Linux.Siggen.3741
Added to the Dr.Web virus database:
2021-03-11
Virus description added:
2021-03-11
Technical Information
Malicious functions:
Modifies firewall settings:
Manages services:
Launches processes:
- bash -c
- chattr -iua /tmp/
- chattr -iua /var/tmp/
- mv /sbin/iptables /sbin/iptables__
- id -u
- sysctl kernel.nmi_watchdog=0
- grep -i [a]liyun
- ps aux
- bash
- pkill aliyun-service
- rm -rf /etc/init.d/agentwatch /usr/sbin/aliyun-service /usr/local/aegis*
Performs operations with the file system:
Creates or modifies files:
- /sbin/iptables
- /proc/sys/kernel/nmi_watchdog
- /etc/sysctl.conf
Deletes files:
- /etc/init.d/agentwatch
- /usr/sbin/aliyun-service
- /usr/local/aegis*
- /tmp/.ICE-unix
Network activity:
Awaits incoming connections on ports:
Establishes connection:
- 127.0.0.1:9
- [:#1]:9
- [:##]:52014
- 127.0.0.1:52014
- <LOCAL_DNS_SERVER>
DNS ASK:
Other:
Collects CPU information
Collects RAM information
Collects information about network activity
Curing recommendations
Linux
Free trial
One month (no registration) or three months (registration and renewal discount)
このウェブサイトを継続して訪問する場合、訪問者に関する統計データを収集するためのCookieファイルおよび他のテクノロジーを弊社が利用することに同意したものとします。詳細