#rotajakiro

paolo_pedaletti@joindiaspora.com

#RotaJakiro: A long live secret #backdoor with 0 VT detection

https://blog.netlab.360.com/stealth_rotajakiro_backdoor_en/

With the sample we have, we discovered the following 4 samples, all of which have 0 detections on VT, and the earliest First Seen time on VT is in 2018.
FileName MD5 Detection First Seen in VT
systemd-daemon 1d45cd2c1283f927940c099b8fab593b 0/61 2018-05-16 04:22:59
systemd-daemon 11ad1e9b74b144d564825d65d7fb37d6 0/58 2018-12-25 08:02:05
systemd-daemon 5c0f375e92f551e8f2321b141c15c48f 0/56 2020-05-08 05:50:06
gvfsd-helper 64f6cfe44ba08b0babdd3904233c4857 0/61 2021-01-18 13:13:19

Would it have been possible to insert it in a bash script?

#systemd, #malware, #backdoor, #virus, #linux, #KISS,