Linux.Siggen.7742
Added to the Dr.Web virus database:
2024-07-05
Virus description added:
2024-07-05
Technical Information
Malicious functions:
Gets access to SSH keys
- /root/.ssh/authorized_keys
Launches processes:
- /usr/bin/cp -f <SAMPLE_FULL_PATH> /usr/bin/vwilnl
- /usr/bin/python3.9 /usr/bin/python3 -Es /usr/bin/lsb_release
- /usr/bin/chattr -i /tmp/nrinvj
- /usr/bin/cp -f <SAMPLE_FULL_PATH> /usr/bin/uvhdjl
- /usr/bin/cp -f <SAMPLE_FULL_PATH> /usr/bin/npgjpp
- /usr/bin/chattr -i /root/.ssh/authorized_keys
- /usr/bin/getconf CLK_TCK
Kills the following processes:
Performs operations with the file system:
Modifies file access rights:
Creates folders:
- /var/lib/.mnon
- /root/.ssh
Deletes folders:
Creates or modifies files:
- /var/lib/.mnon/.local
- /tmp/.X11-unix
- /tmp/nrinvj
- /usr/bin/uvhdjl
- /usr/bin/npgjpp
- /usr/bin/vwilnl
Deletes files:
Locks files:
- /var/lib/.mnon/.local
- /tmp/nrinvj
Network activity:
Establishes connection:
- 8.#.8.8:53
- 58.##.119.191:45569
- 11#.##.189.244:35327
- 21#.##9.32.10:53
- 20#.##.222.222:53
- 19#.#08.88.1:53
- 49.##.234.183:80
- [2#####901:0:bbc3::]:9
- 34.##7.118.44:9
- 34.###.118.44:80
- 34.###.186.192:80
- 18#.###.166.148:37940
- 18#.##4.98.233:9
- 18#.##4.99.233:9
- 18#.##4.98.233:80
- [2#######0:3037::6815:365b]:9
- [2#######0:3030::ac43:a86a]:9
- 17#.##.168.106:9
- 10#.#1.54.91:9
- 17#.##.168.106:80
- 54.##.206.99:9
- 52.##3.236.3:9
- 99.##.7.149:9
- 54.##4.47.36:9
- 52.##.148.69:9
- 52.##0.17.94:9
- 54.##.206.99:80
- 10#.##.185.241:9
- 10#.##.184.241:9
- 10#.##.185.241:80
- 43.###.202.68:44164
- 10#.##.190.41:36492
- 42.###.136.96:35463
- 12#.#5.237.16:9
- 12#.#5.237.51:9
- 12#.##.237.16:80
- [2#######0:3037::6815:365b]:80
- [2#######0:3030::ac43:a86a]:80
- 10#.##.69.154:43511
- 12#.##8.190.84:8000
DNS ASK:
- ns###.#kamaitech.net
- ip##ho.net
- ip##fo.io
- ip##.#canhazip.com
- ch#####.amazonaws.com
- ap#.#pify.org
- v4.#dent.me
- if##nfig.me
- if##nfig.co
- o-#.###ddr.l.google.com
- my##.#pendns.com
- ns#.#oogle.com
- re#####r1.opendns.com
- wh####.akamai.net
- wh#####yip.akamai.com
Sends data to the following servers:
- 19#.#08.88.1:53
- 20#.##.222.222:53
- 21#.##9.32.10:53
- 49.##.234.183:80
- 34.###.186.192:80
- 34.###.118.44:80
- 18#.##4.98.233:80
- 54.##.206.99:80
- 17#.##.168.106:80
- 10#.##.185.241:80
- 12#.##.237.16:80
Receives data from the following servers:
- 19#.#08.88.1:53
- 20#.##.222.222:53
- 21#.##9.32.10:53
- 49.##.234.183:80
- 34.###.186.192:80
- 34.###.118.44:80
- 18#.##4.98.233:80
- 54.##.206.99:80
- 17#.##.168.106:80
- 10#.##.185.241:80
- 12#.##.237.16:80
Other:
Collects CPU information
Collects information about network activity
Curing recommendations
Linux
Free trial
One month (no registration) or three months (registration and renewal discount)
このウェブサイトを継続して訪問する場合、訪問者に関する統計データを収集するためのCookieファイルおよび他のテクノロジーを弊社が利用することに同意したものとします。詳細