Linux.Siggen.3684
Added to the Dr.Web virus database:
2021-02-25
Virus description added:
2021-02-25
Technical Information
Malicious functions:
Modifies firewall settings:
Manages services:
- service iptables reload
- systemctl stop aliyun.service
- systemctl disable aliyun.service
- service bcm-agent stop
Launches processes:
- bash -c
- chattr -iua /tmp/
- chattr -iua /var/tmp/
- mv /sbin/iptables /sbin/iptables__
- id -u
- sysctl kernel.nmi_watchdog=0
- ps aux
- grep -i [a]liyun
- bash
- pkill aliyun-service
- rm -rf /etc/init.d/agentwatch /usr/sbin/aliyun-service /usr/local/aegis*
Performs operations with the file system:
Creates or modifies files:
- /sbin/iptables
- /proc/sys/kernel/nmi_watchdog
- /etc/sysctl.conf
Deletes files:
- /etc/init.d/agentwatch
- /usr/sbin/aliyun-service
- /usr/local/aegis*
Other:
Collects CPU information
Collects RAM information
Collects information about network activity
Curing recommendations
Linux
Free trial
One month (no registration) or three months (registration and renewal discount)
このウェブサイトを継続して訪問する場合、訪問者に関する統計データを収集するためのCookieファイルおよび他のテクノロジーを弊社が利用することに同意したものとします。詳細