{"id":"GSD-2021-1000051","summary":"malware in \"RotaJakiro\" version all","details":"A new Linux malware labeled \"RotaJakiro\" has been found for 64bit Linux. When run as a root user  the program creates entries in systems to run binaries labeled:\r\n\r\n/bin/systemd/systemd-daemon\r\n/usr/lib/systemd/systemd-daemon\r\n\r\nWhen run as a non root user it creates an autostart script$HOME/.config/au-tostart/gnomehelper.desktop\r\n\r\nto run binaries labeled as:\r\n\r\n$HOME/.dbus/sessions/session-dbus\r\n$HOME/.gvfsd/.profile/gvfsd-helper\r\n\r\nMD5 hashes of the binaries involved include:\r\n\r\nMD5:1d45cd2c1283f927940c099b8fab593b\r\nMD5:11ad1e9b74b144d564825d65d7fb37d6\r\nMD5:5c0f375e92f551e8f2321b141c15c48f\r\nMD5:64f6cfe44ba08b0babdd3904233c4857\r\n\r\nThe \"RotaJakiro\" malware interacts with command and control servers at the following domains on port 443, but using a custom protocol:\r\n\r\nnews.thaprior.net:443\r\nblog.eduelects.com:443\r\ncdn.mirror-codes.net:443\r\nstatus.sublineover.net:443\r\n\r\nFor more details please see the Qihoo 360 Netlab blog posting.","modified":"2023-03-14T07:04:18.325187Z","published":"2021-05-31T15:39:45.031586Z","withdrawn":"2023-03-14T07:04:18.325187Z","references":[{"type":"WEB","url":"https://www.theregister.com/2021/04/29/stealthy_linux_backdoor_malware_spotted/"},{"type":"WEB","url":"https://blog.netlab.360.com/stealth_rotajakiro_backdoor_en/"},{"type":"WEB","url":"https://news.ycombinator.com/item?id=26981886"}],"schema_version":"1.7.3"}