Hey All,
I had a wordpress site and a drupal site on aws free tier that I moved over to linode yesterday. I've installed a basic lamp stack and nothing else to a centos box. Both are very low traffic sites and last night I got a warning about a cpu spike and looking at my httpd access_log there are ~113000 entries for a single night. Looking at the entries there are a lot of get request to random sites. I'm pretty sure something somewhere is compromised. Where should I start cleaning this up? The most frequent entries were
http://godtrck.com. Here is an example:
199.15.112.172 - - [03/May/2013:12:47:50 +0000] "GET
http://godtrck.com/?a=5535&oc=1405&c=7983&s1= HTTP/1.0" 404 7078 "https://mail.google.com/mail/?shva=1#inbox/13157cecaadcf61d" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; MS-RTC LM 8; .NET4.0C; .NET4.0E; Zune 4.7; InfoPath.3)"
Anyone ever heard of this, am I missing something?
Thanks.
Tanner J.