Library
My library

+ Add to library

Contact us
24/7 Tech support | Rules regarding submitting

Send a message

Your tickets

Profile

Linux.Siggen.3389

Added to the Dr.Web virus database: 2020-11-14

Virus description added:

Technical Information

Malicious functions:
Removes itself
Launches itself as a daemon
Substitutes application name for:
  • zpgam4otulkdasaohcuhp
  • tjsh30rlnm2xf55ag5zr
  • mu0gaofasv0n300cntmw
  • w4soyrc1anokd2xpxkpkmi
  • wnt5nkzspkv4w54upmxe
  • lnhxmqyawns3mljqfdkxqvuj
  • wsdqnm15djdtetcg3h241
  • 35gofoo2tssz3wtxk1znu2xa
  • ko55cyp5wccblx5ptiw1gfp
  • xxgnb3qkwxcyaijdqkkz4y
  • qfz5xzjlqyi0rux2c00lmez
  • uhgrrmd43hrv3dzeugn201q
  • epj10alem2sema2khq2q
  • 24amcoeohdjn0znl4tiwwnuh
  • jjmd4xvwzsu4f21cvkxn20w
  • zf4qjmyq0ukufpkq0iaztbk
  • 32zlndqyvf0zb0liuprusm
  • jo2s0a1yo2mtg1hcvs5t
  • mav3k43xi1gmcbuhgvib
  • jdn4gu5nhenpfcb3thn2pb3n
  • ngcq0kuxjekuxspprftauwl
  • rzghlgbyxajmc3ub5fa10
  • dbezvvhgldpg3ccbwhnv4gmc
  • mowjsxa43pckdgojg3l0
  • 4phpu2ydnkrxz0ez0mkydsdc
  • astrshnv5zhdd4qihayahu
  • n12qm2eutvtnqx42z2pho
  • 1zl4eepfjssrfh3nfdrq
  • nfp4tqdkyhfjocfejqlgitxi
  • cetsa4hi5vccxv4gutl2t2
  • ekh5v4qe5vlraqottefg2
Performs operations with the file system:
Creates or modifies files:
  • <SAMPLE_FULL_PATH>
Network activity:
Awaits incoming connections on ports:
  • 19#.##8.200.50:3467
Establishes connection:
  • 8.#.8.8:53
  • 20#.###.251.223:32145

Curing recommendations


Linux

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Free trial

One month (no registration) or three months (registration and renewal discount)

Download Dr.Web

Download by serial number