0:00 php-fpm: pool starclass.at
htseeba+ 777048 6.8 0.2 368588 131796 ? S 11:46 0:00 php-fpm: pool seebacher-haustechnik.at
alp-sho+ 777050 16.7 0.2 436432 141240 ? S 11:46 0:01 php-fpm: pool alp-shop.at
htseeba+ 777055 3.8 0.1 282032 115476 ? S 11:46 0:00 php-fpm: pool seebacher-haustechnik.at
alp-sho+ 777057 21.4 0.2 362380 138396 ? S 11:46 0:01 php-fpm: pool alp-shop.at
hausmit+ 777060 17.0 0.1 327436 102140 ? S 11:46 0:01 php-fpm: pool hausmitherz.at
spinnan+ 777062 44.2 0.2 388180 132404 ? S 11:46 0:02 php-fpm: pool spinnanker.com
spinnan+ 777064 50.0 0.1 313820 127372 ? S 11:46 0:02 php-fpm: pool spinnanker.com
fal-con+ 777066 6.5 0.1 359980 90704 ? S 11:46 0:00 php-fpm: pool campaign.fal-con.eu
fal-con+ 777070 44.0 0.1 316568 117780 ? R 11:46 0:01 php-fpm: pool campaign.fal-con.eu
oebr.at+ 777072 29.5 0.1 308824 84976 ? S 11:46 0:00 php-fpm: pool buddhismus-austria.at
volksta+ 777074 43.0 0.1 268808 84232 ? S 11:46 0:00 php-fpm: pool volkstanzkreis-schoenbrunn.at
oeodv 777076 0.0 0.0 261912 29116 ? S 11:46 0:00 php-fpm: pool optimistsegeln.at
root 1288188 0.0 0.0 245544 29912 ? Ss Mar31 0:09 sw-engine-fpm: master process (/etc/sw-engine/sw-engine-fpm.conf)
psaadm 1447802 0.0 0.0 130400 40588 ? Ss Mar23 0:27 /usr/bin/sw-engine -c /opt/psa/admin/conf/php.ini /opt/psa/admin/plib/WebSocket/bin/ws-server.php
root 1459079 0.0 0.2 195956 159484 ? Ss Mar23 0:25 nginx: master process /usr/sbin/nginx
root 1460557 0.0 0.0 261516 34964 ? Ss Mar23 1:05 php-fpm: master process (/opt/plesk/php/8.5/etc/php-fpm.conf)
root 1460757 0.0 0.0 258204 29108 ? Ss Mar23 0:22 php-fpm: master process (/opt/plesk/php/8.4/etc/php-fpm.conf)
root 1474892 0.0 0.0 273420 48376 ? Ssl Mar23 1:08 /usr/sbin/apache2 -k start
root 1594385 0.0 0.0 253136 27564 ? Ss Feb26 1:00 php-fpm: master process (/var/www/vhosts/system/jugendmeisterschaft.at/etc/php-fpm.conf)
root 1594386 0.0 0.0 253120 27336 ? Ss Feb26 2:12 php-fpm: master process (/var/www/vhosts/system/zuhoerakademie.at/etc/php-fpm.conf)
root 1598808 0.0 0.0 254472 33128 ? Ss Feb26 3:43 php-fpm: master process (/opt/plesk/php/8.3/etc/php-fpm.conf)
root 1598839 0.0 0.0 254260 36848 ? Ss Feb26 28:40 php-fpm: master process (/opt/plesk/php/8.2/etc/php-fpm.conf)
root 1722017 0.0 0.0 193756 25380 ? Ss Feb26 1:32 php-fpm: master process (/etc/php/5.6/fpm/php-fpm.conf)
www-data 1722018 0.0 0.0 193852 5328 ? S Feb26 0:00 php-fpm: pool www
www-data 1722019 0.0 0.0 193852 5328 ? S Feb26 0:00 php-fpm: pool www
root 1722353 0.0 0.0 193684 20860 ? Ss Feb26 1:09 php-fpm: master process (/etc/php/7.0/fpm/php-fpm.conf)
