Linux.Packed.523
Added to the Dr.Web virus database:
2019-07-16
Virus description added:
2019-07-16
Technical Information
To ensure autorun and distribution:
Creates or modifies the following files:
Malicious functions:
Removes itself
Launches processes:
- /bin/sh -c ([crypto] &)
- [crypto]
- /bin/sh -c touch -r /etc/cron.hourly/0anacron /etc/cron.hourly/anacron
- touch -r /etc/cron.hourly/0anacron /etc/cron.hourly/anacron
- /bin/sh -c id
- id
- /bin/sh -c uname -a
- uname -a
Performs operations with the file system:
Creates or modifies files:
- /tmp/.4922efcbb2e3ba85f575e37d2d808d2d
- /usr/local/sbin/[crypto]
Deletes files:
- /usr/local/sbin/[crypto]
- /tmp/.4922efcbb2e3ba85f575e37d2d808d2d
- /tmp/.lang-unix
Network activity:
Establishes connection:
HTTP POST requests:
- 45.##.##9.124/v2/index.php
DNS ASK:
- m.####dserver.com
- a.####dserver.com
Curing recommendations
Linux
Free trial
One month (no registration) or three months (registration and renewal discount)
欢迎下载
Dr.Web for Android
-
免费3个月
-
可使用所有保护组件
-
可在AppGallery/Google Pay延期
继续使用此网站意味着您同意我们使用Cookie文件和其他用于收集网站访问统计信息的技术手段。详细信息