Library
My library

+ Add to library

Contact us
24/7 Tech support | Rules regarding submitting

Send a message

Your tickets

Profile

Linux.Packed.584

Added to the Dr.Web virus database: 2019-09-05

Virus description added:

Technical Information

Malicious functions:
Launches itself as a daemon
Modifies firewall settings:
  • iptables -F
Manages services:
  • service iptables stop
Launches processes:
  • sh -c echo Infected By Arh
  • sh -c rm -rf /tmp/* /var/* /var/run/* /var/tmp/*
  • rm -rf /tmp/* /var/backups /var/cache /var/lib /var/local /var/lock /var/log /var/mail /var/opt /var/run /var/spool /var/tmp /var/run/acpid.pid /var/run/acpid.socket /var/run/atd.pid /var/run/crond.pid /var/run/crond.reboot /var/run/dbus /var/run/dhclient.eth0.pid /var/run/exim4 /var/run/initctl /var/run/initramfs /var/run/lock /var/run/log /var/run/mount /var/run/network /var/run/rpc.statd.pid /var/run/rpc_pipefs /var/run/rpcbind /var/run/rpcbind.lock /var/run/rpcbind.pid /var/run/rpcbind.sock /var/run/rsyslogd.pid /var/run/sendsigs.omit.d /var/run/shm /var/run/sm-notify.pid /var/run/sshd /var/run/sshd.pid /var/run/systemd /var/run/tmpfiles.d /var/run/udev /var/run/user /var/run/utmp /var/tmp/*
  • sh -c rm -rf /var/log/wtmp
  • rm -rf /var/log/wtmp
  • sh -c rm -rf /tmp/*
  • rm -rf /tmp/*
  • sh -c rm -rf /bin/netstat
  • rm -rf /bin/netstat
  • sh -c iptables -F
  • sh -c pkill -9 busybox
  • pkill -9 busybox
  • sh -c pkill -9 perl
  • pkill -9 perl
  • sh -c pkill -9 python
  • pkill -9 python
  • sh -c service iptables stop
Kills system processes:
  • sshd
Kills the following processes:
  • rpc.idmapd
  • cron
  • atd
  • systemd-logind
  • rsyslogd
  • acpid
  • dbus-daemon
  • agetty
  • exim4
Performs operations with the file system:
Creates or modifies files:
  • /etc/resolv.conf
Deletes files:
  • /tmp/*
  • /dpkg.statoverride.5.gz
  • /dpkg.diversions.2.gz
  • /dpkg.statoverride.4.gz
  • /alternatives.tar.0
  • /dpkg.diversions.0
  • /dpkg.status.6.gz
  • /dpkg.status.0
  • /dpkg.status.2.gz
  • /dpkg.diversions.5.gz
  • /apt.extended_states.0
  • /apt.extended_states.1.gz
  • /dpkg.status.5.gz
  • /group.bak
  • /dpkg.status.3.gz
  • /dpkg.status.1.gz
  • /dpkg.statoverride.0
  • /passwd.bak
  • /dpkg.diversions.3.gz
  • /dpkg.statoverride.1.gz
  • /dpkg.statoverride.6.gz
  • /shadow.bak
  • /dpkg.diversions.6.gz
  • /dpkg.statoverride.3.gz
  • /gshadow.bak
  • /var/log/wtmp
  • /bin/netstat
Network activity:
Establishes connection:
  • 8.#.8.8:53
  • 18#.###.25.169:32957
Sends data to the following servers:
  • 18#.###.25.169:32957
Other:
Collects CPU information

Curing recommendations


Linux

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Free trial

One month (no registration) or three months (registration and renewal discount)

Download Dr.Web

Download by serial number