www-data 1722355 0.0 0.0 194104 5484 ? S Feb26 0:00 php-fpm: pool www
www-data 1722356 0.0 0.0 194104 5484 ? S Feb26 0:00 php-fpm: pool www
root 1722684 0.0 0.0 262716 32512 ? Ss Feb26 1:12 php-fpm: master process (/etc/php/7.2/fpm/php-fpm.conf)
horethwp 2231139 0.0 0.0 245340 50000 ? S Mar24 0:17 php /tmp/phpbbi9oO4R phpbb
www-data 3054826 0.0 0.0 262960 10384 ? S Mar30 0:00 php-fpm: pool www
www-data 3054827 0.0 0.0 262960 10452 ? S Mar30 0:00 php-fpm: pool www
root 3329065 0.0 0.0 252716 34768 ? Ss Feb02 19:39 php-fpm: master process (/opt/plesk/php/8.1/etc/php-fpm.conf)
reichho+ 3688753 10.3 0.1 343936 106620 ? S 00:00 73:27 php-fpm: pool reichholf.info
reichho+ 3688757 10.3 0.1 344516 106728 ? S 00:00 73:28 php-fpm: pool reichholf.info
reichho+ 3688763 10.3 0.1 343808 107492 ? R 00:00 73:27 php-fpm: pool reichholf.info
reichho+ 3688764 10.4 0.1 343816 105524 ? S 00:00 73:30 php-fpm: pool reichholf.info
reichho+ 3688766 10.3 0.1 344596 107908 ? S 00:00 73:28 php-fpm: pool reichholf.info
reichho+ 3688767 10.3 0.1 344812 107588 ? S 00:00 73:29 php-fpm: pool reichholf.info
horethwp 3688769 0.6 0.3 528448 237800 ? S 00:00 4:52 php-fpm: pool manuelhoreth.at
horethwp 3688771 0.6 0.3 534832 242860 ? S 00:00 4:50 php-fpm: pool manuelhoreth.at
horethwp 3688772 0.6 0.3 533716 243032 ? S 00:00 4:52 php-fpm: pool manuelhoreth.at
horethwp 3688773 0.6 0.3 536236 245408 ? S 00:00 4:53 php-fpm: pool manuelhoreth.at
horethwp 3688774 0.6 0.3 534744 243704 ? S 00:00 4:49 php-fpm: pool manuelhoreth.at
horethwp 3688775 0.6 0.3 532624 241648 ? S 00:00 4:48 php-fpm: pool manuelhoreth.at
horethwp 3688776 0.6 0.3 530524 238992 ? S 00:00 4:48 php-fpm: pool manuelhoreth.at
horethwp 3688777 0.6 0.3 538480 247364 ? S 00:00 4:49 php-fpm: pool manuelhoreth.at
horethwp 3688779 0.6 0.3 559284 253424 ? S 00:00 4:49 php-fpm: pool manuelhoreth.at
horethwp 3688780 0.6 0.3 536612 245512 ? S 00:00 4:49 php-fpm: pool manuelhoreth.at
horethwp 3688782 0.6 0.3 539784 248128 ? S 00:00 4:52 php-fpm: pool manuelhoreth.at
horethwp 3688783 0.6 0.3 529488 236924 ? S 00:00 4:48 php-fpm: pool manuelhoreth.at
horethwp 3688784 0.6 0.3 532388 239628 ? S 00:00 4:45 php-fpm: pool manuelhoreth.at
horethwp 3688785 0.6 0.3 541884 251972 ? S 00:00 4:50 php-fpm: pool manuelhoreth.at
horethwp 3688786 0.6 0.3 534572 241168 ? S 00:00 4:49 php-fpm: pool manuelhoreth.at
reichho+ 3688800 10.4 0.1 269256 101212 ? S 00:00 73:31 php-fpm: pool reichholf.info
reichho+ 3688802 10.3 0.1 343764 107084 ? S 00:00 73:27 php-fpm: pool reichholf.info