Library
My library

+ Add to library

Contact us
24/7 Tech support | Rules regarding submitting

Send a message

Your tickets

Profile

Linux.Siggen.7483

Added to the Dr.Web virus database: 2024-05-19

Virus description added:

Technical Information

Malicious functions:
Removes itself
Launches itself as a daemon
Substitutes application name for:
  • (null)
Kills system processes:
  • sshd
Kills the following processes:
  • exim4
Network activity:
Awaits incoming connections on ports:
  • 127.0.0.1:2174
Establishes connection:
  • 8.#.8.8:53
  • 17#.##4.22.166:53
  • 19#.#.81.97:2222
Attacks using a special dictionary (brute-force technique) via the Telnet protocol.
DNS ASK:
  • na###ne.pirate
Sends data to the following servers:
  • 19#.#.81.97:2222
  • 11#.##.127.124:23
  • 14#.##5.225.66:23
  • 11#.##3.83.116:23
  • 43.##.205.25:23
  • 18#.##0.233.212:23
  • 82.###.196.81:23
  • 20#.##5.201.52:23
  • 34.###.63.230:23
  • 70.##.39.92:23
  • 10#.##0.91.178:23
  • 20#.##8.63.61:23
  • 12#.##.229.221:23
  • 21#.##1.61.182:23
  • 75.###.222.82:23
  • 60.###.133.76:23
  • 15#.##.110.216:23
  • 10#.##0.81.78:23
  • 23.##4.25.37:23
  • 15#.##.180.224:23
  • 11#.##1.87.31:23
  • 14#.##.117.91:23
  • 13#.##.248.49:23
  • 19#.##7.211.51:23
  • 19#.##.28.143:23
  • 19#.##5.204.213:23
  • 57.##.146.135:23
  • 73.##4.248.1:23
  • 10#.##.48.195:23
  • 11#.##8.27.114:23
  • 17#.##.179.23:23
  • 1.##.131.142:23
  • 32.###.200.84:23
  • 72.###.191.16:23
  • 12#.##8.255.18:23
  • 11#.#2.29.57:23
  • 38.##.134.192:23
  • 11#.##2.78.240:23
  • 97.##6.83.85:23
  • 36.###.121.85:23
  • 12#.##3.218.142:23
  • 16#.##0.247.120:23
  • 21#.##.79.218:23
  • 21#.##0.85.95:23
  • 10#.##2.204.240:23
  • 10#.##8.4.133:23
  • 17#.##6.194.179:23
  • 20#.##9.46.87:23
  • 12.##.115.136:23
  • 14#.##7.11.157:23
  • 12#.##2.227.230:23
  • 12#.#.14.114:23
  • 2.##.148.25:23
  • 62.###.96.149:23
  • 11#.##.180.56:23
  • 10#.#.252.197:23
  • 10#.##.169.221:23
  • 22#.##.253.113:23
  • 13#.#6.149.3:23
  • 11#.##9.37.120:23
  • 12#.##.20.115:23
  • 19#.##5.80.111:23
  • 77.##2.69.22:23
  • 14#.##2.39.138:23
  • 20#.#4.7.203:23
  • 18#.##9.102.196:23
  • 53.##.90.45:23
  • 22#.##1.162.223:23
  • 12#.#6.7.173:23
  • 13#.##0.195.139:23
  • 71.###.101.199:23
  • 19#.#7.15.37:23
  • 49.##.244.185:23
  • 71.##.97.55:23
  • 13#.##8.241.129:23
  • 11#.##4.58.187:23
  • 92.###.245.247:23
  • 49.###.26.217:23
  • 12#.##0.82.131:23
  • 22#.##5.56.23:23
  • 15#.##1.205.175:23
  • 21#.##.234.92:23
  • 78.##9.6.192:23
  • 14#.##.254.148:23
  • 82.###.38.218:23
  • 20#.##.195.24:23
  • 13#.##6.156.216:23
  • 43.###.130.158:23
  • 13#.##9.87.208:23
  • 21#.##4.56.48:23
  • 12#.##2.48.146:23
  • 12#.#8.0.145:23
  • 16#.##.201.195:23
  • 38.###.200.92:23
  • 22#.##4.9.247:23
  • 52.##.1.252:23
  • 84.##.230.69:23
  • 14#.#.131.152:23
  • 10#.#.35.142:23
  • 43.###.236.29:23
  • 15#.##0.78.112:23
  • 21#.#44.20.9:23
  • 41.###.148.101:23
  • 40.###.33.205:23
  • 11#.##0.212.98:23
  • 12#.#5.71.41:23
  • 20#.##0.58.204:23
  • 17#.##0.239.149:23
  • 21#.#4.1.81:23
  • 14#.##3.48.140:23
  • 16#.##8.193.253:23
  • 18#.##.210.165:23
  • 65.#.146.116:23
