Linux.Siggen.3597
Added to the Dr.Web virus database:
2021-02-09
Virus description added:
2021-02-09
Technical Information
Malicious functions:
Gets access to SSH keys
- /root/.ssh/authorized_keys
Modifies firewall settings:
- iptables -F
- iptables -A INPUT -p tcp --dport 1234 -j ACCEPT
- iptables -A OUTPUT -p tcp --dport 1234 -j ACCEPT
- iptables -A INPUT -p tcp --dport 14444 -j ACCEPT
- iptables -A OUTPUT -p tcp --dport 14444 -j ACCEPT
- iptables -A INPUT -p tcp --dport 22 -j ACCEPT
- iptables -A OUTPUT -p tcp --dport 22 -j ACCEPT
- iptables -A INPUT -p tcp --dport 8080 -j ACCEPT
- iptables -A OUTPUT -p tcp --dport 8080 -j ACCEPT
- iptables -A INPUT -p tcp --dport 80 -j ACCEPT
- iptables -A OUTPUT -p tcp --dport 80 -j ACCEPT
- iptables -A INPUT -p tcp --dport 6379 -j ACCEPT
- iptables -A OUTPUT -p tcp --dport 6379 -j ACCEPT
- iptables -A INPUT -p tcp --dport 4444 -j ACCEPT
- iptables -A OUTPUT -p tcp --dport 4444 -j ACCEPT
- iptables -A OUTPUT -p tcp --destination-port 3333 -j DROP
- iptables -A OUTPUT -p tcp --destination-port 5555 -j DROP
- iptables -A OUTPUT -p tcp --destination-port 7777 -j DROP
- iptables -A OUTPUT -p tcp --destination-port 9999 -j DROP
- iptables -A OUTPUT -p tcp --destination-port 14443 -j DROP
Launches processes:
- sh /tmp/c.sh
- sync
- crontab -r
- rm -rf /var/spool/cron/
- rm -rf /var/spool/cron/crontabs/
- rm -rf /etc/cron.d/*
- chattr -iua /tmp/
- apt-get install ps
- /usr/bin/dpkg --print-foreign-architectures
- mv /usr/bin/cd1 /usr/bin/curl
- mv /usr/bin/wd1 /usr/bin/wget
- rm -rf /var/log/syslog
- sysctl -w vm.nr_hugepages=128
- chattr -ia /root/.ssh
- chattr -ia /root/.ssh/authorized_keys
- chmod 700 /root/.ssh/
- chmod 777 /root/.ssh/authorized_keys
- chmod 600 /root/.ssh/authorized_keys
- rm -rf /etc/*.sh
- rm -rf /etc/svc*
- rm -rf /etc/zzh
- rm -rf /etc/config.json
- grep -i [a]liyun
- ps aux
- grep -i [y]unjing
- userdel akay
Performs operations with the file system:
Modifies file access rights:
- /var/cache/apt/pkgcache.bin.hEPaaV
Creates or modifies files:
- /var/a
- /tmp/c.sh
- /root/dev/null
- /etc/sysconfig/selinux
- /proc/sys/vm/drop_caches
- /proc/sys/kernel/nmi_watchdog
- /etc/sysctl.conf
- /var/lib/dpkg/lock
- /var/cache/apt/pkgcache.bin.hEPaaV
- /proc/sys/vm/nr_hugepages
- /var/spool/mail/root
- /var/mail/root
- /var/log/wtmp
- /var/log/secure
- /root/.bash_history
Deletes files:
- /var/spool/cron/.SEQ
- /var/spool/cron/crontabs/
- /etc/cron.d/*
- /var/cache/apt/pkgcache.bin
- /var/log/syslog
- /etc/*.sh
- /etc/svc*
- /etc/zzh
- /etc/config.json
Other:
Collects CPU information
Collects RAM information
Collects information about network activity
Curing recommendations
Linux
Free trial
One month (no registration) or three months (registration and renewal discount)
このウェブサイトを継続して訪問する場合、訪問者に関する統計データを収集するためのCookieファイルおよび他のテクノロジーを弊社が利用することに同意したものとします。詳細