Linux.Siggen.7642
Added to the Dr.Web virus database:
2024-06-14
Virus description added:
2024-06-14
Technical Information
Malicious functions:
Launches itself as a daemon
Substitutes application name for:
Replaces the following system files:
- /usr/bin/ps
- /usr/bin/netstat
- /usr/bin/ss
- /usr/bin/lsof
Launches processes:
- chmod 777 /usr/bin/ss
- mv /usr/bin/lsofs /usr/bin/lsof;mv /usr/bin/lsof /usr/bin/lsofs
- mv /usr/bin/netstat /usr/bin/netstats
- chmod 777 /usr/bin/ps
- mv /usr/bin/lss /usr/bin/ls;mv /usr/bin/ls /usr/bin/lss
- chmod 777 /usr/bin/netstat
- mv /usr/bin/sss /usr/bin/ss;mv /usr/bin/ss /usr/bin/sss
- /tmp/.bash_profi1e ks0ftirqd/0
- mv <SAMPLE_FULL_PATH> /tmp/.bash_profi1e -f
- mv /usr/bin/ls /usr/bin/lss
- mv /usr/bin/lsof /usr/bin/lsofs
- chmod 777 /usr/bin/ls
- mv /usr/bin/ps /usr/bin/pss
- mv /usr/bin/pss /usr/bin/ps;mv /usr/bin/ps /usr/bin/pss
- mv /usr/bin/lsofs /usr/bin/lsof
- mv /usr/bin/sss /usr/bin/ss
- mv <SAMPLE_FULL_PATH> /tmp/.bash_profi1e -f;chmod 777 * /tmp/.bash_prof
- chmod 777 bin boot dev etc home lib lost+found media mnt opt proc root run sbin srv sys tmp usr var /tmp/.bash_prof
- mv /usr/bin/netstats /usr/bin/netstat;mv /usr/bin/netstat /usr/bin/netstats
- mv /usr/bin/pss /usr/bin/ps
- chmod 777 /usr/bin/lsof
- mv /usr/bin/ss /usr/bin/sss
- mv /usr/bin/lss /usr/bin/ls
- rm -rf /tmp/.bash_profi1e
- mv /usr/bin/netstats /usr/bin/netstat
Performs operations with the file system:
Modifies file access rights:
- /bin
- /boot
- /dev
- /etc
- /home
- /lib
- /lost+found
- /media
- /mnt
- /opt
- /proc
- /root
- /run
- /sbin
- /srv
- /sys
- /tmp
- /usr
- /var
- /usr/bin/ps
- /usr/bin/netstat
- /usr/bin/ls
- /usr/bin/ss
- /usr/bin/lsof
Creates or modifies files:
- /proc/847/cmdline
- <SAMPLE_FULL_PATH>
- /proc/855/cmdline
- /usr/bin/ls
- /usr/bin/lsof
Mounts file systems:
Curing recommendations
Linux
Free trial
One month (no registration) or three months (registration and renewal discount)
欢迎下载
Dr.Web for Android
-
免费3个月
-
可使用所有保护组件
-
可在AppGallery/Google Pay延期
继续使用此网站意味着您同意我们使用Cookie文件和其他用于收集网站访问统计信息的技术手段。详细信息