Library
My library

+ Add to library

Contact us
24/7 Tech support | Rules regarding submitting

Send a message

Your tickets

Profile

Linux.Packed.761

Added to the Dr.Web virus database: 2020-03-22

Virus description added:

Technical Information

Malicious functions:
Launches itself as a daemon
Substitutes application name for:
  • PGb7JvoQUR7vjRjCnjvj6fq7
Network activity:
Awaits incoming connections on ports:
  • 0.0.0.0:23
Establishes connection:
  • 8.#.8.8:53
  • 17#.##3.6.186:2074
Attacks using a special dictionary (brute-force technique) via the Telnet protocol.
Sends data to the following servers:
  • 17#.##3.6.186:2074
  • 17#.##5.228.175:23
  • 1.###.41.135:23
  • 10#.##6.213.174:23
  • 14#.##0.210.126:23
  • 66.###.129.116:23
  • 13#.##4.130.81:23
  • 17#.##7.102.100:23
  • 10#.##.178.224:23
  • 11#.#2.96.10:23
  • 11#.#0.58.69:23
  • 19#.##3.29.211:23
  • 21#.##1.196.55:23
  • 20#.##.162.120:23
  • 57.###.232.62:23
  • 18#.##.75.242:23
  • 19.##.20.204:23
  • 99.##.112.129:23
  • 80.###.162.126:23
  • 57.##.219.57:23
  • 22#.##1.114.159:23
  • 18#.##8.28.34:23
  • 21#.##1.87.74:23
  • 17#.##.179.147:23
  • 16#.##1.23.15:23
  • 63.###.253.162:23
  • 77.##.239.160:23
  • 21#.##.46.194:23
  • 12#.##4.252.179:23
  • 81.##9.33.49:23
  • 10#.##2.55.210:23
  • 16#.##9.93.227:23
  • 15#.##.148.193:23
  • 19#.##0.204.66:23
  • 16#.##1.35.254:23
  • 21#.##2.93.155:23
  • 13#.##9.23.60:23
  • 11#.##.149.226:23
  • 19#.#7.5.222:23
  • 57.##.123.71:23
  • 20#.#7.16.61:23
  • 13#.##.178.200:23
  • 88.##.5.15:23
  • 96.##.168.149:23
  • 85.###.173.60:23
  • 80.###.145.150:23
  • 65.###.185.184:23
  • 68.###.232.13:23
  • 12#.##8.119.61:23
  • 88.###.52.248:23
  • 19#.##8.36.48:23
  • 16#.##9.34.177:23
  • 10#.##0.225.151:23
  • 17#.##7.231.161:23
  • 8.###.55.20:23
  • 31.###.245.104:23
  • 10#.##.10.182:23
  • 66.###.248.26:23
  • 81.##.155.7:23
  • 14#.##6.95.134:23
  • 41.##1.74.85:23
  • 15#.##.164.214:23
  • 17.###.28.110:23
  • 18#.##.192.164:23
  • 16#.##1.223.129:23
  • 19#.#.57.20:23
  • 18#.##8.203.31:23
  • 15#.#.246.4:23
  • 19#.##0.117.16:23
  • 85.###.55.215:23
  • 12#.##.52.254:23
  • 77.##4.7.251:23
  • 98.##.237.0:23
  • 13.##0.69.79:23
  • 11#.##3.78.44:23
  • 21#.#3.89.54:23
  • 14#.##6.8.192:23
  • 58.###.22.131:23
  • 11#.##1.195.63:23
  • 86.###.137.130:23
  • 47.###.150.213:23
  • 44.##.11.166:23
  • 12#.##2.122.66:23
  • 1.###.104.102:23
  • 80.#.10.236:23
  • 88.###.114.169:23
  • 74.##.55.13:23
  • 32.###.47.136:23
  • 11#.##6.181.223:23
  • 45.##.60.157:23
  • 10#.##3.94.63:23
  • 86.##6.94.67:23
  • 5.##.160.117:23
  • 61.###.125.196:23
  • 10#.##8.17.252:23
  • 78.##0.167.3:23
  • 11#.#2.52.90:23
  • 13#.##6.144.182:23
  • 17#.##6.132.7:23
  • 21#.##5.238.212:23
  • 14#.##7.102.80:23
  • 20#.##7.87.67:23
  • 18#.##6.115.250:23
  • 64.##1.75.20:23
  • 16#.##.193.20:23
  • 95.##.4.127:23
  • 88.##.93.219:23
  • 21#.##7.126.67:23
  • 85.##4.83.84:23
  • 78.###.122.76:23
  • 76.###.26.153:23
  • 97.##.72.245:23
  • 11#.##5.131.206:23
  • 12.###.27.209:23
  • 16#.##.237.180:23
  • 70.##9.30.48:23
  • 15#.##7.101.177:23
  • 17#.##.214.29:23

Curing recommendations


Linux

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Free trial

One month (no registration) or three months (registration and renewal discount)

Download Dr.Web

Download by serial number