Library
My library

+ Add to library

Contact us
24/7 Tech support | Rules regarding submitting

Send a message

Your tickets

Profile

Linux.DDoS.358

Added to the Dr.Web virus database: 2020-02-21

Virus description added:

Technical Information

Malicious functions:
Launches itself as a daemon
Kills system processes:
  • sshd
Kills the following processes:
  • systemd
Network activity:
Awaits incoming connections on ports:
  • 0.0.0.0:8235
Establishes connection:
  • 8.#.8.8:53
  • 45.##.196.75:4859
Attacks using a special dictionary (brute-force technique) via the Telnet protocol.
Sends data to the following servers:
  • 45.##.196.75:4859
  • 17#.##0.255.98:23
  • 96.###.74.132:23
  • 15#.##9.64.248:23
  • 23#.##.188.167:23
  • 60.###.210.45:23
  • 23#.##1.249.117:23
  • 79.##.2.34:23
  • 17#.##7.125.68:23
  • 16.###.161.145:23
  • 35.##.177.61:23
  • 94.###.187.164:23
  • 80.###.232.90:23
  • 87.###.186.232:23
  • 44.###.152.229:23
  • 24#.##6.130.32:23
  • 26.##9.74.27:23
  • 15#.##.133.105:23
  • 92.###.37.117:23
  • 19#.##.224.110:23
  • 95.##.173.232:23
  • 39.##.232.33:23
  • 10#.##5.124.54:23
  • 22#.##9.161.230:23
  • 43.##.231.206:23
  • 42.###.77.137:23
  • 21#.##3.160.254:23
  • 17#.##.49.150:23
  • 10#.##0.253.224:23
  • 20#.#6.9.239:23
  • 65.##.106.40:23
  • 16#.##8.247.237:23
  • 11#.##.64.148:23
  • 14.##.225.62:23
  • 16#.##.216.35:23
  • 16.###.69.151:23
  • 23#.##.123.213:23
  • 22#.##8.205.88:23
  • 16#.##.33.101:23
  • 22#.##4.33.190:23
  • 11#.##7.82.207:23
  • 21#.##.120.24:23
  • 21#.##1.203.210:23
  • 20#.##0.206.150:23
  • 48.##.215.80:23
  • 54.###.146.214:23
  • 19#.##4.204.146:23
  • 82.###.121.73:23
  • 23#.##.127.56:23
  • 21#.#.39.37:23
  • 17#.#4.82.8:23
  • 11#.##9.206.131:23
  • 18#.##5.222.2:23
  • 24#.##.185.114:23
  • 53.###.188.180:23
  • 47.###.150.85:23
  • 17#.##3.131.125:23
  • 38.###.73.243:23
  • 91.##.179.57:23
  • 8.##.252.65:23
  • 24.###.128.83:23
  • 22.##9.52.43:23
  • 22#.##4.217.101:23
  • 10#.##8.65.173:23
  • 17#.#.165.100:23
  • 20#.##4.241.75:23
  • 21.##.32.148:23
  • 19#.##.53.122:23
  • 13#.##.168.226:23
  • 12#.#1.74.59:23
  • 71.###.123.235:23
  • 18#.##.184.173:23
  • 98.##.102.1:23
  • 26.###.253.206:23
  • 20#.##.30.120:23
  • 22#.##4.255.39:23
  • 11#.##6.150.237:23
  • 10#.##.144.28:23
  • 14#.##2.149.249:23
  • 23#.##6.69.101:23
  • 6.##.55.162:23
  • 23#.##7.157.109:23
  • 73.###.18.222:23
  • 10#.##3.117.120:23
  • 20#.##.89.221:23
  • 86.###.23.154:23
  • 11#.##9.95.44:23
  • 13#.#7.64.39:23
  • 10#.##1.230.246:23
  • 51.##.142.39:23
  • 23#.##1.98.193:23
  • 22#.##.17.251:23
  • 18#.##1.207.25:23
  • 14#.##.182.79:23
  • 18#.##0.181.163:23
  • 2.##.136.15:23
  • 22#.##7.233.63:23
  • 18#.#7.79.68:23
  • 12#.##4.16.78:23
  • 17#.##.184.225:23
  • 25#.##8.222.180:23
  • 8.###.21.15:23
  • 15.###.58.119:23
  • 11#.#3.78.65:23
  • 10#.##1.109.124:23
  • 3.###.232.58:23
  • 19.##.38.241:23
  • 23#.##0.160.122:23
  • 99.#.242.28:23
  • 15#.##.42.234:23
  • 15#.##.13.132:23
  • 24.#.121.255:23
  • 12#.##5.119.166:23
  • 22#.##.122.130:23
  • 1.###.14.114:23
  • 12.###.140.53:23
  • 89.###.77.228:23
  • 31.###.213.151:23
  • 14#.##1.12.11:23
  • 13.###.200.134:23
  • 77.#.208.90:23
  • 20#.##1.5.218:23
  • 25#.##.229.199:23
  • 53.##9.19.10:23
  • 14#.##.18.152:23
  • 20#.##4.18.21:23
  • 12#.##.175.205:23
  • 39.###.31.170:23
  • 56.###.40.156:23
  • 63.###.207.208:23
  • 74.##.117.91:23
  • 27.###.152.171:23
  • 66.##.157.112:23
  • 86.###.17.243:23
  • 13#.##.100.44:23
  • 78.###.150.30:23
  • 23#.##0.23.227:23
  • 11.###.233.34:23
  • 37.##.209.65:23
  • 70.###.232.86:23
  • 16#.##.53.138:23
  • 25#.##6.112.144:23
  • 17#.##4.91.64:23
  • 28.##.96.132:23
  • 13#.#1.77.89:23
  • 15#.#1.127.7:23
  • 10.###.78.189:23
  • 21#.##3.15.68:23
  • 13#.##9.70.93:23
  • 16#.##8.118.7:23
  • 96.##.164.173:23
  • 14#.#03.5.12:23
  • 24#.##8.253.70:23
  • 18#.##3.8.194:23
  • 20#.##.72.147:23
  • 11#.##5.153.104:23
  • 21.##0.76.57:23
  • 17#.##7.191.181:23
  • 14#.##.228.141:23
  • 53.###.138.188:23
  • 22#.##.72.172:23
  • 10#.##.212.129:23
  • 19.###.206.221:23
  • 19#.##3.145.1:23
  • 22#.##.239.69:23
  • 97.###.220.106:23
  • 96.##6.61.39:23
  • 88.##.25.171:23
  • 15#.##.163.236:23
  • 24#.#6.169.1:23
  • 10#.##.188.219:23
  • 21#.##.158.180:23
  • 20#.##7.243.15:23
  • 11#.##9.199.134:23
  • 86.###.77.248:23
  • 23#.##4.189.143:23
  • 10#.##3.201.38:23
  • 23#.##2.17.140:23
  • 18#.##.66.169:23
  • 12#.##0.208.192:23
  • 22#.##9.63.45:23
  • 78.##.117.138:23
  • 93.###.28.166:23
  • 24#.##8.20.129:23
  • 19#.##.124.132:23
  • 10#.##4.243.55:23
  • 14#.##0.211.76:23
  • 22#.##3.85.212:23
  • 24#.#0.21.18:23
  • 44.###.234.64:23
  • 13#.##0.183.5:23
  • 22.###.131.136:23
  • 19#.#3.54.20:23
Receives data from the following servers:
  • 45.##.196.75:4859

Curing recommendations


Linux

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Free trial

One month (no registration) or three months (registration and renewal discount)

Download Dr.Web

Download by serial number