Defend what you create

Other Resources

Close

Library
My library

+ Add to library

Contact us
24/7 Tech support | Rules regarding submitting

Send a message

Your tickets

Profile

Linux.Siggen.1623

Added to the Dr.Web virus database: 2019-04-22

Virus description added:

Technical Information

To ensure autorun and distribution:
Creates or modifies the following files:
  • /etc/init.d/netdns
Malicious functions:
Launches itself as a daemon
Manages services:
  • systemctl enable netdns
  • /usr/sbin/update-rc.d netdns defaults
Launches processes:
  • <SAMPLE_FULL_PATH> [kworker]
  • <SAMPLE_FULL_PATH> [kthreadd]
  • /bin/bash -c chattr -i /usr/lib/systemd/system/netdns.service
  • chattr -i /usr/lib/systemd/system/netdns.service
  • /bin/bash -c chkconfig --add netdns
  • /bin/bash -c systemctl enable netdns
  • /sbin/insserv netdns
Performs operations with the file system:
Creates or modifies files:
  • /tmp/.XIMunix
  • /usr/sbin/kerberods
  • /usr/lib/systemd/system/netdns.service
Locks files:
  • /tmp/.XIMunix
Network activity:
Establishes connection:
  • <LOCAL_DNS_SERVER>
  • 17#.#8.123.25:9
  • [2########::f03c:91ff:fe70:2b9d]:9
  • 19#.##8.217.0:8080
  • <LOCAL_GATE>:8080
  • 19#.##8.217.2:8080
  • 19#.##8.217.3:8080
  • 19#.##8.217.7:8080
  • 19#.##8.217.8:8080
  • 19#.##8.217.9:8080
  • 19#.##8.217.99:8080
  • 19#.##8.217.4:8080
  • 19#.##8.217.5:8080
  • 19#.##8.217.6:8080
  • <LOCAL_GATE>0:8080
  • <LOCAL_GATE>1:8080
  • <LOCAL_GATE>3:8080
  • <LOCAL_GATE>4:8080
  • <LOCAL_GATE>5:8080
  • <LOCAL_GATE>6:8080
  • <LOCAL_GATE>7:8080
  • <LOCAL_GATE>9:8080
  • 19#.##8.217.20:8080
  • 19#.##8.217.21:8080
  • 19#.##8.217.22:8080
  • 19#.##8.217.23:8080
  • 19#.##8.217.24:8080
  • <LOCAL_GATE>2:8080
  • 19#.##8.217.26:8080
  • 19#.##8.217.27:8080
  • 19#.##8.217.28:8080
  • 19#.##8.217.29:8080
  • 19#.##8.217.30:8080
  • 19#.##8.217.32:8080
  • 19#.##8.217.33:8080
  • 19#.##8.217.34:8080
  • 19#.##8.217.35:8080
  • 19#.##8.217.36:8080
  • 19#.##8.217.37:8080
  • 19#.##8.217.38:8080
  • 19#.##8.217.39:8080
  • 19#.##8.217.40:8080
  • 19#.##8.217.41:8080
  • 19#.##8.217.42:8080
  • 19#.##8.217.43:8080
  • 19#.##8.217.44:8080
  • 19#.##8.217.45:8080
  • 19#.##8.217.46:8080
  • 19#.##8.217.47:8080
  • 19#.##8.217.48:8080
  • 19#.##8.217.49:8080
  • 19#.##8.217.50:8080
  • 19#.##8.217.51:8080
  • 19#.##8.217.52:8080
  • 19#.##8.217.53:8080
  • 19#.##8.217.55:8080
  • 19#.##8.217.56:8080
  • 19#.##8.217.57:8080
  • 19#.##8.217.58:8080
  • 19#.##8.217.59:8080
  • 19#.##8.217.60:8080
  • 19#.##8.217.61:8080
  • 19#.##8.217.62:8080
  • 19#.##8.217.64:8080
  • 19#.##8.217.65:8080
  • 19#.##8.217.66:8080
  • 19#.##8.217.68:8080
  • 19#.##8.217.69:8080
  • 19#.##8.217.70:8080
  • 19#.##8.217.71:8080
  • 19#.##8.217.72:8080
  • 19#.##8.217.73:8080
  • 19#.##8.217.74:8080
  • 19#.##8.217.75:8080
  • 19#.##8.217.76:8080
  • 19#.##8.217.77:8080
  • 19#.##8.217.78:8080
  • 19#.##8.217.79:8080
  • 19#.##8.217.80:8080
  • 19#.##8.217.81:8080
  • 19#.##8.217.82:8080
  • 19#.##8.217.83:8080
