Library
My library

+ Add to library

Contact us
24/7 Tech support | Rules regarding submitting

Send a message

Your tickets

Profile

Linux.Siggen.7215

Added to the Dr.Web virus database: 2024-04-20

Virus description added:

Technical Information

Malicious functions:
Removes itself
Launches itself as a daemon
Substitutes application name for:
  • w7e3wca70iwrmnougudloqmt3q7v
Kills system processes:
  • sshd
Kills the following processes:
  • systemd
  • systemd-journal
  • systemd-udevd
  • systemd-timesyn
  • cron
  • dbus-daemon
  • rsyslogd
  • systemd-logind
  • agetty
  • (sd-pam)
  • dhclient
  • run.sh
  • (ogrotate)
  • install
  • dash
  • tmux: client
  • sleep
  • ip
  • w7e3wca70iwrmno
  • udevadm
Network activity:
Awaits incoming connections on ports:
  • 127.0.0.1:8345
Establishes connection:
  • 8.#.8.8:53
  • 8.#.4.4:53
  • 21#.##.149.14:35342
  • 1.#.0.1:53
  • 51.##.149.139:53
  • 19#.##.144.87:53
  • 18#.##1.61.24:53
Sends data to the following servers:
  • 15#.##.248.16:37215
  • 19#.###.171.196:37215
  • 15#.###.242.230:37215
  • 41.##.216.118:37215
  • 15#.###.110.239:37215
  • 41.##.53.173:37215
  • 15#.##2.71.12:37215
  • 21#.##.40.143:37215
  • 37.###.86.228:37215
  • 19#.###.234.40:37215
  • 19#.##.137.226:37215
  • 15#.###.93.247:37215
  • 15#.#.30.109:37215
  • 98.###.41.223:37215
  • 41.###.211.127:37215
  • 19#.##.192.10:37215
  • 41.###.16.254:37215
  • 19#.###.72.116:37215
  • 19#.###.71.251:37215
  • 19#.##4.53.22:37215
  • 15#.##.106.20:37215
  • 19#.##.178.20:37215
  • 17#.##.40.92:37215
  • 68.##.105.115:37215
  • 19#.##.128.82:37215
  • 19#.##4.91.84:37215
  • 41.###.31.141:37215
  • 41.###.105.156:37215
  • 11#.###.158.30:37215
  • 41.##.108.110:37215
  • 41.###.58.75:37215
  • 19#.##.67.74:37215
  • 14#.###.251.96:37215
  • 20#.###.127.60:37215
  • 15#.##.185.98:37215
  • 15#.#.109.45:37215
  • 19#.###.62.148:37215
  • 22#.##.223.176:37215
  • 19#.#.252.151:37215
  • 41.###.200.109:37215
  • 19#.##.34.116:37215
  • 79.###.5.156:37215
  • 41.##.239.88:37215
  • 15#.##.217.232:37215
  • 19#.###.172.71:37215
  • 41.###.13.18:37215
  • 19#.###.109.168:37215
  • 41.###.112.234:37215
  • 41.###.165.128:37215
  • 15#.##9.7.140:37215
  • 41.##.253.53:37215
  • 41.###.104.250:37215
  • 19#.###.72.221:37215
  • 41.##.47.52:37215
  • 15#.##.239.189:37215
  • 19#.##.15.119:37215
  • 15#.##.127.40:37215
  • 11#.##8.8.112:37215
  • 41.###.89.240:37215
  • 41.###.151.238:37215
  • 15#.###.188.167:37215
  • 19#.##.102.176:37215
  • 15#.###.127.16:37215
  • 41.##.200.84:37215
  • 15#.##0.24.45:37215
  • 15#.###.200.57:37215
  • 15#.##.88.36:37215
  • 41.###.115.217:37215
  • 19#.#.100.199:37215
  • 10#.##.143.78:37215
  • 41.###.156.224:37215
  • 15#.###.210.77:37215
  • 19#.#.181.54:37215
  • 15#.##.71.50:37215
  • 19#.###.104.15:37215
  • 19#.#.122.241:37215
  • 41.###.125.188:37215
  • 15#.###.74.177:37215
  • 41.##.223.128:37215
  • 15#.##.47.241:37215
  • 19#.##.86.136:37215
  • 20#.###.111.98:37215
  • 41.##.228.138:37215
  • 18#.###.235.149:37215
  • 15#.##.65.28:37215
  • 41.###.184.91:37215
  • 13#.##.49.255:37215
  • 41.##.117.156:37215
  • 15#.###.244.148:37215
  • 15#.###.213.243:37215
  • 19#.###.157.45:37215
  • 41.###.11.115:37215
  • 41.###.216.7:37215
  • 19#.##6.40.18:37215
  • 64.###.184.42:37215
  • 15#.###.251.145:37215
  • 41.###.84.178:37215
  • 15#.###.83.216:37215
  • 41.###.238.80:37215
  • 15#.#.134.116:37215
  • 41.##.221.43:37215
  • 35.###.12.252:37215
  • 14#.##9.78.47:37215
  • 19#.##.106.235:37215
  • 41.###.89.157:37215
  • 17#.##0.6.75:37215
  • 19#.##.33.177:37215
  • 20#.###.69.178:37215
  • 15#.##.238.66:37215
  • 19#.##7.5.185:37215
  • 41.##.251.177:37215
  • 87.###.76.135:37215
