Library
My library

+ Add to library

Contact us
24/7 Tech support | Rules regarding submitting

Send a message

Your tickets

Profile

Linux.Packed.645

Added to the Dr.Web virus database: 2019-10-13

Virus description added:

Technical Information

Malicious functions:
Removes itself
Launches itself as a daemon
Substitutes application name for:
  • busybox
Kills the following processes:
  • rpc.statd
  • dbus-daemon
  • exim4
  • bash
  • run.sh
  • <SAMPLE>
Network activity:
Awaits incoming connections on ports:
  • 127.0.0.1:31573
Establishes connection:
  • 8.#.8.8:53
Attacks using a special dictionary (brute-force technique) via the Telnet protocol.
Attacks using a special dictionary (brute-force technique) via an undefined protocol.
DNS ASK:
  • sc##.#witchnets.net
Sends data to the following servers:
  • 89.###.91.147:60001
  • 2.###.30.147:60001
  • 81.###.91.147:8000
  • 2.###.30.147:81
  • 11#.##6.239.246:88
  • 16#.###.189.11:60001
  • 4.###.23.146:60001
  • 98.##.114.23:60001
  • 18#.##.109.210:60001
  • 48.###.52.54:60001
  • 40.##.88.68:80
  • 99.##.48.21:8000
  • 10#.##.246.36:80
  • 11#.##6.2.224:81
  • 53.##.194.224:60001
  • 19#.##.174.2:60001
  • 15#.#.143.43:60001
  • 37.###.186.192:60001
  • 20#.##4.236.2:88
  • 12#.##.152.226:8080
  • 8.##.61.34:81
  • 13#.##.181.89:88
  • 20#.###.105.38:60001
  • 21#.##.36.5:60001
  • 88.###.3.20:60001
  • 19#.##3.113.3:60001
  • 14#.##2.231.176:88
  • 11#.##0.221.206:80
  • 20#.##.119.253:8080
  • 17#.##.88.153:8000
  • 8.###.172.95:60001
  • 21#.##.128.65:60001
  • 15#.##.213.142:60001
  • 8.###.40.130:60001
  • 17#.##0.168.250:81
  • 80.###.242.189:80
  • 19#.##4.140.204:81
  • 5.##.14.58:88
  • 14#.##9.228.155:81
  • 31.##.164.245:60001
  • 20#.##.96.227:60001
  • 19#.###.188.91:60001
  • 13#.##.36.28:60001
  • 22#.###.244.112:60001
  • 14#.##.7.123:60001
  • 15#.##.69.180:81
  • 70.###.86.118:8000
  • 19#.##.178.80:88
  • 89.##.46.172:8080
  • 1.###.97.72:60001
  • 13#.###.178.200:60001
  • 21#.##.19.201:88
  • 42.##.157.181:80
  • 44.###.235.70:88
  • 63.###.40.255:60001
  • 17#.###.242.55:60001
  • 16#.###.68.146:60001
  • 42.###.120.157:60001
  • 60.##.122.237:60001
  • 10#.###.43.171:60001
  • 37.##.1.208:8000
  • 11#.##8.70.109:88
  • 11#.##.45.171:80
  • 17#.##4.120.49:8080
  • 17#.##1.220.146:88
  • 81.###.230.47:88
  • 34.###.232.95:8000
  • 89.##.21.179:60001
  • 11#.##6.91.57:60001
  • 21#.###.163.118:60001
  • 22#.###.109.25:60001
  • 19#.##.131.197:60001
  • 12#.###.223.249:60001
  • 16#.###.67.144:60001
  • 15#.##2.222.46:8080
  • 16#.##4.233.65:88
  • 62.###.54.247:8000
  • 21#.#9.35.50:81
  • 10#.##9.109.38:81
  • 15#.##.186.163:60001
  • 58.###.171.125:60001
  • 69.###.239.220:60001
  • 21#.##.61.13:60001
  • 15#.##.162.80:60001
  • 82.###.203.235:60001
  • 12#.###.151.165:60001
  • 96.###.192.71:88
  • 19#.##7.110.30:8080
  • 80.###.188.5:8000
  • 17#.#86.0.62:81
  • 13#.##.240.211:8080
  • 15#.##.66.168:8080
  • 18#.##2.75.38:88
  • 12#.##3.15.129:8000
  • 19#.##5.9.49:60001
  • 18.###.157.21:60001
  • 19#.###.247.142:60001
  • 18#.###.233.176:60001
  • 38.###.238.34:8080
  • 15#.##9.157.222:80
  • 14#.##.238.17:80
  • 23.##.65.214:8000
  • 95.##.138.236:81
  • 17#.##9.48.133:81
  • 10#.###.122.152:60001
  • 67.##.249.157:60001
  • 11#.###.54.177:60001
  • 5.###.139.219:60001
  • 87.###.56.172:60001
  • 19#.###.43.132:60001
  • 85.###.43.226:80
  • 70.##.151.181:81
  • 99.##.105.165:8000
  • 11#.##2.57.93:88
  • 80.###.186.153:80
  • 13#.##.159.94:81
  • 20#.##3.59.152:81
  • 21#.###.215.202:60001
  • 11#.##.25.209:60001
  • 38.###.30.118:60001
  • 23.###.112.80:60001
  • 11#.##3.80.65:60001
  • 18.###.79.42:60001
  • 20#.##4.133.81:80
  • 11#.#6.86.68:80
  • 13#.##2.209.57:8080
  • 10#.##.72.203:88
  • 73.###.201.62:81
  • 10#.##.192.148:60001
  • 91.###.205.219:60001
  • 13#.##.249.113:60001
  • 36.#.#53.148:60001
  • 19.##.189.187:60001
  • 10#.#.7.104:60001
  • 85.##1.203.8:80
  • 13#.##5.97.140:81
  • 16#.##7.56.77:8080
  • 87.###.223.113:8000
  • 51.##.225.107:88
  • 75.##.45.185:8080
  • 53.###.32.14:60001
  • 17#.###.135.68:60001
  • 10#.###.169.106:60001
  • 10#.###.158.127:60001
  • 18#.##.103.14:60001
  • 19#.###.158.135:60001
  • 14#.##6.206.98:80
  • 20#.##.39.164:88
  • 98.#.3.196:80
  • 69.##.30.107:8080
  • 10#.##.140.36:88
  • 24.###.238.66:8080
  • 20#.###.182.136:60001
  • 21#.###.246.200:60001
  • 83.###.201.159:60001
  • 14#.##.198.147:60001
  • 4.###.140.55:60001
  • 88.###.115.121:60001
  • 47.##.211.43:8080
  • 10#.##.237.72:8000
  • 17#.##.176.164:80
  • 36.##.71.222:88
  • 68.#.#30.75:8000
  • 11#.##4.96.78:81
  • 21#.#.30.49:60001
  • 95.###.208.149:60001
  • 96.###.61.149:60001
  • 17#.###.165.176:60001
  • 11#.###.108.189:60001
  • 12#.###.154.101:60001
  • 89.###.159.20:8000
  • 77.##.104.107:8000
  • 78.##.74.71:8080
  • 12#.###.108.116:8000
  • 19#.##.245.122:81
  • 37.###.140.107:8080
  • 16#.###.219.162:8080
  • 79.###.240.62:60001
  • 17#.##.48.176:60001
  • 14#.###.31.153:60001
  • 21#.###.231.145:60001
  • 12#.##.153.145:60001
  • 71.###.245.66:60001
  • 62.##.220.185:88
  • 43.##.159.250:80
  • 81.##.219.150:81
  • 11#.#.50.149:8000
  • 40.##.198.102:8080
  • 10#.##.29.197:88
  • 20#.##.249.78:60001
  • 20#.###.135.164:60001
  • 15#.##.140.1:60001
  • 58.##.32.196:60001
  • 15#.###.112.132:60001
  • 20#.###.60.228:60001
  • 20#.##.203.65:60001
  • 27.###.123.121:60001
  • 50.##.210.250:81
  • 57.##.8.26:81
  • 77.###.216.77:8080
  • 18#.##2.74.43:8080
  • 16#.##2.2.242:80
  • 13#.##9.252.201:80
  • 11#.##.205.95:60001
  • 14#.###.149.215:60001
  • 94.###.193.190:60001
  • 18#.##.39.110:60001
  • 14#.##.15.66:60001
  • 12#.##3.38.240:8080
  • 15#.##6.130.79:8000
  • 84.###.159.27:88
  • 61.###.174.220:81
  • 16#.##.160.70:88
  • 32.###.54.200:88
  • 72.###.13.241:60001
  • 74.###.53.82:60001
  • 9.##.#4.41:60001
  • 20#.##.81.208:60001
  • 22#.##1.97.25:60001
  • 38.###.161.233:60001
  • 16#.##.162.174:60001
  • 12#.###.44.102:60001
  • 12#.##9.49.52:60001
  • 15#.##3.0.237:60001
  • 58.###.170.223:60001
  • 16#.##.1.123:60001

Curing recommendations


Linux

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Free trial

One month (no registration) or three months (registration and renewal discount)

Download Dr.Web

Download by serial number