I just discovered that my router is infected with LuaBot
Information about this ARM specifc malware can be found here : https://w00tsec.blogspot.it/2016_09_01_archive.html
In my process list i can see two of these binaries (.sox and .nttpd) and the file .sox.rslv in /tmp/ .... meaning that my router are certainly infected!
any tips on how to safely remove malware but especially on how to prevent a new infection ?
my fw version is 374.43 (I know a bit old) but updating to the latest version has to be the last chance because I have to reconfigure it all over again
thanks in advance for any help
crpt0
Information about this ARM specifc malware can be found here : https://w00tsec.blogspot.it/2016_09_01_archive.html
Indicators of Compromise (IOCs)
LuaBot ARMEB Binaries:
- drop (5deb17c660de9d449675ab32048756ed)
- .nttpd (c867d00e4ed65a4ae91ee65ee00271c7)
- .sox (4b8c0ec8b36c6bf679b3afcc6f54442a)
- .sox.rslv (889100a188a42369fd93e7010f7c654b)
- .arm_puma5 (061b03f8911c41ad18f417223840bce0)
In my process list i can see two of these binaries (.sox and .nttpd) and the file .sox.rslv in /tmp/ .... meaning that my router are certainly infected!
any tips on how to safely remove malware but especially on how to prevent a new infection ?
my fw version is 374.43 (I know a bit old) but updating to the latest version has to be the last chance because I have to reconfigure it all over again
thanks in advance for any help
crpt0