Library
My library

+ Add to library

Contact us
24/7 Tech support | Rules regarding submitting

Send a message

Your tickets

Profile

Linux.Siggen.7212

Added to the Dr.Web virus database: 2024-04-20

Virus description added:

Technical Information

Malicious functions:
Removes itself
Launches itself as a daemon
Substitutes application name for:
  • tege5mbisu6e
Kills system processes:
  • sshd
Kills the following processes:
  • systemd
  • systemd-journal
  • systemd-udevd
  • systemd-timesyn
  • dbus-daemon
  • cron
  • rsyslogd
  • systemd-logind
  • agetty
  • (sd-pam)
  • dhclient
  • run.sh
  • (ogrotate)
  • install
  • dash
  • tmux: client
  • sleep
  • tege5mbisu6e
  • apt-helper
Network activity:
Awaits incoming connections on ports:
  • 127.0.0.1:8345
Establishes connection:
  • 8.#.8.8:53
  • 21#.##.149.14:35342
  • 1.#.0.1:53
  • 94.##.114.254:53
  • 18#.##1.61.24:53
  • 8.#.4.4:53
  • 81.###.136.222:53
DNS ASK:
  • se#.####re-cyber-security
Sends data to the following servers:
  • 15#.##.232.49:37215
  • 21#.##.39.112:37215
  • 41.###.191.56:37215
  • 15#.##.215.30:37215
  • 41.###.234.172:37215
  • 15#.###.199.224:37215
  • 15#.###.174.253:37215
  • 11#.###.143.89:37215
  • 11#.###.241.218:37215
  • 19#.###.67.242:37215
  • 19#.#.102.236:37215
  • 15#.#.182.92:37215
  • 21#.###.152.187:37215
  • 41.###.219.56:37215
  • 41.###.129.252:37215
  • 13#.##4.0.1:37215
  • 19#.##.6.243:37215
  • 19#.###.100.193:37215
  • 19#.##.249.21:37215
  • 23.##.206.40:37215
  • 19#.###.196.34:37215
  • 22#.###.206.150:37215
  • 19#.###.80.198:37215
  • 61.###.168.221:37215
  • 15#.###.125.189:37215
  • 19#.##.203.145:37215
  • 19#.##.151.68:37215
  • 20.##.245.57:37215
  • 19#.##.102.145:37215
  • 19#.##.153.116:37215
  • 15#.##5.67.52:37215
  • 15#.###.92.210:37215
  • 41.##.115.245:37215
  • 41.###.75.55:37215
  • 19#.##7.34.20:37215
  • 41.##.187.240:37215
  • 12#.##.213.179:37215
  • 41.###.68.148:37215
  • 15#.##.67.132:37215
  • 41.###.107.98:37215
  • 93.##.12.118:37215
  • 19#.###.152.70:37215
  • 17#.##.186.188:37215
  • 19#.##.218.135:37215
  • 32.##.11.207:37215
  • 53.###.243.44:37215
  • 41.##.198.140:37215
  • 19#.###.213.30:37215
  • 19#.##.43.51:37215
  • 10#.###.169.52:37215
  • 15#.##.201.67:37215
  • 19#.#.68.89:37215
  • 12.###.53.200:37215
  • 41.##.14.7:37215
  • 41.###.54.127:37215
  • 19#.##.41.9:37215
  • 19#.###.81.149:37215
  • 15#.##4.70.48:37215
  • 41.###.173.98:37215
  • 18#.###.101.110:37215
  • 41.##.175.11:37215
  • 15#.###.160.136:37215
  • 41.###.80.49:37215
  • 41.###.77.221:37215
  • 19#.###.223.151:37215
  • 15#.##.75.230:37215
  • 18#.##.241.33:37215
  • 15#.###.109.179:37215
  • 44.###.190.227:37215
  • 15#.##.135.116:37215
  • 41.##.111.54:37215
  • 41.##.89.164:37215
  • 15#.##.10.173:37215
  • 12#.##4.95.66:37215
  • 15#.###.92.137:37215
  • 27.###.153.174:37215
  • 19#.##.96.185:37215
  • 19#.##.178.82:37215
  • 19#.##0.78.42:37215
  • 12#.##.120.115:37215
  • 41.##.26.249:37215
  • 15#.##.194.245:37215
  • 15#.##0.54.95:37215
  • 14.###.180.193:37215
  • 41.###.97.141:37215
  • 19#.###.104.205:37215
  • 41.###.131.21:37215
  • 19#.###.29.204:37215
  • 19#.###.10.246:37215
  • 41.###.107.93:37215
  • 19#.##.123.80:37215
  • 15#.###.222.176:37215
  • 41.##.49.196:37215
  • 15#.###.112.45:37215
  • 15#.###.66.173:37215
  • 41.###.28.142:37215
  • 18#.##1.61.24:53
  • 8.#.4.4:53
  • 81.###.136.222:53
Receives data from the following servers:
  • 18#.##1.61.24:53
  • 8.#.4.4:53

Curing recommendations


Linux

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Free trial

One month (no registration) or three months (registration and renewal discount)

Download Dr.Web

Download by serial number