I have a weird problem on server after the attack. In the web folder I have the index.php
with malicious content. When I try to delete, rename it or change its content it is re-created somehow.
I checked crontab and ps but I haven't found anything suspicious.
Also it is very interesting that if I change the owner of the file to root it is still re-creating without any problem.
Server system name and version: Debian GNU/Linux 8 (jessie)