JavaScript support is required for our site to be fully operational in your browser.
Linux.Packed.56
Added to the Dr.Web virus database:
2018-03-15
Virus description added:
2018-03-14
Technical Information
To ensure autorun and distribution:
Creates or modifies the following symlinks:
/etc/init.d/wipefs"
/etc/rc0.d/S01wipefs"
/etc/rc1.d/S01wipefs"
/etc/rc2.d/S01wipefs"
/etc/rc3.d/S01wipefs"
/etc/rc4.d/S01wipefs"
/etc/rc5.d/S01wipefs"
/etc/rc6.d/S01wipefs"
Malicious functions:
Launches itself as a daemon
Launches processes:
sh -c
sh -c /tmp/tmpnam_GNKLAM upgrade >/dev/null 2>&1; rm /tmp/tmpnam_GNKLAM >/dev/null 2>&1
cp -f <SAMPLE_FULL_PATH> /bin/wipefs
/tmp/tmpnam_GNKLAM upgrade
/bin/sh ##which ss 1>/dev/null 2>&1
which ss
ln -fs /bin/wipefs /etc/init.d/wipefs
/bin/sh ##which ss
ln -fs /etc/init.d/wipefs /etc/rc0.d/S01wipefs
ln -fs /etc/init.d/wipefs /etc/rc1.d/S01wipefs
/bin/sh ##which netstat 1>/dev/null 2>&1
ln -fs /etc/init.d/wipefs /etc/rc2.d/S01wipefs
which netstat
ln -fs /etc/init.d/wipefs /etc/rc3.d/S01wipefs
ln -fs /etc/init.d/wipefs /etc/rc4.d/S01wipefs
ln -fs /etc/init.d/wipefs /etc/rc5.d/S01wipefs
ln -fs /etc/init.d/wipefs /etc/rc6.d/S01wipefs
/bin/sh ##chattr -i /bin/ddus-uidgen /etc/init.d/acpidtd /etc/rc.d/rc*.d/S01acpidtd /bin/ss /bin/scss /bin/netstat /bin/scnetstat 1>/dev/null 2>&1
ln -fs /etc/init.d/wipefs /etc/rc.d/rc0.d/S01wipefs
chattr -i /bin/ddus-uidgen /etc/init.d/acpidtd /etc/rc.d/rc*.d/S01acpidtd /bin/ss /bin/scss /bin/netstat /bin/scnetstat
ln -fs /etc/init.d/wipefs /etc/rc.d/rc1.d/S01wipefs
ln -fs /etc/init.d/wipefs /etc/rc.d/rc2.d/S01wipefs
/bin/sh ##cp -f /tmp/tmpnam_GNKLAM /bin/ddus-uidge
Performs operations with the file system:
Modifies file access rights:
Creates or modifies files:
/etc/resolv.conf
/tmp/tmpnam_GNKLAM
/bin/wipefs
Curing recommendations
Linux
Free trial
One month (no registration) or three months (registration and renewal discount)
Download Dr.Web for Android
Free three-month trial
All protection features available
Renew your trial license in AppGallery/on Google Pay
By continuing to use this website, you are consenting to Doctor Web’s use of cookies and other technologies related to the collection of visitor statistics. Learn more
OK