Linux.Siggen.3512
Added to the Dr.Web virus database:
2021-01-10
Virus description added:
2021-01-10
Technical Information
To ensure autorun and distribution:
Creates or modifies the following files:
- /var/spool/cron/crontabs/root
Malicious functions:
Launches processes:
- sh -c touch -r /opt/zimbra/jetty/webapps/zimbraAdmin/public/jsp/Zimbra.jsp /opt/zimbra/jetty/webapps/zimbraAdmin/public/jsp/Alert.jsp
- touch -r /opt/zimbra/jetty/webapps/zimbraAdmin/public/jsp/Zimbra.jsp /opt/zimbra/jetty/webapps/zimbraAdmin/public/jsp/Alert.jsp
- sh -c touch -r /opt/zimbra/jetty/webapps/zimbra/public/jsp/Crypt.jsp /opt/zimbra/jetty/webapps/zimbra/public/jsp/CryptCore.jsp
- touch -r /opt/zimbra/jetty/webapps/zimbra/public/jsp/Crypt.jsp /opt/zimbra/jetty/webapps/zimbra/public/jsp/CryptCore.jsp
- sh -c (crontab -l|grep -v 'zmstorewatch'|grep -v '/tmp/'|grep -v 'wget'|grep -v 'curl')|crontab -
- crontab -
- crontab -l
- grep -v zmstorewatch
- grep -v wget
- grep -v /tmp/
- grep -v curl
- sh -c (crontab -l|grep -v zmlogswatch|grep -v 'DO NOT EDIT ANYTHING';printf \"*/60 * * * * /opt/zimbra/lib/zmlogswatc
- grep -v zmlogswatch
- grep -v DO NOT EDIT ANYTHING
Performs operations with the file system:
Modifies file access rights:
- /opt/zimbra/jetty/webapps/zimbraAdmin/public/jsp
- /opt/zimbra/jetty/webapps/zimbra/public/jsp
- /var/spool/cron/crontabs/tmp.3eoIdF
- /var/spool/cron/crontabs/tmp.tQmxdF
Creates folders:
- /opt/zimbra
- /opt/zimbra/jetty
- /opt/zimbra/jetty/webapps
- /opt/zimbra/jetty/webapps/zimbraAdmin
- /opt/zimbra/jetty/webapps/zimbraAdmin/public
- /opt/zimbra/jetty/webapps/zimbraAdmin/public/jsp
- /opt/zimbra/jetty/webapps/zimbra
- /opt/zimbra/jetty/webapps/zimbra/public
- /opt/zimbra/jetty/webapps/zimbra/public/jsp
Creates or modifies files:
- /opt/zimbra/jetty/webapps/zimbraAdmin/public/jsp/Alert.jsp
- /opt/zimbra/jetty/webapps/zimbra/public/jsp/CryptCore.jsp
- /var/spool/cron/crontabs/tmp.3eoIdF
- /var/spool/cron/crontabs/tmp.tQmxdF
Deletes files:
- /opt/zimbra/jetty/webapps/zimbra/public/jsp/infoc.jsp
- /opt/zimbra/jetty/webapps/zimbra/public/jsp/BootCore.jsp
- /opt/zimbra/jetty/webapps/zimbra/public/jsp/ShareCore.jsp
- /opt/zimbra/jetty/webapps/zimbra/public/jsp/ZimbraCore.jsp
- /opt/zimbra/jetty/webapps/zimbra/public/jsp/Online.jsp
- /opt/zimbra/jetty/webapps/zimbra/public/404.jsp
- /opt/zimbra/conf/zmsstorewatch.cnf
- /opt/zimbra/conf/zmsstore.cnf
- /opt/zimbra/lib/zmmailboxdwatch
- /opt/zimbra/lib/zmstorewatch
Curing recommendations
Linux
Free trial
One month (no registration) or three months (registration and renewal discount)
欢迎下载
Dr.Web for Android
-
免费3个月
-
可使用所有保护组件
-
可在AppGallery/Google Pay延期
继续使用此网站意味着您同意我们使用Cookie文件和其他用于收集网站访问统计信息的技术手段。详细信息