http://forums.cpanel.net – Hello, I have 290 hosted sites. For some vulnerability in joomla, (what I'd consider), some people managed to insert malicious files in the tmp folder of some domains, and executed them. Several shell scripts encrypted (such as c99shell) were injected. Most of the process in my server was being killed every minute. (HowTos)