JavaScript support is required for our site to be fully operational in your browser.
Linux.Packed.578
Added to the Dr.Web virus database:
2019-08-28
Virus description added:
2019-08-28
Technical Information
Malicious functions:
Launches itself as a daemon
Launches processes:
sh -c echo Infected By Arh
sh -c rm -rf /tmp/* /var/* /var/run/* /var/tmp/*
rm -rf /tmp/* /var/backups /var/cache /var/lib /var/local /var/lock /var/log /var/mail /var/opt /var/run /var/spool /var/tmp /var/run/acpid.pid /var/run/acpid.socket /var/run/atd.pid /var/run/crond.pid /var/run/crond.reboot /var/run/dbus /var/run/dhclient.eth0.pid /var/run/exim4 /var/run/initctl /var/run/initramfs /var/run/lock /var/run/log /var/run/mount /var/run/network /var/run/rpc.statd.pid /var/run/rpc_pipefs /var/run/rpcbind /var/run/rpcbind.lock /var/run/rpcbind.pid /var/run/rpcbind.sock /var/run/rsyslogd.pid /var/run/sendsigs.omit.d /var/run/shm /var/run/sm-notify.pid /var/run/sshd /var/run/sshd.pid /var/run/systemd /var/run/tmpfiles.d /var/run/udev /var/run/user /var/run/utmp /var/tmp/*
Kills system processes:
Kills the following processes:
Performs operations with the file system:
Deletes files:
/tmp/*
/shadow.bak
/dpkg.diversions.0
/dpkg.diversions.1.gz
/alternatives.tar.0
/dpkg.statoverride.1.gz
/dpkg.statoverride.2.gz
/group.bak
/dpkg.statoverride.0
/dpkg.status.1.gz
/passwd.bak
/gshadow.bak
/dpkg.status.2.gz
/dpkg.status.0
/apt.extended_states.0
/dpkg.diversions.2.gz
/sqspell.php
/ispell.db
/wordlist-default
/emacsen-ispell-default.el
/wordlist.db
/hunspell.db
/ispell-default
/jed-ispell-dicts.sl
/aspell.db
/ispell-dicts-list.txt
/emacsen-ispell-dicts.el
/aux-cache
/index.db
Network activity:
Establishes connection:
8.#.8.8:53
18#.###.25.122:12192
Sends data to the following servers:
Curing recommendations
Linux
Free trial
One month (no registration) or three months (registration and renewal discount)
Download Dr.Web for Android
Free three-month trial
All protection features available
Renew your trial license in AppGallery/on Google Pay
By continuing to use this website, you are consenting to Doctor Web’s use of cookies and other technologies related to the collection of visitor statistics. Learn more
OK