JavaScript support is required for our site to be fully operational in your browser.
Linux.Siggen.7169
Added to the Dr.Web virus database:
2024-04-18
Virus description added:
2024-04-18
Technical Information
Malicious functions:
Launches itself as a daemon
Substitutes application name for:
Kills the following processes:
systemd
kthreadd
ksoftirqd/0
kworker/0:0
kworker/0:0H
watchdog/0
khelper
kdevtmpfs
netns
khungtaskd
writeback
ksmd
crypto
kintegrityd
bioset
kblockd
kswapd0
fsnotify_mark
kthrotld
ipv6_addrconf
deferwq
kworker/u2:1
kpsmoused
scsi_eh_0
scsi_tmf_0
kworker/0:1H
kworker/u2:2
jbd2/sda1-8
ext4-rsv-conver
kauditd
kworker/0:3
systemd-journal
systemd-udevd
rpciod
nfsiod
systemd-logind
kworker/0:1
dhclient
kworker/0:2
9bc2fd2a
systemd-cgroups
Network activity:
Awaits incoming connections on ports:
Establishes connection:
8.#.8.8:53
45.###.232.208:33335
Attacks using a special dictionary (brute-force technique) via the Telnet protocol.
DNS ASK:
Sends data to the following servers:
45.###.232.208:33335
84.##.158.71:23
84.###.203.116:23
10#.##0.13.101:23
13#.##.203.116:23
20#.##6.61.146:23
18#.#.10.170:23
14.##5.6.59:23
14#.##9.233.41:23
12#.##5.110.125:23
93.###.137.121:23
24#.##4.196.0:23
25#.##.126.29:23
16#.##6.98.160:23
27.###.138.102:23
20#.##5.99.219:23
14#.##1.159.104:23
10#.##3.249.163:23
6.###.19.247:23
18#.##3.97.246:23
86.##.157.69:23
19#.##7.52.19:23
15#.##4.27.215:23
81.##.202.100:23
12#.##.88.209:23
17#.#6.55.89:23
24#.#.34.146:23
66.###.69.109:23
21#.##.86.184:23
10#.##0.101.170:23
12#.##.157.18:23
86.###.86.210:23
10#.##6.116.89:23
18#.##9.114.230:23
79.##.82.196:23
16#.##8.202.79:23
21.##2.94.37:23
15#.##4.188.91:23
18#.#1.60.4:23
16#.##8.220.30:23
57.##.188.138:23
57.##.248.153:23
19#.##5.70.138:23
19#.##6.183.201:23
24#.##3.196.61:23
25#.##6.38.94:23
40.##.28.105:23
17#.##.22.208:23
36.###.50.215:23
17#.#6.98.26:23
19#.##7.6.114:23
21#.##4.147.144:23
24#.#9.94.96:23
1.###.115.183:23
11#.##9.70.56:23
12#.##1.123.160:23
68.###.14.241:23
62.###.168.206:23
20#.#.84.86:23
70.###.206.173:23
16.##.181.240:23
23#.##.188.195:23
16#.##2.106.93:23
12#.##.119.182:23
19#.#7.47.83:23
Receives data from the following servers:
Curing recommendations
Linux
Free trial
One month (no registration) or three months (registration and renewal discount)
Download Dr.Web for Android
Free three-month trial
All protection features available
Renew your trial license in AppGallery/on Google Pay
By continuing to use this website, you are consenting to Doctor Web’s use of cookies and other technologies related to the collection of visitor statistics. Learn more
OK