Library
My library

+ Add to library

Contact us
24/7 Tech support | Rules regarding submitting

Send a message

Your tickets

Profile

Linux.Siggen.2002

Added to the Dr.Web virus database: 2019-07-16

Virus description added:

Technical Information

Malicious functions:
Launches itself as a daemon
Substitutes application name for:
  • iogvxvukno0
Performs operations with the file system:
Deletes folders:
  • <SAMPLE_FULL_PATH>
Creates or modifies files:
  • <SAMPLE_FULL_PATH>
Deletes files:
  • <SAMPLE_FULL_PATH>
Network activity:
Awaits incoming connections on ports:
  • 127.0.0.1:8888
Establishes connection:
  • 8.#.8.8:53
  • 8.#.4.4:53
  • 5.###.227.65:6593
HTTP GET requests:
  • http://##.##5.186.250/
DNS ASK:
  • oh####.#aiseyourdongers.pw
Sends data to the following servers:
  • 24#.##8.62.17:8080
  • 16#.##.144.206:82
  • 20#.#0.97.52:82
  • 21#.###.120.208:8080
  • 14#.##4.231.233:80
  • 16#.##6.176.59:81
  • 94.##.131.46:8000
  • 22#.##9.11.47:8000
  • 13.##.140.242:8000
  • 16#.##6.173.166:81
  • 29.###.55.145:81
  • 95.###.1.254:8080
  • 77.##.98.102:8000
  • 19#.##1.32.130:8000
  • 25.###.120.41:8000
  • 75.###.77.135:80
  • 19#.##1.27.34:8000
  • 20#.##3.40.94:8080
  • 23#.##8.197.170:82
  • 24#.##.153.225:80
  • 14#.##.248.233:81
  • 25#.##.171.250:82
  • 8.##.81.76:8080
  • 17#.##.197.15:80
  • 24#.##5.63.155:88
  • 91.###.69.123:80
  • 78.##.36.210:8000
  • 13#.##8.40.69:82
  • 22#.##7.86.34:88
  • 14#.##.131.213:80
  • 23#.##7.131.5:8000
  • 20#.##6.102.240:81
  • 23#.##.112.208:8080
  • 13#.##.114.194:8080
  • 19#.##8.92.166:8000
  • 56.#.20.108:80
  • 16#.#0.33.6:80
  • 20#.##8.74.121:8000
  • 10.###.10.158:82
  • 11#.##7.83.152:80
  • 58.##.206.227:80
  • 35.#.4.186:88
  • 59.###.90.100:80
  • 12#.##3.85.213:82
  • 16.###.128.29:81
  • 16#.##.213.97:80
  • 20#.###.156.160:8080
  • 17#.##1.56.16:8000
  • 21#.#4.40.23:82
  • 10#.#7.91.8:80
  • 12#.##0.154.132:82
  • 25#.##9.180.216:80
  • 17#.##4.241.224:88
  • 16#.###.127.232:8000
  • 71.##8.48.69:82
  • 17#.##.25.145:88
  • 24#.##.233.16:81
  • 12#.##8.253.142:82
  • 14#.##.186.100:88
  • 42.###.201.19:8000
  • 10#.##2.251.166:80
  • 97.###.172.172:81
  • 15#.##2.127.10:8080
  • 25#.#.239.232:81
  • 11#.##.245.184:8000
  • 19#.##.218.125:82
  • 23#.##7.226.141:82
  • 24#.##8.44.202:88
  • 32.###.163.180:82
  • 10#.##.173.134:8000
  • 16#.##.168.5:8080
  • 31.###.143.39:88
  • 19#.##0.131.98:88
  • 1.###.251.56:82
  • 23#.##7.117.29:8080
  • 72.###.13.178:80
  • 13#.##3.84.55:8080
  • 17#.#6.7.14:88
  • 19#.##3.210.41:80
  • 25#.###.121.148:8080
  • 61.###.154.237:8000
  • 39.##.124.178:8080
  • 23#.##9.194.200:82
  • 34.###.250.47:8080
  • 17#.##.254.117:8000
  • 15#.##3.56.96:88
