JavaScript support is required for our site to be fully operational in your browser.
Linux.Siggen.7270
Added to the Dr.Web virus database:
2024-04-24
Virus description added:
2024-04-24
Technical Information
Malicious functions:
Removes itself
Launches itself as a daemon
Substitutes application name for:
1lubcgolb56csdejgaojeii0ie47nmpv
Kills system processes:
Kills the following processes:
systemd
systemd-journal
systemd-udevd
systemd-timesyn
dbus-daemon
cron
rsyslogd
systemd-logind
agetty
(sd-pam)
dhclient
run.sh
install
(ogrotate)
dash
tmux: client
sleep
flock
1lubcgolb56csde
apt-helper
Network activity:
Awaits incoming connections on ports:
Establishes connection:
8.#.8.8:53
8.#.4.4:53
21#.##.149.10:35342
DNS ASK:
se######.rebirth-network.su
Sends data to the following servers:
21#.##.149.10:35342
15#.#.203.105:37215
19#.##.204.60:37215
19#.###.105.96:37215
15#.##2.89.92:37215
19#.##.174.19:37215
43.##.136.34:37215
19#.###.181.249:37215
85.##.152.19:37215
86.###.189.99:37215
62.###.93.27:37215
19#.##.167.118:37215
19#.###.245.244:37215
15#.#.34.58:37215
15#.##.116.25:37215
12.###.161.58:37215
41.##.220.35:37215
60.###.173.83:37215
21#.##.29.145:37215
41.###.164.153:37215
13#.###.240.219:37215
17#.###.243.40:37215
19#.###.169.98:37215
15#.##8.21.64:37215
41.###.109.254:37215
15#.###.11.125:37215
41.##.244.132:37215
15#.###.118.40:37215
11#.###.60.199:37215
15#.##.91.149:37215
41.##.156.121:37215
19#.###.127.87:37215
41.##.45.165:37215
17#.###.33.158:37215
19#.##.102.202:37215
41.###.114.113:37215
15#.###.255.138:37215
19#.###.14.147:37215
41.###.178.221:37215
41.##.129.136:37215
19#.###.157.151:37215
Receives data from the following servers:
Curing recommendations
Linux
Free trial
One month (no registration) or three months (registration and renewal discount)
Download Dr.Web for Android
Free three-month trial
All protection features available
Renew your trial license in AppGallery/on Google Pay
By continuing to use this website, you are consenting to Doctor Web’s use of cookies and other technologies related to the collection of visitor statistics. Learn more
OK