Backdoor.Linux.ROTAJAKIRO.A
2021年6月25日
別名:
Backdoor:Linux/RotaJakiro.A!MTB (MICROSOFT)
プラットフォーム:
Linux
危険度:
ダメージ度:
感染力:
感染確認数:
情報漏えい:
- マルウェアタイプ: バックドア型
- 破壊活動の有無: なし
- 暗号化:
- 感染報告の有無: はい
概要
感染経路 インターネットからのダウンロード, 他のマルウェアからの作成
マルウェアは、他のマルウェアに作成されるか、悪意あるWebサイトからユーザが誤ってダウンロードすることによりコンピュータに侵入します。
マルウェアは、不正リモートユーザからのコマンドを実行し、感染コンピュータを改ざんします。 マルウェアは、特定のWebサイトにアクセスし、情報を送受信します。
詳細
ファイルサイズ 133,632 bytes
タイプ None
メモリ常駐 はい
発見日 2021年5月18日
ペイロード URLまたはIPアドレスに接続, ファイルの作成
侵入方法
マルウェアは、他のマルウェアに作成されるか、悪意あるWebサイトからユーザが誤ってダウンロードすることによりコンピュータに侵入します。
インストール
マルウェアは、感染したコンピュータ内に以下のように自身のコピーを作成します。
- For non-root user:
- $HOME/.gvfsd/.profile/gvfsd-helper
- $HOME/.dbus/sessions/session-dbus
- For root user: (one of the following):
- /usr/lib/systemd/systemd-daemon
- /bin/systemd/systemd-daemon
マルウェアは、以下のプロセスを追加します。
- For non-root user:
- $HOME/.gvfsd/.profile/gvfsd-helper
- $HOME/.dbus/sessions/session-dbus
- For root user:
- (systemctl enable systemd-agent.service) >/dev/null 2>&1
- (systemctl start systemd-agent.service) >/dev/null 2>&1
バックドア活動
マルウェアは、不正リモートユーザからの以下のコマンドを実行します。
- Terminate process
- Set timeout for connection to C2 server
- Get device information and send to server
- Create a file
- Query file status
- Deletes a file
- Run a plugin
マルウェアは、以下のWebサイトにアクセスし、情報を送受信します。
- status.{BLOCKED}eover.net:443
- blog.{BLOCKED}cts.com:443
- news.{BLOCKED}or.net:443
- cdn.{BLOCKED}-codes.net:443
その他
マルウェアは、以下を実行します。
- It creates/modifies the following files to establish persistence:
- For non-root user:
- creates the following autostart script:
- $HOME/.config/autostart/gnomehelper.desktop
contains the following contents:- [Desktop Entry]
- Type=Application
- Exec=$HOME/.gvfsd/.profile/gvfsd-helper
- Name=GNOME Helper
- $HOME/.config/autostart/gnomehelper.desktop
- modifies the following file:
- ~/.bashrc
adds the following contents:- if [ -d ${HOME} ]; then
${HOME}/.gvfsd/.profile/gvfsd-helper - fi
- ~/.bashrc
- creates the following autostart script:
- For root user:
- creates the following autostart script:
- /lib/systemd/system/systemd-agent.service
contains the following contents:- [Unit]
- Description=System Daemon
- Wants=network-online.target
- After=network-online.target
- [Service]
- ExecStart=/usr/lib/systemd/systemd-daemon
- Restart=always
- [Install]
- WantedBy=multi-user.target
- /lib/systemd/system/systemd-agent.service
- creates the following autostart script:
- For non-root user:
対応方法
対応検索エンジン: 9.800
初回 VSAPI パターンバージョン 16.800.07
初回 VSAPI パターンリリース日 2021年6月24日
VSAPI OPR パターンバージョン 16.801.00
VSAPI OPR パターンリリース日 2021年6月25日
最新のバージョン(エンジン、パターンファイル)を導入したウイルス対策製品を用い、ウイルス検索を実行してください。「Backdoor.Linux.ROTAJAKIRO.A」と検出したファイルはすべて削除してください。 検出されたファイルが、弊社ウイルス対策製品により既に駆除、隔離またはファイル削除の処理が実行された場合、ウイルスの処理は完了しており、他の削除手順は特にありません。
ご利用はいかがでしたか? アンケートにご協力ください

