Library
My library

+ Add to library

Contact us
24/7 Tech support | Rules regarding submitting

Send a message

Your tickets

Profile

Linux.Siggen.4461

Added to the Dr.Web virus database: 2022-04-03

Virus description added:

Technical Information

Malicious functions:
Launches itself as a daemon
Substitutes application name for:
  • YouuuufpCPUqQv7C7u7TCnZV
Network activity:
Establishes connection:
  • 8.#.8.8:53
  • 17#.##5.36.116:9372
Attacks using a special dictionary (brute-force technique) via the Telnet protocol.
Sends data to the following servers:
  • 17#.##5.36.116:9372
  • 15#.##4.123.66:23
  • 12#.##.149.45:23
  • 12#.##4.151.88:23
  • 22#.##9.160.25:23
  • 11#.##.18.165:23
  • 18#.##1.228.31:23
  • 95.###.153.163:23
  • 36.##.24.93:23
  • 10.###.128.229:23
  • 2.###.149.140:23
  • 18.###.223.156:23
  • 70.#.94.8:23
  • 24#.##.132.237:23
  • 83.##.38.198:23
  • 72.##.28.140:23
  • 22#.##4.160.21:23
  • 18#.##.208.105:23
  • 10#.##7.133.70:23
  • 18#.##.242.168:23
  • 22#.##4.213.78:23
  • 21.###.131.39:23
  • 21#.##1.215.81:23
  • 18.###.240.165:23
  • 79.###.251.156:23
  • 23#.##0.45.134:23
  • 68.##5.87.92:23
  • 41.##4.5.20:23
  • 81.###.24.116:23
  • 17#.##5.178.235:23
  • 14#.#48.2.1:23
  • 14#.##4.141.149:23
  • 17#.##3.57.225:23
  • 23#.##.238.57:23
  • 18.###.182.176:23
  • 46.###.246.39:23
  • 24#.##9.228.119:23
  • 25#.##8.113.15:23
  • 17#.#2.96.0:23
  • 99.##.31.124:23
  • 81.##9.2.11:23
  • 37.##2.5.255:23
  • 4.###.171.94:23
  • 6.##.123.198:23
  • 78.###.229.36:23
  • 72.##8.83.10:23
  • 18#.##3.115.205:23
  • 32.###.144.211:23
  • 10#.##8.239.133:23
  • 19#.##5.15.54:23
  • 54.##.10.251:23
  • 22.##2.57.15:23
  • 11#.##8.162.223:23
  • 82.###.199.29:23
  • 69.##.43.153:23
  • 16#.##.107.198:23
  • 12.#.208.20:23
  • 31.##2.45.36:23
  • 21#.##.212.101:23
  • 93.#.16.114:23
  • 15#.##8.232.219:23
  • 20#.##5.140.185:23
  • 28.##.76.165:23
  • 46.##.61.33:23
  • 17#.#2.0.17:23
  • 16#.##4.205.67:23
  • 25.###.209.224:23
  • 30.##.180.131:23
  • 23#.##5.210.78:23
  • 14#.##9.225.222:23
  • 17#.#03.56.7:23
  • 14#.##.242.22:23
  • 65.###.191.85:23
  • 23.##.61.84:23
  • 18.###.128.169:23
  • 25#.##.143.186:23
  • 14#.##8.233.220:23
  • 14#.##.218.40:23
  • 85.##.105.79:23
  • 13#.##6.253.55:23
  • 62.##7.2.222:23
  • 97.###.131.171:23
  • 21#.##1.235.146:23
  • 83.###.61.221:23
  • 13#.##5.192.152:23
  • 22#.##5.57.177:23
  • 23#.##0.142.228:23
  • 20#.##9.44.52:23
  • 13#.##5.245.127:23
  • 21#.##7.41.127:23
  • 16#.#1.88.36:23
  • 25#.##7.96.189:23
  • 17#.##1.247.185:23
  • 20#.##5.46.220:23
  • 93.##.109.250:23
  • 15.###.251.110:23
  • 23#.##3.250.73:23
  • 40.###.126.161:23
  • 96.##8.0.35:23
  • 14#.##.157.138:23
  • 19#.#.209.101:23
  • 24#.##.183.79:23
  • 14#.#.44.94:23
  • 20#.##6.132.219:23
  • 67.###.87.207:23
  • 5.##.197.21:23
  • 10#.##.162.196:23
  • 11#.##7.242.35:23
  • 21#.##8.139.219:23
  • 94.##.137.52:23
  • 46.###.128.18:23
  • 71.##.180.60:23
  • 7.###.158.17:23
  • 22#.##0.61.74:23
  • 23#.##0.97.12:23
  • 48.##5.58.58:23
  • 27.##.153.43:23
  • 24#.##3.47.214:23
  • 1.##.255.67:23
  • 16#.#4.51.34:23
  • 99.###.173.135:23
  • 20#.#55.49.0:23
  • 21#.##7.128.212:23
  • 11#.##5.84.234:23
  • 11#.##1.1.172:23
  • 92.###.50.192:23
  • 19#.##0.6.207:23
  • 17#.##5.129.181:23
  • 10#.##9.0.166:23
  • 12#.##.110.86:23
  • 49.###.156.237:23
  • 22#.##7.254.175:23
  • 68.##.107.147:23
  • 13#.##0.187.172:23
  • 59.###.83.101:23
  • 19#.##.222.245:23
  • 46.##.30.117:23
  • 97.##4.189.1:23
  • 13#.##.235.39:23
  • 4.##.122.189:23
  • 16#.#5.87.57:23
  • 23#.##5.95.165:23
  • 12#.##9.229.51:23
  • 17#.##7.40.253:23
  • 87.###.28.245:23
  • 24#.#.239.123:23
  • 6.###.79.10:23
  • 77.##.157.133:23
  • 48.##.105.203:23
  • 10#.##.212.109:23
  • 56.##.165.255:23
  • 52.###.14.130:23
  • 11#.#4.99.92:23
  • 18.###.57.217:23
  • 21#.#02.2.22:23
  • 25#.##.147.119:23
  • 24#.##2.160.188:23
  • 14#.#.186.150:23
  • 74.###.251.202:23
  • 21#.##6.196.173:23
  • 60.##.204.255:23
  • 40.##.60.59:23
  • 14#.##4.56.45:23
  • 46.###.233.244:23
  • 10#.##.84.213:23
  • 20#.##.182.44:23
  • 22#.##6.204.76:23
  • 49.##.87.155:23
  • 11#.##2.165.61:23
  • 20#.##.94.131:23
  • 17#.##7.66.183:23
  • 21#.##0.252.51:23
  • 21#.##.93.215:23
  • 17.#.202.63:23
  • 16#.##4.53.181:23
  • 10#.##.165.79:23
  • 21#.##6.24.125:23
  • 25#.##.61.141:23
  • 24#.##5.244.164:23
  • 18#.##9.207.227:23
  • 90.###.141.167:23
  • 25#.##9.145.155:23
  • 24#.##.198.200:23
  • 14#.##.224.31:23
  • 17#.##6.187.48:23
  • 21#.##7.109.243:23
  • 11#.##.224.183:23
Receives data from the following servers:
  • 17#.##5.36.116:9372

Curing recommendations


Linux

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Free trial

One month (no registration) or three months (registration and renewal discount)

Download Dr.Web

Download by serial number