JavaScript support is required for our site to be fully operational in your browser.
Linux.Packed.809
Added to the Dr.Web virus database:
2020-03-27
Virus description added:
2020-03-26
Technical Information
Malicious functions:
Removes itself
Launches itself as a daemon
Substitutes application name for:
Network activity:
Awaits incoming connections on ports:
127.0.0.1:3389
0.0.0.0:58303
0.0.0.0:108
0.0.0.0:22
Establishes connection:
8.#.8.8:53
66.###.225.174:5103
Attacks using a special dictionary (brute-force technique) via the Telnet protocol.
Sends data to the following servers:
21#.##7.71.244:23
32.##.221.206:23
17#.##.252.243:23
15#.##.249.150:23
19#.##9.212.71:23
14#.##7.132.189:23
80.###.184.247:23
17.###.133.162:23
23.##.225.55:23
66.###.225.174:5103
Curing recommendations
Linux
Free trial
One month (no registration) or three months (registration and renewal discount)
Download Dr.Web for Android
Free three-month trial
All protection features available
Renew your trial license in AppGallery/on Google Pay
By continuing to use this website, you are consenting to Doctor Web’s use of cookies and other technologies related to the collection of visitor statistics. Learn more
OK