JavaScript support is required for our site to be fully operational in your browser.
Linux.Siggen.1150
Added to the Dr.Web virus database:
2018-10-11
Virus description added:
2018-10-11
Technical Information
Malicious functions:
Substitutes application name for:
Performs process tracing:
Injects data to the following processes:
Launches processes:
sh -c getprop ro.product.brand
sh -c getprop ro.product.manufacturer
sh -c getprop ro.product.model
sh -c /root/kitty 0 &
sh -c /root/kitty 360 &
Performs operations with the file system:
Modifies file access rights:
/root/busybox
/root/kitty
Creates or modifies files:
/root/busybox
/root/kitty
/acct/uid/0/tasks
Deletes files:
/root/busybox
/root/kitty
Curing recommendations
Linux
Free trial
One month (no registration) or three months (registration and renewal discount)
By continuing to use this website, you are consenting to Doctor Web’s use of cookies and other technologies related to the collection of visitor statistics. Learn more
OK