JavaScript support is required for our site to be fully operational in your browser.
Linux.Siggen.2186
Added to the Dr.Web virus database:
2019-10-03
Virus description added:
2019-10-03
Technical Information
Malicious functions:
Removes itself
Substitutes application name for:
apMMpew8HuQM2t6lveW1bMjAd1jMWBauAQ6y1CjttjnwMwBy1AWnA2jjCMpjQlbKdAoN1eWKM3rN4aW1K7xpjtAlp11yKj3vNXxjxKtKjaAWpAHQbuajNv1KWoAK3pov3yjtt1AKybRbAxKao4MV4Co8AMWl1A8jKjNjNpwoalpArwlWNnnrCjcVab71KK7eowByeBAntQAvpjv1wMRd4veuVtvwpWA3V6x4jdM2B1j712QW8aw13CpBHvAlQa1QtQ1nnWttoWNAA7vbtKapp3AxloVayKvdR1paAAvupuQpWAMxwlrVAAQaW8oj8j2jKd6oKjQK61AQlreuHAjoawvCNAWtBjKAWj1tnjWAcAR2ljNjW4wj71AbAwKVBp6l2tcM4A8H1ejnVatVpoAjK6ldo6XavBaWR6W1CaWoQdAo3oNAjuAWvjt8AKjXj1pyrNcoadaKjA1toaauMoQnAK4anw6aoNaKoHaXKRMyX87e7A8NNeKuaWAvoKRAMwBHvWbCWr1A4dwNeynodWetp14K1jwjoA2aupMbjjMQCwxaw161WtAaKApWWAK1bjrnCAWppMpyMKBKAxAWHAu1VBnAnN1MyyrwojNMjwMjMw1NNwAaACadMd7AKAMWpAlewxj8VwAtVaacoQMyoCuRvK71oKAy6olKVna4KAuelXtBK3KAaa4oAuKQjKwbpp87bNCoANAbCwQaR16vRp31prjArblRlwtd3jQA2lvp1altM1bvv1MpvQbjaAAlAdearRxjMMrNpXvcRjdN11BW6CadNX1ooXAa1Koe1BNyQAQ1dAwxnvdM4ApKtnaaAKAewjoa1WMWp1tbWWa1yMtyv14AWpA2MWVdKejr6oVtllHdNxrtrvN7p7No7MMAN[rkmodule] [run.sh][PPID:0x217] [sleep][PID:0x21b] do_filp_open. Filename: "/usr/lib/locale/locale-archive"
Network activity:
Awaits incoming connections on ports:
Establishes connection:
8.#.8.8:53
5.#.##.205:34255
Attacks using a special dictionary (brute-force technique) via the Telnet protocol.
DNS ASK:
Sends data to the following servers:
20.##.7.200:23
11#.#.156.242:23
22#.##7.221.157:23
13#.##5.21.114:23
82.###.235.105:23
18#.##2.104.143:23
74.###.24.136:23
17#.##.43.131:23
98.##.167.81:23
37.##3.80.37:23
20#.##3.170.195:23
92.##.178.36:23
61.###.126.237:23
45.##.180.152:23
66.##6.11.75:23
13#.##7.163.224:23
10#.##7.133.62:23
19#.##.110.234:23
15#.##.112.141:23
17#.##0.123.114:23
12#.##6.88.236:23
13#.##6.104.6:23
45.##6.58.58:23
13#.##9.7.121:23
11#.##6.53.245:23
75.###.242.198:23
13#.##.239.138:23
18#.##4.41.245:23
10#.##.49.138:23
19#.#.46.165:23
20#.##7.115.111:23
13#.##3.121.23:23
19#.##8.249.154:23
41.###.252.38:23
32.###.166.57:23
16#.##.255.145:23
18#.##8.123.21:23
10#.##.153.100:23
63.##.74.229:23
97.###.44.189:23
11#.##1.242.79:23
10#.##5.74.128:23
77.###.149.69:23
79.##.83.20:23
18.###.112.203:23
15#.##7.196.47:23
19#.##3.106.34:23
22#.##.46.147:23
18#.##7.25.64:23
57.##7.38.65:23
18.###.104.204:23
17#.##.174.219:23
53.###.16.145:23
46.###.124.59:23
72.#.216.100:23
74.##3.240.3:23
48.##.108.160:23
10#.##0.64.114:23
81.##8.82.17:23
13#.##3.52.183:23
18#.##.216.245:23
14#.##5.117.244:23
19#.##.177.133:23
68.##.211.97:23
21#.##3.203.9:23
13#.##.33.129:23
61.###.176.41:23
53.##.90.17:23
51.##.211.82:23
11#.##.39.255:23
99.##.76.60:23
15#.##6.110.103:23
31.###.219.169:23
14.###.225.112:23
22#.##7.112.253:23
12#.##5.222.152:23
61.##.225.154:23
89.##.151.152:23
38.###.28.200:23
37.#.157.43:23
27.###.177.76:23
18.##.91.16:23
39.###.43.128:23
89.##.30.183:23
95.###.103.54:23
81.##.176.125:23
65.##.75.90:23
15#.##.20.192:23
15#.##2.176.50:23
19#.##9.154.61:23
11#.##.187.44:23
82.#.137.232:23
81.##.168.17:23
18#.##5.134.91:23
95.##.61.183:23
17.###.196.179:23
21#.##3.83.237:23
84.###.125.173:23
12#.##.217.36:23
Curing recommendations
Linux
Free trial
One month (no registration) or three months (registration and renewal discount)
Download Dr.Web for Android
Free three-month trial
All protection features available
Renew your trial license in AppGallery/on Google Pay
By continuing to use this website, you are consenting to Doctor Web’s use of cookies and other technologies related to the collection of visitor statistics. Learn more
OK