Perl/Shellbot.NAK trojan (NOD32); Troj/PerlShel-C (SOPHOS_LITE)
Windows, Unix, Linux
Downloaded from specific site
This backdoor comes bundled with a Monero miner, both spread by a botnet. The techniques employed are reminiscent of the Outlaw hacking group that Trend Micro reported in November 2018.
This Backdoor connects to Internet Relay Chat (IRC) servers. It joins an Internet Relay Chat (IRC) channel.
28 May 2019
Connects to URLs/IPs
This Backdoor may be downloaded from the following remote site(s):
This Backdoor connects to any of the following Internet Relay Chat (IRC) servers:
It joins any of the following Internet Relay Chat (IRC) channels:
It accesses a remote Internet Relay Chat (IRC) server where it receives the following commands from a remote malicious user:
28 May 2019
29 May 2019
Before doing any scans, Windows 7, Windows 8, Windows 8.1, and Windows 10 users must disable System Restore to allow full scanning of their computers.
Scan your computer with your Trend Micro product to delete files detected as Backdoor.Perl.SHELLBOT.AB. If the detected files have already been cleaned, deleted, or quarantined by your Trend Micro product, no further step is required. You may opt to simply delete the quarantined files. Please check the following Trend Micro Support pages for more information: