JavaScript support is required for our site to be fully operational in your browser.
Linux.Siggen.584
Added to the Dr.Web virus database:
2018-05-08
Virus description added:
2018-05-07
Technical Information
Malicious functions:
Launches processes:
sh -c fanspeed h
sh -c touch /web/swap
touch /web/swap
sh -c touch /web/swap_a
touch /web/swap_a
sh -c touch /web/hddok
touch /web/hddok
sh -c insmod /sys/crfs/driver/fat.ko
insmod /sys/crfs/driver/fat.ko
sh -c insmod /sys/crfs/driver/vfat.ko
insmod /sys/crfs/driver/vfat.ko
sh -c rmmod usb-storage.ko
rmmod usb-storage.ko
sh -c cp usb_driver usb-storage.ko
cp usb_driver usb-storage.ko
sh -c insmod usb-storage.ko
insmod usb-storage.ko
sh -c lsmod
lsmod
sh -c /tmp/s_mount_usb_sda.sh
/tmp/s_mount_usb_sda.sh
mkdir /mnt/HD_c2
mount -t vfat -o umask=0 /dev/sda /mnt/HD_c2
/bin/mount
grep /dev/sda on /mnt/HD_c2
mount -t vfat -o umask=0 /dev/sda1 /mnt/HD_c2
grep /dev/sda1 on /mnt/HD_c2
sh -c mount | grep sda
grep sda
mount
sh -c kill -9 `pidof upnp`
pidof upnp
sh -c kill -9 `pidof udhcpc`
pidof udhcpc
sh -c rm -f /etc/rc.d/rc.init.sh
rm -f /etc/rc.d/rc.init.sh
sh -c rm -f /sbin/crond
rm -f /sbin/crond
sh -c kill -9 `pidof crond`
pidof crond
sh -c kill -9 `pidof fancontrol`
pidof fancontrol
sh -c rm /web/log.conf
rm /web/log.conf
sh -c touch /tmp/mfg
touch /tmp/mfg
sh -c kill -9 `pidof chkbutton`
pidof chkbutton
sh -c kill -9 `pidof SyncMms`
pidof SyncMms
sh -c kill -9 `pidof getMsg`
pidof getMsg
Performs operations with the file system:
Creates folders:
Creates or modifies files:
/web/swap
/web/swap_a
/web/hddok
/tmp/s_mount_usb_sda.sh
/run/mount/utab
/tmp/mfg
Deletes files:
/etc/rc.d/rc.init.sh
/sbin/crond
/web/log.conf
Mounts file systems:
Network activity:
Awaits incoming connections on ports:
Curing recommendations
Linux
Free trial
One month (no registration) or three months (registration and renewal discount)
Download Dr.Web for Android
Free three-month trial
All protection features available
Renew your trial license in AppGallery/on Google Pay
By continuing to use this website, you are consenting to Doctor Web’s use of cookies and other technologies related to the collection of visitor statistics. Learn more
OK