Is there a way to detect that a file with
if you have root access to the server then i'm sure that you can run ps, watch, strace, iostat, etc to monitor where it's coming from. Now, with that being said, if you have root access, I hope that you are patching your systems and you likely wouldn't have this problem anyway. Sadly all the samples I've found via hunting on VT and referenced in any public sources look like the Decrypter tool and not the malicious binary as well.
Disclaimer: "These opinions are my own, though for a small fee they be yours too." -- Dave Haynie