RotaJakiro ืื™ื– ืึท ื ื™ื™ึทืข ืœื™ื ื•ืงืก ืžืึทืœื•ื•ืึทืจืข ื•ื•ืึธืก ืื™ื– ืžืึทืกื™ื•ื• ื•ื•ื™ ืึท ืกื™ืกื˜ืขื ืคึผืจืึธืฆืขืก

ืคืึธืจืฉื•ื ื’ ืœืึทื‘ืึธืจืึทื˜ืึธืจื™ืข 360 Netlab ื”ืึธื˜ ื’ืขืžืืœื“ืŸ ื“ื™ ืœืขื’ื™ื˜ื™ืžืึทืฆื™ืข ืคื•ืŸ โ€‹โ€‹ื ื™ื™ึทืข ืžืึทืœื•ื•ืึทืจืข ืคึฟืึทืจ ืœื™ื ื•ืงืก, ืงืึธื“ืขื ืึทืžืขื“ ืจืึธื˜ืึทื“ื–ืฉืึทืงื™ืจืึธ ืื•ืŸ ืึทืจื™ื™ึทื ื’ืขืจืขื›ื ื˜ ื“ื™ ื™ืžืคึผืœืึทืžืขื ื˜ื™ื™ืฉืึทืŸ ืคื•ืŸ ืึท ื‘ืึทืงื“ืึธืจ ื•ื•ืึธืก ืึทืœืึทื•ื– ืื™ืจ ืฆื• ืงืึธื ื˜ืจืึธืœื™ืจืŸ ื“ื™ ืกื™ืกื˜ืขื. ื“ื™ ืžืึทืœื•ื•ืึทืจืข ืงืขืŸ ื–ื™ื™ืŸ ืื™ื ืกื˜ืึทืœื™ืจืŸ ื“ื•ืจืš ืึทื˜ืึทืงืขืจื– ื ืึธืš ืขืงืกืคึผืœื•ื™ื˜ื™ื ื’ ืึทื ืคึผืึทื˜ืฉื˜ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ืื™ืŸ ื“ื™ ืกื™ืกื˜ืขื ืึธื“ืขืจ ื’ืขืกื™ื ื’ ืฉื•ื•ืึทืš ืคึผืึทืกื•ื•ืขืจื“ื–.

ื“ื™ ื‘ืึทืงื“ืึธืจ ืื™ื– ื“ื™ืกืงืึทื•ื•ืขืจื“ ื‘ืขืฉืึทืก ื“ื™ ืึทื ืึทืœื™ืกื™ืก ืคื•ืŸ ืกืึทืกืคึผื™ืฉืึทืก ืคืึทืจืงืขืจ ืคื•ืŸ ืื™ื™ื ืขืจ ืคื•ืŸ ื“ื™ ืกื™ืกื˜ืขื ืคึผืจืึทืกืขืกืึทื–, ื™ื™ื“ืขื ืึทืคื™ื™ื“ ื‘ืขืฉืึทืก ืึทื ืึทืœื™ืกื™ืก ืคื•ืŸ ื“ื™ ืกื˜ืจื•ืงื˜ื•ืจ ืคื•ืŸ ื“ื™ ื‘ืึธื˜ื ืขื˜ ื’ืขื ื™ืฆื˜ ืคึฟืึทืจ ื“ื™ DDoS ื‘ืึทืคืึทืœืŸ. ืื™ื™ื“ืขืจ ื“ืขื, RotaJakiro ืื™ื– ื’ืขื‘ืœื™ื‘ืŸ ืึทื ื“ื™ื˜ืขืงื˜ื™ื“ ืคึฟืึทืจ ื“ืจื™ื™ ื™ืึธืจ; ืื™ืŸ ื‘ืึทื–ื•ื ื“ืขืจ, ื“ื™ ืขืจืฉื˜ืขืจ ืคืจื•ื•ื•ืŸ ืฆื• ื™ื‘ืขืจืงื•ืงืŸ ื˜ืขืงืขืก ืžื™ื˜ MD5 ื”ืึทืฉืขืก ื•ื•ืึธืก ืจื™ื›ื˜ืŸ ื–ื™ืš ืžื™ื˜ ื“ื™ ื™ื™ื“ืขื ืึทืคื™ื™ื“ ืžืึทืœื•ื•ืึทืจืข ืื™ืŸ ื“ื™ VirusTotal ืกืขืจื•ื•ื™ืก ื–ืขื ืขืŸ ื“ื™ื™ื˜ื™ื“ ืžืื™ 2018.

ืื™ื™ื ืขืจ ืคื•ืŸ ื“ื™ ืคึฟืขื™ึดืงื™ื™ื˜ืŸ ืคื•ืŸ RotaJakiro ืื™ื– ื“ื™ ื ื•ืฆืŸ ืคื•ืŸ ืคืึทืจืฉื™ื“ืขื ืข ืงืึทืžืึทืคืœืึทื–ืฉ ื˜ืขืงื ื™ืงืก ื•ื•ืขืŸ ืคืœื™ืกื ื“ื™ืง ื•ื•ื™ ืึท ืึทื ืคึผืจื™ื•ื•ื™ืœื™ื“ื–ืฉื“ ื‘ืึทื ื™ืฆืขืจ ืื•ืŸ ื•ื•ืึธืจืฆืœ. ืฆื• ื‘ืึทื”ืึทืœื˜ืŸ ื–ื™ื™ืŸ ื‘ื™ื™ึทื–ื™ื™ึทืŸ, ื“ื™ ื‘ืึทืงื“ืึธืจ ื’ืขื ื™ืฆื˜ ื“ื™ ืคึผืจืึธืฆืขืก ื ืขืžืขืŸ systemd-daemon, session-dbus ืื•ืŸ gvfsd-helper, ื•ื•ืึธืก, ื’ืขื’ืขื‘ืŸ ื“ื™ ืงืœืึทื˜ืขืจ ืคื•ืŸ ืžืึธื“ืขืจืŸ ืœื™ื ื•ืงืก ื“ื™ืกื˜ืจื™ื‘ื™ื•ืฉืึทื ื– ืžื™ื˜ ืึทืœืข ืกืึธืจืฅ ืคื•ืŸ ืกืขืจื•ื•ื™ืก ืคึผืจืึทืกืขืกืึทื–, ืื™ืŸ ืขืจืฉื˜ืขืจ ื‘ืœื™ืง ื’ืขื•ื•ืขืŸ ืœืึทื“ื–ืฉื™ื˜ืึทืžืึทื˜ ืื•ืŸ ื”ืื˜ ื ื™ืฉื˜ ื“ืขืจื•ื•ืขืงืŸ ืงื™ื™ืŸ ื—ืฉื“.

ื•ื•ืขืŸ ืœื•ื™ืคืŸ ืžื™ื˜ ื•ื•ืึธืจืฆืœ ืจืขื›ื˜, ื“ื™ ืกืงืจื™ืคึผืก /etc/init/systemd-agent.conf ืื•ืŸ /lib/systemd/system/sys-temd-agent.service ื–ืขื ืขืŸ ื‘ืืฉืืคืŸ ืฆื• ืึทืงื˜ืึทื•ื•ื™ื™ื˜ ื“ื™ ืžืึทืœื•ื•ืึทืจืข, ืื•ืŸ ื“ื™ ื‘ื™ื™ื–ืข ืขืงืกืขืงื•ื˜ืึทื‘ืœืข ื˜ืขืงืข ื–ื™ืš ืื™ื– ื’ืขื•ื•ืขืŸ ืœื™ื’ืŸ ื•ื•ื™ / bin/systemd/systemd -daemon ืื•ืŸ /usr/lib/systemd/systemd-daemon (ืคืึทื ื’ืงืฉืึทื ืึทืœื™ื˜ื™ ืื™ื– ื’ืขื•ื•ืขืŸ ื“ื•ืคึผืœื™ืงื™ื™ื˜ื™ื“ ืื™ืŸ ืฆื•ื•ื™ื™ ื˜ืขืงืขืก). ื•ื•ืขืŸ ืคืœื™ืกื ื“ื™ืง ื•ื•ื™ ืึท ื ืึธืจืžืึทืœ ื‘ืึทื ื™ืฆืขืจ, ื“ื™ ืึทื•ื˜ืึธืกื˜ืึทืจื˜ ื˜ืขืงืข $HOME/.config/au-tostart/gnomehelper.desktop ืื™ื– ื’ืขื ื™ืฆื˜ ืื•ืŸ ืขื ื“ืขืจื•ื ื’ืขืŸ ื–ืขื ืขืŸ ื’ืขืžืื›ื˜ ืฆื• .ื‘ืึทืฉืจืง, ืื•ืŸ ื“ื™ ืขืงืกืขืงื•ื˜ืึทื‘ืœืข ื˜ืขืงืข ืื™ื– ื’ืขืจืื˜ืขื•ื•ืขื˜ ื•ื•ื™ $HOME/.gvfsd/.profile/gvfsd -ื”ืขืœืคืขืจ ืื•ืŸ $HOME/ .dbus/sessions/session-dbus. ื‘ื™ื™ื“ืข ืขืงืกืขืงื•ื˜ืึทื‘ืœืข ื˜ืขืงืขืก ื–ืขื ืขืŸ ืœืึธื ื˜ืฉื˜ ืกื™ื™ืžืึทืœื˜ื™ื™ื ื™ืึทืกืœื™, ื™ืขื“ืขืจ ืคื•ืŸ ื•ื•ืึธืก ืžืึธื ื™ื˜ืึธืจืขื“ ื“ื™ ื‘ื™ื™ึทื–ื™ื™ึทืŸ ืคื•ืŸ ื“ื™ ืื ื“ืขืจืข ืื•ืŸ ื’ืขื–ื•ื ื˜ ืขืก ืื•ื™ื‘ ืขืก ื˜ืขืจืžืึทื ื™ื™ื˜ื™ื“.

