Library
My library

+ Add to library

Contact us
24/7 Tech support | Rules regarding submitting

Send a message

Your tickets

Profile

Linux.Siggen.563

Added to the Dr.Web virus database: 2018-04-30

Virus description added:

Technical Information

Malicious functions:
Launches processes:
  • sh -c uname -r >/tmp/ibm_ux_pkg_uname.txt 2>/dev/null
  • uname -r
  • sh -c uname -a >/tmp/ibm_ux_pkg_uname.txt 2>/dev/null
  • uname -a
  • sh -c mkdir -p \"/tmp/ibm_ux_pkg_000002ac\"
  • mkdir -p /tmp/ibm_ux_pkg_000002ac
  • sh -c ./miniunz image.zip > /dev/null
  • ./miniunz image.zip
  • /bin/sh ./miniunz image.zip
  • sh -c rm -rf \"/tmp/ibm_ux_pkg_000002ac\"
  • rm -rf /tmp/ibm_ux_pkg_000002ac
Performs operations with the file system:
Modifies file access rights:
  • /tmp/ibm_ux_pkg_000002ac/image.tar
  • /tmp/ibm_ux_pkg_000002ac/image.zip
  • /tmp/ibm_ux_pkg_000002ac/miniunz
Creates folders:
  • /tmp/ibm_ux_pkg_000002ac
Creates or modifies files:
  • /tmp/ibm_ux_pkg_uname.txt
  • /tmp/ibm_ux_pkg_000002ac"/image.tar
  • /tmp/ibm_ux_pkg_000002ac"/image.zip
  • /tmp/ibm_ux_pkg_000002ac"/miniunz
Deletes files:
  • /tmp/ibm_ux_pkg_uname.txt"
  • /tmp"/image.zip"
  • /tmp"/miniunz"
  • /tmp"/image.tar"

Curing recommendations


Linux

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Free trial

One month (no registration) or three months (registration and renewal discount)

Download Dr.Web

Download by serial number