Linux.Siggen.3808
Added to the Dr.Web virus database:
2021-03-23
Virus description added:
2021-03-22
Technical Information
Malicious functions:
Manages services:
- systemctl start opendkim
- systemctl enable opendkim
- systemctl restart postfix
- systemctl start named
- systemctl enable named
- systemctl restart mysqld
- systemctl enable mysqld
- systemctl restart httpd
- systemctl enable httpd
- systemctl stop sendmail
- systemctl disable sendmail
Launches processes:
- /bin/bash <SAMPLE_FULL_PATH> -c exec '<SAMPLE_FULL_PATH>' \"$@\" <SAMPLE_FULL_PATH>
- <SAMPLE_FULL_PATH>
- /bin/bash <SAMPLE_FULL_PATH> -c
- rm -rf /root/install.sh
- mkdir -p /root/mailamigos-scripts/backup-local/.Originais
- ip a
- grep inet
- cut -f1 -d/
- awk {print $2}
- grep -v ^127.[0-9]
- grep -v ^10.[0-9]
- grep -v ^172.16.[0-9]
- grep -v ^192.168.[0-9]
- cat /root/mailamigos-scripts/ips.info
- head -1 /root/mailamigos-scripts/ips.info
- wc -l
- rm -rf /etc/localtime
- ln -s /usr/share/zoneinfo/America/Chicago /etc/localtime
- md5sum
- date
- cut -c -12
- base64
- useradd
- chpasswd
- mkdir /home//websites
- chmod 755 /home// -R
- chown : /home// -R
- useradd return -s /sbin/nologin
- nscd -i passwd
- nscd -i group
- useradd admin
- useradd fbl
- useradd abuse
- useradd reply
- useradd postmaster
- mv /etc/named.conf /etc/named.conf-bkp
- date +%Y%m%d%H%M%S
- cut -f1-3 -d.
- sort /tmp/ips.info
- uniq
- sed -i s/^/ip4:/ /tmp/spfconfig.info
- sed -i s/$/.0\/24 / /tmp/spfconfig.info
- sed -i :a;$!N;s/\n//;ta; /tmp/spfconfig.info
- cat /tmp/spfconfig.info
- mv /etc/opendkim/keys/default.private /tmp/dkim-default
- cat /etc/opendkim/keys/default.txt
- mv .db /var/named/.db
- chown root:named /var/named/.db
- mv /etc/opendkim.conf /etc/opendkim.conf.orig
- cat
- sleep 0.5
- mv /etc/my.cnf /etc/my.cnf-bkp
- mv /mailamigos/repositories/*.sql /root/mailamigos-scripts/backup-local/.Originais/
- mv /etc/php.ini /etc/php.ini-bkp
- mv /mailamigos/repositories/ioncube_loader_lin_5.6.so /usr/lib64/php/modules/ioncube_loader_lin_5.6.so
- chmod 777 /usr/lib64/php/modules/ioncube_loader_lin_5.6.so
- mv /etc/httpd/conf/httpd.conf /etc/httpd/conf/httpd.conf-bkp
- rm -rf /var/www/html
- mkdir /var/www/mailer
- unzip -q /mailamigos/repositories/mumara.zip -d /var/www/mailer
- mv /mailamigos/repositories/mumara.zip /root/mailamigos-scripts/backup-local/.Originais/mumara.zip
- sed -i 177d /etc/squirrelmail/config.php
- sed -i 1
- mv /etc/httpd/conf.d/phpMyAdmin.conf /etc/httpd/conf.d/phpMyAdmin.conf-bkp
- chown apache:apache /var/www/ -R
- mv /etc/postfix/main.cf /etc/postfix/main.cf-bkp
- mv /etc/postfix/master.cf /etc/postfix/master.cf-bkp
- mv /etc/sysctl.conf /etc/sysctl.conf-bkp
Performs operations with the file system:
Curing recommendations
Linux
Free trial
One month (no registration) or three months (registration and renewal discount)
このウェブサイトを継続して訪問する場合、訪問者に関する統計データを収集するためのCookieファイルおよび他のテクノロジーを弊社が利用することに同意したものとします。詳細