  • 40.#.143.219:23
  • 14#.##2.218.41:23
  • 18#.##9.86.203:23
  • 48.###.236.70:23
  • 16#.##8.131.225:23
  • 32.##.4.212:23
  • 19#.##4.171.150:23
  • 92.##.76.125:23
  • 41.##.29.173:23
  • 18.###.129.140:23
  • 66.##.105.169:23
  • 19.##.58.201:23
  • 23.##.214.194:23
  • 20.###.189.104:23
  • 17#.##0.75.123:23
  • 11#.#7.12.58:23
  • 8.##.172.237:23
  • 16#.#4.94.0:23
  • 20#.#.164.165:23
  • 17#.#1.234.2:23
  • 76.##.180.53:23
  • 75.###.23.213:23
  • 10#.##.230.202:23
  • 19#.##0.69.196:23
  • 48.##2.22.88:23
  • 15#.#8.43.25:23
  • 17#.##0.114.149:23
  • 13#.#09.8.46:23
  • 96.##.11.151:23
  • 31.###.103.155:23
  • 70.##.25.190:23
  • 58.#.41.220:23
  • 15#.##.26.146:23
  • 74.###.226.169:23
  • 21#.##2.44.181:23
  • 88.###.213.184:23
  • 57.###.137.32:23
  • 51.###.255.191:23
  • 17#.##.73.202:23
  • 16#.##0.148.71:23
  • 2.##.177.170:23
  • 41.###.165.136:23
  • 16#.##.114.111:23
  • 18#.##.14.159:23
  • 17#.##.111.105:23
  • 14#.##7.145.206:23
  • 19#.##2.193.157:23
  • 84.##.160.195:23
  • 15#.##.241.159:23
  • 17#.##.242.33:23
  • 14#.##.105.73:23
  • 49.##.80.201:23
  • 13.###.196.241:23
  • 21#.##2.221.76:23
  • 99.##.61.131:23
  • 13#.##.138.239:23
  • 46.###.230.33:23
  • 12#.##6.12.228:23
  • 17#.##8.229.225:23
  • 18.###.94.196:23
  • 27.###.251.140:23
  • 19#.##3.140.113:23
  • 22#.##2.52.146:23
  • 99.##7.142.2:23
  • 43.###.144.14:23
  • 19#.##9.236.25:23
  • 43.##.90.142:23
  • 41.###.104.250:23
  • 12#.##8.59.229:23
  • 72.###.231.31:23
  • 14.###.56.164:23
  • 27.##.69.96:23
  • 14#.##5.39.224:23
  • 21#.##.141.33:23
  • 42.###.180.135:23
  • 14.###.11.112:23
  • 10#.##1.56.46:23
  • 10#.##4.164.75:23
  • 96.##.96.153:23
  • 86.###.71.167:23
  • 45.#.22.230:23
  • 19.##.41.123:23
  • 13#.##8.32.247:23
  • 95.###.237.230:23
  • 17#.##.226.252:23
  • 84.##2.64.93:23
  • 85.##.76.174:23
  • 13#.##1.244.223:23
  • 52.###.32.249:23
  • 38.##.57.134:23
  • 31.###.224.116:23
  • 17#.##5.189.207:23
  • 11#.##4.56.184:23
  • 14#.##.117.130:23
  • 15#.##.31.115:23
  • 20#.##4.176.30:23
  • 2.##.193.181:23
  • 21#.##.253.26:23
  • 80.##.178.117:23
  • 2.##.174.56:23
  • 13#.##7.164.108:23
  • 10#.##4.221.178:23
  • 96.###.128.159:23
  • 41.##.91.80:23
  • 15#.##.111.26:23
  • 5.##.206.67:23
  • 15#.#9.2.203:23
  • 66.###.255.251:23
  • 19#.##1.169.112:23
  • 19#.##9.147.115:23
  • 18#.##1.138.180:23
  • 10#.##.161.124:23
  • 16#.#2.56.6:23
  • 19#.##6.132.121:23
  • 86.###.32.170:23
  • 15#.#5.38.36:23
  • 76.##2.64.57:23
  • 79.###.163.182:23
  • 16#.##9.153.65:23
  • 17#.##.109.73:23
  • 99.###.200.61:23
  • 11#.#5.17.0:23
  • 48.##9.84.71:23
  • 15#.##.67.187:23
  • 18#.#1.3.242:23
  • 20#.#6.18.37:23
  • 46.##.164.45:23
  • 16#.##.173.243:23
  • 22#.##.190.187:23
  • 40.###.16.148:23
  • 20#.##0.235.155:23
  • 32.##4.29.84:23
  • 18#.##1.188.213:23
  • 20#.##.126.223:23
  • 88.###.61.205:23
  • 11#.#.134.208:23
Receives data from the following servers:
  • 19#.#.81.97:2222

Curing recommendations


Linux

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Free trial

One month (no registration) or three months (registration and renewal discount)

Download Dr.Web

Download by serial number