Library
My library

+ Add to library

Contact us
24/7 Tech support | Rules regarding submitting

Send a message

Your tickets

Profile

Linux.Siggen.483

Added to the Dr.Web virus database: 2018-03-18

Virus description added:

Technical Information

Malicious functions:
Substitutes application name for:
  • bitcoin-scheduler
  • bitcoin-http
  • bitcoin-httpworker
  • bitcoin-loadblk
  • bitcoin-torcontrol
  • bitcoin-dnsseed
  • bitcoin-net
  • bitcoin-addcon
  • bitcoin-msghand
  • bitcoin-opencon
  • bitcoin-wallet
Performs operations with the file system:
Creates folders:
  • /root/.bitcoin
  • /root/.bitcoin/database
  • /root/.bitcoin/blocks
  • /root/.bitcoin/blocks/index
  • /root/.bitcoin/chainstate
Creates or modifies files:
  • /root/.bitcoin/.lock
  • /root/.bitcoin/bitcoind.pid
  • /root/.bitcoin/debug.log
  • /root/.bitcoin/.cookie
  • /root/.bitcoin/db.log
  • /root/.bitcoin/blocks/index/LOG
  • /root/.bitcoin/blocks/index/LOCK
  • /root/.bitcoin/blocks/index/MANIFEST-000001
  • /root/.bitcoin/blocks/index/000001.dbtmp
  • /root/.bitcoin/blocks/index/000003.log
  • /root/.bitcoin/blocks/index/MANIFEST-000002
  • /root/.bitcoin/blocks/index/000002.dbtmp
  • /root/.bitcoin/chainstate/LOG
  • /root/.bitcoin/chainstate/LOCK
  • /root/.bitcoin/chainstate/MANIFEST-000001
  • /root/.bitcoin/chainstate/000001.dbtmp
  • /root/.bitcoin/chainstate/000003.log
  • /root/.bitcoin/chainstate/MANIFEST-000002
  • /root/.bitcoin/chainstate/000002.dbtmp
  • /root/.bitcoin/blocks/blk00000.dat
  • /root/.bitcoin/blocks/rev00000.dat
  • /root/.bitcoin/database/log.0000000001
  • /root/.bitcoin/__db.80000001.5a8b4d2
  • /root/.bitcoin/wallet.dat
Deletes files:
  • /root/.bitcoin/blocks/index/MANIFEST-000001"
  • /root/.bitcoin/chainstate/MANIFEST-000001"
Network activity:
Awaits incoming connections on ports:
  • 127.0.0.1:8332
  • 0.0.0.0:8333
Establishes connection:
  • 127.0.0.1:9051
  • <LOCAL_DNS_SERVER>
  • 10#.#32.26.0:0
  • 11#.##.173.205:0
  • 47.##.114.32:0
  • 52.##.202.159:0
  • 10#.#5.53.2:0
  • 47.##.37.150:0
  • 13.##.172.137:0
  • 10#.#4.105.56:0
  • 39.###.246.170:0
  • 11#.##.161.187:0
  • 35.###.225.108:0
  • 19#.#7.68.86:0
  • 18#.##1.104.124:0
  • 21#.#3.7.96:0
  • 19#.#9.12.47:0
  • 47.##.78.228:0
  • 17#.##4.138.110:0
  • 11#.#3.161.21:0
  • 66.##7.65.6:0
  • 10#.##1.23.122:0
  • 10#.#9.2.208:0
  • 10#.##.104.229:0
  • 47.##.32.168:0
  • [2##########:6ab8:3cb8:277a:bd18:6545]:0
  • [2##########:6ab8:1864:1114:fa42:acdc]:0
  • [2#########8:6ab8:185b:2d9:faec:f7]:0
  • [2#########8:6ab8:4:3dda:851d:1939]:0
  • [2##########:79fb:247b:1da4:ba53:51ea]:0
  • [2#########5:79fb:6:3826:cd81:b765]:0
  • [2#########a:64c:384b:1f3b:e8a3:7531]:0
  • [2#####70:67:39d::91]:0
