nekodetector icon indicating copy to clipboard operation
nekodetector copied to clipboard

Add systemd mimicking malware files from stage 2 on linux

Open huzvanec opened this issue 2 years ago • 0 comments

According to the fractureiser-investigation there are two additional files that stage 2 creates in paths /etc/systemd/system/systemd-utility.service and ~/.config/systemd/user/systemd-utility.service that try to mimic some kind of systemd utility.

This pull request simply adds the files to the suspiciousFilesFound list when they exist.

huzvanec avatar Jun 08 '23 12:06 huzvanec