Linux.Siggen.3417
Added to the Dr.Web virus database:
2020-11-21
Virus description added:
2020-11-21
Technical Information
Malicious functions:
Performs process tracing:
- <SAMPLE>
- <SAMPLE_FULL_PATH>
Launches processes:
- /bin/sh <SAMPLE_FULL_PATH> -c exec '<SAMPLE_FULL_PATH>' \"$@\" <SAMPLE_FULL_PATH>
- <SAMPLE_FULL_PATH>
- /bin/sh <SAMPLE_FULL_PATH> -c
- mkdir .sftp
- chmod 777 .sh
- chmod 777 .php
- chmod 777 .sphp
- chattr -a /etc/.bashpid
- nohup ./.sphp
- ./.sphp
- ./.php
- ./.sh
- sleep 6
- cat /etc/.bashpid
- sleep 1
- chattr +a /etc/.bashpid
- pkill -f joseph
- pkill -f osama
- pkill -f xm64
- pkill -f obama1
- pkill -f kswapd0
- pkill -f jehgms
- pkill -f tsm
- pkill -f rig
- pkill -f xmr
- pkill -f playstation
- pkill -f ld-linux-x86-64
- pkill -f ruckusapd
- pkill -f run64
- pkill -f pwnrig
- pkill -f phpupdate
- pkill -f sysupdate
- pkill -f phpguard
- pkill -f firstpress
- pkill -f zerocert
- pkill -f masscan
- pkill -f -bash
- pkill -f spreadQlmnop
- pkill -f cnrig
- pkill -f crond
- rm -rf /tmp/.bash/
- rm -rf /root/.bash/
- rm -rf /root/.cache/
- rm -rf /tmp/.cache/
- rm -rf /dev/shm/.ssh/
- rm -rf /etc/.etcservice/linuxservice
- rm -rf /etc/.vhost/netvhost
- rm -rf /tmp/up.txt
- pkill -f netvhost
- pkill -f kthreadds
- pkill -f kdevtmpfsi
- pkill -f linuxservice
- pkill -f rtmonitor
- pkill -f dev
- pkill -f xmrig
Attempts to kill the following processes:
- killall joseph
- killall osama
- killall xm64
- killall daemon
- killall obama1
- killall kswapd0
- killall jehgms
- killall tsm
- killall rig
- killall xmr
- killall playstation
- killall ld-linux-x86-64
- killall ruckusapd
- killall run64
- killall pwnrig
- killall phpupdate
- killall sysupdate
- killall phpguard
- killall firstpress
- killall zerocert
- killall masscan
- killall spreadQlmnop
- killall -bash
- killall cnrig
- killall crond
- killall netvhost
- killall kthreadds
- killall kdevtmpfsi
- killall linuxservice
- killall rtmonitor
- killall dev
- killall xmrig
Kills the following processes:
- <SAMPLE>
- <SAMPLE_FULL_PATH>
- /root/.sftp/.sh
- kswapd0
- kdevtmpfs
- systemd-udevd
Performs operations with the file system:
Modifies file access rights:
- /root/.sftp/.sh
- /root/.sftp/.php
- /root/.sftp/.sphp
Creates folders:
Creates or modifies files:
- /root/.sftp/.sh
- /root/.sftp/.php
- /root/.sftp/.sphp
- /etc/.bashpid
Deletes files:
- /tmp/.bash/
- /root/.bash/
- /root/.cache/
- /tmp/.cache/
- /dev/shm/.ssh/
- /etc/.etcservice/linuxservice
- /etc/.vhost/netvhost
- /tmp/up.txt
Other:
Collects CPU information
Collects RAM information
Curing recommendations
Linux
Free trial
One month (no registration) or three months (registration and renewal discount)
このウェブサイトを継続して訪問する場合、訪問者に関する統計データを収集するためのCookieファイルおよび他のテクノロジーを弊社が利用することに同意したものとします。詳細