Per il corretto funzionamento del sito, è necessario attivare il supporto di JavaScript nel browser.
Linux.Siggen.7545
Aggiunto al database dei virus Dr.Web:
2024-05-28
La descrizione è stata aggiunta:
2024-05-28
Technical Information
Malicious functions:
Removes itself
Launches itself as a daemon
Substitutes application name for:
7riwLmB7y3DiU6M
xcEl44q70Ud1iIT
5b4T60skXqG03JO
Launches processes:
/usr/sbin/xtables-nft-multi iptables -I INPUT -p tcp --syn -s 10.0.0.0/8 -j ACCEPT
iptables -D INPUT -p tcp -m state --state ESTABLISHED,RELATED -j ACCEPT
iptables -I INPUT -p tcp --syn -s 192.0.0.0/8 -j ACCEPT
rm -rf /var/tmp/x
iptables -D INPUT -p tcp --syn -s 10.0.0.0/8 -j ACCEPT
/usr/sbin/xtables-nft-multi iptables -I INPUT -p tcp --syn -s 127.0.0.0/8 -j ACCEPT
killall tftp
iptables -D INPUT -p tcp --syn -s 127.0.0.0/8 -j ACCEPT
rm -rf /var/tmp/v
rm -rf /var/tmp/a
iptables -I INPUT -p tcp --syn -j DROP
iptables -D INPUT -p tcp --syn -j DROP
iptables -I INPUT -p tcp --syn -s 172.16.0.0/12 -j ACCEPT
iptables -D INPUT -p tcp --syn -s 172.16.0.0/12 -j ACCEPT
/usr/sbin/xtables-nft-multi iptables -I INPUT -p tcp --syn -j DROP
rm -rf /var/tmp/i
/usr/sbin/xtables-nft-multi iptables -D INPUT -p tcp --syn -j DROP
iptables -D INPUT -p tcp --syn -s 100.64.0.0/10 -j ACCEPT
rm -rf /var/tmp/l
/usr/sbin/xtables-nft-multi iptables -I INPUT -p tcp --syn -s 192.0.0.0/8 -j ACCEPT
rm -rf /var/tmp/b
iptables -I INPUT -p tcp --syn -s 10.0.0.0/8 -j ACCEPT
killall ipping
/usr/sbin/xtables-nft-multi iptables -D INPUT -p tcp --syn -s 172.16.0.0/12 -j ACCEPT
/usr/sbin/xtables-nft-multi iptables -D INPUT -p tcp --syn -s 127.0.0.0/8 -j ACCEPT
/usr/sbin/xtables-nft-multi iptables -I INPUT -p tcp --syn -s 100.64.0.0/10 -j ACCEPT
/usr/sbin/xtables-nft-multi iptables -D INPUT -p tcp --syn -s 10.0.0.0/8 -j ACCEPT
iptables -I INPUT -p tcp --syn -s 100.64.0.0/10 -j ACCEPT
/usr/sbin/xtables-nft-multi iptables -D INPUT -p tcp -m state --state ESTABLISHED,RELATED -j ACCEPT
/usr/sbin/xtables-nft-multi iptables -I INPUT -p tcp --syn -s 172.16.0.0/12 -j ACCEPT
/usr/sbin/xtables-nft-multi iptables -D INPUT -p tcp --syn -s 100.64.0.0/10 -j ACCEPT
/usr/sbin/xtables-nft-multi iptables -D INPUT -p tcp --syn -s 192.0.0.0/8 -j ACCEPT
iptables -D INPUT -p tcp --syn -s 192.0.0.0/8 -j ACCEPT
rm -rf /var/tmp/z
iptables -I INPUT -p tcp --syn -s 127.0.0.0/8 -j ACCEPT
Kills the following processes:
Performs operations with the file system:
Modifies file access rights:
Creates or modifies files:
<SAMPLE_FULL_PATH>
/dev/watchdog
Mounts file systems:
Network activity:
Awaits incoming connections on ports:
127.0.0.1:65524
127.0.0.1:65525
Establishes connection:
Sends data to the following servers:
Receives data from the following servers:
Curing recommendations
Linux
Free trial
One month (no registration) or three months (registration and renewal discount)
Scaricate Dr.Web per Android
Gratis per 3 mesi
Tutti i componenti di protezione
Rinnovo versione di prova tramite AppGallery/Google Pay
Continuando a utilizzare questo sito, l'utente acconsente al nostro utilizzo di file Cookie e di altre tecnologie per la raccolta di informazioni statistiche sui visitatori. Per maggiori informazioni
OK