Defend what you create

Other Resources

Close

Library
My library

+ Add to library

Contact us
24/7 Tech support | Rules regarding submitting

Send a message

Your tickets

Profile

Linux.Mirai.4852

Added to the Dr.Web virus database: 2020-08-26

Virus description added:

Technical Information

Malicious functions:
Launches itself as a daemon
Network activity:
Awaits incoming connections on ports:
  • 0.0.0.0:23
  • 0.0.0.0:80
Establishes connection:
  • 8.#.8.8:53
Attacks using a special dictionary (brute-force technique) via the Telnet protocol.
Connects to the following servers over the IRC protocol:
  • Server: 18#.#0.68.175; Command: NICK [KEK|MIPS]zCMC\nUSER zCMC localhost localhost :zCMC\n
  • Server: 18#.#0.68.175; Command: PONG :E78CB95B\n
  • Server: 18#.#0.68.175; Command: MODE zCMC -xi\n
  • Server: 18#.#0.68.175; Command: JOIN #donks :swagfag\n
  • Server: 18#.#0.68.175; Command: WHO zCMC\n
Sends data to the following servers:
  • 18#.##4.198.229:23
  • 99.###.208.95:23
  • 40.##1.13.98:23
  • 15#.##3.219.45:23
  • 12#.##6.63.208:23
  • 16#.##.177.88:23
  • 19#.##.90.184:23
  • 17#.##1.29.75:23
  • 91.##.250.251:23
  • 15#.##0.28.61:23
  • 18#.##5.161.225:23
  • 96.#.115.182:23
  • 80.###.139.238:23
  • 16#.##2.200.147:23
  • 15#.#.213.172:23
  • 10#.##.131.172:23
  • 1.###.241.52:23
  • 18#.##2.44.217:23
  • 36.###.37.177:23
  • 13.##.231.115:23
  • 21#.##8.155.195:23
  • 21#.##.46.100:23
  • 12#.##1.134.200:23
  • 14#.##.63.243:23
  • 1.##.218.215:23
  • 92.##.116.166:23
  • 18#.##4.117.60:23
  • 60.###.246.187:23
  • 8.##.109.86:23
  • 17.###.158.156:23
  • 19#.##3.188.157:23
  • 18#.##1.186.73:23
  • 85.##.94.77:23
  • 53.###.252.148:23
  • 38.##1.103.5:23
  • 14#.##.50.182:23
  • 21#.##6.186.240:23
  • 12#.##9.237.234:23
  • 60.###.29.203:23
  • 14#.##.210.168:23
  • 89.###.164.163:23
  • 19#.##3.175.231:23
  • 1.###.165.62:23
  • 12#.##.17.186:23
  • 14#.##0.61.205:23
  • 57.###.116.26:23
  • 20#.#0.14.20:23
  • 11#.##0.239.190:23
  • 15#.##.151.96:23
  • 4.###.92.202:23
  • 50.##.236.214:23
  • 14#.##3.124.210:23
  • 85.##.147.213:23
  • 17#.##1.9.143:23
  • 14#.##.20.213:23
  • 10#.##.229.136:23
  • 37.##.197.248:23
  • 74.##.236.107:23
  • 65.###.171.22:23
  • 97.###.86.110:23
  • 59.##.43.152:23
  • 20#.##.165.29:23
  • 11#.##.135.10:23
  • 17#.##2.249.90:23
  • 53.###.91.176:23
  • 54.###.154.124:23
  • 10#.##8.227.193:23
  • 12.##.87.149:23
  • 82.###.244.105:23
  • 97.##.30.102:23
  • 13#.##1.97.156:23
  • 9.###.77.59:23
  • 60.##.63.86:23
  • 49.###.106.204:23
  • 47.##.219.165:23
  • 34.##.255.47:23
  • 19.###.191.66:23
  • 52.###.105.97:23
  • 17.###.212.99:23
  • 20.###.187.180:23
  • 17#.##9.26.100:23
  • 15#.##9.5.172:23
  • 60.##7.142.9:23
  • 20#.#7.12.68:23
  • 60.##.17.57:23
  • 14#.##4.210.113:23
  • 13#.##6.81.211:23
  • 20#.##.163.120:23
  • 15#.#.173.0:23
  • 97.###.78.207:23
  • 32.##.34.221:23
  • 27.##.239.23:23
  • 85.##.178.116:23
  • 14#.##3.195.113:23
  • 8.###.33.17:23
  • 71.##.249.44:23
  • 14#.##.132.72:23
  • 14#.##.202.212:23
  • 19#.##8.28.139:23
  • 39.##2.4.104:23
  • 21#.##9.245.233:23
  • 52.##.226.245:23
  • 10#.##5.241.228:23
  • 14#.##5.238.27:23
  • 14#.##1.227.87:23
  • 20#.#.170.191:23
  • 11#.##6.211.64:23
  • 21#.##9.218.151:23
  • 81.##.123.104:23
  • 12#.##5.149.95:23

Curing recommendations


Linux

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Free trial

One month (no registration) or three months (registration and renewal discount)

Download Dr.Web

Download by serial number

The Russian developer of Dr.Web anti-viruses
Doctor Web has been developing anti-virus software since 1992
Dr.Web is trusted by users around the world in 200+ countries
The company has delivered an anti-virus as a service since 2007
24/7 tech support

Dr.Web © Doctor Web
2003 — 2020

Doctor Web is the Russian developer of Dr.Web anti-virus software. Dr.Web anti-virus software has been developed since 1992.

2-12А, 3rd street Yamskogo polya, Moscow, Russia, 125124