ELF_DDOSER.DJD
Backdoor.Linux.Mayday.g (Kaspersky), Linux/Elknot.A (ESET-NOD32)
Linux
Threat Type: Trojan
Destructiveness: No
Encrypted: Yes
In the wild: Yes
OVERVIEW
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
It executes commands from a remote malicious user, effectively compromising the affected system. It connects to a website to send and receive information.
TECHNICAL DETAILS
1,128,800 bytes
ELF
Yes
11 Nov 2016
Arrival Details
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Backdoor Routine
This Trojan executes the following commands from a remote malicious user:
- Get system information
- Get processor information
- Get memory information
- Manipulate files and directories
- Execute commands
- Perform DDOS attack
It connects to the following websites to send and receive information:
- {BLOCKED}.{BLOCKED}.81.131:10991
SOLUTION
9.850
12.892.05
11 Nov 2016
12.893.00
12 Nov 2016
Scan your computer with your Trend Micro product to delete files detected as ELF_DDOSER.DJD. If the detected files have already been cleaned, deleted, or quarantined by your Trend Micro product, no further step is required. You may opt to simply delete the quarantined files. Please check this Knowledge Base page for more information.
Did this description help? Tell us how we did.