Defend what you create

Other Resources

Close

Library
My library

+ Add to library

Contact us
24/7 Tech support

Send a message

Your tickets

Profile

Linux.BackDoor.Irc.16

Added to Dr.Web virus database:2016-09-05
Virus description was added:2016-09-09

SHA1: 03c1ca6ec8718aa4d4cb6ba041276df421f4450f

A backdoor for Linux written in Rust. The Trojan uses the https://github.com/aatxe/irc library and gets commands over the IRC (Internet Relay Chat) protocol. It can perform the following actions:

Command Value
!login secure2016@ Authorize to send commands to a bot
!sinfo <*|botName> Send data on an infected computer
!processes <*|botName> Send a list of running processes
!kill <*|botName> Terminate operation of a specified bot
!update <*|botName> Not implemented. The “Downloading update right now...” message is displayed.

News about the Trojan

Curing recommendations


Linux

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Free trial

One month (no registration) or three months (registration and renewal discount)

Download Dr.Web

Download by serial number

The Russian developer of Dr.Web anti-viruses

Doctor Web has been developing anti-virus software since 1992

Dr.Web is trusted by users around the world in 200+ countries

The company has delivered an anti-virus as a service since 2007

24/7 tech support

© Doctor Web
2003 — 2018

Doctor Web is the Russian developer of Dr.Web anti-virus software. Dr.Web anti-virus software has been developed since 1992.

2-12А, 3rd street Yamskogo polya, Moscow, Russia, 125040