Content

Linux/Lion.worm

Type
Virus
SubType
Internet Worm
Discovery Date
03/23/2001
Length
Minimum DAT
4131 (03/28/2001)
Updated DAT
5069 (07/06/2007)
Minimum Engine
5.1.00
Description Added
03/23/2001
Description Modified
03/23/2001 6:26 PM (PT)
Risk Assessment
Corporate User
Low
Home User
Low

Tab Navigation

Characteristics

This is an Internet worm that targets servers running Linux operating systems. This worm retrieves a package file from an account on the 51.net domain. This domain is registered in China.

It may be useful to block the IP address 211.100.18.56 to prevent any attempt to communicate to this address.

This Internet worm uses a random port scan and seeks systems which contain a root access vulnerability in the BIND DNS service on Linux servers. Once a target is found, the system is attempted for compromise, and password information is sent to the email address "1i0nsniffer@china.com".

Additional information available at this link.

Symptoms

This Internet worm will attempt to gain root access to Linux Servers. Servers affected contain a version of BIND DNS service which has a vulnerability.

Systems which have been compromised will contain files with the following names:

In the /lib folder:

2-25-01 14:12 8,445 1i0n.sh 2-27-00 9:44 22,460 du 2-27-00 9:44 57,452 find 2-25-01 13:48 929 getip.sh 2-27-00 9:44 32,728 ifconfig 2-27-00 9:44 6,408 in.fingerd 2-27-00 9:44 35,100 in.telnetd 2-27-00 9:44 3,964 login 2-27-00 9:44 39,484 ls 2-27-00 9:44 16,634 mjy 2-27-00 9:44 19,085 name 2-27-00 9:44 53,364 netstat 2-27-00 9:44 4,568 pg 2-27-00 9:44 31,336 ps 2-27-00 9:44 13,184 pstree 2-27-00 9:44 100,424 ssh.tgz 2-27-00 9:44 11,934 sush 2-27-00 9:44 1,441 sz 2-27-00 9:44 7,884 t0rnp 2-27-00 9:44 6,948 t0rns 2-27-00 9:44 1,345 t0rnsb 2-27-00 9:44 33,820 tfn 2-27-00 9:44 266,140 top

In the /scan folder:

2-25-01 16:46 130 1i0n.sh 2-25-01 16:43 19,033 bind 2-25-01 16:45 0 bindname.log 2-20-01 19:21 42 bindx.sh 2-20-01 19:22 92 hack.sh 2-18-01 11:35 15,715 pscan 1-11-01 20:34 12,331 randb 2-20-01 19:22 76 scan.sh 2-20-01 19:23 119 star.sh

This worm will attempt to make Internet connection to a website on the 51.net domain in order to download the file "crew.tgz". It will also attempt to send an email to the email account "1i0nsniffer@china.com".

Method of Infection

This Internet worm attempts to gain root access against Linux servers which also have a vulnerable version of the BIND DNS service.

Once root access is gained, the worm will gather details about the system into a file named "mail.log". The contents of mail.log will include the following:

You owned this one: <- string text ###.###.###.### <- ip address name: XXXXXXX <- uname value network: XXXXXXX <- data from /sbin/ifconfig passwd: XXXXXXX <- data from /etc/passwd shadow: XXXXXXX <- data from /etc/shadow

This log file is then mailed to the email address "1i0nsniffer@china.com".

Removal

Use suggested DAT and engine to detect. Delete files identified by the scanner.

Linux/Lion can hack bind versions 8.2, 8.2-P1, 8.2.1, 8.2.2-Px, and all 8.2.3-betas, according to SANS. Administrators should upgrad the BIND DNS service to avoid being a target of this root attack.

Recommended links:

Redhat Linux - Bind remote exploit

Debian GNU/Linux

Caldera Linux Advisory CSSA-2001-008.0
Caldera Linux Advisory CSSA-2001-008.1

Administrators can prevent it from spreading out of their networks by blocking access to the host coollion.51.net (where the payload is currently stored) and china.com (wherethe e-mail is sent).

