Linux.Siggen.607
Added to the Dr.Web virus database:
2018-05-18
Virus description added:
2018-05-18
Technical Information
Malicious functions:
Gains root privileges
Launches processes:
- sh -c ping -c 4 194.186.207.182 > Ping.log
- ping -c 4 194.186.207.182
- sh -c ifconfig -a > IFConfig.log
- ifconfig -a
- sh -c cp /usr/lib/Amicon_ip-client/log/* ./ > /dev/null
- cp /usr/lib/Amicon_ip-client/log/* ./
- sh -c cp /var/log/dpkg.log ./ > /dev/null
- cp /var/log/dpkg.log ./
- sh -c cp /var/log/dmesg ./ > /dev/null
- cp /var/log/dmesg ./
- sh -c cp /var/log/kern.log ./ > /dev/null
- cp /var/log/kern.log ./
- sh -c zip -mr ./CliDiagn.zip ./CliDiagn > /dev/null
- zip -mr ./CliDiagn.zip ./CliDiagn
Performs operations with the file system:
Modifies file access rights:
Creates folders:
Deletes folders:
Creates or modifies files:
- /root/CliDiagn/Ping.log
- /root/CliDiagn/IFConfig.log
- /root/CliDiagn/dpkg.log
- /root/CliDiagn/dmesg
- /root/CliDiagn/kern.log
- /root/CliDiagn.zip
- /root/zi5v2hOU
Deletes files:
- /root/CliDiagn.zip
- /root/CliDiagn/dmesg
- /root/CliDiagn/kern.log
- /root/CliDiagn/IFConfig.log
- /root/CliDiagn/Ping.log
- /root/CliDiagn/dpkg.log
Network activity:
Establishes connection:
Sends data to the following servers:
Curing recommendations
Linux
Free trial
One month (no registration) or three months (registration and renewal discount)
欢迎下载
Dr.Web for Android
-
免费3个月
-
可使用所有保护组件
-
可在AppGallery/Google Pay延期
继续使用此网站意味着您同意我们使用Cookie文件和其他用于收集网站访问统计信息的技术手段。详细信息