Library
My library

+ Add to library

Contact us
24/7 Tech support | Rules regarding submitting

Send a message

Your tickets

Profile

Linux.Siggen.1061

Added to the Dr.Web virus database: 2018-10-02

Virus description added:

Technical Information

Malicious functions:
Removes itself
Launches itself as a daemon
Substitutes application name for:
  • 9wm0lvo0l
Performs operations with the file system:
Creates or modifies files:
  • /home/.HqMBksnBExR82Ja
Network activity:
Establishes connection:
  • 8.#.8.8:53
  • 18#.##8.208.141:53
  • 27.###.106.241:7000
DNS ASK:
  • mu##.lib
Sends data to the following servers:
  • 18#.###.165.113:5555
  • 24#.##.121.79:5555
  • 65.##.204.163:5555
  • 22#.###.148.173:5555
  • 23#.###.193.219:5555
  • 14#.##1.83.207:5555
  • 13#.##.73.65:5555
  • 10#.##3.43.38:5555
  • 93.##.184.148:5555
  • 21#.##.72.57:5555
  • 3.##.#04.94:5555
  • 23#.##8.164.58:5555
  • 37.###.98.201:5555
  • 24#.##.86.24:5555
  • 17#.##.33.135:5555
  • 19#.##3.95.232:5555
  • 23#.##.92.194:5555
  • 17#.##.70.136:5555
  • 14#.##.170.214:5555
  • 43.##.249.122:5555
  • 96.##.96.85:5555
  • 10.###.218.198:5555
  • 19#.###.246.188:5555
  • 15#.##6.170.39:5555
  • 11#.##.164.234:5555
  • 21#.##.80.232:5555
  • 15#.##5.26.207:5555
  • 12#.###.114.140:5555
  • 15#.##.211.27:5555
  • 22.###.84.68:5555
  • 61.###.60.139:5555
  • 14#.###.142.138:5555
  • 5.##.#12.18:5555
  • 62.###.171.47:5555
  • 8.##.57.99:5555
  • 94.###.48.72:5555
  • 33.###.120.150:5555
  • 4.###.77.253:5555
  • 94.##.12.242:5555
  • 18#.##.55.95:5555
  • 42.##.155.109:5555
  • 21#.##.148.103:5555
  • 5.###.199.49:5555
  • 21#.##.37.93:5555
  • 42.##.2.236:5555
  • 14#.##.59.186:5555
  • 23#.##.159.103:5555
  • 22#.###.195.254:5555
  • 82.###.93.69:5555
  • 92.###.184.159:5555
  • 19.##.13.211:5555
  • 27.###.112.173:5555
  • 14.###.161.217:5555
  • 14#.##3.193.74:5555
  • 14#.##3.7.10:5555
  • 22#.##2.20.177:5555
  • 19#.##6.74.114:5555
  • 15#.##.172.28:5555
  • 49.##.175.21:5555
  • 66.###.244.179:5555
  • 22#.##.126.190:5555
  • 72.###.54.165:5555
  • 13#.##.201.208:5555
  • 20#.##.117.155:5555
  • 38.##.185.62:5555
  • 16#.###.229.161:5555
  • 16#.##8.53.82:5555
  • 15.##.236.150:5555
  • 85.##.215.100:5555
  • 22#.##6.119.67:5555
  • 16.##.17.60:5555
  • 14#.#.161.132:5555
  • 99.###.158.243:5555
  • 91.###.203.206:5555
  • 15#.###.143.225:5555
  • 13#.##.121.182:5555
  • 19#.###.138.101:5555
  • 22#.##.171.65:5555
  • 79.###.47.183:5555
  • 12#.##6.45.230:5555
  • 29.##.24.246:5555
  • 24#.##5.67.243:5555
  • 17#.##.254.29:5555
  • 20#.##8.162.97:5555
  • 40.###.198.87:5555
  • 85.###.137.158:5555
  • 22#.##8.226.29:5555
  • 21.###.147.147:5555
  • 23#.##.155.92:5555
  • 40.###.136.191:5555
  • 67.###.24.167:5555
  • 23#.##.249.164:5555
  • 71.###.41.224:5555
  • 10#.##.217.195:5555
  • 80.###.135.62:5555
  • 10#.##6.239.63:5555
  • 17#.##5.85.244:5555
  • 21#.##.124.5:5555
  • 89.##.241.61:5555
  • 18#.##7.38.102:5555
  • 82.##.196.224:5555
  • 11#.##6.65.201:5555
  • 23#.#.91.95:5555
  • 17#.#.115.170:5555
  • 27.###.235.74:5555
  • 62.###.67.34:5555
  • 18#.##.209.48:5555
  • 78.#.1.238:5555
  • 31.###.161.184:5555
  • 11#.###.146.171:5555
  • 30.###.78.80:5555
  • 94.##.180.203:5555
  • 14#.##.127.142:5555
  • 5.###.14.92:5555
  • 63.###.179.81:5555
  • 96.##.52.59:5555
  • 15#.##.144.134:5555

Curing recommendations


Linux

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Free trial

One month (no registration) or three months (registration and renewal discount)

Download Dr.Web

Download by serial number