Library
My library

+ Add to library

Contact us
24/7 Tech support | Rules regarding submitting

Send a message

Your tickets

Profile

Linux.Siggen.3391

Added to the Dr.Web virus database: 2020-11-14

Virus description added:

Technical Information

Malicious functions:
Removes itself
Launches itself as a daemon
Substitutes application name for:
  • kk0yiiml2myvb2udnfnti1i
  • urtbu0cgkla4e1lqh2ar
  • 31s4kp200f3utfgx0nyjomy
  • qy20nqnmyejfyb2ipekcpmf
  • lerm1iaa423iastxwvmc02
  • 4qldokn3qsflftxyzchnrmfv
  • eycbtqlknhudgocscumtphg
  • 2d5igfnkhkvdrxc2zhpbb
  • ccyh0hvboi0pachx5r02fj
  • 2o5eixnkl2eyji1vpelwxyb
  • pydbvps3rorkkarweknjmi1
  • f25mbvcun2cnkymd4dwqbt
  • iq2vdevt1wlkve41kn4a3d
  • nnk424c5ic1b5gpxajyjr
  • 1usm0qboc5supnbog0et
  • bzslu13cpwxkem5ql2qr2xhl
  • 04vp4awdzskphqufq1eob
  • k4rjd05kd1nnvtvy4z1z
  • n23g2xhbfwues5hsaq5bu
  • 1zhctrj10lipljy1krdrn5bt
  • rwkffhb5kqnw2dqbl4b1w
  • uqs0pwkhj2u3s0ig4hpzn0wr
  • t1lhfskm55ur5fb2dmgpl
  • otvcy2icjbth0tf3oqnquv
  • 0d2diah0nc5ypbcucksyiqtc
  • 05jmuk4dzv5fvmwaicohy0d
  • dqxlcekf10ecgn5vhnzlqmy
  • l3idak4q3w5n3bixjaj1ky
  • jymskmgwndhq5hmqj0al1t2i
  • qt1wgr3dg2wtbyk3ahyxemp
  • cylu2g1bbib4tb5pb15myze
Performs operations with the file system:
Creates or modifies files:
  • <SAMPLE_FULL_PATH>
Network activity:
Awaits incoming connections on ports:
  • 19#.##8.216.50:3467
Establishes connection:
  • 8.#.8.8:53
  • 20#.###.251.223:32145

Curing recommendations


Linux

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Free trial

One month (no registration) or three months (registration and renewal discount)

Download Dr.Web

Download by serial number