Linux.Siggen.607
Added to the Dr.Web virus database:
2018-05-18
Virus description added:
2018-05-18
Technical Information
Malicious functions:
Gains root privileges
Launches processes:
- sh -c ping -c 4 194.186.207.182 > Ping.log
- ping -c 4 194.186.207.182
- sh -c ifconfig -a > IFConfig.log
- ifconfig -a
- sh -c cp /usr/lib/Amicon_ip-client/log/* ./ > /dev/null
- cp /usr/lib/Amicon_ip-client/log/* ./
- sh -c cp /var/log/dpkg.log ./ > /dev/null
- cp /var/log/dpkg.log ./
- sh -c cp /var/log/dmesg ./ > /dev/null
- cp /var/log/dmesg ./
- sh -c cp /var/log/kern.log ./ > /dev/null
- cp /var/log/kern.log ./
- sh -c zip -mr ./CliDiagn.zip ./CliDiagn > /dev/null
- zip -mr ./CliDiagn.zip ./CliDiagn
Performs operations with the file system:
Modifies file access rights:
Creates folders:
Deletes folders:
Creates or modifies files:
- /root/CliDiagn/Ping.log
- /root/CliDiagn/IFConfig.log
- /root/CliDiagn/dpkg.log
- /root/CliDiagn/dmesg
- /root/CliDiagn/kern.log
- /root/CliDiagn.zip
- /root/zi5v2hOU
Deletes files:
- /root/CliDiagn.zip
- /root/CliDiagn/dmesg
- /root/CliDiagn/kern.log
- /root/CliDiagn/IFConfig.log
- /root/CliDiagn/Ping.log
- /root/CliDiagn/dpkg.log
Network activity:
Establishes connection:
Sends data to the following servers:
Curing recommendations
Linux
Free trial
One month (no registration) or three months (registration and renewal discount)
このウェブサイトを継続して訪問する場合、訪問者に関する統計データを収集するためのCookieファイルおよび他のテクノロジーを弊社が利用することに同意したものとします。詳細