ืฆื• ื‘ืึทื”ืึทืœื˜ืŸ ื“ื™ ืจืขื–ื•ืœื˜ืึทื˜ืŸ ืคื•ืŸ ื–ื™ื™ืขืจ ืึทืงื˜ื™ื•ื•ื™ื˜ืขื˜ืŸ ืื™ืŸ ื“ื™ ื‘ืึทืงื“ืึธืจ, ืขื˜ืœืขื›ืข ืขื ืงืจื™ืคึผืฉืึทืŸ ืึทืœื’ืขืจื™ื“ืึทืžื– ื–ืขื ืขืŸ ื’ืขื ื™ืฆื˜, ืœืžืฉืœ, AES ืื™ื– ื’ืขื ื™ืฆื˜ ืฆื• ื™ื ืงืจื™ืคึผื˜ ื–ื™ื™ืขืจ ืจืขืกื•ืจืกืŸ, ืื•ืŸ ืึท ืงืึธืžื‘ื™ื ืึทืฆื™ืข ืคื•ืŸ โ€‹โ€‹โ€‹โ€‹AES, XOR ืื•ืŸ ROTATE ืื™ืŸ ืงืึธืžื‘ื™ื ืึทืฆื™ืข ืžื™ื˜ ืงืึทืžืคึผืจืขืฉืึทืŸ ื ื™ืฆืŸ ZLIB ืื™ื– ื’ืขื ื™ืฆื˜ ืฆื• ื‘ืึทื”ืึทืœื˜ืŸ ื“ื™ ืงืึธืžื•ื ื™ืงืึทืฆื™ืข ืงืึทื ืึทืœ. ืžื™ื˜ ื“ื™ ืงืึธื ื˜ืจืึธืœ ืกืขืจื•ื•ืขืจ.

ืฆื• ื‘ืึทืงื•ืžืขืŸ ืงืึธื ื˜ืจืึธืœ ืงืึทืžืึทื ื“ื–, ื“ื™ ืžืึทืœื•ื•ืึทืจืข ืงืึธื ื˜ืึทืงื˜ืขื“ 4 ื“ืึธื•ืžื™ื™ื ื– ื“ื•ืจืš ื ืขืฅ ืคึผืึธืจื˜ 443 (ื“ืขืจ ืงืึธืžื•ื ื™ืงืึทืฆื™ืข ืงืึทื ืึทืœ ื’ืขื ื™ืฆื˜ ื–ื™ื™ืŸ ืื™ื™ื’ืขื ืข ืคึผืจืึธื˜ืึธืงืึธืœ, ื ื™ืฉื˜ HTTPS ืื•ืŸ TLS). ื“ื™ ื“ืึธื•ืžื™ื™ื ื– (cdn.mirror-codes.net, status.sublineover.net, blog.eduelects.com ืื•ืŸ news.thaprior.net) ื–ืขื ืขืŸ ืจืขื’ื™ืกื˜ืจื™ืจื˜ ืื™ืŸ 2015 ืื•ืŸ ื›ืึธื•ืกื˜ื™ื“ ื“ื•ืจืš ื“ื™ ืงื™ื™ื•ื• ื”ืึธืกื˜ื™ื ื’ ืฉืคึผื™ื™ึทื–ืขืจ Deltahost. 12 ื™ืงืขืจื“ื™ืง ืคืึทื ื’ืงืฉืึทื ื– ื–ืขื ืขืŸ ื™ื ืึทื’ืจื™ื™ื˜ื™ื“ ืื™ืŸ ื“ื™ ื‘ืึทืงื“ืึธืจ, ื•ื•ืึธืก ืขืจืœื•ื™ื‘ื˜ ืœืึธื•ื“ื™ื ื’ ืื•ืŸ ืขืงืกืึทืงื™ื•ื˜ื™ื ื’ ืคึผืœื•ื’ื™ื ืก ืžื™ื˜ ืึทื•ื•ืึทื ืกื™ืจื˜ืข ืคืึทื ื’ืงืฉืึทื ืึทืœื™ื˜ื™, ื˜ืจืึทื ืกืžื™ื˜ื™ื ื’ ืžื™ื˜ืœ ื“ืึทื˜ืŸ, ื™ื ื˜ืขืจืกืขืคึผื˜ื™ื ื’ ืฉืคึผื™ืจืขื•ื•ื“ื™ืง ื“ืึทื˜ืŸ ืื•ืŸ ืึธื ืคื™ืจื•ื ื’ ื”ื™ื’ืข ื˜ืขืงืขืก.

ืžืงื•ืจ: opennet.ru

ืœื™ื™ื’ืŸ ืึท ื‘ืึทืžืขืจืงื•ื ื’