{"id":178,"date":"2017-02-09T14:44:19","date_gmt":"2017-02-09T14:44:19","guid":{"rendered":"http:\/\/kloxo.id\/?p=178"},"modified":"2017-02-09T14:44:19","modified_gmt":"2017-02-09T14:44:19","slug":"mengatasi-unix-trojan-ddos_xor-1-pada-server-linux","status":"publish","type":"post","link":"https:\/\/kloxo.web.id\/?p=178","title":{"rendered":"Mengatasi Unix.Trojan.DDoS_XOR-1 pada Server Linux"},"content":{"rendered":"<p>Dikontak via WA oleh seorang kawan, dengan keluhan udah 2 hari ini traffic full pada salah satu interface router nya :<\/p>\n<p><a href=\"http:\/\/kloxo.id\/wp-content\/uploads\/2017\/02\/IMG-20170209-WA0006.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-medium wp-image-179\" src=\"http:\/\/kloxo.id\/wp-content\/uploads\/2017\/02\/IMG-20170209-WA0006-300x169.jpg\" alt=\"IMG-20170209-WA0006\" width=\"300\" height=\"169\" srcset=\"https:\/\/kloxo.web.id\/wp-content\/uploads\/2017\/02\/IMG-20170209-WA0006-300x169.jpg 300w, https:\/\/kloxo.web.id\/wp-content\/uploads\/2017\/02\/IMG-20170209-WA0006-768x432.jpg 768w, https:\/\/kloxo.web.id\/wp-content\/uploads\/2017\/02\/IMG-20170209-WA0006-1024x576.jpg 1024w, https:\/\/kloxo.web.id\/wp-content\/uploads\/2017\/02\/IMG-20170209-WA0006.jpg 1032w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>saya minta scan dengan clamav pada server production nya :<\/p>\n<p><a href=\"http:\/\/kloxo.id\/wp-content\/uploads\/2017\/02\/IMG-20170209-WA0012.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-medium wp-image-180\" src=\"http:\/\/kloxo.id\/wp-content\/uploads\/2017\/02\/IMG-20170209-WA0012-300x169.jpg\" alt=\"IMG-20170209-WA0012\" width=\"300\" height=\"169\" srcset=\"https:\/\/kloxo.web.id\/wp-content\/uploads\/2017\/02\/IMG-20170209-WA0012-300x169.jpg 300w, https:\/\/kloxo.web.id\/wp-content\/uploads\/2017\/02\/IMG-20170209-WA0012-768x432.jpg 768w, https:\/\/kloxo.web.id\/wp-content\/uploads\/2017\/02\/IMG-20170209-WA0012-1024x576.jpg 1024w, https:\/\/kloxo.web.id\/wp-content\/uploads\/2017\/02\/IMG-20170209-WA0012.jpg 1032w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>\/lib\/libudev.so: Unix.Trojan.DDoS_XOR-1 FOUND<\/p>\n<p>dan ketika dilakukan &#8216;top&#8217; muncul aplikasi bernama aneh yang menggunakan resource system cukup besar :<\/p>\n<p><a href=\"http:\/\/kloxo.id\/wp-content\/uploads\/2017\/02\/IMG-20170209-WA0023.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-medium wp-image-181\" src=\"http:\/\/kloxo.id\/wp-content\/uploads\/2017\/02\/IMG-20170209-WA0023-169x300.jpg\" alt=\"IMG-20170209-WA0023\" width=\"169\" height=\"300\" srcset=\"https:\/\/kloxo.web.id\/wp-content\/uploads\/2017\/02\/IMG-20170209-WA0023-169x300.jpg 169w, https:\/\/kloxo.web.id\/wp-content\/uploads\/2017\/02\/IMG-20170209-WA0023-576x1024.jpg 576w, https:\/\/kloxo.web.id\/wp-content\/uploads\/2017\/02\/IMG-20170209-WA0023.jpg 581w\" sizes=\"auto, (max-width: 169px) 100vw, 169px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>cara mengatasi trojan ini saya copas dari :<\/p>\n<p>(https:\/\/admin-ahead.com\/forum\/server-security-hardening\/unix-trojan-ddos_xor-1-chinese-chicken-multiplatform-dos-botnets-trojan\/)<\/p>\n<p>(http:\/\/superuser.com\/questions\/863997\/ddos-virus-infection-as-a-unix-service-on-a-debian-8-vm-webserver)<\/p>\n<p>kalo mencobanya command nya hati2 ya.. DWYOR<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Dikontak via WA oleh seorang kawan, dengan keluhan udah 2 hari ini traffic full pada salah satu interface router nya : saya minta scan dengan clamav pada server production nya : \/lib\/libudev.so: Unix.Trojan.DDoS_XOR-1 FOUND dan ketika dilakukan &#8216;top&#8217; muncul aplikasi bernama aneh yang menggunakan resource system cukup besar : &nbsp; cara mengatasi trojan ini saya [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-178","post","type-post","status-publish","format-standard","hentry","category-linux-server"],"_links":{"self":[{"href":"https:\/\/kloxo.web.id\/index.php?rest_route=\/wp\/v2\/posts\/178","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/kloxo.web.id\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/kloxo.web.id\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/kloxo.web.id\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/kloxo.web.id\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=178"}],"version-history":[{"count":1,"href":"https:\/\/kloxo.web.id\/index.php?rest_route=\/wp\/v2\/posts\/178\/revisions"}],"predecessor-version":[{"id":182,"href":"https:\/\/kloxo.web.id\/index.php?rest_route=\/wp\/v2\/posts\/178\/revisions\/182"}],"wp:attachment":[{"href":"https:\/\/kloxo.web.id\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=178"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/kloxo.web.id\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=178"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/kloxo.web.id\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=178"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}