Linux.Packed.40
Added to the Dr.Web virus database:
2017-11-15
Virus description added:
2017-11-15
Technical Information
To ensure autorun and distribution:
Creates or modifies the following files:
- /etc/init.d/yzhjdtaolr
- /etc/cron.hourly/cron.sh
- /etc/crontab
- /etc/init.d/.depend.boot
- /etc/init.d/.depend.start
- /etc/init.d/.depend.stop
- /etc/init.d/nybpyyitbh
Creates or modifies the following symlinks:
- /etc/rc1.d/S90yzhjdtaolr
- /etc/rc2.d/S90yzhjdtaolr
- /etc/rc3.d/S90yzhjdtaolr
- /etc/rc4.d/S90yzhjdtaolr
- /etc/rc5.d/S90yzhjdtaolr
- /etc/rc1.d/S01yzhjdtaolr
- /etc/rc2.d/S01yzhjdtaolr
- /etc/rc3.d/S01yzhjdtaolr
- /etc/rc4.d/S01yzhjdtaolr
- /etc/rc5.d/S01yzhjdtaolr
- /etc/rc1.d/S90nybpyyitbh
- /etc/rc2.d/S90nybpyyitbh
- /etc/rc3.d/S90nybpyyitbh
- /etc/rc4.d/S90nybpyyitbh
- /etc/rc5.d/S90nybpyyitbh
Malicious functions:
Removes itself
Launches itself as a daemon
Manages services:
- update-rc.d yzhjdtaolr defaults
- systemctl daemon-reload
- update-rc.d yzhjdtaolr remove
- update-rc.d nybpyyitbh defaults
Launches processes:
- /boot/yzhjdtaolr
- chkconfig --add yzhjdtaolr
- sh -c sed -i '/\/etc\/cron.hourly\/cron.sh/d' /etc/crontab && echo '*/3 * * * * root /etc/cron.hourly/cron.sh' >> /etc/crontab
- sed -i /\/etc\/cron.hourly\/cron.sh/d /etc/crontab
- /boot/touzeqfkpa cd /etc 688
- /sbin/insserv yzhjdtaolr
- /boot/zwzamrflae echo \"find\" 688
- /boot/adrjyvooty ifconfig eth0 688
- /boot/tnmnqgltnt route -n 688
- /boot/tneaxdagyx echo \"find\" 688
- /boot/rasuaviszz ls -la 688
- /boot/nipfxxmxvi echo \"find\" 688
- chkconfig --del yzhjdtaolr
- /boot/nybpyyitbh
- chkconfig --add nybpyyitbh
- /sbin/insserv
- /sbin/insserv nybpyyitbh
- /boot/oxcchrekxl cd /etc 737
- /boot/tmxvlfbfyp bash 737
- /boot/yabaaxgpxn netstat -antop 737
- /boot/pcoxtlrdtj uptime 737
- /boot/sybynctnun who 737
Performs operations with the file system:
Modifies file access rights:
- /etc/sedaxW3Qu
- /etc/sed7JvBTm
Creates or modifies files:
- /lib/udev/udev
- /boot/yzhjdtaolr
- /etc/sedaxW3Qu
- /var/run/sftp.pid
- /run/sftp.pid
- /boot/touzeqfkpa
- /boot/zwzamrflae
- /boot/adrjyvooty
- /boot/tnmnqgltnt
- /boot/tneaxdagyx
- /boot/rasuaviszz
- /boot/nipfxxmxvi
- /boot/nybpyyitbh
- /etc/sed7JvBTm
- /boot/oxcchrekxl
- /boot/tmxvlfbfyp
- /boot/yabaaxgpxn
- /boot/pcoxtlrdtj
- /boot/sybynctnun
Deletes files:
- /lib/udev/udev
- /etc/rc1.d/S90yzhjdtaolr
- /etc/rc2.d/S90yzhjdtaolr
- /etc/rc3.d/S90yzhjdtaolr
- /etc/rc4.d/S90yzhjdtaolr
- /etc/rc5.d/S90yzhjdtaolr
- /etc/rc.d/rc1.d/S90yzhjdtaolr
- /etc/rc.d/rc2.d/S90yzhjdtaolr
- /etc/rc.d/rc3.d/S90yzhjdtaolr
- /etc/rc.d/rc4.d/S90yzhjdtaolr
- /etc/rc.d/rc5.d/S90yzhjdtaolr
- /boot/touzeqfkpa
- /boot/zwzamrflae
- /boot/adrjyvooty
- /boot/tnmnqgltnt
- /boot/tneaxdagyx
- /boot/rasuaviszz
- /boot/nipfxxmxvi
- /boot/yzhjdtaolr
- /etc/init.d/yzhjdtaolr
- /etc/rc1.d/S90nybpyyitbh
- /etc/rc2.d/S90nybpyyitbh
- /etc/rc3.d/S90nybpyyitbh
- /etc/rc4.d/S90nybpyyitbh
- /etc/rc5.d/S90nybpyyitbh
- /etc/rc.d/rc1.d/S90nybpyyitbh
- /etc/rc.d/rc2.d/S90nybpyyitbh
- /etc/rc.d/rc3.d/S90nybpyyitbh
- /etc/rc.d/rc4.d/S90nybpyyitbh
- /etc/rc.d/rc5.d/S90nybpyyitbh
- /etc/rc1.d/S01yzhjdtaolr
- /etc/rc2.d/S01yzhjdtaolr
- /etc/rc3.d/S01yzhjdtaolr
- /etc/rc4.d/S01yzhjdtaolr
- /etc/rc5.d/S01yzhjdtaolr
- /boot/oxcchrekxl
- /boot/tmxvlfbfyp
- /boot/yabaaxgpxn
- /boot/pcoxtlrdtj
- /boot/sybynctnun
Network activity:
Establishes connection:
- 11#.##8.88.136:2897
- 20#.###.152.209:2897
DNS ASK:
- yy###.tpddns.cn
- li###.bc5j.com
Other:
Collects information about network activity
Curing recommendations
Linux
Free trial
One month (no registration) or three months (registration and renewal discount)
このウェブサイトを継続して訪問する場合、訪問者に関する統計データを収集するためのCookieファイルおよび他のテクノロジーを弊社が利用することに同意したものとします。詳細