Library
My library

+ Add to library

Contact us
24/7 Tech support | Rules regarding submitting

Send a message

Your tickets

Profile

Linux.Packed.999

Added to the Dr.Web virus database: 2020-11-12

Virus description added:

Technical Information

Malicious functions:
Removes itself
Launches itself as a daemon
Substitutes application name for:
  • (sd-pam)
Kills the following processes:
  • <SAMPLE>
Performs operations with the file system:
Creates or modifies files:
  • <SAMPLE_FULL_PATH>
Network activity:
Awaits incoming connections on ports:
  • 19#.##8.200.50:3467
Establishes connection:
  • 8.#.8.8:53
  • 18#.###.111.199:4321
  • 18#.###.111.199:7685
Attacks using a special dictionary (brute-force technique) via the Telnet protocol.
Sends data to the following servers:
  • 18#.###.111.199:4321
  • 18#.###.111.199:7685
  • 0.0.0.0:0
  • 26.###.148.71:23
  • 33.###.205.74:23
  • 11#.##4.55.170:23
  • 41.###.177.190:23
  • 18#.#3.64.46:23
  • 24#.##3.12.152:23
  • 11.###.59.148:23
  • 15#.##1.124.49:23
  • 45.##.44.242:23
  • 12#.##9.119.48:23
  • 20#.##4.111.179:23
  • 17#.##3.41.225:23
  • 18#.##0.99.173:23
  • 20.###.34.226:23
  • 12#.##9.153.148:23
  • 23#.##.220.97:23
  • 51.###.113.18:23
  • 23#.##1.181.91:23
  • 33.##.161.173:23
  • 23#.##.61.122:23
  • 18.##.54.56:23
  • 89.##.183.138:23
  • 24#.##9.127.248:23
  • 17.###.41.239:23
  • 80.#.177.238:23
  • 11.##.209.132:23
  • 11#.##5.57.106:23
  • 22.##.55.99:23
  • 24#.##9.116.199:23
  • 23#.##4.139.138:23
  • 24#.#64.4.53:23
  • 19#.##.19.102:23
  • 7.##.100.146:23
  • 17#.##4.109.230:23
  • 23#.##5.155.95:23
  • 88.##.180.233:23
  • 23#.#96.61.2:23
  • 28.###.122.77:23
  • 20.###.130.62:23
  • 17#.##6.97.38:23
  • 5.###.156.236:23
  • 33.##.194.4:23
  • 20#.##.164.78:23
  • 10#.##6.65.204:23
  • 19.##3.3.184:23
  • 17#.##.200.229:23
  • 47.###.46.239:23
  • 26.##.155.250:23
  • 14#.##3.149.196:23
  • 17#.##6.13.249:23
  • 25#.##.183.243:23
  • 17#.##7.227.28:23
  • 90.###.194.204:23
  • 24.###.232.145:23
  • 17#.##2.198.104:23
  • 84.##.92.189:23
  • 21#.##5.251.219:23
  • 12#.##8.121.250:23
  • 96.###.119.207:23
  • 14#.##.147.92:23
  • 20#.##.178.142:23
  • 41.###.242.13:23
  • 21#.##2.48.93:23
  • 11#.##4.142.5:23
  • 25#.##.61.205:23
  • 24#.##0.11.184:23
  • 18#.##.122.166:23
  • 10#.##4.160.133:23
  • 10.###.165.214:23
  • 65.###.90.223:23
  • 21#.##0.90.90:23
  • 3.##.152.234:23
  • 96.##.123.227:23
  • 17.###.92.198:23
  • 17#.##8.206.83:23
  • 20#.##6.34.85:23
  • 21#.##4.162.9:23
  • 13#.##4.138.152:23
  • 25#.##.147.160:23
  • 12.###.100.14:23
  • 19#.##.195.31:23
  • 9.###.142.130:23
  • 11#.#.38.179:23
  • 20.###.255.14:23
  • 12#.##.240.188:23
  • 47.###.110.241:23
  • 13.##.147.70:23
  • 14#.#0.76.26:23
  • 23#.##.157.56:23
  • 17#.#.175.219:23
  • 13#.##.162.152:23
  • 84.###.118.249:23
  • 27.###.243.99:23
  • 25#.##7.174.68:23
  • 12#.#9.41.19:23
  • 64.###.239.42:23
  • 4.###.45.29:23
  • 23#.##7.110.190:23
  • 20#.##5.118.173:23
  • 91.##.192.177:23
  • 41.###.20.224:23
  • 12#.##9.142.11:23
  • 14#.##1.2.151:23
  • 75.##.131.87:23
  • 21#.##9.168.238:23
  • 21#.##.237.234:23
  • 57.###.133.73:23
  • 14#.##6.247.37:23
  • 8.###.216.247:23
  • 10#.##4.146.240:23
  • 11#.##3.53.31:23
  • 13#.##4.134.253:23
  • 14.###.75.121:23
  • 23#.##.236.154:23
  • 25#.##1.245.169:23
  • 75.###.252.33:23
  • 46.###.139.189:23
  • 14#.##.225.90:23
  • 7.###.165.231:23
  • 10#.##9.85.62:23
  • 23#.##2.68.207:23
  • 16#.##4.129.132:23
  • 87.##.16.225:23
  • 17#.##.225.188:23
  • 19#.##8.196.239:23
  • 24#.##1.175.25:23
  • 21.##0.18.14:23
  • 19#.##8.5.106:23
  • 54.##0.50.68:23
  • 12#.##.114.248:23
  • 42.###.217.55:23
  • 21#.##.150.214:23
  • 14#.##4.167.236:23
  • 54.###.134.179:23
  • 83.###.71.126:23
  • 15.###.53.182:23
  • 24#.##.13.155:23
  • 13#.##.223.225:23
  • 23.#.166.154:23
  • 21.###.116.141:23
  • 12#.##4.2.231:23
  • 1.##.246.33:23
  • 53.###.100.131:23
  • 39.##.151.52:23
  • 21#.##6.180.1:23
  • 71.###.136.57:23
  • 21#.#0.87.74:23
  • 16.#.131.203:23
  • 14#.#.49.67:23
  • 20.###.206.183:23
  • 28.##9.43.76:23
  • 11#.#3.76.95:23
  • 13#.##.14.250:23
  • 23#.##0.158.73:23
  • 93.##.208.32:23
  • 4.###.244.53:23
  • 11#.##5.108.226:23
  • 21#.##1.133.197:23
  • 25#.##4.65.197:23
  • 22#.##3.75.198:23
  • 20.##.170.233:23
  • 24#.##.203.181:23
  • 10#.##.48.152:23
  • 70.###.245.164:23
  • 44.###.67.169:23
  • 16#.##5.156.132:23
  • 19#.##.158.178:23
  • 19#.##4.101.32:23
  • 11.##1.62.68:23
  • 89.###.102.255:23
  • 22.###.196.85:23
  • 77.###.127.51:23
  • 18#.#0.25.34:23
  • 1.##.61.73:23
  • 21#.##.51.144:23
  • 18#.##0.239.79:23
  • 99.###.167.169:23
  • 23.##.198.169:23
  • 23#.##.188.172:23
  • 19#.##4.62.215:23
  • 24#.##.188.196:23
  • 16#.#9.60.74:23
  • 28.##6.58.15:23
  • 17#.##1.215.155:23
  • 19#.##5.59.248:23
  • 14#.##4.14.213:23
  • 13.###.173.142:23
  • 90.###.232.182:23
  • 23#.##.221.58:23
  • 25#.##1.220.217:23
  • 17#.##.21.212:23
  • 13#.##.189.242:23
  • 68.###.203.64:23
  • 15#.##.233.177:23
  • 20#.##4.216.74:23
  • 79.##.72.166:23
  • 23#.##9.222.97:23
  • 12#.##1.245.113:23
  • 14#.##5.61.144:23
  • 14.###.88.255:23
  • 13#.##6.228.51:23
  • 20#.#4.165.9:23
  • 10#.#86.8.30:23
  • 11#.##5.89.12:23
  • 27.##.15.64:23
  • 78.##.134.226:23
  • 17#.##.46.204:23
  • 21#.##.143.73:23
  • 16#.##4.107.77:23
  • 19#.##6.181.177:23
  • 23#.##.178.76:23
  • 13#.#.11.144:23
Receives data from the following servers:
  • 18#.###.111.199:7685
  • 18#.###.111.199:4321

Curing recommendations


Linux

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Free trial

One month (no registration) or three months (registration and renewal discount)

Download Dr.Web

Download by serial number