  • [2#########8:953c:479:2e77:b44f:a9f5]:0
  • [2#######0:100:d0::e85:7001]:0
  • [2#########8:953c:407:3a42:7c40:c160]:0
  • [2##########:90d7:10fd:2294:3e77:9ffe]:0
  • [2##########:6abd:38ae:2230:c172:88e1]:0
  • 10#.#8.24.45:0
  • 10#.#8.25.45:0
  • [2#######0:2048:1::681c:192d]:0
  • [2#######0:2048:1::681c:182d]:0
  • 15#.#5.66.14:0
  • 67.##5.149.31:0
  • 71.##.46.76:0
  • 45.##.55.186:0
  • 15#.#9.84.33:0
  • 14#.#6.58.130:0
  • 47.##.36.250:0
  • 11#.##.136.252:0
  • 10#.##.117.172:0
  • 13.##.168.64:0
  • 52.##.14.67:0
  • 45.##.233.225:0
  • 34.##0.57.214:0
  • 10#.#4.104.34:0
  • 17#.##4.151.66:0
  • 80.##2.234.11:0
  • 35.###.234.207:0
  • 10#.#5.213.57:0
  • 54.##9.231.55:0
  • 47.##.56.232:0
  • 20#.#60.27.54:0
  • 10#.##.245.190:0
  • 47.##.189.92:0
  • 10#.##.2.208:8333
  • 19#.##8.218.67:0
  • 11#.#7.181.81:0
  • 78.##9.229.69:0
  • 94.##0.64.143:0
  • 54.##.176.224:0
  • 13#.##1.56.149:0
  • 47.##.32.214:0
  • 11#.##5.143.174:0
  • 18#.##4.156.58:0
  • 10#.##0.220.38:0
  • 15#.#9.241.58:0
  • 39.##7.24.8:0
  • 82.##1.30.36:0
  • 5.###.137.146:0
  • 76.##7.112.69:0
  • 39.##9.11.197:0
  • 21#.#8.5.83:0
  • 67.###.142.252:0
  • 83.##3.66.120:0
  • 13#.##6.109.169:0
  • 13.###.122.196:0
  • 52.##.237.235:0
  • 19#.##7.121.43:0
  • 13#.##.178.160:0
  • 39.##7.59.76:0
  • 10#.##8.144.27:0
  • 89.##1.37.229:0
  • 5.##.61.239:0
  • 17#.##.161.245:0
  • 18#.#.60.45:0
  • 16#.##7.202.193:0
  • 20#.##8.18.222:0
  • 11#.##3.141.87:0
  • 47.##.57.99:0
  • 47.##.62.100:0
  • 47.##.22.103:0
  • 76.##.146.32:0
  • 10#.##8.131.116:0
  • 47.###.144.129:0
  • 19#.##8.102.35:0
  • 84.###.133.114:0
  • 13.##.112.11:0
  • 82.##1.139.97:0
  • 20#.##.247.254:0
  • 17#.##0.102.241:0
  • 88.##8.33.214:0
  • 10#.##4.189.24:0
  • 10#.##.112.123:0
  • 13#.##6.106.118:0
  • 10#.#37.4.33:0
  • 14#.#17.73.86:0
  • 17#.#0.98.177:0
  • 45.##.221.251:0
  • 95.##.228.22:0
  • 35.##2.12.181:0
  • 37.##8.214.19:0
  • 77.###.104.137:0
  • 67.###.190.111:0
  • 11#.##5.211.73:0
  • 47.##.95.148:0
  • 95.##.44.100:0
  • 19#.##4.177.49:0
  • 15#.#9.77.131:0
  • 82.###.133.145:0
  • 16#.##2.168.36:0
DNS ASK:
  • bt#########der.bitcoinunlimited.info
  • bi#####unlimited.info
  • se##.#itcoinabc.org
  • bi###inabc.org
  • se######.bitcoinforks.org
Sends data to the following servers:
  • 10#.##.2.208:8333
  • <LOCAL_DNS_SERVER>
Receives data from the following servers:
  • 127.0.0.1:9051
  • <LOCAL_DNS_SERVER>
  • 10#.##.2.208:8333
Other:
Collects CPU information

Curing recommendations


Linux

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Free trial

One month (no registration) or three months (registration and renewal discount)

Download Dr.Web

Download by serial number