  • 10#.##.138.192:8080
  • 14#.##.13.132:81
  • 11#.##9.196.82:82
  • 19#.#.119.173:82
  • 21#.##8.15.187:81
  • 20#.##1.77.92:80
  • 11#.##3.237.63:81
  • 89.###.209.132:88
  • 72.###.129.237:88
  • 13#.##5.189.17:80
  • 14#.##3.183.44:8000
  • 5.###.209.176:80
  • 17#.##5.17.91:80
  • 34.##1.53.72:81
  • 11#.##0.155.135:80
  • 23#.##3.47.239:88
  • 66.##.120.187:8000
  • 85.##.236.130:82
  • 13#.##.131.137:8000
  • 93.##0.88.55:80
  • 83.###.237.236:8000
  • 14#.###.163.236:8000
  • 81.###.40.67:8000
  • 19#.##9.52.35:8080
  • 10.###.222.185:82
  • 33.###.72.69:8000
  • 15#.##.92.129:8000
  • 14#.##6.21.250:8080
  • 24#.##1.187.188:80
  • 48.###.156.145:8000
  • 10#.###.144.223:8080
  • 24#.##.127.195:8000
  • 21.##.6.37:80
  • 99.###.198.155:82
  • 34.##.132.16:8000
  • 69.###.86.186:8000
  • 70.##.7.237:8080
  • 23#.##.164.102:8080
  • 12#.##.85.231:8000
  • 23#.##.22.226:88
  • 29.##.14.108:80
  • 74.###.141.148:8080
  • 14#.##2.203.242:80
  • 23#.##2.33.49:82
  • 12#.#.144.68:81
  • 11#.##3.173.83:88
  • 25#.##1.56.244:81
  • 17#.##.169.244:8000
  • 20#.##2.134.246:82
  • 15#.##8.140.240:88
  • 14#.##1.137.161:81
  • 94.###.222.243:8000
  • 85.###.215.144:82
  • 20#.##8.40.58:82
  • 46.###.1.69:8000
  • 40.##5.108.5:88
  • 12#.##8.167.16:81
  • 10#.##9.45.100:8080
  • 12#.##1.148.43:82
  • 12#.##4.155.23:82
  • 10.###.147.66:8000
  • 20#.##.28.198:8080
  • 16#.##4.156.239:81
  • 8.###.149.86:8000
  • 36.###.233.57:88
  • 21#.#5.19.61:82
  • 18#.###.179.102:8080
  • 59.##4.72.23:80
  • 20#.###.123.249:8000
  • 10#.##.217.173:88
  • 77.###.167.55:88
  • 92.###.234.254:80
  • 16#.#6.2.21:88
  • 19#.##.147.200:81
  • 71.##.230.253:80
  • 12#.##9.244.240:88
  • 11#.##9.92.10:8000
  • 20#.###.110.149:8000
  • 23#.##3.174.84:81
  • 17#.##2.158.168:82
  • 13#.###.217.114:8000
  • 25#.##4.164.70:81
  • 21#.##.180.61:82
  • 13#.#3.213.5:81
  • 51.###.35.155:88
  • 20#.#.233.29:8000
  • 20#.##.206.43:8080
  • 14#.##3.110.38:8000
  • 42.###.200.99:8000
  • 16#.##9.12.132:82
  • 21#.##.122.221:88
  • 23#.#8.57.93:80
  • 12#.#.213.55:8080
  • 22#.##.128.65:80
  • 20.###.25.46:8080
  • 10#.##.145.71:88
  • 18#.##2.65.249:88
  • 23#.#.20.43:88
  • 10#.##.232.70:8000
  • 81.###.105.111:8080
  • 19#.##5.82.236:88
  • 13#.##4.172.75:82
  • 16#.##9.118.153:81
  • 59.###.193.12:8000
  • 11#.##.106.246:8000
  • 24#.##.160.99:82
  • 24.###.134.12:81
  • 13#.##9.94.10:88
  • 22#.#3.3.53:80
  • 12#.##3.117.156:81
  • 70.###.62.63:8080
  • 18#.##8.98.165:82
  • 16.##.14.234:80
  • 21#.##.87.103:8080
  • 91.##.236.122:88
  • 12#.##3.49.165:80
  • 6.###.216.125:8000
  • 22#.###.129.168:8080
  • 17#.#.4.25:8000
  • 54.###.254.247:81
  • 37.###.205.184:81
