Comment Re:Haha maybe that should be running (Score 1) 71
several sources have cited security researchers stating that it's likely due to the Exim CVE exploits.
One very detailed article is published here on ITW attempts in using the CVE exploit are being seen to deploy malware:
https://securityaffairs.co/wor...
I also did some independent research and searched around on Shodan for about 10-15 of of the hosts showing up with lilocked file extensions on their webservers now and they are all 1) Hosted in Russia 2) have out of date EXIM software vulnerable to the recent CVE's posted....