Library
My library

+ Add to library

Contact us
24/7 Tech support | Rules regarding submitting

Send a message

Your tickets

Profile

Linux.DDoS.353

Added to the Dr.Web virus database: 2020-02-20

Virus description added:

Technical Information

Malicious functions:
Launches itself as a daemon
Kills system processes:
  • sshd
Kills the following processes:
  • systemd
Network activity:
Awaits incoming connections on ports:
  • 0.0.0.0:8235
Establishes connection:
  • 8.#.8.8:53
  • 45.##.196.75:4859
Attacks using a special dictionary (brute-force technique) via the Telnet protocol.
Sends data to the following servers:
  • 45.##.196.75:4859
  • 23#.#67.4.87:23
  • 15#.#5.42.22:23
  • 22.##2.8.86:23
  • 40.###.151.208:23
  • 86.###.198.65:23
  • 14#.##8.161.99:23
  • 52.###.199.164:23
  • 24.###.233.123:23
  • 13#.##.25.255:23
  • 23#.##4.129.77:23
  • 57.###.215.33:23
  • 19#.##4.198.152:23
  • 6.##.218.217:23
  • 21#.##.251.229:23
  • 11#.##.227.110:23
  • 11#.##.166.220:23
  • 19#.##9.58.148:23
  • 20.##9.8.130:23
  • 23#.##0.235.110:23
  • 40.###.12.130:23
  • 15#.##6.82.140:23
  • 19#.##.239.122:23
  • 18#.#47.38.7:23
  • 19#.##7.44.10:23
  • 22#.##7.143.112:23
  • 18.##2.68.69:23
  • 5.###.24.226:23
  • 16#.##.10.217:23
  • 3.###.216.239:23
  • 15#.##8.206.165:23
  • 64.###.154.131:23
  • 18#.##3.32.252:23
  • 20#.##1.132.213:23
  • 27.###.178.223:23
  • 14#.##5.182.134:23
  • 12#.#2.17.80:23
  • 95.##.219.135:23
  • 96.###.206.76:23
  • 16.###.172.70:23
  • 78.###.113.82:23
  • 21#.##1.130.209:23
  • 12.###.39.199:23
  • 24#.##.159.189:23
  • 18#.##.146.170:23
  • 11#.##3.132.128:23
  • 18#.##6.137.180:23
  • 48.###.222.48:23
  • 10#.##3.146.4:23
  • 82.##0.81.96:23
  • 19.###.14.114:23
  • 45.#.188.159:23
  • 2.##.223.188:23
  • 15#.##.246.213:23
  • 33.###.200.222:23
  • 39.##.178.135:23
  • 15#.##.224.130:23
  • 95.##.21.198:23
  • 92.##.247.92:23
  • 16#.##.37.168:23
  • 17.###.206.81:23
  • 56.##.147.174:23
  • 21#.##1.209.69:23
  • 30.###.70.194:23
  • 45.##5.106.1:23
  • 10.#.57.30:23
  • 15#.##3.191.37:23
  • 18#.##2.44.121:23
  • 23#.##.194.234:23
  • 21#.#7.48.4:23
  • 24#.##1.79.76:23
  • 33.###.26.173:23
  • 20#.##7.115.8:23
  • 89.###.71.105:23
  • 6.###.141.47:23
  • 10#.##.125.143:23
  • 77.###.115.66:23
  • 24#.##5.122.126:23
  • 6.##.108.150:23
  • 5.##.120.105:23
  • 14#.##0.154.2:23
  • 17#.##.23.156:23
  • 18#.##.183.230:23
  • 15#.##4.130.18:23
  • 7.###.28.136:23
  • 40.##4.56.24:23
  • 17#.##.122.27:23
  • 92.###.150.46:23
  • 47.##.81.51:23
  • 25#.##.220.224:23
  • 21#.##.127.230:23
  • 96.##.64.140:23
  • 11#.##5.221.69:23
  • 22#.##4.220.99:23
  • 14#.##1.181.19:23
  • 11.###.26.235:23
  • 20#.##.36.230:23
  • 44.###.103.19:23
  • 22#.##4.121.166:23
  • 24#.#.213.177:23
  • 76.##3.55.80:23
  • 18#.##.44.185:23
  • 20#.#.85.204:23
  • 18#.##.134.33:23
  • 10#.##2.96.181:23
  • 19#.##7.239.194:23
  • 24#.##.83.125:23
  • 21#.##.43.239:23
  • 18.##.238.66:23
  • 10#.##.239.222:23
  • 93.##.75.210:23
  • 42.###.27.231:23
  • 12#.##5.16.20:23
  • 21#.##2.57.187:23
  • 10.##.133.113:23
  • 21#.##.170.70:23
  • 77.###.128.63:23
  • 20#.##7.78.101:23
  • 22#.##8.6.121:23
  • 6.##.6.83:23
  • 39.###.118.169:23
  • 28.###.187.66:23
  • 19#.#94.9.77:23
  • 91.##.147.2:23
  • 8.###.132.164:23
  • 15#.##.211.212:23
  • 13#.##.242.189:23
  • 54.###.234.18:23
  • 26.#.233.177:23
  • 26.##.34.142:23
  • 10#.##2.245.213:23
  • 89.##.241.51:23
  • 2.###.42.108:23
  • 35.###.29.112:23
  • 16#.##3.229.122:23
  • 90.##.223.33:23
  • 47.###.68.202:23
  • 21.#.178.70:23
  • 82.###.201.80:23
  • 21#.##1.123.230:23
  • 15#.#.137.4:23
  • 12#.##1.65.217:23
  • 58.#.64.125:23
  • 24#.##6.89.163:23
  • 1.###.69.202:23
  • 13#.#2.81.1:23
  • 6.##.139.142:23
  • 13#.##7.255.74:23
  • 12#.##1.233.59:23
  • 59.##.17.19:23
  • 23#.#0.66.44:23
  • 6.###.251.87:23
  • 12#.##.207.11:23
  • 11#.##.114.239:23
  • 84.##4.95.61:23
  • 22#.##9.81.110:23
Receives data from the following servers:
  • 45.##.196.75:4859

Curing recommendations


Linux

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Free trial

One month (no registration) or three months (registration and renewal discount)

Download Dr.Web

Download by serial number