Library
My library

+ Add to library

Contact us
24/7 Tech support | Rules regarding submitting

Send a message

Your tickets

Profile

Linux.Siggen.6463

Added to the Dr.Web virus database: 2024-01-20

Virus description added:

Technical Information

Malicious functions:
Launches processes:
  • /tmp/staticx-kjcgdJ/tor
Performs operations with the file system:
Modifies file access rights:
  • /tmp/staticx-kjcgdJ/tor
  • /tmp/staticx-kjcgdJ/ld-musl-x86_64.so.1
  • /tmp/staticx-kjcgdJ/libz.so.1.2.11
  • /tmp/staticx-kjcgdJ/libevent-2.1.so.7.0.1
  • /tmp/staticx-kjcgdJ/libssl.so.1.1
  • /tmp/staticx-kjcgdJ/libcrypto.so.1.1
  • /tmp/staticx-kjcgdJ/liblzma.so.5.2.5
  • /tmp/staticx-kjcgdJ/libzstd.so.1.5.0
  • /tmp/staticx-kjcgdJ/libseccomp.so.2.5.2
  • /tmp/staticx-kjcgdJ/libcap.so.2.61
Modifies file owner:
  • /tmp/staticx-kjcgdJ/tor
  • /tmp/staticx-kjcgdJ/ld-musl-x86_64.so.1
  • /tmp/staticx-kjcgdJ/libz.so.1.2.11
  • /tmp/staticx-kjcgdJ/libevent-2.1.so.7.0.1
  • /tmp/staticx-kjcgdJ/libssl.so.1.1
  • /tmp/staticx-kjcgdJ/libcrypto.so.1.1
  • /tmp/staticx-kjcgdJ/liblzma.so.5.2.5
  • /tmp/staticx-kjcgdJ/libzstd.so.1.5.0
  • /tmp/staticx-kjcgdJ/libseccomp.so.2.5.2
  • /tmp/staticx-kjcgdJ/libcap.so.2.61
Creates folders:
  • /tmp/staticx-kjcgdJ
  • /root/.tor
  • /root/.tor/keys
Creates symlinks:
  • /tmp/staticx-kjcgdJ/.staticx.prog
  • /tmp/staticx-kjcgdJ/.staticx.interp
  • /tmp/staticx-kjcgdJ/libz.so.1
  • /tmp/staticx-kjcgdJ/libevent-2.1.so.7
  • /tmp/staticx-kjcgdJ/liblzma.so.5
  • /tmp/staticx-kjcgdJ/libzstd.so.1
  • /tmp/staticx-kjcgdJ/libseccomp.so.2
  • /tmp/staticx-kjcgdJ/libcap.so.2
Creates or modifies files:
  • /tmp/staticx-kjcgdJ/tor
  • /tmp/staticx-kjcgdJ/ld-musl-x86_64.so.1
  • /tmp/staticx-kjcgdJ/libz.so.1.2.11
  • /tmp/staticx-kjcgdJ/libevent-2.1.so.7.0.1
  • /tmp/staticx-kjcgdJ/libssl.so.1.1
  • /tmp/staticx-kjcgdJ/libcrypto.so.1.1
  • /tmp/staticx-kjcgdJ/liblzma.so.5.2.5
  • /tmp/staticx-kjcgdJ/libzstd.so.1.5.0
  • /tmp/staticx-kjcgdJ/libseccomp.so.2.5.2
  • /tmp/staticx-kjcgdJ/libcap.so.2.61
  • /root/.tor/lock
  • /root/.tor/state.tmp
Locks files:
  • /root/.tor/lock
Changes time of creation/access/modification of files:
  • /tmp/staticx-kjcgdJ/tor
  • /tmp/staticx-kjcgdJ/ld-musl-x86_64.so.1
  • /tmp/staticx-kjcgdJ/libz.so.1.2.11
  • /tmp/staticx-kjcgdJ/libevent-2.1.so.7.0.1
  • /tmp/staticx-kjcgdJ/libssl.so.1.1
  • /tmp/staticx-kjcgdJ/libcrypto.so.1.1
  • /tmp/staticx-kjcgdJ/liblzma.so.5.2.5
  • /tmp/staticx-kjcgdJ/libzstd.so.1.5.0
  • /tmp/staticx-kjcgdJ/libseccomp.so.2.5.2
  • /tmp/staticx-kjcgdJ/libcap.so.2.61
Network activity:
Awaits incoming connections on ports:
  • 127.0.0.1:9050
Establishes connection:
  • 45.#.#48.31:9001
  • 51.###.39.70:9001
  • 37.###.173.173:9001
Other:
Collects RAM information

Curing recommendations


Linux

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Free trial

One month (no registration) or three months (registration and renewal discount)

Download Dr.Web

Download by serial number