Bibliothèque
Ma bibliothèque

+ Ajouter à la bibliothèque

Contacter-nous !
Support 24/24 | Rules regarding submitting

Nous téléphoner

0 825 300 230

Forum

Vos requêtes

  • Toutes : -
  • Non clôturées : -
  • Dernière : le -

Nous téléphoner

0 825 300 230

Profil

Linux.Kluh.1

Added to the Dr.Web virus database: 2015-05-08

Virus description added:

SHA1: c357fbcf428b07970f7a2ab26823336c5ff51f5c

A Trojan for Linux designed to mount DDoS attacks. Due to the fact that it is compatible with Linux distribution packages for ARM and MIPS processors, this program is very likely to be intended for routers.

The Trojan can execute the following commands:

CmdCommand
HULKHTTP Flood
RANDHTTP Flood
SSYNSpoofed SYN Flood
HTTPHTTP Flood (GET requests)
DNSQAttack on a DNS server using requests for domain addresses
TCPMSYN Flood
DNSLAttack on a DNS server using requests for domain addresses
STOPTerminate a DDoS attack

The HULK command triggers HTTP Flood with GET requests; at that, the Trojan will disguise itself as Baidu spider.

"GET %s HTTP/1.1\r\n"
"Accept: */*\r\n"
"Accept-Encoding: gzip, deflate\r\n"
"User-Agent: Mozilla/5.0+(compatible;+Baiduspider/2.0;++http:/"
"/www.baidu.com/search/spider.html)\r\n"
"Host: %s:%d\r\n"
"Cache-Control: no-cache\r\n"
"Pragma: no-cache\r\n"
"Connection: Keep-Alive\r\n"
"Keep-Alive: %d\r\n"
"\r\n"

The RAND command triggers HTTP Flood with GET requests; at that, a package will be generated. It can look as follows:

"GET %s?%d=%d HTTP/1.1\r\n"
"Accept: */*\r\n"
"Accept-Language: zh-cn\r\n"
"Accept-Encoding: gzip, deflate\r\n"
"User-Agent: Mozilla/5.0+(compatible;+Baiduspider/2.0;++http://www.baidu.com/search/spider.html)\r\n"
"Host: %s\r\n"
"X-Forwarded-For: %d.%d.%d.%d\r\n"
"Connection: Keep-Alive\r\n"
"\r\n"

A randomly generated IP address is taken as a value for X-Forwarded-For.

The difference between DNSQ и DNSL lies in the way requests are generated—that is, to execute the DNSQ command, the Trojan generates packages by itself, while to create requests for the DNSL command execution, library functions are used.

Recommandations pour le traitement


Linux

Veuillez lancer le scan complet de toutes les partitions du disque à l'aide de Dr.Web Antivirus pour Linux.

Version démo gratuite

Pour 1 mois (sans enregistrement) ou 3 mois (avec enregistrement et remise pour le renouvellement)

Télécharger Dr.Web

Par le numéro de série