Linux.Packed.689
Added to the Dr.Web virus database:
2019-12-26
Virus description added:
2019-12-26
Technical Information
Malicious functions:
Removes itself
Launches itself as a daemon
Substitutes application name for:
- f9ffdds9scfcvmjjvzxsssmxvddsjv09
Launches processes:
- sh -c clear
- clear
- sh -c echo Infected By Arh
- sh -c rm -rf /tmp/* /var/* /var/run/* /var/tmp/*
- rm -rf /tmp/* /var/backups /var/cache /var/lib /var/local /var/lock /var/log /var/mail /var/opt /var/run /var/spool /var/tmp /var/run/acpid.pid /var/run/acpid.socket /var/run/atd.pid /var/run/crond.pid /var/run/crond.reboot /var/run/dbus /var/run/dhclient.eth0.pid /var/run/exim4 /var/run/initctl /var/run/initramfs /var/run/lock /var/run/log /var/run/mount /var/run/network /var/run/rpc.statd.pid /var/run/rpc_pipefs /var/run/rpcbind /var/run/rpcbind.lock /var/run/rpcbind.pid /var/run/rpcbind.sock /var/run/rsyslogd.pid /var/run/sendsigs.omit.d /var/run/shm /var/run/sm-notify.pid /var/run/sshd /var/run/sshd.pid /var/run/systemd /var/run/tmpfiles.d /var/run/udev /var/run/user /var/run/utmp /var/tmp/*
Kills the following processes:
Performs operations with the file system:
Creates or modifies files:
Deletes files:
- /tmp/*
- /shadow.bak
- /dpkg.diversions.0
- /dpkg.diversions.1.gz
- /alternatives.tar.0
- /dpkg.statoverride.1.gz
- /dpkg.statoverride.2.gz
- /group.bak
- /dpkg.statoverride.0
- /dpkg.status.1.gz
- /passwd.bak
- /gshadow.bak
- /dpkg.status.2.gz
- /dpkg.status.0
- /apt.extended_states.0
- /dpkg.diversions.2.gz
- /sqspell.php
- /ispell.db
- /wordlist-default
- /emacsen-ispell-default.el
- /wordlist.db
- /hunspell.db
- /ispell-default
- /jed-ispell-dicts.sl
- /aspell.db
- /ispell-dicts-list.txt
- /emacsen-ispell-dicts.el
- /aux-cache
- /index.db
- /CACHEDIR.TAG
- /d589a48862398ed80a3d6066f4f56f4c-le32d4.cache-4
- /4c599c202bc5c08e2d34565a40eac3b2-le32d4.cache-4
- /d82eb4fd963d448e2fcb7d7b793b5df3-le32d4.cache-4
- /7ef2298fde41cc6eeb7af42e48b7d293-le32d4.cache-4
- /d3e5c4ee2ceb1fc347f91d4cefc53bc0-le32d4.cache-4
- /3f7329c5293ffd510edef78f73874cfd-le32d4.cache-4
- /57e423e26b20ab21d0f2f29c145174c3-le32d4.cache-4
- /c855463f699352c367813e37f3f70ea7-le32d4.cache-4
- /e13b20fdb08344e0e664864cc2ede53d-le32d4.cache-4
- /945677eb7aeaf62f1d50efc3fb3ec7d8-le32d4.cache-4
- /95530828ff6c81d309f8258d8d02a23e-le32d4.cache-4
- /f1f2465696798768e9653f19e17ccdc8-le32d4.cache-4
- /e52a45a1c8c8fe895fc0fc8c4e6999b8-le32d4.cache-4
- /3830d5c3ddfd5cd38a049b759396e72e-le32d4.cache-4
Network activity:
Establishes connection:
- 8.#.8.8:53
- 19#.###.177.142:12984
Sends data to the following servers:
Curing recommendations
Linux
Free trial
One month (no registration) or three months (registration and renewal discount)
このウェブサイトを継続して訪問する場合、訪問者に関する統計データを収集するためのCookieファイルおよび他のテクノロジーを弊社が利用することに同意したものとします。詳細