Backdoor

Backdoor.Linux.Tsunami.bq malicious file

Malware Removal

The Backdoor.Linux.Tsunami.bq is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor.Linux.Tsunami.bq virus can do?

  • Injection (inter-process)
  • Injection with CreateRemoteThread in a remote process
  • Uses Windows utilities for basic functionality
  • A potential decoy document was displayed to the user
  • Network activity detected but not expressed in API logs

How to determine Backdoor.Linux.Tsunami.bq?


File Info:

crc32: 68174D58
md5: 86f57b73f60f82b47813ee2954c37b5d
name: upload_file
sha1: e00a30e794f7e64d98d501c2d6a586fa5d3a1c0e
sha256: c2b6a1cbd5ace02cdf393cf70431cf97e3c202985b5a80d9ccb9da4563fa2154
sha512: 997b75077c363e20af5fa50c77b2f2a59bc4683d1bef7aba8c475394377cb744ef3ab26a96196fae844250c22feb7aed032b99a5b8a195efd3bc3b62bd098b34
ssdeep: 3072:1gra+VZZHUrQ0eOuhsqyEWhwFszZ9SLuhvMLlG2Z37WhKORKb:1gO+VZZHUrQtO8sqbWhXyuhvMLlG2Z3b
type: ELF 32-bit MSB executable, PowerPC or cisco 4500, version 1 (SYSV), statically linked, not stripped

Version Info:

0: [No Data]

Backdoor.Linux.Tsunami.bq also known as:

MicroWorld-eScanGen:Variant.Backdoor.Linux.Tsunami.1
FireEyeGen:Variant.Backdoor.Linux.Tsunami.1
ALYacGen:Variant.Backdoor.Linux.Tsunami.1
AegisLabTrojan.Linux.Tsunami.m!c
BitDefenderThetaGen:NN.Mirai.34196
CyrenELF/Gafgyt.D.gen!Camelot
SymantecTrojan.Gen.NPE
TrendMicro-HouseCallPossible_BASHLITE.SMLBQ2
AvastELF:Mirai-AVO [Trj]
ClamAVUnix.Trojan.Gafgyt-6981154-0
KasperskyHEUR:Backdoor.Linux.Tsunami.bq
BitDefenderGen:Variant.Backdoor.Linux.Tsunami.1
NANO-AntivirusTrojan.Tsunami.hrwxql
Ad-AwareGen:Variant.Backdoor.Linux.Tsunami.1
Comodo.UnclassifiedMalware@0
F-SecureMalware.LINUX/Tsunami.vhsyi
DrWebLinux.BackDoor.Tsunami.1348
TrendMicroELF_KAITEN.SM
SophosMal/Generic-S
IkarusTrojan.Linux.Tsunami
GDataLinux.Trojan.Gafgyt.A
JiangminBackdoor.Linux.finn
AviraLINUX/Tsunami.vhsyi
Antiy-AVLTrojan[Backdoor]/Linux.Tsunami.bq
MicrosoftTrojan:Win32/Skeeyah.A!rfn
ArcabitTrojan.Backdoor.Linux.Tsunami.1
ZoneAlarmHEUR:Backdoor.Linux.Tsunami.bq
Avast-MobileELF:Mirai-AVP [Trj]
CynetMalicious (score: 85)
AhnLab-V3Linux/Mirai.Gen
McAfeeLinux/Tsunami!86F57B73F60F
ESET-NOD32a variant of Linux/Tsunami.NCD
TencentBackdoor.Linux.Tsunami.ad
MAXmalware (ai score=81)
FortinetELF/Tsunami.NDJ!tr
AVGELF:Mirai-AVO [Trj]
Qihoo-360Linux/Backdoor.ea3

How to remove Backdoor.Linux.Tsunami.bq?

Backdoor.Linux.Tsunami.bq removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment