Library
My library

+ Add to library

Contact us
24/7 Tech support | Rules regarding submitting

Send a message

Your tickets

Profile

Linux.Packed.977

Added to the Dr.Web virus database: 2020-10-31

Virus description added:

Technical Information

Malicious functions:
Launches itself as a daemon
Substitutes application name for:
  • sshd
Modifies firewall settings:
  • iptables -I INPUT -p tcp --destination-port 46557 -j ACCEPT
Launches processes:
  • sh -c killall -9 telnetd utelnetd scfgmgr
  • sh -c iptables -I INPUT -p tcp --destination-port 46557 -j ACCEPT
Attempts to kill the following processes:
  • killall -9 telnetd utelnetd scfgmgr
Performs operations with the file system:
Creates or modifies files:
  • /proc/self/oom_score_adj
  • /proc/539/oom_score_adj
  • /root/.ips
Network activity:
Awaits incoming connections on ports:
  • 127.0.0.1:14737
  • 0.0.0.0:33445
  • 0.0.0.0:46557
Establishes connection:
  • 8.#.8.8:53
  • 18.##.147.194:80
  • 18#.##.199.107:8443
  • 9.###.248.252:60001
  • 76.##.73.78:80
  • 20#.##.3.65:8443
  • 60.###.121.139:80
  • 15#.##6.147.26:80
  • 13#.##4.27.93:8081
  • 80.###.150.236:8080
  • 26.##.199.115:37215
  • 20#.###.156.70:52869
  • 44.##.107.185:80
  • 29.##.154.12:8081
  • 14.###.22.245:80
  • 20#.###.209.220:8080
  • 22#.###.212.120:52869
  • 58.##.184.98:80
  • 94.###.132.64:80
  • 21#.##8.145.70:5555
  • 19#.#.13.36:7574
  • 13#.#1.45.80:80
  • 81.##.203.103:5555
  • 13#.##.245.152:80
  • 62.##.136.227:8181
  • 18#.##9.124.71:8080
  • 31.###.155.170:80
  • 84.##.254.96:8080
  • 12#.##.193.190:8080
  • 75.###.91.214:80
  • 39.###.131.75:52869
  • 15#.##4.66.70:7574
  • 14#.##7.76.150:8081
  • 70.###.229.229:8080
  • 54.##.22.119:80
  • 85.###.152.192:8443
  • 59.###.100.104:80
  • 92.##.151.36:8080
  • 18#.##.104.25:52869
  • 64.###.76.131:81
  • 10#.##3.123.214:80
  • 10#.##6.59.249:80
  • 29.###.202.198:80
  • 35.#.67.11:8080
  • 16#.##.71.10:8081
  • 13#.##4.148.65:8080
  • 17#.##.199.131:8080
  • 13.##.73.132:60001
  • 16#.##.29.60:8081
  • 74.###.69.250:80
  • 66.##.160.30:49152
  • 56.###.125.193:8081
  • 28.###.18.40:8181
  • 15#.#66.5.95:80
  • 28.##.109.222:49152
  • 18#.##5.24.178:80
  • 28.###.70.211:8081
  • 12#.##6.19.189:8443
  • 16#.##7.115.55:8080
  • 58.###.234.74:60001
  • 19#.##2.234.181:80
  • 14.##2.87.17:80
  • 73.###.148.30:8080
  • 19#.##.232.108:37215
  • 21#.##2.172.85:8080
  • 18#.##7.127.86:8080
  • 81.###.69.208:60001
  • 68.##.24.98:80
  • 86.###.92.211:80
  • 15#.##6.8.83:8181
  • 67.##.217.106:80
  • 26.##.85.133:80
  • 82.###.156.22:81
  • 67.##.245.121:8080
  • 11#.##.181.42:60001
  • 11#.###.223.181:8080
  • 11#.##7.42.254:8080
  • 91.##.202.20:8081
  • 12#.###.232.105:8080
  • 13#.###.63.152:49152
  • 10#.#.206.189:60001
  • 18#.##5.93.57:37215
  • 21#.##.184.214:81
  • 21#.##3.218.99:8080
  • 18#.##.176.35:8081
  • 48.##.90.195:60001
  • 14.###.115.215:7574
  • 26.##.173.155:80
  • 19#.###.250.241:8080
  • 20#.##.241.86:8443
  • 36.###.92.135:80
  • 17#.##.176.14:80
  • 52.###.146.16:80
  • 50.##.168.166:81
  • 35.##.100.92:80
  • 11#.###.192.111:8080
  • 15#.##.146.94:8080
  • 67.##.113.203:8080
  • 13#.###.129.21:60001
  • 54.##.50.142:81
  • 10#.##5.226.166:80
  • 11#.##5.235.38:7574
  • 15#.###.139.167:52869
  • 14#.##7.217.24:8080
  • 49.###.10.80:8443
  • 16#.##.240.103:8080
  • 94.###.183.52:80
  • 90.##.33.114:80
  • 57.###.246.40:8081
  • 14#.###.244.252:5555
  • 19#.###.195.101:5555
  • 17#.##.176.10:8080
  • 18#.###.124.109:8181
  • 10#.##.159.95:8080
  • 47.###.206.212:80
  • 12#.##.182.253:80
  • 12#.##5.18.235:80
  • 65.###.177.191:8080
  • 17.##.157.237:5555
  • 15#.##.220.23:52869
  • 15.###.241.46:8080
  • 39.###.134.38:80
  • 49.###.206.203:81
  • 14#.##1.167.76:8443
  • 43.###.136.169:8081
  • 49.###.173.209:8081
  • 96.###.197.107:7574
  • 20#.##.51.190:8080
  • 11#.##.177.237:8080
  • 17#.##.160.158:52869
  • 20.###.124.137:80
  • 57.###.190.106:8443
  • 20#.##.249.120:80
  • 48.##.149.245:8080
  • 12#.###.196.26:49152
  • 15#.##0.243.105:80
  • 54.##.11.124:80
  • 67.###.206.69:60001
  • 80.###.198.74:81
  • 77.###.245.21:7574
  • 62.###.211.181:52869
  • 27.###.196.205:8080
  • 13#.##.245.145:8080
  • 16#.##7.162.64:8080
  • 18#.##4.121.73:8181
  • 57.##.235.147:80
  • 12#.##.220.18:80
  • 10#.###.207.195:8080
  • 28.##.79.145:8080
  • 13#.###.231.155:8181
  • 90.##6.190.3:80
  • 59.##.134.37:80
  • 35.###.113.102:37215
  • 19.###.188.169:49152
  • 18#.##4.84.133:8181
  • 19#.##5.17.183:8181
  • 38.###.2.127:49152
  • 20#.###.178.139:8443
  • 15#.##.166.34:81
  • 22#.##2.78.85:8181
  • 73.###.230.120:8080
  • 19#.##.100.28:80
  • 45.##.12.65:8080
  • 11#.##.111.30:80
  • 17#.##.32.149:8081
  • 88.###.239.139:80
  • 13#.##4.32.49:49152
  • 21#.##.226.233:7574
  • 62.###.60.170:80
  • 13#.##7.191.3:80
  • 21#.##.213.126:8081
  • 19#.##6.93.170:8081
  • 30.###.198.67:8080
  • 35.##.184.28:80
  • 5.##.#64.218:37215
  • 73.###.169.135:8080
  • 15#.##.55.177:81
  • 14#.##4.83.3:60001
  • 8.###.221.127:8080
  • 15.###.217.239:80
  • 37.##.79.173:8080
  • 31.##.92.173:8443
  • 18.###.170.87:80
  • 14#.##.62.111:80
  • 1.##.132.243:80
  • 15#.##1.76.81:37215
  • 21#.##7.169.63:8080
  • 20#.##7.122.61:8443
  • 21#.##5.82.191:80
  • 98.###.187.152:5555
  • 43.###.210.243:80
  • 22#.##8.63.174:8080
  • 15#.##0.32.144:8080
  • 15#.##.20.226:81
  • 78.###.148.35:8443
  • 17#.###.116.155:37215
  • 21#.###.211.108:7574
  • 56.##7.23.41:80
  • 1.###.109.48:80
  • 53.##.123.149:8080
  • 21.###.141.113:8080
  • 11.##.125.121:8181
  • 15#.##.95.104:80
  • 16.##.191.249:8081
  • 99.##1.49.4:80
  • 14#.##.122.71:8080
  • 18#.##2.92.169:8181
  • 18#.##.233.239:80
  • 20#.##7.110.22:8081
  • 16.##.110.66:80
  • 98.###.22.71:7574
  • 3.###.193.170:7574
  • 13#.##.87.178:8443
  • 11#.##0.26.127:8080
  • 87.#.#28.156:8080
  • 21.###.250.118:8080
  • 64.###.6.17:8080
  • 75.##.161.11:37215
  • 18#.##.131.24:7574
  • 22.##.249.184:52869
  • 19#.##8.82.72:80
  • 60.###.211.120:80
  • 86.##.194.37:60001
  • 18#.###.70.137:37215
  • 29.###.127.15:8080
  • 34.###.126.73:80
  • 95.##.121.197:80
  • 11#.##8.205.55:8080
  • 19#.#6.19.77:80
  • 30.##.124.141:8080
  • 14#.##4.165.221:80
  • 17#.##.206.41:80
  • 21#.##5.33.179:80
  • 70.###.131.7:5555
  • 22.###.241.117:8080
  • 58.##.25.44:8080
  • 71.###.106.132:80
  • 21#.##.243.204:81
  • 11#.#.93.136:80
  • 70.#.#19.84:8080
  • 16#.#.155.135:8081
  • 40.###.11.211:80
  • 13#.##1.99.1:8080
  • 20#.###.125.194:5555
  • 67.###.20.221:8080
  • 15#.##.149.210:8080
  • 12.###.171.152:81
  • 19#.##9.47.128:80
  • 41.###.251.117:8080
  • 17#.###.192.149:49152
  • 74.###.125.60:49152
  • 64.###.158.173:80
  • 11#.##.94.115:80
  • 88.##.18.131:8443
  • 77.##.151.50:80
  • 20#.##4.117.22:8080
  • 47.##8.61.79:81
  • 11#.###.225.165:8080
  • 22#.##1.30.124:8443
  • 13#.###.189.182:8080
  • 5.##.47.24:8443
  • 14.###.194.40:49152
  • 30.###.122.203:52869
  • 96.###.229.237:8443
  • 32.###.81.216:8081
  • 18#.##6.43.107:8080
  • 48.###.251.229:8080
  • 87.###.227.92:8080
  • 92.###.71.46:52869
  • 13#.##3.46.97:60001
  • 37.###.68.253:80
  • 41.##.194.192:8080
  • 17#.###.198.101:8080
  • 22#.##8.250.36:8080
  • 22#.##.15.207:80
  • 21#.##.134.137:80
  • 12#.##.36.246:80
  • 11#.#.145.128:8080
  • 15#.###.150.251:8081
  • 72.##.242.34:49152
  • 22.###.244.207:81
  • 96.###.118.139:8443
  • 10#.##.242.27:49152
  • 13#.##.208.46:80
  • 27.###.185.186:37215
Attacks using a special dictionary (brute-force technique) via the Telnet protocol.
HTTP POST requests:
  • 16#.###.209.215:80/HNAP1/
Sends data to the following servers:
  • 23#.###.255.250:1900
  • 20#.##0.131.166:23
  • 27.##.117.242:23
  • 17#.##4.44.236:23
  • 35.###.12.230:23
  • 16#.#4.87.63:23
  • 18#.##.154.141:23
  • 47.##.92.147:23
  • 77.##.131.160:23
  • 96.##8.246.2:23

Curing recommendations


Linux

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Free trial

One month (no registration) or three months (registration and renewal discount)

Download Dr.Web

Download by serial number