  • 10#.###.151.141:8080
  • 47.##1.49.52:82
  • 22#.##6.137.37:80
  • 93.##.174.41:8000
  • 10#.##4.60.144:82
  • 21#.###.236.151:8000
  • 24#.###.126.240:8000
  • 15#.##.156.27:82
  • 27.###.123.65:82
  • 12#.##.76.157:8000
  • 19#.##4.100.180:80
  • 15#.##8.149.174:82
  • 10#.##9.244.218:82
  • 17#.##1.22.60:88
  • 89.###.226.76:8080
  • 51.###.128.70:81
  • 34.###.169.58:81
  • 24#.##4.105.62:80
  • 20#.##.148.194:81
  • 14#.##.214.135:8000
  • 32.###.184.32:81
  • 62.###.238.119:88
  • 17#.##9.18.89:88
  • 20#.###.232.254:8080
  • 18#.###.240.225:8000
  • 18#.##.122.99:82
  • 13#.###.248.174:8080
  • 21#.##.159.229:8000
  • 39.##.114.106:80
  • 17#.##.24.138:80
  • 22#.#6.2.51:88
  • 48.###.145.231:88
  • 38.##.80.41:8000
  • 18#.##2.46.252:81
  • 62.###.65.236:8000
  • 36.###.72.217:82
  • 17#.##.125.197:80
  • 16#.##.7.216:8080
  • 16#.##.91.164:8000
  • 14#.###.236.211:8000
  • 24#.##4.37.93:81
  • 13#.##.95.140:8000
  • 19#.###.142.169:8000
  • 21#.#.96.227:82
  • 19#.##.226.100:82
  • 22#.##2.82.241:88
  • 11#.##7.94.178:81
  • 12#.##8.20.216:8000
  • 22#.##9.82.119:8000
  • 23.###.128.14:82
  • 18#.##8.175.101:82
  • 10.##.161.104:80
  • 24#.##1.248.237:81
  • 65.###.151.173:81
  • 41.###.102.86:8000
  • 16.##9.113.8:81
  • 18#.##5.226.76:8080
  • 20#.##2.158.96:8000
  • 4.###.214.172:81
  • 70.###.142.226:8080
  • 14#.##.174.176:82
  • 23.##.30.200:80
  • 16#.##0.26.238:82
  • 11#.##.185.66:80
  • 66.###.148.155:80
  • 11#.###.107.200:8000
  • 22#.##3.145.164:82
  • 62.##7.63.66:82
  • 3.##.216.172:81
  • 35.###.103.39:88
  • 48.##.76.61:8080
  • 22#.#8.80.69:82
  • 14#.##.165.199:8080
  • 7.###.33.153:88
  • 25#.##.214.130:82
  • 12#.#59.7.27:88
  • 11.##3.5.245:88
  • 70.###.73.217:8000
  • 20#.##4.72.60:88
  • 69.###.137.64:81
  • 23#.##.57.93:8080
  • 85.##.216.206:8080
  • 20#.##.234.181:88
  • 49.##.222.181:80
  • 19#.##.62.136:8000
  • 19#.##.9.66:8080
  • 66.##.240.170:8000
  • 19#.##.209.1:8000
  • 24#.##8.118.104:82
  • 12#.##.227.240:8000
  • 16#.##.75.203:82
  • 15#.##1.67.185:80
  • 14#.##4.128.12:8080
  • 23#.##3.64.10:8080
  • 83.###.135.118:8080
  • 21#.#.15.215:82
  • 24#.#.235.76:81
  • 24.##.154.2:88
  • 18#.##4.137.97:82
  • 10#.##4.215.90:80
  • 99.##.17.173:82
  • 92.##5.17.27:82
  • 16#.##3.6.144:82
  • 10#.##1.254.20:81
  • 18.###.129.26:8000
  • 18#.###.184.238:8080
  • 15#.##6.74.216:8000
  • 25#.##.213.26:8000
  • 19#.##.35.55:8080
  • 19#.##6.84.171:8000
  • 23#.##8.149.218:81
  • 20#.##4.44.170:8000

Curing recommendations


Linux

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Free trial

One month (no registration) or three months (registration and renewal discount)

Download Dr.Web

Download by serial number