  • 19#.##8.217.84:8080
  • 19#.##8.217.86:8080
  • 19#.##8.217.87:8080
  • 19#.##8.217.88:8080
  • 19#.##8.217.90:8080
  • 19#.##8.217.91:8080
  • 19#.##8.217.92:8080
  • 19#.##8.217.93:8080
  • 19#.##8.217.94:8080
  • 19#.##8.217.95:8080
  • 19#.##8.217.96:8080
  • 19#.##8.217.97:8080
  • 19#.##8.217.98:8080
  • 19#.##8.217.25:8080
  • 19#.##8.217.85:8080
  • <LOCAL_GATE>8:8080
  • 19#.##8.217.31:8080
  • 19#.##8.217.54:8080
  • 19#.##8.217.63:8080
  • 19#.##8.217.67:8080
  • 19#.##8.217.89:8080
  • <LOCAL_GATE>00:8080
  • <LOCAL_GATE>01:8080
  • <LOCAL_GATE>02:8080
  • <LOCAL_GATE>03:8080
  • <LOCAL_GATE>04:8080
  • <LOCAL_GATE>05:8080
  • <LOCAL_GATE>06:8080
  • <LOCAL_GATE>07:8080
  • <LOCAL_GATE>08:8080
  • <LOCAL_GATE>09:8080
  • <LOCAL_GATE>10:8080
  • <LOCAL_GATE>11:8080
  • <LOCAL_GATE>12:8080
  • <LOCAL_GATE>13:8080
  • <LOCAL_GATE>14:8080
  • <LOCAL_GATE>15:8080
  • <LOCAL_GATE>16:8080
  • <LOCAL_GATE>17:8080
  • <LOCAL_GATE>18:8080
  • <LOCAL_GATE>19:8080
  • <LOCAL_GATE>20:8080
  • <LOCAL_GATE>21:8080
  • <LOCAL_GATE>22:8080
  • <LOCAL_GATE>25:8080
  • <LOCAL_GATE>26:8080
  • <LOCAL_GATE>29:8080
  • <LOCAL_GATE>30:8080
  • <LOCAL_GATE>31:8080
  • <LOCAL_GATE>32:8080
  • <LOCAL_GATE>33:8080
  • <LOCAL_GATE>34:8080
  • <LOCAL_GATE>35:8080
  • <LOCAL_GATE>36:8080
  • <LOCAL_GATE>23:8080
  • <LOCAL_GATE>24:8080
  • <LOCAL_GATE>27:8080
  • <LOCAL_GATE>28:8080
  • <LOCAL_GATE>37:8080
  • <LOCAL_GATE>39:8080
  • <LOCAL_GATE>43:8080
  • <LOCAL_GATE>44:8080
  • <LOCAL_GATE>45:8080
  • <LOCAL_GATE>46:8080
  • <LOCAL_GATE>48:8080
  • <LOCAL_GATE>49:8080
  • <LOCAL_GATE>50:8080
  • <LOCAL_GATE>51:8080
  • <LOCAL_GATE>52:8080
  • <LOCAL_GATE>54:8080
  • <LOCAL_GATE>55:8080
  • <LOCAL_GATE>56:8080
  • <LOCAL_GATE>57:8080
  • <LOCAL_GATE>58:8080
  • <LOCAL_GATE>59:8080
  • <LOCAL_GATE>60:8080
  • <LOCAL_GATE>62:8080
  • <LOCAL_GATE>38:8080
  • <LOCAL_GATE>40:8080
  • <LOCAL_GATE>41:8080
  • <LOCAL_GATE>42:8080
  • <LOCAL_GATE>47:8080
  • <LOCAL_GATE>53:8080
  • <LOCAL_GATE>63:8080
  • <LOCAL_GATE>61:8080
  • <LOCAL_GATE>65:8080
  • <LOCAL_GATE>67:8080
  • <LOCAL_GATE>69:8080
  • <LOCAL_GATE>70:8080
  • <LOCAL_GATE>71:8080
  • <LOCAL_GATE>72:8080
  • <LOCAL_GATE>73:8080
  • <LOCAL_GATE>74:8080
  • <LOCAL_GATE>75:8080
HTTP GET requests:
  • id##t.me/
DNS ASK:
  • id##t.me
Other:
Collects RAM information

Curing recommendations


Linux

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Free trial

One month (no registration) or three months (registration and renewal discount)

Download Dr.Web

Download by serial number

The Russian developer of Dr.Web anti-viruses
Doctor Web has been developing anti-virus software since 1992
Dr.Web is trusted by users around the world in 200+ countries
The company has delivered an anti-virus as a service since 2007
24/7 tech support

Dr.Web © Doctor Web
2003 — 2020

Doctor Web is the Russian developer of Dr.Web anti-virus software. Dr.Web anti-virus software has been developed since 1992.

2-12А, 3rd street Yamskogo polya, Moscow, Russia, 125040