Linux.Siggen.837
Added to the Dr.Web virus database:
2018-08-12
Virus description added:
2018-08-11
Technical Information
Malicious functions:
Launches processes:
- sh -c mkdir \"/log\" > /dev/null 2>&1
- mkdir /log
- uname -a
- sh -c route | grep default | grep -v grep
- grep -v grep
- route
- grep default
Performs operations with the file system:
Creates folders:
Creates or modifies files:
- //bin/.xCloudClientRunOne.pid
- /bin/.xCloudClientRunOne.pid
- /etc/xCloud.db
- /log/Log.txt
- /bin/.version
- /etc/xCloud.db-journal
- /bin/.pid
Deletes files:
- /etc/xCloud.db-wal
- /etc/xCloud.db-journal
Network activity:
Awaits incoming connections on ports:
- 0.0.0.0:61617
- 0.0.0.0:15008
Establishes connection:
DNS ASK:
- 1.###.##8.192.in-addr.arpa
Sends data to the following servers:
- 23#.###.255.250:1900
- <LOCAL_DNS_SERVER>
Receives data from the following servers:
Curing recommendations
Linux
Free trial
One month (no registration) or three months (registration and renewal discount)
欢迎下载
Dr.Web for Android
-
免费3个月
-
可使用所有保护组件
-
可在AppGallery/Google Pay延期
继续使用此网站意味着您同意我们使用Cookie文件和其他用于收集网站访问统计信息的技术手段。详细信息