- Threat Encyclopedia
- Malware
- Backdoor.SH.SHELLBOT.AA
Windows, Unix, Linux
Downloaded from specific site, Dropped by other malware
This backdoor comes bundled with a Monero miner, both spread by a botnet. The techniques employed are reminiscent of the Outlaw hacking group that Trend Micro reported in November 2018.
This Backdoor arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
It connects to Internet Relay Chat (IRC) servers. It joins an Internet Relay Chat (IRC) channel.
47,407 bytes
Other
Yes
19 Dec 2019
Connects to URLs/IPs, Receive commands
Arrival Details
This Backdoor arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Installation
This Backdoor drops the following files:
Backdoor Routine
This Backdoor connects to any of the following Internet Relay Chat (IRC) servers:
It joins any of the following Internet Relay Chat (IRC) channels:
It accesses a remote Internet Relay Chat (IRC) server where it receives the following commands from a remote malicious user:
9.850
15.568.03
19 Dec 2019
15.569.00
20 Dec 2019
Step 1
Before doing any scans, Windows 7, Windows 8, Windows 8.1, and Windows 10 users must disable System Restore to allow full scanning of their computers.
Step 2
Scan your computer with your Trend Micro product to delete files detected as Backdoor.SH.SHELLBOT.AA. If the detected files have already been cleaned, deleted, or quarantined by your Trend Micro product, no further step is required. You may opt to simply delete the quarantined files. Please check the following Trend Micro Support pages for more information: