GSD-2021-1000051

    Dashboard / Vulnerabilities / GSD-2021-1000051

    GSD-2021-1000051

    Published: 31 May 2021Last Modified: 14 Mar 2023

    Summary: malware in "RotaJakiro" version all

    Details: A new Linux malware labeled "RotaJakiro" has been found for 64bit Linux. When run as a root user the program creates entries in systems to run binaries labeled: /bin/systemd/systemd-daemon /usr/lib/systemd/systemd-daemon When run as a non root user it creates an autostart script$HOME/.config/au-tostart/gnomehelper.desktop to run binaries labeled as: $HOME/.dbus/sessions/session-dbus $HOME/.gvfsd/.profile/gvfsd-helper MD5 hashes of the binaries involved include: MD5:1d45cd2c1283f927940c099b8fab593b MD5:11ad1e9b74b144d564825d65d7fb37d6 MD5:5c0f375e92f551e8f2321b141c15c48f MD5:64f6cfe44ba08b0babdd3904233c4857 The "RotaJakiro" malware interacts with command and control servers at the following domains on port 443, but using a custom protocol: news.thaprior.net:443 blog.eduelects.com:443 cdn.mirror-codes.net:443 status.sublineover.net:443 For more details please see the Qihoo 360 Netlab blog posting.

    Affected packages

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GSD-2021-1000051 | CVE-DB