Library
My library

+ Add to library

Contact us
24/7 Tech support | Rules regarding submitting

Send a message

Your tickets

Profile

Linux.Siggen.4376

Added to the Dr.Web virus database: 2022-01-31

Virus description added:

Technical Information

Malicious functions:
Launches itself as a daemon
Substitutes application name for:
  • mbjlRjUdg2TaO
Kills the following processes:
  • <SAMPLE>
Network activity:
Awaits incoming connections on ports:
  • 19#.##8.214.50:1333
Establishes connection:
  • 8.#.8.8:53
  • 16#.##2.70.193:8080
Attacks using a special dictionary (brute-force technique) via the Telnet protocol.
Sends data to the following servers:
  • 16#.##2.70.193:8080
  • 23#.##8.53.112:23
  • 24#.#.174.102:23
  • 19#.##3.221.229:23
  • 22#.##1.35.73:23
  • 17#.#4.92.51:23
  • 22#.##.77.122:23
  • 23#.##9.148.149:23
  • 12.#.177.204:23
  • 15#.##.121.219:23
  • 21#.##3.172.129:23
  • 22#.##3.49.39:23
  • 18#.##9.208.212:23
  • 20#.##9.120.66:23
  • 25#.##2.198.26:23
  • 22#.##5.227.228:23
  • 98.###.203.86:23
  • 85.###.213.217:23
  • 10#.##1.85.85:23
  • 10#.##2.170.70:23
  • 18#.##.198.201:23
  • 21#.##8.225.12:23
  • 24#.##2.92.181:23
  • 15#.##4.217.119:23
  • 12#.#.232.180:23
  • 45.##.244.168:23
  • 14#.##4.131.48:23
  • 22#.##.98.231:23
  • 11#.##1.201.48:23
  • 13#.##.137.205:23
  • 14#.##.193.72:23
  • 15#.##0.253.213:23
  • 15#.##6.230.98:23
  • 52.##.160.13:23
  • 17#.##.25.186:23
  • 86.##.228.29:23
  • 22#.##.89.142:23
  • 17#.##.127.134:23
  • 12#.##2.102.76:23
  • 11.##.96.134:23
  • 99.###.205.126:23
  • 70.##.225.142:23
  • 14#.##7.111.174:23
  • 20#.##0.123.143:23
  • 85.###.42.109:23
  • 13#.##.230.16:23
  • 21#.##.255.149:23
  • 16#.##9.106.236:23
  • 19#.##0.136.24:23
  • 7.###.242.187:23
  • 18#.##3.132.230:23
  • 95.##.51.190:23
  • 68.##.107.252:23
  • 21#.##3.179.125:23
  • 13#.##.84.104:23
  • 35.###.195.255:23
  • 21#.##9.74.125:23
  • 61.###.96.114:23
  • 11#.#1.4.127:23
  • 20#.##.141.147:23
  • 63.##.8.67:23
  • 9.###.121.138:23
  • 46.##.205.199:23
  • 15#.##8.189.232:23
  • 18#.##2.172.185:23
  • 12#.##1.51.254:23
  • 14#.#9.19.73:23
  • 24#.##9.115.32:23
  • 6.##.157.102:23
  • 23#.##5.231.112:23
  • 13#.##8.26.65:23
  • 18#.##7.139.114:23
  • 24#.##0.36.233:23
  • 15#.#2.92.1:23
  • 37.##2.10.81:23
  • 62.##6.66.33:23
  • 17.##.201.5:23
  • 13#.##4.84.163:23
  • 15#.#.48.213:23
  • 16.###.221.64:23
  • 21#.##1.169.101:23
  • 58.###.210.78:23
  • 14#.##.250.21:23
  • 43.##.154.201:23
  • 36.###.254.46:23
  • 77.###.85.195:23
  • 24#.##2.58.73:23
  • 15#.##7.123.74:23
  • 13#.##5.222.166:23
  • 18.###.168.55:23
  • 56.##.85.61:23
  • 21#.##1.54.212:23
  • 12#.##9.223.29:23
  • 35.###.173.94:23
  • 18#.##6.235.150:23
  • 17#.##8.238.56:23
  • 17#.##.114.201:23
  • 15.##.133.15:23
  • 12#.##3.110.247:23
  • 12#.##.105.15:23
  • 95.###.187.98:23
  • 11#.##2.237.85:23
  • 16#.##5.165.248:23
  • 64.###.170.226:23
  • 11#.##3.113.51:23
  • 25#.##3.29.34:23
  • 18#.#09.43.4:23
  • 13#.##.176.145:23
  • 86.##8.93.27:23
  • 42.###.99.187:23
  • 17#.##3.246.42:23
  • 25#.##.179.68:23
  • 13#.##6.53.203:23
  • 15#.#5.8.199:23
  • 23#.##.154.112:23
  • 15#.##9.69.63:23
  • 25#.##3.138.251:23
  • 16#.##.142.239:23
  • 19#.##.196.175:23
  • 35.##.169.98:23
  • 50.##.217.157:23
  • 20#.##.193.243:23
  • 15#.##7.110.20:23
  • 54.###.131.98:23
  • 17#.##5.51.91:23
  • 13#.##.185.143:23
  • 23#.##5.124.236:23
  • 77.##0.65.11:23
  • 19#.##9.230.131:23
  • 94.###.99.223:23
  • 66.##.152.5:23
  • 19.###.109.179:23
  • 15#.##6.195.251:23
  • 91.##.66.32:23
  • 13#.##.91.200:23
  • 19#.##.201.184:23
  • 17#.#9.72.75:23
  • 22#.##1.198.185:23
  • 16#.##.128.23:23
  • 38.###.214.203:23
  • 24#.#3.23.63:23
  • 48.###.119.16:23
  • 58.###.54.132:23
  • 9.###.252.244:23
  • 42.###.92.130:23
  • 29.##3.10.36:23
  • 15#.##.158.60:23
  • 53.###.134.216:23
  • 13#.##8.58.43:23
  • 40.###.74.216:23
  • 24#.##4.18.99:23
  • 24#.##.151.131:23
  • 60.##.114.206:23
  • 21#.##4.83.120:23
  • 21#.##.251.35:23
  • 86.###.182.196:23
  • 22#.#.78.114:23
  • 81.###.200.139:23
  • 84.###.182.16:23
  • 10#.##.195.62:23
  • 3.###.141.103:23
  • 12#.##.140.192:23
  • 88.###.226.89:23
  • 20#.##9.120.128:23
  • 72.###.61.189:23
  • 17#.##7.158.173:23
  • 35.#.233.134:23
  • 8.###.3.202:23
  • 46.##.122.117:23
  • 13#.##.37.226:23
  • 34.###.193.154:23
  • 32.##.74.111:23
  • 22.###.167.121:23
  • 44.##8.38.58:23
  • 15#.##4.57.89:23
  • 12#.##8.137.1:23
  • 11#.##4.167.47:23
  • 31.##.197.210:23
  • 47.#.120.145:23
  • 79.##.66.220:23
  • 19#.##1.38.237:23
  • 10#.##.223.35:23
  • 91.###.81.243:23
  • 16#.#7.81.80:23
  • 15#.##3.194.144:23
  • 16#.##6.12.243:23
  • 14#.##0.159.249:23
  • 21#.##.118.16:23
  • 23#.##0.236.67:23

Curing recommendations


Linux

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Free trial

One month (no registration) or three months (registration and renewal discount)

Download Dr.Web

Download by serial number