マイライブラリ
マイライブラリ

+ マイライブラリに追加

電話

お問い合わせ履歴

電話(英語)

+7 (495) 789-45-86

Profile

Linux.DDoS.372

Added to the Dr.Web virus database: 2020-02-23

Virus description added:

Technical Information

Malicious functions:
Launches itself as a daemon
Kills system processes:
  • sshd
Kills the following processes:
  • systemd
Network activity:
Awaits incoming connections on ports:
  • 0.0.0.0:8235
Establishes connection:
  • 8.#.8.8:53
  • 45.##.196.75:4859
Attacks using a special dictionary (brute-force technique) via the Telnet protocol.
Sends data to the following servers:
  • 45.##.196.75:4859
  • 21#.##8.207.149:23
  • 37.##.124.52:23
  • 21#.##5.88.241:23
  • 14#.##.224.92:23
  • 12#.##3.86.114:23
  • 20#.##0.126.199:23
  • 76.##.109.153:23
  • 58.###.198.246:23
  • 15#.#6.62.15:23
  • 17#.##2.145.2:23
  • 43.##.173.161:23
  • 62.###.208.235:23
  • 20#.##2.172.56:23
  • 13#.##.116.33:23
  • 17#.#2.53.11:23
  • 9.###.83.47:23
  • 20#.##7.85.83:23
  • 62.###.185.113:23
  • 20#.##8.68.209:23
  • 38.###.135.116:23
  • 72.#.144.118:23
  • 83.###.173.243:23
  • 4.##.206.103:23
  • 59.###.60.191:23
  • 70.###.57.141:23
  • 14#.##3.142.162:23
  • 20#.##.70.228:23
  • 17.###.138.138:23
  • 7.###.50.3:23
  • 12#.##1.97.93:23
  • 22#.##7.115.243:23
  • 20#.##8.69.190:23
  • 16#.##2.234.117:23
  • 16#.##4.237.133:23
  • 15#.##.249.133:23
  • 11#.#9.20.62:23
  • 25.###.79.144:23
  • 29.##7.86.25:23
  • 15#.#6.4.8:23
  • 20.##6.3.226:23
  • 92.##.121.234:23
  • 13#.##1.111.29:23
  • 60.###.71.171:23
  • 88.###.217.70:23
  • 21#.##.183.104:23
  • 13#.##9.150.39:23
  • 40.###.175.190:23
  • 11#.##3.155.239:23
  • 16#.#5.52.27:23
  • 17#.##0.98.86:23
  • 10#.##.178.155:23
  • 92.##.18.206:23
  • 15#.#4.12.88:23
  • 12#.##.144.111:23
  • 8.###.209.82:23
  • 22.##.114.31:23
  • 12#.##.66.102:23
  • 12#.##.189.100:23
  • 84.###.129.17:23
  • 16#.#4.26.35:23
  • 43.###.91.137:23
  • 20#.##1.57.20:23
  • 77.###.176.152:23
  • 10#.##6.102.142:23
  • 15#.##.160.70:23
  • 21.###.20.208:23
  • 15#.##.185.49:23
  • 30.###.66.238:23
  • 13#.##2.48.198:23
  • 19.###.183.155:23
  • 14#.##.85.203:23
  • 24.##.145.97:23
  • 21#.#.149.109:23
  • 40.##5.25.57:23
  • 12#.##.227.57:23
  • 12#.#2.81.35:23
  • 81.#.110.92:23
  • 21#.##.159.125:23
  • 21#.##4.118.172:23
  • 77.###.167.171:23
  • 11#.##5.45.44:23
  • 16.###.190.218:23
  • 10#.##8.63.140:23
  • 15#.##9.122.157:23
  • 20#.#.237.53:23
  • 15#.##7.57.128:23
  • 15#.##2.122.204:23
  • 12#.##6.214.147:23
  • 18#.##3.133.95:23
  • 16#.##.153.137:23
  • 11#.##1.28.107:23
  • 13#.##8.230.247:23
