Linux.Siggen.411
Added to the Dr.Web virus database:
2018-02-11
Virus description added:
2018-02-11
Technical Information
Malicious functions:
Substitutes application name for:
- pinkcoin-wallet
- pinkcoin-stake
- pinkcoin-smsg
- pinkcoin-smsg-pow
- pinkcoin-rpclist
- pinkcoin-start
- pinkcoin-shutoff
- pinkcoin-ext-ip
- pinkcoin-UPnP
- pinkcoin-dnsseed
- pinkcoin-net
- pinkcoin-opencon
- pinkcoin-msghand
- pinkcoin-adrdump
- pinkcoin-miner
Performs operations with the file system:
Creates folders:
- /root/.pink2
- /root/.pink2/database
- /root/.pink2/txleveldb
- /root/.pink2/smsgDB
Creates or modifies files:
- /root/.pink2/.lock
- /root/.pink2/debug.log
- /root/.pink2/db.log
- /root/.pink2/txleveldb/LOG
- /root/.pink2/txleveldb/LOCK
- /root/.pink2/txleveldb/MANIFEST-000001
- /root/.pink2/txleveldb/000001.dbtmp
- /root/.pink2/txleveldb/000003.log
- /root/.pink2/txleveldb/MANIFEST-000002
- /root/.pink2/txleveldb/000002.dbtmp
- /root/.pink2/blk0001.dat
- /root/.pink2/database/log.0000000001
- /root/.pink2/__db.80000001.7948e18e
- /root/.pink2/wallet.dat
- /root/.pink2/__db.80000004.5854be56
- /root/.pink2/stake.dat
- /root/.pink2/smsgDB/LOG
- /root/.pink2/smsgDB/LOCK
- /root/.pink2/smsgDB/MANIFEST-000001
- /root/.pink2/smsgDB/000001.dbtmp
- /root/.pink2/smsg.ini~
- /root/.pink2/smsgDB/000003.log
- /root/.pink2/smsgDB/MANIFEST-000002
- /root/.pink2/smsgDB/000002.dbtmp
- /root/.pink2/peers.dat.0866
Deletes files:
- /root/.pink2/txleveldb/MANIFEST-000001"
- /root/.pink2/smsgDB/MANIFEST-000001"
Network activity:
Awaits incoming connections on ports:
Establishes connection:
HTTP GET requests:
DNS ASK:
- pi##army.ml
- pr#mary
- fr#####rt.pinkarmy.ml
- fr##kfurt
- pa###.pinkarmy.ml
- pa#is
- si#####re.pinkarmy.ml
- si##apore
- sy####.pinkarmy.ml
- sy#ney
- to###.pinkarmy.ml
- to#yo
Sends data to the following servers:
Curing recommendations
Linux
Free trial
One month (no registration) or three months (registration and renewal discount)
このウェブサイトを継続して訪問する場合、訪問者に関する統計データを収集するためのCookieファイルおよび他のテクノロジーを弊社が利用することに同意したものとします。詳細