Library
My library

+ Add to library

Contact us
24/7 Tech support | Rules regarding submitting

Send a message

Your tickets

Profile

Linux.DDoS.374

Added to the Dr.Web virus database: 2020-02-23

Virus description added:

Technical Information

Malicious functions:
Launches itself as a daemon
Kills system processes:
  • sshd
Kills the following processes:
  • systemd
  • run.sh
Network activity:
Awaits incoming connections on ports:
  • 0.0.0.0:8235
Establishes connection:
  • 8.#.8.8:53
  • 45.##.196.75:4859
Attacks using a special dictionary (brute-force technique) via the Telnet protocol.
Sends data to the following servers:
  • 45.##.196.75:4859
  • 15#.##7.220.203:23
  • 15#.##7.218.113:23
  • 15#.##7.243.42:23
  • 15#.##7.246.227:23
  • 15#.##7.117.135:23
  • 15#.##7.27.142:23
  • 15#.##7.252.139:23
  • 15#.##7.4.146:23
  • 15#.##7.51.81:23
  • 15#.##7.84.234:23
  • 15#.##7.151.36:23
  • 15#.##7.116.255:23
  • 15#.##7.205.218:23
  • 15#.#77.12.1:23
  • 15#.##7.88.133:23
  • 15#.##7.137.143:23
  • 15#.#77.31.9:23
  • 15#.##7.245.184:23
  • 15#.##7.114.53:23
  • 15#.##7.197.76:23
  • 15#.#77.5.87:23
  • 15#.#77.9.50:23
  • 15#.##7.211.32:23
  • 15#.##7.21.214:23
  • 15#.##7.171.84:23
  • 15#.##7.99.98:23
  • 15#.##7.166.109:23
  • 15#.##7.185.7:23
  • 15#.##7.227.251:23
  • 15#.##7.132.244:23
  • 15#.##7.166.5:23
  • 15#.##7.155.154:23
  • 15#.##7.251.156:23
  • 15#.##7.58.116:23
  • 15#.##7.41.183:23
  • 15#.##7.204.208:23
  • 15#.##7.255.44:23
  • 15#.##7.124.9:23
  • 15#.##7.233.190:23
  • 15#.##7.141.209:23
  • 15#.##7.28.98:23
  • 15#.##7.164.78:23
  • 15#.##7.125.2:23
  • 15#.##7.251.209:23
  • 15#.##7.175.198:23
  • 15#.##7.208.5:23
  • 15#.##7.128.202:23
  • 15#.##7.45.214:23
  • 15#.##7.182.84:23
  • 15#.##7.9.163:23
  • 15#.##7.101.147:23
  • 15#.##7.165.5:23
  • 15#.##7.248.238:23
  • 15#.##7.197.136:23
  • 15#.##7.111.37:23
  • 15#.##7.25.133:23
  • 15#.##7.206.250:23
  • 15#.##7.183.196:23
  • 15#.##7.14.118:23
  • 15#.##7.71.115:23
  • 15#.##7.85.230:23
  • 15#.##7.24.48:23
  • 15#.##7.68.171:23
  • 15#.##7.128.226:23
  • 15#.##7.179.56:23
  • 15#.##7.102.232:23
  • 15#.##7.218.225:23
  • 15#.##7.233.242:23
  • 15#.##7.169.127:23
  • 15#.##7.171.169:23
  • 15#.##7.226.183:23
  • 15#.##7.59.157:23
  • 15#.##7.5.212:23
  • 15#.##7.216.164:23
  • 15#.##7.133.210:23
  • 15#.##7.69.69:23
  • 15#.##7.67.227:23
  • 15#.##7.13.203:23
  • 15#.#77.2.93:23
  • 15#.##7.249.206:23
  • 15#.##7.163.235:23
  • 15#.##7.16.42:23
  • 15#.##7.123.107:23
  • 15#.##7.47.138:23
  • 15#.##7.237.178:23
  • 15#.##7.252.160:23
  • 15#.##7.252.65:23
  • 15#.##7.143.150:23
  • 15#.#77.1.92:23
  • 15#.##7.5.214:23
  • 15#.##7.192.164:23
  • 15#.##7.46.107:23
  • 15#.##7.157.63:23
  • 15#.##7.94.122:23
  • 15#.##7.186.207:23
  • 15#.##7.101.66:23
  • 15#.##7.30.35:23
  • 15#.##7.120.151:23
  • 15#.##7.186.223:23
  • 15#.##7.201.7:23
  • 15#.##7.69.149:23
  • 15#.##7.15.21:23
  • 15#.##7.100.202:23
  • 15#.##7.139.9:23
  • 15#.##7.171.34:23
  • 15#.##7.56.233:23
  • 15#.##7.72.129:23
  • 15#.##7.7.219:23
  • 15#.##7.112.244:23
  • 15#.##7.137.103:23
  • 15#.##7.49.86:23
  • 15#.##7.221.97:23
  • 15#.##7.130.44:23
  • 15#.##7.148.133:23
  • 15#.##7.7.132:23
  • 15#.##7.96.226:23
  • 15#.##7.87.194:23
  • 15#.##7.41.19:23
  • 15#.##7.231.126:23
  • 15#.##7.94.118:23
  • 15#.##7.33.247:23
  • 15#.##7.124.194:23
  • 15#.##7.71.251:23
  • 15#.##7.222.228:23
  • 15#.##7.166.64:23
  • 15#.##7.82.93:23
Receives data from the following servers:
  • 45.##.196.75:4859

Curing recommendations


Linux

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Free trial

One month (no registration) or three months (registration and renewal discount)

Download Dr.Web

Download by serial number