- Threat Encyclopedia
- Malware
- Backdoor.Perl.SHELLBOT.AB
Perl/Shellbot.NAK trojan (NOD32); Troj/PerlShel-C (SOPHOS_LITE)
Windows, Unix, Linux
Downloaded from specific site
This backdoor comes bundled with a Monero miner, both spread by a botnet. The techniques employed are reminiscent of the Outlaw hacking group that Trend Micro reported in November 2018.
This Backdoor connects to Internet Relay Chat (IRC) servers. It joins an Internet Relay Chat (IRC) channel.
35,116 bytes
PL
Yes
28 May 2019
Connects to URLs/IPs
Arrival Details
This Backdoor may be downloaded from the following remote site(s):
Backdoor Routine
This Backdoor connects to any of the following Internet Relay Chat (IRC) servers:
It joins any of the following Internet Relay Chat (IRC) channels:
It accesses a remote Internet Relay Chat (IRC) server where it receives the following commands from a remote malicious user:
9.850
15.138.06
28 May 2019
15.139.00
29 May 2019
Step 1
Before doing any scans, Windows 7, Windows 8, Windows 8.1, and Windows 10 users must disable System Restore to allow full scanning of their computers.
Step 2
Scan your computer with your Trend Micro product to delete files detected as Backdoor.Perl.SHELLBOT.AB. If the detected files have already been cleaned, deleted, or quarantined by your Trend Micro product, no further step is required. You may opt to simply delete the quarantined files. Please check the following Trend Micro Support pages for more information: