Meine Bibliothek
Meine Bibliothek

+ Zur Bibliothek hinzufügen

Support

Ihre Anfragen

Rufen Sie uns an

+7 (495) 789-45-86

Profil

Linux.Packed.655

Added to the Dr.Web virus database: 2019-10-17

Virus description added:

Technical Information

Malicious functions:
Launches itself as a daemon
Substitutes application name for:
  • dLdUUP01dx3L1dLYd1idYr0hiJQTx1iZ
Network activity:
Establishes connection:
  • 21#.##7.11.112:697
  • 8.#.8.8:53
Attacks using a special dictionary (brute-force technique) via the Telnet protocol.
Sends data to the following servers:
  • 21#.##7.11.112:697
  • 69.#.109.20:23
  • 36.###.171.157:23
  • 15#.##9.31.232:23
  • 15#.##9.82.153:23
  • 18#.##3.37.25:23
  • 20#.##2.244.49:23
  • 18#.##5.188.186:23
  • 18#.##1.79.234:23
  • 84.###.147.161:23
  • 16#.##7.101.43:23
  • 17#.##1.212.84:23
  • 22#.##2.97.142:23
  • 17#.##6.241.9:23
  • 11#.#3.8.48:23
  • 57.##.141.3:23
  • 53.###.38.107:23
  • 18#.#.190.219:23
  • 11#.##4.17.108:23
  • 16#.##6.222.65:23
  • 69.##5.94.78:23
  • 72.##.201.132:23
  • 15#.##2.88.188:23
  • 19#.##6.173.100:23
  • 16#.##.133.194:23
  • 73.###.215.248:23
  • 47.##.56.225:23
  • 13.###.116.46:23
  • 95.###.63.229:23
  • 18#.##.137.158:23
  • 21#.##.186.26:23
  • 19#.#.235.138:23
  • 44.##.49.64:23
  • 91.###.238.99:23
  • 42.###.173.180:23
  • 17#.##.60.228:23
  • 18.##.242.238:23
  • 22#.##8.48.130:23
  • 17#.#7.80.48:23
  • 12#.##.86.124:23
  • 58.###.243.153:23
  • 21#.##.185.100:23
  • 88.###.110.129:23
  • 18#.##8.86.172:23
  • 89.#.43.10:23
  • 16#.##4.34.235:23
  • 93.##.143.75:23
  • 17#.##.126.188:23
  • 12.###.208.158:23
  • 74.###.154.237:23
  • 19#.##9.242.80:23
  • 21#.##9.252.0:23
  • 18#.##1.233.92:23
  • 43.###.178.244:23
  • 15#.##.108.89:23
  • 91.##.130.94:23
  • 90.##.155.196:23
  • 11#.##1.216.151:23
  • 17#.#.166.246:23
  • 14#.##.192.22:23
  • 14#.##4.100.4:23
  • 12#.##6.90.201:23
  • 13#.##6.8.234:23
  • 43.##4.247.6:23
  • 67.##1.52.89:23
  • 13#.##.19.209:23
  • 78.###.186.157:23
  • 84.##.53.168:23
  • 46.###.229.168:23
  • 85.###.242.153:23
  • 11#.##2.14.22:23
  • 18#.##9.172.194:23
  • 22#.##0.80.216:23
  • 17#.#.98.212:23
  • 53.##.210.107:23
  • 18#.#10.1.27:23
  • 22#.##0.62.79:23
  • 79.##5.51.42:23
  • 14.#.128.42:23
  • 11#.##.172.80:23
  • 15#.#7.23.37:23
  • 15#.##6.192.115:23
  • 15#.##.183.10:23
  • 69.###.115.173:23
  • 11#.##7.22.162:23
  • 20#.##5.144.156:23
  • 9.###.196.186:23
  • 16#.##9.75.213:23
  • 94.#.153.36:23
  • 61.###.126.203:23
  • 18#.##1.234.111:23
  • 15#.##6.119.191:23
  • 18.##.181.42:23
  • 16#.#9.98.64:23
  • 94.##0.95.45:23
  • 63.##9.49.76:23
  • 96.##.232.101:23
  • 70.##.191.13:23
  • 20#.##4.54.159:23
  • 39.###.185.198:23
  • 77.###.116.121:23
  • 17#.#7.1.59:23
  • 10#.#8.8.21:23
  • 12#.##7.237.91:23
  • 71.###.216.24:23
  • 18#.##1.224.71:23
  • 12#.##9.100.198:23
  • 90.##.68.31:23
  • 93.##.41.117:23
  • 14#.##9.53.114:23
  • 91.##.31.24:23
  • 44.###.116.150:23
  • 96.##.241.79:23
  • 18#.##3.112.248:23
  • 78.###.73.157:23
  • 15#.##3.105.27:23
  • 15#.##7.70.139:23
  • 10#.##1.55.14:23
  • 18#.##2.15.192:23
  • 16#.##.94.217:23
  • 9.###.183.90:23
  • 16#.##0.125.143:23
  • 20#.##.99.137:23
  • 11#.##2.8.222:23
  • 48.##.189.59:23
  • 78.##.88.52:23
  • 10#.##5.39.95:23
  • 45.###.40.249:23
  • 13.##.199.100:23
  • 16#.##0.191.202:23
  • 91.###.208.29:23
  • 11#.##3.101.174:23
  • 89.###.174.118:23
  • 12#.##6.22.92:23
  • 11#.##0.124.137:23
  • 21#.##0.172.197:23
  • 17#.##5.39.12:23
  • 93.###.231.85:23
  • 10#.#.133.122:23
  • 74.###.129.160:23
  • 17.###.133.77:23
  • 61.###.117.75:23
  • 95.##.146.234:23
  • 18#.##.80.246:23
  • 65.###.223.154:23
  • 12#.##.209.110:23
  • 60.##.161.72:23
  • 16#.##.185.233:23
  • 27.###.238.20:23
  • 85.###.180.130:23
  • 17#.##.113.133:23
  • 11#.##3.83.116:23
  • 18#.##9.241.30:23
  • 83.###.182.50:23
  • 16#.##4.31.198:23
  • 22#.##5.95.175:23
  • 14.###.75.254:23
  • 80.##1.76.47:23
  • 45.##.176.179:23
  • 81.###.135.234:23
  • 22#.##6.137.143:23
  • 22#.##3.8.215:23
  • 22#.##.39.179:23
  • 16#.##9.101.207:23
  • 20#.##0.240.162:23
  • 99.##2.9.35:23
  • 13.##.149.22:23
  • 57.##2.98.82:23
  • 97.##.94.179:23
  • 10#.#.196.174:23
  • 34.##.41.95:23
  • 95.##.63.89:23
  • 15#.##.131.70:23
  • 18.###.193.95:23
  • 27.##1.63.92:23
  • 20#.##.187.21:23
  • 22#.##0.64.20:23
  • 15#.##6.13.246:23
  • 21#.##0.68.75:23
  • 85.###.114.228:23
  • 41.###.34.131:23
  • 1.##.150.97:23
  • 48.##.243.37:23
  • 10#.##6.138.238:23
  • 11#.##.127.183:23
  • 17#.#3.61.84:23
  • 19#.##1.79.57:23
  • 14#.##.184.150:23
  • 10#.##.158.29:23
  • 19#.#4.66.92:23
  • 66.###.49.102:23
  • 15#.#8.66.44:23
  • 20#.##2.72.16:23
Receives data from the following servers:
  • 21#.##7.11.112:697

Curing recommendations


Linux

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Free trial

One month (no registration) or three months (registration and renewal discount)

Download Dr.Web

Download by serial number