Analysis by: Vincent Martin Hermosura

ALIASES:

Backdoor.Linux.Ganiw.a (Kaspersky), Trojan.Gen.2 (Symmantec), Linux/RST.b (Mcafee), Linux/DDoS-BD (Sophos), ELF/GATES.BA!tr.bdr (Fortinet), Trojan.Linux.Agent (Ikarus), Linux/Agent.I.Gen trojan (Esset)

 PLATFORM:

Linux/UNIX

 OVERALL RISK RATING:
 DAMAGE POTENTIAL:
 DISTRIBUTION POTENTIAL:
 REPORTED INFECTION:
 INFORMATION EXPOSURE:

  • Threat Type: Backdoor

  • Destructiveness: No

  • Encrypted: Yes

  • In the wild: Yes

  OVERVIEW

This backdoor arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.

  TECHNICAL DETAILS

File Size: 1,135,000 bytes
File Type: ELF
Memory Resident: Yes
Initial Samples Received Date: 20 Aug 2014

Arrival Details

This backdoor arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.

NOTES:

This backdoor drops and executes a file.

The name of the dropped file is based from the name of the current running file.

The dropped file can be found in the same location with the dropper.

This backdoor creates the script named "DbSecuritySpt" which is located in /etc/init.d/: to enable itself to run in every system startup.