JavaScript support is required for our site to be fully operational in your browser.
Linux.Siggen.3417
Added to the Dr.Web virus database:
2020-11-21
Virus description added:
2020-11-21
Technical Information
Malicious functions:
Performs process tracing:
<SAMPLE>
<SAMPLE_FULL_PATH>
Launches processes:
/bin/sh <SAMPLE_FULL_PATH> -c exec '<SAMPLE_FULL_PATH>' \"$@\" <SAMPLE_FULL_PATH>
<SAMPLE_FULL_PATH>
/bin/sh <SAMPLE_FULL_PATH> -c
mkdir .sftp
chmod 777 .sh
chmod 777 .php
chmod 777 .sphp
chattr -a /etc/.bashpid
nohup ./.sphp
./.sphp
./.php
./.sh
sleep 6
cat /etc/.bashpid
sleep 1
chattr +a /etc/.bashpid
pkill -f joseph
pkill -f osama
pkill -f xm64
pkill -f obama1
pkill -f kswapd0
pkill -f jehgms
pkill -f tsm
pkill -f rig
pkill -f xmr
pkill -f playstation
pkill -f ld-linux-x86-64
pkill -f ruckusapd
pkill -f run64
pkill -f pwnrig
pkill -f phpupdate
pkill -f sysupdate
pkill -f phpguard
pkill -f firstpress
pkill -f zerocert
pkill -f masscan
pkill -f -bash
pkill -f spreadQlmnop
pkill -f cnrig
pkill -f crond
rm -rf /tmp/.bash/
rm -rf /root/.bash/
rm -rf /root/.cache/
rm -rf /tmp/.cache/
rm -rf /dev/shm/.ssh/
rm -rf /etc/.etcservice/linuxservice
rm -rf /etc/.vhost/netvhost
rm -rf /tmp/up.txt
pkill -f netvhost
pkill -f kthreadds
pkill -f kdevtmpfsi
pkill -f linuxservice
pkill -f rtmonitor
pkill -f dev
pkill -f xmrig
Attempts to kill the following processes:
killall joseph
killall osama
killall xm64
killall daemon
killall obama1
killall kswapd0
killall jehgms
killall tsm
killall rig
killall xmr
killall playstation
killall ld-linux-x86-64
killall ruckusapd
killall run64
killall pwnrig
killall phpupdate
killall sysupdate
killall phpguard
killall firstpress
killall zerocert
killall masscan
killall spreadQlmnop
killall -bash
killall cnrig
killall crond
killall netvhost
killall kthreadds
killall kdevtmpfsi
killall linuxservice
killall rtmonitor
killall dev
killall xmrig
Kills the following processes:
<SAMPLE>
<SAMPLE_FULL_PATH>
/root/.sftp/.sh
kswapd0
kdevtmpfs
systemd-udevd
Performs operations with the file system:
Modifies file access rights:
/root/.sftp/.sh
/root/.sftp/.php
/root/.sftp/.sphp
Creates folders:
Creates or modifies files:
/root/.sftp/.sh
/root/.sftp/.php
/root/.sftp/.sphp
/etc/.bashpid
Deletes files:
/tmp/.bash/
/root/.bash/
/root/.cache/
/tmp/.cache/
/dev/shm/.ssh/
/etc/.etcservice/linuxservice
/etc/.vhost/netvhost
/tmp/up.txt
Other:
Collects CPU information
Collects RAM information
Curing recommendations
Linux
Free trial
One month (no registration) or three months (registration and renewal discount)
Download Dr.Web for Android
Free three-month trial
All protection features available
Renew your trial license in AppGallery/on Google Pay
By continuing to use this website, you are consenting to Doctor Web’s use of cookies and other technologies related to the collection of visitor statistics. Learn more
OK