Library
My library

+ Add to library

Contact us
24/7 Tech support | Rules regarding submitting

Send a message

Your tickets

Profile

Linux.Siggen.4109

Added to the Dr.Web virus database: 2021-08-11

Virus description added:

Technical Information

Malicious functions:
Launches itself as a daemon
Kills system processes:
  • sshd
Kills the following processes:
  • rpc.idmapd
  • cron
  • atd
  • systemd-logind
  • rsyslogd
  • dbus-daemon
  • agetty
  • exim4
  • bash
  • run.sh
  • kworker/u2:1
Network activity:
Establishes connection:
  • 8.#.8.8:53
  • 80.###.134.53:666
  • 80.###.134.53:374
Attacks using a special dictionary (brute-force technique) via the Telnet protocol.
Sends data to the following servers:
  • 89.##6.86.51:23
  • 20#.##6.13.170:23
  • 32.##.192.158:23
  • 2.###.62.218:23
  • 81.###.127.87:23
  • 93.##2.6.114:23
  • 36.###.130.21:23
  • 32.##7.0.198:23
  • 12#.##8.135.116:23
  • 81.##.225.244:23
  • 65.#.85.151:23
  • 11#.#1.40.89:23
  • 20#.##.199.194:23
  • 18#.#5.49.18:23
  • 71.###.34.110:23
  • 11#.##.205.166:23
  • 17#.##.196.91:23
  • 16#.##2.84.106:23
  • 20#.##0.48.91:23
  • 17#.#55.6.6:23
  • 19#.##.247.41:23
  • 59.###.48.149:23
  • 52.###.229.153:23
  • 13#.##.21.185:23
  • 21#.##8.47.23:23
  • 18#.##.141.67:23
  • 15#.##6.135.190:23
  • 17#.##.245.112:23
  • 11#.##.109.37:23
  • 15#.##.159.59:23
  • 18#.#9.87.38:23
  • 99.###.32.105:23
  • 19#.##4.16.188:23
  • 20#.#4.31.92:23
  • 31.###.248.113:23
  • 5.###.218.179:23
  • 15#.#7.5.33:23
  • 1.##.34.253:23
  • 17#.##.94.210:23
  • 18#.##4.178.59:23
  • 18#.##.254.110:23
  • 75.#.186.90:23
  • 20.###.204.230:23
  • 47.###.224.166:23
  • 12#.##.241.250:23
  • 12.##.253.80:23
  • 18#.##.179.224:23
  • 41.##.80.56:23
  • 11#.##2.125.56:23
  • 95.###.159.50:23
  • 18#.##7.13.175:23
  • 11#.##7.139.145:23
  • 14#.##7.209.145:23
  • 19#.##0.61.246:23
  • 14.##8.160.6:23
  • 11#.#.96.193:23
  • 15#.##.255.245:23
  • 19#.##3.107.135:23
  • 16#.##5.56.172:23
  • 20.##.98.99:23
  • 94.###.236.237:23
  • 11#.##4.4.121:23
  • 21#.##.213.39:23
  • 11#.##7.198.9:23
  • 12#.##.171.223:23
  • 27.##.244.10:23
  • 82.##8.94.13:23
  • 21#.##4.182.75:23
  • 18#.##1.153.160:23
  • 87.###.133.77:23
  • 39.#.222.163:23
  • 21#.##9.94.117:23
  • 8.##.33.94:23
  • 38.###.164.63:23
  • 10#.##3.252.17:23
  • 17#.##3.126.97:23
  • 15#.##.240.199:23
  • 20#.##.63.152:23
  • 22#.##7.160.161:23
  • 17#.##1.214.62:23
  • 13#.##1.175.196:23
  • 15#.##0.83.161:23
  • 63.###.142.215:23
  • 75.###.107.189:23
  • 19#.##.242.187:23
  • 53.##2.80.16:23
  • 19#.##9.11.22:23
  • 18#.#18.21.5:23
  • 54.###.226.165:23
  • 12#.##2.57.106:23
  • 2.###.58.109:23
  • 24.##2.99.94:23
  • 4.##.155.116:23
  • 68.##.162.250:23
  • 18#.##.168.18:23
  • 31.##.58.151:23
  • 46.###.62.144:23
  • 19#.##6.97.24:23
  • 10#.##.67.186:23
  • 21#.##.51.175:23
  • 76.##.135.235:23
  • 60.###.87.251:23
  • 72.###.125.175:23
  • 17#.##8.215.182:23
  • 15#.##0.154.20:23
  • 17#.#.124.20:23
  • 45.###.215.221:23
  • 21#.#.175.109:23
  • 92.###.193.65:23
  • 21#.##.181.149:23
  • 17#.##.199.210:23
  • 11#.##.199.42:23
  • 20#.##8.156.103:23
  • 27.###.163.136:23
  • 41.###.210.171:23
  • 17#.##.85.160:23
  • 12#.##0.73.58:23
  • 18#.##7.50.107:23
  • 11#.##.245.213:23
  • 44.##.240.32:23
  • 39.###.203.175:23
  • 11#.##6.121.123:23
  • 13#.##4.80.44:23
  • 2.###.7.70:23
  • 11#.##4.61.195:23
  • 19#.##0.106.149:23
  • 65.###.38.255:23
  • 11#.##9.133.72:23
  • 73.##.209.1:23
  • 85.##.19.138:23
  • 22#.##3.139.41:23
  • 62.##.243.182:23
  • 20#.##.29.253:23
  • 42.###.37.131:23
  • 40.###.187.107:23
  • 11#.##.252.165:23
  • 12#.##4.37.240:23
  • 66.###.56.159:23
  • 12#.##.249.135:23
  • 80.##.36.224:23
  • 23.###.226.26:23
  • 17#.##.98.156:23
  • 16#.##7.16.193:23
  • 19#.##.234.175:23
  • 65.###.51.202:23
  • 14#.#.142.20:23
  • 48.#.210.162:23
  • 17#.##1.196.157:23
  • 20.##9.82.2:23
  • 64.##.238.64:23
  • 69.###.127.53:23
  • 20#.##4.253.183:23
  • 85.##.203.119:23
  • 21#.##.102.196:23
  • 43.##.179.80:23
  • 9.#.#43.164:23
  • 13#.##8.178.126:23
  • 89.##.22.2:23
  • 14#.##9.234.232:23

Curing recommendations


Linux

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Free trial

One month (no registration) or three months (registration and renewal discount)

Download Dr.Web

Download by serial number