Library
My library

+ Add to library

Contact us
24/7 Tech support | Rules regarding submitting

Send a message

Your tickets

Profile

Linux.Siggen.1046

Added to the Dr.Web virus database: 2018-09-30

Virus description added:

Technical Information

Malicious functions:
Launches itself as a daemon
Substitutes application name for:
  • PiJSldU1nai2FK5K
Network activity:
Awaits incoming connections on ports:
  • 0.0.0.0:23
  • 0.0.0.0:22
  • 0.0.0.0:443
  • 0.0.0.0:81
  • 0.0.0.0:8080
Establishes connection:
  • 8.#.8.8:53
  • 20#.##1.34.89:721
Attacks using a special dictionary (brute-force technique) via the Telnet protocol.
Sends data to the following servers:
  • 20#.##1.34.89:721
  • 20#.##2.172.159:23
  • 43.###.32.211:23
  • 76.##.87.58:23
  • 63.##6.5.206:23
  • 79.###.169.167:23
  • 69.###.252.16:23
  • 14#.#.142.123:23
  • 21#.##0.186.187:23
  • 38.###.19.222:23
  • 40.###.123.131:23
  • 70.##4.93.75:23
  • 22#.##.247.125:23
  • 4.###.138.190:23
  • 10#.##.173.221:23
  • 76.##.217.236:23
  • 74.###.148.224:23
  • 11#.##.209.149:23
  • 12#.##6.208.20:23
  • 12#.#9.150.4:23
  • 67.##3.129.9:23
  • 24.###.14.171:23
  • 10#.##1.102.198:23
  • 10#.##2.208.62:23
  • 12.##9.74.5:23
  • 86.###.235.81:23
  • 19#.##.241.54:23
  • 64.###.211.125:23
  • 46.###.30.131:23
  • 14#.##.20.176:23
  • 17#.##.23.231:23
  • 59.##2.54.89:23
  • 18#.##.148.66:23
  • 18#.##6.44.37:23
  • 32.###.133.74:23
  • 96.###.194.230:23
  • 18#.##.191.202:23
  • 95.##.186.204:23
  • 53.#.164.80:23
  • 27.###.250.124:23
  • 74.##.47.176:23
  • 18.###.249.104:23
  • 59.##0.1.113:23
  • 12#.##5.73.45:23
  • 42.##.3.199:23
  • 17#.##2.124.14:23
  • 15#.##8.239.25:23
  • 53.##.216.120:23
  • 69.###.108.133:23
  • 18#.##.232.77:23
  • 65.##.87.173:23
  • 10#.##0.169.54:23
  • 24.###.27.225:23
  • 75.###.175.134:23
  • 21#.##3.167.3:23
  • 10#.##0.235.244:23
  • 19#.##1.81.195:23
  • 10#.##1.160.221:23
  • 13#.##9.192.71:23
  • 19#.#6.9.252:23
  • 84.###.14.244:23
  • 69.###.159.121:23
  • 18#.##1.108.98:23
  • 18#.##0.172.167:23
  • 18#.##.181.39:23
  • 14#.##.43.232:23
  • 12#.##1.61.127:23
  • 68.###.77.102:23
  • 96.###.183.139:23
  • 36.##.164.79:23
  • 19#.##1.144.50:23
  • 14#.##8.231.77:23
  • 78.##.252.53:23
  • 18#.#5.13.5:23
  • 80.###.179.84:23
  • 11#.#39.95.8:23
  • 10#.#4.52.60:23
  • 14#.#6.147.5:23
  • 19.###.152.200:23
  • 53.##.29.113:23
  • 36.###.198.191:23
  • 16#.##.135.23:23
  • 11#.##.152.21:23
  • 12#.##.149.245:23
  • 65.###.146.220:23
  • 20#.##.191.80:23
  • 86.##.85.224:23
  • 20.##.109.234:23
  • 93.##.105.130:23
  • 1.##.218.177:23
  • 21#.#0.37.14:23
  • 22#.##.107.201:23
  • 24.##3.12.18:23
  • 16#.##5.52.233:23
  • 18#.#4.2.244:23
  • 21#.#3.86.76:23
  • 10#.##8.110.174:23
  • 17#.#.182.66:23
  • 11#.##.112.20:23
  • 15#.##3.46.80:23
  • 40.#.31.155:23
  • 19#.##4.229.211:23
  • 88.##.106.40:23
  • 19#.##4.169.2:23
  • 16#.##.229.139:23
  • 53.###.171.219:23
  • 84.##.57.49:23
  • 58.###.69.188:23
  • 8.###.2.111:23
  • 12#.##9.252.149:23
  • 12#.##4.211.245:23
  • 11#.##.250.46:23
  • 17#.##5.220.23:23
  • 53.###.124.153:23
  • 17#.##.237.173:23
  • 35.###.112.201:23
  • 22#.##0.189.23:23
  • 18#.##.254.243:23
  • 14.###.50.153:23
  • 9.##.197.228:23
  • 34.###.89.151:23
  • 12#.#7.139.0:23
  • 57.##.247.201:23
  • 16#.##6.202.153:23
  • 11#.##1.77.136:23
  • 12#.##1.199.23:23
  • 20.#.19.136:23
  • 89.###.151.106:23
  • 19#.##7.87.159:23
  • 10#.##.231.69:23
  • 40.###.193.31:23
  • 18#.##2.124.186:23
  • 62.##.136.45:23
  • 20#.##0.75.58:23
  • 34.##.58.192:23
  • 20#.##3.147.84:23
  • 42.###.165.36:23
  • 17#.##5.217.90:23
  • 89.#.213.147:23
  • 67.##5.0.41:23
  • 17#.##0.199.84:23
  • 19#.##8.223.218:23
  • 32.##.249.195:23
  • 41.###.189.202:23
  • 46.##3.83.30:23
  • 53.##9.2.213:23
  • 72.##3.89.24:23
  • 11#.##.170.187:23
  • 16#.##4.202.76:23
  • 16#.##9.102.216:23
  • 16#.#9.3.54:23
  • 90.##.128.199:23
  • 59.###.81.252:23
  • 42.###.160.31:23
  • 69.###.173.118:23
  • 20#.##9.78.41:23
  • 69.##9.94.3:23
  • 11#.##.130.218:23
  • 84.##.244.163:23
  • 75.###.136.62:23
  • 41.##.105.249:23
  • 21#.#.241.4:23
  • 99.##.79.233:23
  • 41.###.109.78:23
  • 15#.##6.70.32:23
  • 19#.##8.82.245:23
  • 82.##6.238.7:23
  • 24.###.10.220:23
  • 43.###.199.52:23
  • 13#.#.50.174:23
  • 78.##.216.43:23
  • 78.###.241.98:23
  • 16#.#.113.116:23
  • 19#.#.105.132:23
  • 78.##.162.78:23
  • 10#.##.206.192:23
  • 40.##.72.7:23
  • 16#.##.92.116:23
Receives data from the following servers:
  • 20#.##1.34.89:721

Curing recommendations


Linux

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Free trial

One month (no registration) or three months (registration and renewal discount)

Download Dr.Web

Download by serial number