Linux.Siggen.6707
Added to the Dr.Web virus database:
2024-03-09
Virus description added:
2024-03-09
Technical Information
To ensure autorun and distribution:
Creates or modifies the following files:
- /var/spool/cron/crontabs/root
Malicious functions:
Launches processes:
- /bin/sh ./gTTM198ngk
- sleep 2
- /usr/sbin/killall5 pidof FijZK0os7r
- cat
- nohup ./gTTM198ngk
- crontab cron.d
- chmod +x /tmp/.system/./gTTM198ngk
- /bin/bash /dev/fd/3
- mkdir -p /tmp/.
- head -c 10
- crontab -l
- ln -s /tmp/.system/./s /tmp/.system/./FijZK0os7r
- sleep 4h
- mkdir -p /tmp/.system/.
- chmod u+x /tmp/.system/./79YPRCp7V0
- head /dev/urandom
- cp ./s /tmp/.system/./
- grep 79YPRCp7V0
- tr -dc A-Za-z0-9
- mkdir -p /dev/shm/.
- mkdir -p /var/tmp/.
Performs operations with the file system:
Modifies file access rights:
- /tmp/.system/79YPRCp7V0
- /tmp/.system/gTTM198ngk
- /var/spool/cron/crontabs/tmp.uag0GR
Creates folders:
Creates symlinks:
Creates or modifies files:
- /tmp/.system/gTTM198ngk
- /tmp/.system/79YPRCp7V0
- /tmp/.system/cron.d
- /var/spool/cron/crontabs/tmp.uag0GR
- /tmp/.system/.bash.pid
Changes time of creation/access/modification of files:
Curing recommendations
Linux
Free trial
One month (no registration) or three months (registration and renewal discount)
このウェブサイトを継続して訪問する場合、訪問者に関する統計データを収集するためのCookieファイルおよび他のテクノロジーを弊社が利用することに同意したものとします。詳細