Library
My library

+ Add to library

Contact us
24/7 Tech support | Rules regarding submitting

Send a message

Your tickets

Profile

Linux.Packed.932

Added to the Dr.Web virus database: 2020-10-02

Virus description added:

Technical Information

Malicious functions:
Removes itself
Launches itself as a daemon
Substitutes application name for:
  • 03pk3xf1rk0po3tn0lne
Network activity:
Awaits incoming connections on ports:
  • 19#.##8.218.50:3467
Establishes connection:
  • 8.#.8.8:53
  • 5.###.227.140:4321
  • 5.###.227.140:7685
Attacks using a special dictionary (brute-force technique) via the Telnet protocol.
Sends data to the following servers:
  • 5.###.227.140:4321
  • 5.###.227.140:7685
  • 0.0.0.0:0
  • 13#.##0.142.244:23
  • 20#.#1.193.5:23
  • 2.##.3.158:23
  • 38.###.68.211:23
  • 57.###.247.250:23
  • 22#.##8.219.52:23
  • 18#.#9.219.7:23
  • 54.###.200.44:23
  • 22#.##1.193.202:23
  • 17#.##9.13.141:23
  • 14#.##.53.222:23
  • 25#.##1.23.206:23
  • 11#.##3.122.33:23
  • 80.###.196.157:23
  • 18#.##1.241.0:23
  • 59.#.55.184:23
  • 83.##.247.212:23
  • 10#.##.136.221:23
  • 17.###.123.38:23
  • 22#.##4.208.214:23
  • 13#.##6.69.252:23
  • 62.###.241.57:23
  • 20#.#.35.133:23
  • 20#.##.128.15:23
  • 14#.#8.31.27:23
  • 23#.#2.146.3:23
  • 86.###.123.12:23
  • 15#.##.212.250:23
  • 21#.#9.91.90:23
  • 16#.##.79.252:23
  • 98.#.186.104:23
  • 20#.##2.137.45:23
  • 55.##.124.163:23
  • 21#.##.51.177:23
  • 42.##.45.251:23
  • 10.###.10.134:23
  • 10.##.92.124:23
  • 21#.##7.233.181:23
  • 14#.##.233.173:23
  • 77.##.120.104:23
  • 13#.#75.99.1:23
  • 16#.##.236.46:23
  • 40.###.103.51:23
  • 11#.##.42.166:23
  • 68.###.195.195:23
  • 21#.##9.139.173:23
  • 69.##.7.123:23
  • 31.###.50.252:23
  • 11#.##3.38.232:23
  • 14#.##3.249.189:23
  • 18#.##4.39.114:23
  • 18#.#6.132.4:23
  • 24#.##7.230.201:23
  • 12#.##.117.221:23
  • 38.###.193.115:23
  • 20#.##.107.44:23
  • 20#.##6.146.59:23
  • 16#.##0.10.11:23
  • 15#.#.190.47:23
  • 14#.##4.165.73:23
  • 34.##.110.165:23
  • 10#.##.236.53:23
  • 77.##.201.199:23
  • 95.###.117.195:23
  • 12#.##6.241.162:23
  • 57.##.42.205:23
  • 51.###.215.191:23
  • 24#.##0.10.185:23
  • 60.##.114.85:23
  • 49.#.16.105:23
  • 54.##7.81.81:23
  • 20#.##3.62.183:23
  • 14#.##6.54.207:23
  • 35.###.157.41:23
  • 21#.##0.198.42:23
  • 63.###.61.179:23
  • 56.##.228.81:23
  • 21#.##7.153.71:23
  • 3.###.219.144:23
  • 86.###.162.138:23
  • 21.###.125.112:23
  • 33.##.176.123:23
  • 16#.##8.104.83:23
  • 22#.##5.74.255:23
  • 38.###.37.188:23
  • 30.##.236.32:23
  • 15#.##8.215.237:23
  • 25.##.119.16:23
  • 17#.##3.121.205:23
  • 10#.##1.48.140:23
  • 9.###.148.118:23
  • 18#.##.193.244:23
  • 17.###.136.33:23
  • 16#.##.161.59:23
  • 84.##.112.108:23
  • 62.##.107.111:23
  • 16#.##9.199.239:23
  • 22#.##.112.238:23
  • 8.##.19.246:23
  • 78.##.71.89:23
  • 20#.##4.69.81:23
  • 10#.##5.70.220:23
  • 15#.##.129.193:23
  • 18#.##.56.190:23
  • 10#.##7.54.32:23
  • 24#.##3.220.155:23
  • 24#.#54.12.1:23
  • 46.##.132.210:23
  • 11.###.231.221:23
  • 15#.##3.44.45:23
  • 24#.##.215.177:23
  • 67.##.220.150:23
  • 19#.#93.89.6:23
  • 15#.##0.128.84:23
  • 96.##.65.170:23
  • 18#.##2.173.4:23
  • 22.##1.39.82:23
  • 20#.##1.120.20:23
  • 22#.##1.109.76:23
  • 25#.##.202.238:23
Receives data from the following servers:
  • 5.###.227.140:7685

Curing recommendations


Linux

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Free trial

One month (no registration) or three months (registration and renewal discount)

Download Dr.Web

Download by serial number