Library
My library

+ Add to library

Contact us
24/7 Tech support | Rules regarding submitting

Send a message

Your tickets

Profile

Linux.Siggen.4104

Added to the Dr.Web virus database: 2021-08-09

Virus description added:

Technical Information

Malicious functions:
Replaces the following system files:
  • /bin/ps
Launches processes:
  • mkdir -p /var/tmp/.share/.crypto/...
  • chmod a+x /var/tmp/.share/.crypto/.../h-r.sh
  • /var/tmp/.share/.crypto/.../h-r.sh
  • ls -l /bin/ps
  • awk { print $5 }
  • mv /bin/ps /bin/ps.lanigiro
  • chmod +x /bin/ps
  • touch -d 20160825 /bin/ps
  • ls -l /bin/top
  • mv /bin/top /bin/top.lanigiro
  • chmod a+x /bin/top
  • ls -l /bin/pstree
  • awk { print $5}
  • mv /bin/pstree /bin/pstree.lanigiro
  • mv /usr/bin/chattr /usr/bin/tntcht
  • mv /usr/bin/wgettnt /usr/bin/wget
  • mv /usr/bin/curltnt /usr/bin/curl
  • mv /usr/bin/wget1 /usr/bin/wget
  • mv /usr/bin/curl1 /usr/bin/curl
  • mv /usr/bin/cur /usr/bin/curl
  • mv /usr/bin/cdl /usr/bin/curl
  • mv /usr/bin/cdt /usr/bin/curl
  • mv /usr/bin/xget /usr/bin/wget
  • mv /usr/bin/wge /usr/bin/wget
  • mv /usr/bin/wdl /usr/bin/wget
  • mv /usr/bin/wdt /usr/bin/wget
  • mv /usr/bin/wget /usr/bin/wget
  • mv /usr/bin/curl /usr/bin/curl
  • mv /usr/bin/wget /usr/bin/wdz
  • mv /usr/bin/curl /usr/bin/cdz
  • netstat -anp
  • grep 185.71.65.238
  • awk {print $7}
  • awk -F[/] {print $1}
  • xargs -I % kill -9 %
  • grep 140.82.52.87
  • grep :443
  • grep -v -
  • grep :23
  • grep :143
Performs operations with the file system:
Modifies file access rights:
  • /var/tmp/.share/.crypto/.../h-r.sh
  • /bin/ps
  • /bin/top
Creates folders:
  • /var/tmp/.share
  • /var/tmp/.share/.crypto
  • /var/tmp/.share/.crypto/...
Creates or modifies files:
  • /var/tmp/.share/.crypto/.../h-r.sh
  • /bin/ps
  • /bin/top
  • /usr/bin/chattr
  • /usr/bin/wget
Other:
Collects RAM information

Curing recommendations


Linux

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Free trial

One month (no registration) or three months (registration and renewal discount)

Download Dr.Web

Download by serial number