Library
My library

+ Add to library

Contact us
24/7 Tech support | Rules regarding submitting

Send a message

Your tickets

Profile

Linux.Sshdkit.6

Added to the Dr.Web virus database: 2013-06-03

Virus description added:

A modification of Linux.Sshdkit (current version is 1.3.1) designed to steal data stored on servers running Linux. In this version, cybercriminals implemented a modified routine for generation of command and control servers' addresses.

Cybercriminals also changed the command reception algorithm; that is, for command to be successfully executed, the program receives a special string, for which the hash function value is checked.

Cybercriminals use the following command and control servers:

Second-level domainThird-level domain IPModified IP
o8rad5ccx***r.net135.61.**.2474.82.**.14
zbqaf5zcv***x.biz40.11.***.226211.49.***.161
c0dbq5vcj***e.info
x7sbu5hcg***f.net

Curing recommendations


Linux

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Free trial

One month (no registration) or three months (registration and renewal discount)

Download Dr.Web

Download by serial number