Notes on Linux/BillGates
ID: db566da6-0d77-5d75-8efb-744a3b615084
STIX ID: report--db566da6-0d77-5d75-8efb-744a3b615084
Feed Name: Blaze's Security Blog
This post provides practical notes on the Linux/BillGates botnet, a Linux-focused DDoS malware with limited backdoor/rootkit capabilities. It lists key artefacts and indicators (e.g., files under /etc, /tmp, /usr/bin/bsd-port, and libamplify.so), identifies typical DDoS module names (atddd, cupsdd[h], ksapdd/kysapdd, sksapdd/skysapdd), and describes how it replaces system tools (ps, netstat, lsof, ss) while storing legitimate copies in /usr/bin/dpkgd/. The document outlines persistence via init/cron and provides step-by-step remediation: identify and kill processes, remove artefacts, restore binaries, check cron, and optionally use AV (e.g., ClamAV). While the botnet is older, the guidance emphasizes it remains a relevant threat.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
