Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Vinodhini
Participant

"obamal" process consumes High CPU 100% in Mgmt server R80.20 with latest JHF

Dear All,

 

I have customer Mgmt server 80.20 with latest JHF.

In "top" command - could see "obamal" process taking 100% High CPU. SO unable to open SmartConsole.

The appliance rebooted a day before only, still no luck. Unable to get what this process is about. no much details in messages file also.

 

Attached screenshot. Can anyone give shed some info on this please....

 

 

Regards, Vinodhini

0 Kudos
Reply
5 Replies
PhoneBoy
Admin
Admin

I've never seen that process before and there's not even anything in SK about it.
Recommend a TAC case.

0 Kudos
Reply
John_Fleming
Advisor

Its a bitcoin miner mangs.. its not obamal its obama1. Explains the high cpu and memory usage.

Welcome to being owned. Proceed directly to pant pooping and give the IR line a call.

 

https://www.checkpoint.com/support-services/threatcloud-incident-response/

 

0 Kudos
Reply
Timothy_Hall
Champion
Champion

After seeing John's post I initially thought he was answering in jest, but after some quick poking around on one of my lab systems it looks like he is not.

There is no legitimate process or program with anything approaching that name included in R80.20, so the process shouldn't be there.  Perhaps it is part of some kind of Threat Prevention update that my lab system does not have (hence the "mal" part of the name) but the question of how the program got onto that system needs to be answered, specifically as to whether it was placed there by an authorized user or an unauthorized one.  Good luck.

"Max Capture: Know Your Packets" Video Series
now available at http://www.maxpowerfirewalls.com
0 Kudos
Reply
John_Fleming
Advisor

My post was %100 was not in jest to be clear. Call the IR team as I said. Best case i'm completely wrong and IR team is like "thanks for wasting our time". Worst case you have an amazing team starting an IR process for you with a skill set you most likely can not bring. Checkpoint is here to help secure your everything.

0 Kudos
Reply
PhoneBoy
Admin
Admin

100% in agreement here, best to get IRT involved.

0 Kudos
Reply