Variants

Variants

    N/A

All Information

Overview -

This is a virus detection. Viruses are programs that self-replicate recursively, meaning that infected systems spread the virus to other systems, which then propagate the virus further. While many viruses contain a destructive payload, it's quite common for viruses to do nothing more than spread from one system to another.

Aliases

  • 1ion
  • Linux.Lion.Worm (NAV)
  • Lion worm

Characteristics

Characteristics -

This is an Internet worm that targets servers running Linux operating systems. This worm retrieves a package file from an account on the 51.net domain. This domain is registered in China.

It may be useful to block the IP address 211.100.18.56 to prevent any attempt to communicate to this address.

This Internet worm uses a random port scan and seeks systems which contain a root access vulnerability in the BIND DNS service on Linux servers. Once a target is found, the system is attempted for compromise, and password information is sent to the email address "1i0nsniffer@china.com".

Additional information available at this link.

Symptoms

Symptoms -

This Internet worm will attempt to gain root access to Linux Servers. Servers affected contain a version of BIND DNS service which has a vulnerability.

Systems which have been compromised will contain files with the following names:

In the /lib folder:

2-25-01 14:12 8,445 1i0n.sh 2-27-00 9:44 22,460 du 2-27-00 9:44 57,452 find 2-25-01 13:48 929 getip.sh 2-27-00 9:44 32,728 ifconfig 2-27-00 9:44 6,408 in.fingerd 2-27-00 9:44 35,100 in.telnetd 2-27-00 9:44 3,964 login 2-27-00 9:44 39,484 ls 2-27-00 9:44 16,634 mjy 2-27-00 9:44 19,085 name 2-27-00 9:44 53,364 netstat 2-27-00 9:44 4,568 pg 2-27-00 9:44 31,336 ps 2-27-00 9:44 13,184 pstree 2-27-00 9:44 100,424 ssh.tgz 2-27-00 9:44 11,934 sush 2-27-00 9:44 1,441 sz 2-27-00 9:44 7,884 t0rnp 2-27-00 9:44 6,948 t0rns 2-27-00 9:44 1,345 t0rnsb 2-27-00 9:44 33,820 tfn 2-27-00 9:44 266,140 top

In the /scan folder:

2-25-01 16:46 130 1i0n.sh 2-25-01 16:43 19,033 bind 2-25-01 16:45 0 bindname.log 2-20-01 19:21 42 bindx.sh 2-20-01 19:22 92 hack.sh 2-18-01 11:35 15,715 pscan 1-11-01 20:34 12,331 randb 2-20-01 19:22 76 scan.sh 2-20-01 19:23 119 star.sh

This worm will attempt to make Internet connection to a website on the 51.net domain in order to download the file "crew.tgz". It will also attempt to send an email to the email account "1i0nsniffer@china.com".

Method of Infection

Method of Infection -

This Internet worm attempts to gain root access against Linux servers which also have a vulnerable version of the BIND DNS service.

Once root access is gained, the worm will gather details about the system into a file named "mail.log". The contents of mail.log will include the following:

You owned this one: <- string text ###.###.###.### <- ip address name: XXXXXXX <- uname value network: XXXXXXX <- data from /sbin/ifconfig passwd: XXXXXXX <- data from /etc/passwd shadow: XXXXXXX <- data from /etc/shadow

This log file is then mailed to the email address "1i0nsniffer@china.com".

Removal -

Removal -

Use suggested DAT and engine to detect. Delete files identified by the scanner.

Linux/Lion can hack bind versions 8.2, 8.2-P1, 8.2.1, 8.2.2-Px, and all 8.2.3-betas, according to SANS. Administrators should upgrad the BIND DNS service to avoid being a target of this root attack.

Recommended links:

Redhat Linux - Bind remote exploit

Debian GNU/Linux

Caldera Linux Advisory CSSA-2001-008.0
Caldera Linux Advisory CSSA-2001-008.1

Administrators can prevent it from spreading out of their networks by blocking access to the host coollion.51.net (where the payload is currently stored) and china.com (wherethe e-mail is sent).

Variants

Variants -

    N/A