Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Vinodhini
Participant

"obamal" process consumes High CPU 100% in Mgmt server R80.20 with latest JHF

Dear All,

 

I have customer Mgmt server 80.20 with latest JHF.

In "top" command - could see "obamal" process taking 100% High CPU. SO unable to open SmartConsole.

The appliance rebooted a day before only, still no luck. Unable to get what this process is about. no much details in messages file also.

 

Attached screenshot. Can anyone give shed some info on this please....

 

 

Regards, Vinodhini

0 Kudos
5 Replies
PhoneBoy
Admin
Admin

I've never seen that process before and there's not even anything in SK about it.
Recommend a TAC case.

0 Kudos
John_Fleming
Advisor

Its a bitcoin miner mangs.. its not obamal its obama1. Explains the high cpu and memory usage.

Welcome to being owned. Proceed directly to pant pooping and give the IR line a call.

 

https://www.checkpoint.com/support-services/threatcloud-incident-response/

 

0 Kudos
Timothy_Hall
Legend Legend
Legend

After seeing John's post I initially thought he was answering in jest, but after some quick poking around on one of my lab systems it looks like he is not.

There is no legitimate process or program with anything approaching that name included in R80.20, so the process shouldn't be there.  Perhaps it is part of some kind of Threat Prevention update that my lab system does not have (hence the "mal" part of the name) but the question of how the program got onto that system needs to be answered, specifically as to whether it was placed there by an authorized user or an unauthorized one.  Good luck.

Gateway Performance Optimization R81.20 Course
now available at maxpowerfirewalls.com
0 Kudos
John_Fleming
Advisor

My post was %100 was not in jest to be clear. Call the IR team as I said. Best case i'm completely wrong and IR team is like "thanks for wasting our time". Worst case you have an amazing team starting an IR process for you with a skill set you most likely can not bring. Checkpoint is here to help secure your everything.

0 Kudos
PhoneBoy
Admin
Admin

100% in agreement here, best to get IRT involved.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events