Library
My library

+ Add to library

Contact us
24/7 Tech support | Rules regarding submitting

Send a message

Your tickets

Profile

Linux.Siggen.7534

Added to the Dr.Web virus database: 2024-05-27

Virus description added:

Technical Information

Malicious functions:
Removes itself
Launches itself as a daemon
Substitutes application name for:
  • (null)
Kills system processes:
  • sshd
Network activity:
Awaits incoming connections on ports:
  • 127.0.0.1:2174
Establishes connection:
  • 8.#.8.8:53
  • 94.###.43.254:53
  • 94.###.83.102:1114
Attacks using a special dictionary (brute-force technique) via the Telnet protocol.
DNS ASK:
  • na###ne.pirate
Sends data to the following servers:
  • 94.###.83.102:1114
  • 11#.##.164.226:23
  • 58.##9.61.17:23
  • 19#.##9.95.213:23
  • 17#.##2.209.11:23
  • 47.##.114.37:23
  • 11#.##.26.108:23
  • 96.###.191.105:23
  • 42.###.104.57:23
  • 18#.##3.28.114:23
  • 11#.##7.183.111:23
  • 36.##.245.58:23
  • 13.###.201.198:23
  • 89.##.207.228:23
  • 13#.##4.126.149:23
  • 5.###.222.33:23
  • 17#.##4.35.195:23
  • 10#.##.114.14:23
  • 62.###.130.29:23
  • 67.##.241.233:23
  • 20#.##.176.66:23
  • 14#.#3.66.37:23
  • 12#.##.83.109:23
  • 15#.##.42.216:23
  • 31.##.50.43:23
  • 65.##.8.65:23
  • 60.###.186.194:23
  • 13#.##6.97.157:23
  • 18#.##.147.41:23
  • 88.##2.89.36:23
  • 20#.##9.126.73:23
  • 19#.##.176.237:23
  • 20#.##2.242.87:23
  • 73.###.75.151:23
  • 14#.##.60.184:23
  • 11#.##3.70.84:23
  • 10#.##4.199.59:23
  • 10#.##8.53.95:23
  • 80.##.90.2:23
  • 41.##9.52.14:23
  • 10#.##.110.84:23
  • 14#.##6.74.214:23
  • 19#.##1.68.221:23
  • 81.###.246.55:23
  • 54.###.37.198:23
  • 11#.##1.250.166:23
  • 4.##.151.19:23
  • 12#.##9.127.27:23
  • 22#.##.229.207:23
  • 46.###.88.155:23
  • 12#.##6.251.216:23
  • 37.###.195.166:23
  • 10#.##7.176.181:23
  • 79.##.109.153:23
  • 13#.##3.79.200:23
  • 11#.##5.43.33:23
  • 15#.##2.241.222:23
  • 14#.#.21.15:23
  • 20.###.64.133:23
  • 18#.##.167.136:23
  • 89.##.161.112:23
  • 14#.##4.59.84:23
  • 15#.##.227.119:23
  • 21#.##7.226.83:23
  • 13#.##.70.249:23
  • 13#.##6.17.88:23
  • 92.###.137.230:23
  • 17#.##4.246.68:23
  • 13#.##5.133.68:23
  • 22#.##0.153.36:23
  • 12#.##2.160.202:23
  • 14#.##.103.21:23
  • 9.##.111.180:23
  • 13#.##1.250.33:23
  • 78.##.177.238:23
  • 48.###.188.121:23
  • 32.##.199.59:23
  • 13#.##6.32.237:23
  • 11#.##.122.136:23
  • 8.###.178.100:23
  • 14#.##9.244.170:23
  • 10#.##.30.111:23
  • 20#.##6.147.75:23
  • 69.###.108.77:23
  • 17#.#2.4.175:23
  • 92.###.254.45:23
  • 57.###.225.96:23
  • 14#.##5.131.118:23
  • 17.##9.149.8:23
  • 20#.##4.194.192:23
  • 8.#.#88.39:23
  • 63.###.27.232:23
  • 99.###.220.185:23
  • 47.##.183.247:23
  • 11#.##.11.142:23
  • 15#.##.111.159:23
  • 38.##.241.105:23
  • 18#.#2.18.86:23
  • 14#.##.230.27:23
  • 2.###.131.255:23
  • 75.##.20.65:23
  • 11#.#91.3.5:23
  • 1.###.128.240:23
  • 17#.##.103.206:23
  • 20#.##.160.158:23
  • 43.##.178.128:23
  • 52.##.180.93:23
