Library
My library

+ Add to library

Contact us
24/7 Tech support | Rules regarding submitting

Send a message

Your tickets

Profile

Linux.Mirai.4309

Added to the Dr.Web virus database: 2020-04-28

Virus description added:

Technical Information

Malicious functions:
Removes itself
Launches itself as a daemon
Substitutes application name for:
  • pewphjzt3u1xteof3raf
  • scoxnrovh4qmqqq1lw1ngaxg
  • wg0rsq4wzhdxwh2fu4wa
  • di2q1pvzwcesjhaacomd5
  • bidklowrkl55uz01ctbz
  • iiwpfwtnaejfivtym12x0aai
  • 12vclxw43hcs331a5ctafkx
  • wb3vihihncjoc34z5y3e
  • 2ldpb2npjou01k2vplxerqv
  • z3eowxmlhucg1wibh5ulyg
  • r1egjhp1ck3hk51qlfmgrhg
  • nkqawo05uqpmxyuvqf5udo
  • mjkwn0q1qdptxfcdf3h1g
  • n0uh5ynjakqqtjaab02y
  • vpo2crydi3vx5fu2bie1aokt
  • rkn1y5wwwwtw4ifmww0ghpi
  • 4pqao5ddrjwpvyfwtdufz5w0
  • hsk00sfe4fxdx3uiqaukzb1
  • pnnyt3a4rnc0nnqmpdyjcs
  • jzrjpxzzeaucblnuy3m1
  • v4ym4zrfuzgdei5t0bcaedl
  • qnpzmkwj0qxyctnunno432iu
  • zas1txvdhpzyqmvdwkxgkzc
  • ukxl4aheyjav3rabknyjbwd1
  • vlebqfdwopy0lig4h0gup
  • czyyvzbki524d5z5gzs45eb2
  • idnfjgnttokbxikrdonwtlhp
  • hmahoybo2mnsytjinqgr3pgp
  • wim45w23mwaodfmf55vfc1
  • gj3cn3ruij5nlydxl4d2t
  • qznmxigqs0bzqv2s4x4otlpf
  • erlxaw03rfjhfyjm4byigr
Performs operations with the file system:
Creates or modifies files:
  • <SAMPLE_FULL_PATH>
Network activity:
Awaits incoming connections on ports:
  • 19#.##8.216.50:3467
Establishes connection:
  • 8.#.8.8:53
  • 5.###.227.18:4321
  • 5.###.227.18:7685

Curing recommendations


Linux

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Free trial

One month (no registration) or three months (registration and renewal discount)

Download Dr.Web

Download by serial number