JavaScript support is required for our site to be fully operational in your browser.
Linux.Siggen.7184
Added to the Dr.Web virus database:
2024-04-19
Virus description added:
2024-04-18
Technical Information
Malicious functions:
Launches itself as a daemon
Substitutes application name for:
Kills the following processes:
rpcbind
rpc.statd
rpc.idmapd
cron
dbus-daemon
rsyslogd
agetty
lockfile-touch
run.sh
sleep
stub.sh
tee
Network activity:
Awaits incoming connections on ports:
Establishes connection:
8.#.8.8:53
45.###.232.208:33335
Attacks using a special dictionary (brute-force technique) via the Telnet protocol.
DNS ASK:
Sends data to the following servers:
45.###.232.208:33335
14#.##4.175.117:23
75.##4.2.11:23
24#.#.40.30:23
11.###.215.116:23
36.##2.90.87:23
15#.##.54.140:23
13#.##.231.28:23
17#.##9.247.169:23
66.###.56.127:23
53.###.172.160:23
13#.#.184.52:23
30.###.82.217:23
14#.##5.135.211:23
25#.##.78.197:23
73.###.245.52:23
28.###.212.147:23
18#.#.204.96:23
68.##.25.101:23
51.###.129.212:23
23#.##7.128.64:23
24#.##3.220.74:23
11#.##7.83.135:23
21#.##7.75.213:23
55.###.100.67:23
13#.##1.14.62:23
13#.##7.34.133:23
17#.##9.83.104:23
25#.##1.52.68:23
27.##.177.118:23
23#.##2.181.38:23
5.###.82.16:23
18#.##.55.191:23
29.###.89.254:23
38.##.55.138:23
98.###.65.194:23
19#.##6.203.162:23
19#.##.169.19:23
24#.##0.18.205:23
13#.##.120.225:23
14#.#9.75.63:23
6.###.78.75:23
98.###.241.113:23
44.##.230.117:23
11#.##6.5.144:23
18#.##.96.184:23
11#.##.149.120:23
23#.##2.170.227:23
14#.##9.70.132:23
22#.##6.233.133:23
98.###.252.55:23
24#.##2.16.216:23
19#.##7.142.163:23
13#.#.226.201:23
18#.##5.119.127:23
30.###.94.246:23
42.##.92.130:23
24#.##.158.100:23
63.##.187.103:23
22#.##0.11.157:23
16#.##8.204.10:23
11#.##0.104.227:23
91.##4.64.46:23
28.###.126.144:23
74.##.56.254:23
19#.##5.12.41:23
17#.#7.20.94:23
19#.##1.14.97:23
21#.##0.240.30:23
20#.#1.73.2:23
11#.#5.62.93:23
69.##.251.185:23
31.##.162.122:23
6.##.7.210:23
16#.##6.13.176:23
10#.##.30.129:23
14#.##9.227.123:23
20#.##9.88.191:23
Receives data from the following servers:
Curing recommendations
Linux
Free trial
One month (no registration) or three months (registration and renewal discount)
Download Dr.Web for Android
Free three-month trial
All protection features available
Renew your trial license in AppGallery/on Google Pay
By continuing to use this website, you are consenting to Doctor Web’s use of cookies and other technologies related to the collection of visitor statistics. Learn more
OK