Skip to content

Add systemd mimicking malware files from stage 2 on linux#40

Open
huzvanec wants to merge 1 commit intoMCRcortex:masterfrom
huzvanec:master
Open

Add systemd mimicking malware files from stage 2 on linux#40
huzvanec wants to merge 1 commit intoMCRcortex:masterfrom
huzvanec:master

Conversation

@huzvanec
Copy link
Copy Markdown

@huzvanec huzvanec commented Jun 8, 2023

According to the fractureiser-investigation there are two additional files that stage 2 creates in paths /etc/systemd/system/systemd-utility.service and ~/.config/systemd/user/systemd-utility.service that try to mimic some kind of systemd utility.

This pull request simply adds the files to the suspiciousFilesFound list when they exist.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant