My library

+ Add to library

Contact us
24/7 Tech support | Rules regarding submitting

Send a message

Your tickets



Added to the Dr.Web virus database: 2015-05-08

Virus description added:

SHA1: c357fbcf428b07970f7a2ab26823336c5ff51f5c

A Trojan for Linux designed to mount DDoS attacks. Due to the fact that it is compatible with Linux distribution packages for ARM and MIPS processors, this program is very likely to be intended for routers.

The Trojan can execute the following commands:

SSYNSpoofed SYN Flood
HTTPHTTP Flood (GET requests)
DNSQAttack on a DNS server using requests for domain addresses
DNSLAttack on a DNS server using requests for domain addresses
STOPTerminate a DDoS attack

The HULK command triggers HTTP Flood with GET requests; at that, the Trojan will disguise itself as Baidu spider.

"GET %s HTTP/1.1\r\n"
"Accept: */*\r\n"
"Accept-Encoding: gzip, deflate\r\n"
"User-Agent: Mozilla/5.0+(compatible;+Baiduspider/2.0;++http:/"
"Host: %s:%d\r\n"
"Cache-Control: no-cache\r\n"
"Pragma: no-cache\r\n"
"Connection: Keep-Alive\r\n"
"Keep-Alive: %d\r\n"

The RAND command triggers HTTP Flood with GET requests; at that, a package will be generated. It can look as follows:

"GET %s?%d=%d HTTP/1.1\r\n"
"Accept: */*\r\n"
"Accept-Language: zh-cn\r\n"
"Accept-Encoding: gzip, deflate\r\n"
"User-Agent: Mozilla/5.0+(compatible;+Baiduspider/2.0;++\r\n"
"Host: %s\r\n"
"X-Forwarded-For: %d.%d.%d.%d\r\n"
"Connection: Keep-Alive\r\n"

A randomly generated IP address is taken as a value for X-Forwarded-For.

The difference between DNSQ и DNSL lies in the way requests are generated—that is, to execute the DNSQ command, the Trojan generates packages by itself, while to create requests for the DNSL command execution, library functions are used.

Curing recommendations


After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Free trial

One month (no registration) or three months (registration and renewal discount)

Download Dr.Web

Download by serial number