Linux.Siggen.6480
Added to the Dr.Web virus database:
2024-01-23
Virus description added:
2024-01-23
Technical Information
Malicious functions:
Removes itself
Launches itself as a daemon
Substitutes application name for:
Launches processes:
- cat /var/tmp/.systemd.*
- cat /tmp/.X11-unix/*
- base64 -d
- chmod +x ./.637923c31f7904085906
- rm -f ./.637923c31f7904085906
- xargs kill -9
- find /tmp -type d -name *systemd-logind*
- rm -rf
- xargs rm -rf
- crontab -l
- grep -q tor2w /etc/hosts
- find /root/.config/systemd/user/systemd-tmpfiles-cleanup -type f
- kill -9 2 17 561
- /usr/bin/mawk awk {print $NF}
- cut -d/ -f1
- /usr/bin/mawk awk -F {print $(NF-1)}
- ps x
- sed s/pid=//g
- md5sum
- grep -E gs-dbus-kernel|wget|curl|base64|systemd-private|watchdog|\x5c* \x5c* \x5c* \x5c* \x5c*
- rm -f i
- grep -v 6jlqwE
- ss -antp
- kill -9
- echo NmpscXdFCmV4ZWMgJj4vZGV2L251bGwKc29qWWVoV089Li8uJChkYXRlfG1kNXN1bXxoZWFkIC1jMjApCmZpYld5cWRuPShkb2gtY2guYmxhaGRucy5jb20gZG9oLWRlLmJsYWhkbnMuY29tIGRvaC1zZy5ibGFoZG5zLmNvbSBkb2gubGkgZG9oLnB1YiBkb2guZG5zLnNiIGRucy50d25pYy50dykKVmxR
- rm -rf /tmp/systemd-private-9a696143c12e4a2d879683f675cf06b2-systemd-logind.service-d16u7f
- bash
- grep -E kinsing|kdevtmpfs|kthreadd|watchdog
- chmod +x ./i
- date
- /usr/bin/mawk awk {print $1}
- /usr/bin/pgrep pkill -9 -f kinsing|kdevtmpfs|kthreadd|watchdog
- head -c20
- rm -f /tmp/.X11-unix/* /var/tmp/.systemd.* /tmp/kinsing* /tmp/kdev* /tmp/*watchdog*
Kills the following processes:
Performs operations with the file system:
Modifies file access rights:
Deletes folders:
- /tmp/systemd-private-9a696143c12e4a2d879683f675cf06b2-systemd-logind.service-d16u7f/tmp
- /tmp/systemd-private-9a696143c12e4a2d879683f675cf06b2-systemd-logind.service-d16u7f
Creates or modifies files:
- /tmp/systemd-private-5d13972c34e47d1119af139c5afcfd6d-systemd-logind.service-6jlqwE/i
- /root/i
- /tmp/.systemd.1
Deletes files:
Locks files:
Other:
Collects OS information
Collects CPU information
Collects RAM information
Curing recommendations
Linux
Free trial
One month (no registration) or three months (registration and renewal discount)
このウェブサイトを継続して訪問する場合、訪問者に関する統計データを収集するためのCookieファイルおよび他のテクノロジーを弊社が利用することに同意したものとします。詳細