VIRUS NAME: Linux/Alfa
Virus Characteristics
The Linux/Alfa virus was included inside a virus collector set that was sent to AVERT. The malicious code has not been encountered "in the wild".
Linux/Alfa is not a true virus, it doesn't spread recursively. Basically, there is a dropper file called "a", when run against a target ELF binary file, that file will be infected. During testing, this routine didn't work well unless the target files were specifically renamed to a certain filename - not disclosed here. The modified files didn't spread recursively.
Symptoms
-Modified ELF binary files
Method Of Infection
ELF binary files may get infected when they're manually targeted.
Linux/Alfa doesn't spread recursively.
|