  • 45.##.124.156:23
  • 17#.##7.87.233:23
  • 16#.#3.15.40:23
  • 14#.##.39.123:23
  • 91.###.209.127:23
  • 13#.##2.91.51:23
  • 18#.##6.192.198:23
  • 20.###.123.27:23
  • 16#.#25.19.8:23
  • 18#.##.149.131:23
  • 13#.##0.163.105:23
  • 82.###.210.213:23
  • 14#.##8.192.212:23
  • 52.##.56.200:23
  • 81.##.194.249:23
  • 10#.##.185.160:23
  • 14#.##2.238.79:23
  • 96.###.196.243:23
  • 97.##.129.163:23
  • 12#.#99.86.3:23
  • 24.##4.90.82:23
  • 18#.##.209.212:23
  • 20#.##.213.204:23
  • 18#.##9.22.241:23
  • 12#.##4.111.11:23
  • 21#.##2.159.152:23
  • 78.###.196.246:23
  • 20#.##6.69.221:23
  • 15#.##8.118.78:23
  • 16#.##8.110.27:23
  • 11#.##4.43.75:23
  • 61.##7.36.57:23
  • 10#.##7.75.224:23
  • 89.###.37.252:23
  • 19#.##1.98.29:23
  • 24.###.25.213:23
  • 69.###.136.103:23
  • 10#.##2.35.121:23
  • 15#.#.28.223:23
  • 18#.##.126.155:23
  • 10#.##6.94.190:23
  • 45.##.253.235:23
  • 68.##.204.114:23
  • 10#.##3.220.58:23
  • 18#.##.166.134:23
  • 19#.#93.1.54:23
  • 18.##.244.120:23
  • 53.###.27.132:23
  • 54.###.74.174:23
  • 19#.##3.11.151:23
  • 16#.##6.15.36:23
  • 72.###.144.103:23
  • 15#.##5.29.55:23
  • 16#.##.127.102:23
  • 55.##.82.35:23
  • 51.##.217.151:23
  • 59.###.16.102:23
  • 53.###.184.105:23
  • 40.##.48.100:23
  • 20#.##2.49.247:23
  • 21#.##5.176.1:23
  • 50.##9.4.107:23
  • 16#.##0.8.255:23
  • 60.###.147.11:23
  • 11#.##6.121.53:23
  • 13#.##1.24.222:23
  • 21#.##7.72.207:23
  • 15#.##.29.216:23
  • 16.#.76.184:23
  • 16#.##.204.57:23
  • 58.###.167.254:23
  • 16#.#0.8.73:23
  • 96.##8.63.9:23
  • 17#.##1.194.19:23
  • 16#.##.164.184:23
  • 15#.##.105.209:23
  • 16#.##.246.234:23
  • 21#.#9.68.5:23
  • 53.###.246.217:23
  • 67.##.183.46:23
  • 15#.##4.165.1:23
  • 18#.##8.219.44:23
  • 68.##.210.136:23
  • 71.##.181.189:23
  • 11#.#5.17.48:23
  • 13#.##.167.174:23
  • 12#.##3.136.58:23
  • 71.###.84.217:23
  • 32.##.216.192:23
  • 16#.##9.85.52:23
  • 90.###.201.130:23
  • 22#.##.142.103:23
  • 17#.##9.64.134:23
  • 15#.##3.89.120:23
  • 17#.##4.248.8:23
  • 66.###.108.13:23
  • 9.###.64.23:23
  • 21#.##.76.147:23
  • 19#.##6.241.157:23
  • 20#.##7.92.197:23
  • 52.###.41.160:23
  • 54.###.50.118:23
  • 15#.##.150.226:23
  • 17#.##1.215.34:23
  • 11#.##7.89.82:23
  • 21#.##.125.12:23
  • 19#.##5.169.19:23
Receives data from the following servers:
  • 45.##.196.75:4859

Curing recommendations


Linux

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Free trial

One month (no registration) or three months (registration and renewal discount)

Download Dr.Web

Download by serial number