1

I found a strange file under/var/tmp directory, named ietd.conf

{
    "url" : "stratum+tcp://188.165.254.85:80",
    "user" : "46Z6dQ77i2qAapF4kjLXaaYKCB59eajwaZbmtyyPsxDXWyxPS5nfYoe5t4R7yTgsvT
AxgE8DRwwtKiMxCmM39KCBPfEgL5b",
    "pass" : "x",
    "algo" : "cryptonight",
    "quiet" : true
}

Can someone explain it to me please

Murch
  • 71,155
  • 33
  • 180
  • 600

1 Answers1

2

You most likely have a stealth Monero miner installed, I recommend checking your system for rootkits.