Техническая информация
- /var/spool/cron/crontabs/root
- /root/.ssh/authorized_keys
- sleep 1
- rm -rf /.tempo
- crontab -r
- grep -q updat3
- chattr -R -iajtdu /var/tmp/.logs/.xmr
- chattr -R -iajtdu /var/spool/cron/crontabs
- cat /var/tmp/.logs/.xmr
- pgrep -x xmrig
- /usr/bin/mawk awk {print $1}
- chattr -iajtdu /root
- rm -rf /var/tmp/.logs/.xmr
- id -u
- mkdir /root/.ssh/
- chmod 600 /root/.ssh/authorized_keys
- <0x7c>
- crontab /.tempo
- chattr +ia /root/.ssh/authorized_keys
- sha256sum /xmrig
- crontab -l
- chattr -R -iajtdu /root/.ssh
- <SAMPLE_FULL_PATH> -c exec \x27<SAMPLE_FULL_PATH>\x27 \x22$@\x22 <SAMPLE_FULL_PATH>
- /root/.ssh/authorized_keys
- /var/spool/cron/crontabs/tmp.HxNlQX
- /root/.ssh
- /.tempo
- /var/spool/cron/crontabs/tmp.HxNlQX
- /.tempo
- /var/spool/cron/crontabs/root
- /var/spool/cron/crontabs