  • 15#.###.121.44:37215
  • 19#.##.112.68:37215
  • 41.###.235.22:37215
  • 19#.##.23.210:37215
  • 15#.##.100.59:37215
  • 57.###.1.0:37215
  • 15#.##.10.1:37215
  • 41.###.87.88:37215
  • 62.###.153.179:37215
  • 15#.###.154.118:37215
  • 41.#.#61.250:37215
  • 41.###.236.63:37215
  • 21#.###.117.220:37215
  • 41.#.#16.60:37215
  • 15#.##.215.25:37215
  • 19#.###.105.68:37215
  • 41.###.35.242:37215
  • 42.###.168.218:37215
  • 41.##.103.219:37215
  • 69.###.211.53:37215
  • 11#.###.20.162:37215
  • 41.###.208.47:37215
  • 15#.##.59.244:37215
  • 15#.###.190.202:37215
  • 19#.###.54.129:37215
  • 82.##.94.79:37215
  • 19#.##9.15.96:37215
  • 19#.###.171.52:37215
  • 19#.###.101.93:37215
  • 15#.###.61.200:37215
  • 19#.###.172.168:37215
  • 19#.##.202.14:37215
  • 41.##.146.58:37215
  • 41.##.188.207:37215
  • 21#.###.98.117:37215
  • 41.###.11.128:37215
  • 19#.###.219.88:37215
  • 19#.###.188.170:37215
  • 15#.##4.11.25:37215
  • 41.###.0.135:37215
  • 19#.##.69.151:37215
  • 15#.###.207.174:37215
  • 20#.###.38.245:37215
  • 19#.###.100.216:37215
  • 41.###.9.38:37215
  • 15#.##.91.54:37215
  • 18#.###.140.26:37215
  • 41.##.93.55:37215
  • 15#.###.72.171:37215
  • 17#.##4.34.69:37215
  • 15#.##0.81.50:37215
  • 19#.##.129.155:37215
  • 15#.##.169.217:37215
  • 22#.###.219.163:37215
  • 15#.###.62.163:37215
  • 15#.###.141.142:37215
  • 15#.###.205.61:37215
  • 19#.###.13.253:37215
  • 15#.##3.35.75:37215
  • 15#.###.219.74:37215
  • 41.###.216.250:37215
  • 15#.###.134.237:37215
  • 89.##.136.203:37215
  • 15#.##.152.228:37215
  • 19#.###.205.177:37215
  • 14#.##.64.196:37215
  • 93.##.75.224:37215
  • 41.##.99.6:37215
  • 15#.##.107.204:37215
  • 15#.###.63.238:37215
  • 41.###.176.8:37215
  • 75.###.133.198:37215
  • 41.###.196.197:37215
  • 41.##.93.90:37215
  • 19#.###.153.186:37215
  • 15#.##.99.221:37215
  • 19#.##.38.87:37215
  • 50.###.180.129:37215
  • 41.###.162.194:37215
  • 41.###.73.34:37215
  • 41.###.229.100:37215
  • 57.###.127.228:37215
  • 41.###.11.149:37215
  • 41.###.219.90:37215
  • 15#.##.91.250:37215
  • 15#.##.65.66:37215
  • 15#.###.202.22:37215
  • 18#.##7.2.231:37215
  • 19#.##.179.11:37215
  • 15#.##.241.199:37215
  • 19#.##0.171.9:37215
  • 15#.###.203.222:37215
  • 41.##.199.139:37215
  • 41.###.85.241:37215
  • 19#.###.95.226:37215
  • 19#.##.114.123:37215
  • 40.##.39.85:37215
  • 41.##.225.168:37215
  • 15#.##.6.214:37215
  • 43.##.149.241:37215
  • 15#.##4.95.13:37215
  • 19#.##.230.89:37215
  • 22#.###.125.100:37215
  • 15#.###.167.105:37215
  • 17.###.112.195:37215
  • 15#.###.201.91:37215
  • 82.###.215.146:37215
  • 17#.###.61.157:37215
  • 15#.###.202.158:37215
  • 41.##.217.171:37215
  • 41.##.5.49:37215
  • 41.#.#3.63:37215
  • 19#.##.225.97:37215
  • 41.###.118.215:37215
  • 41.##.21.232:37215
  • 10#.###.193.242:37215
  • 41.###.164.111:37215
  • 2.###.68.82:37215
  • 41.##.222.70:37215
  • 41.###.82.73:37215
  • 15#.###.144.89:37215
  • 41.##.3.3:37215
  • 15#.###.154.201:37215
  • 19#.##.19.172:37215
  • 19#.###.218.156:37215
  • 19#.##.186.17:37215
  • 19#.##.63.32:37215
  • 15#.##.18.118:37215
  • 19#.##.228.213:37215
  • 19#.##4.170.8:37215
  • 15#.###.231.224:37215
  • 90.###.61.189:37215
  • 15#.##3.49.47:37215
  • 41.###.16.205:37215
  • 15#.###.155.72:37215
  • 19#.###.205.175:37215
  • 15#.##.43.245:37215
  • 15#.###.60.187:37215
  • 15#.##.76.113:37215
  • 15#.##.116.19:37215
  • 15#.###.239.15:37215
  • 41.##.81.177:37215
  • 41.###.181.177:37215
  • 19#.###.101.189:37215
  • 0.0.0.0

Curing recommendations


Linux

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Free trial

One month (no registration) or three months (registration and renewal discount)

Download Dr.Web

Download by serial number