  • 54.##.198.217:23
  • 14#.##0.217.136:23
  • 57.###.226.130:23
  • 54.###.223.44:23
  • 14.###.176.123:23
  • 12#.##6.122.104:23
  • 13#.##.191.41:23
  • 91.##.197.150:23
  • 21#.##3.207.64:23
  • 21#.##.34.118:23
  • 12#.##5.78.126:23
  • 68.###.125.129:23
  • 67.###.151.82:23
  • 95.###.145.93:23
  • 36.##.91.185:23
  • 31.###.218.31:23
  • 14#.##.165.139:23
  • 11#.##.225.102:23
  • 19#.##5.149.136:23
  • 59.##.38.172:23
  • 47.###.46.134:23
  • 88.###.175.93:23
  • 14#.##5.207.49:23
  • 12#.##.231.23:23
  • 21#.##8.183.209:23
  • 10#.##.121.189:23
  • 12#.##4.68.57:23
  • 95.###.238.17:23
  • 50.##.68.204:23
  • 20#.##.211.111:23
  • 18.###.240.60:23
  • 50.###.224.77:23
  • 17#.##6.147.42:23
  • 99.##5.1.76:23
  • 19#.##9.50.198:23
  • 15#.##.35.127:23
  • 5.##.108.98:23
  • 19#.##4.185.197:23
  • 21#.##2.48.250:23
  • 17#.#8.89.72:23
  • 83.###.145.246:23
  • 15#.##5.101.207:23
  • 13#.##9.62.225:23
  • 90.###.103.140:23
  • 60.###.110.47:23
  • 72.###.76.252:23
  • 12#.##6.160.196:23
  • 93.###.218.112:23
  • 16#.##.237.16:23
  • 20#.##1.134.240:23
  • 17#.##6.14.149:23
  • 99.###.171.96:23
  • 15#.##4.76.213:23
  • 20#.##.126.162:23
  • 20#.##6.88.116:23
  • 17#.##0.151.199:23
  • 10#.##3.91.216:23
  • 19#.##3.112.11:23
  • 13#.##9.198.74:23
  • 14.##.45.104:23
  • 19#.##2.80.194:23
  • 16#.##.54.201:23
  • 14#.##6.247.155:23
  • 12#.##3.138.74:23
  • 17#.#7.0.238:23
  • 24.##.151.19:23
  • 18#.##.98.248:23
  • 19#.##5.140.182:23
  • 16#.##.73.245:23
  • 51.###.225.192:23
  • 20#.##.162.47:23
  • 17#.##9.180.227:23
  • 12#.##0.211.66:23
  • 44.###.166.246:23
  • 20#.##5.72.154:23
  • 18.##.100.190:23
  • 13.##8.86.98:23
  • 60.###.246.107:23
  • 22#.##.23.105:23
  • 50.###.247.243:23
  • 81.###.91.183:23
  • 89.##.133.48:23
  • 17#.##.223.71:23
  • 61.###.147.135:23
  • 53.##.93.99:23
  • 9.###.72.207:23
  • 12#.##1.142.25:23
  • 20#.##.129.122:23
  • 20#.#4.36.79:23
  • 20#.##9.211.78:23
  • 39.##.216.239:23
  • 14#.##1.118.244:23
  • 16#.##4.226.121:23
  • 18#.##3.146.67:23
  • 19#.##1.176.35:23
  • 45.###.47.144:23
  • 94.###.35.103:23
  • 17#.##3.209.50:23
  • 51.#.98.122:23
  • 38.###.178.192:23
  • 12#.##.195.34:23
  • 13#.##1.187.180:23
  • 93.##.232.88:23
  • 18#.##4.90.81:23
  • 20#.##8.93.92:23
  • 88.##.186.77:23
  • 18#.##.238.103:23
  • 58.##.174.81:23
  • 21#.##6.101.15:23
  • 91.###.53.221:23
  • 87.###.238.59:23
  • 10#.##1.35.121:23
  • 95.###.27.198:23
  • 10#.#.87.123:23
  • 72.##.150.176:23
  • 14#.##6.137.49:23
  • 72.##8.52.47:23
  • 15#.##9.74.149:23
  • 12#.##3.189.189:23
  • 38.###.247.64:23
  • 14#.##3.229.206:23
  • 14#.##7.215.0:23
  • 12.###.167.242:23
  • 21#.##.216.13:23
  • 78.###.168.160:23
  • 72.###.110.165:23
  • 14#.##9.254.110:23
  • 16#.##0.223.137:23
  • 53.##.247.201:23
  • 99.##.77.50:23
  • 21#.##8.205.82:23
  • 25.###.164.64:23
  • 14#.##1.188.200:23
  • 10#.##.247.255:23
  • 4.##.183.225:23
  • 18#.##9.196.150:23
  • 16#.##9.179.171:23
  • 10#.##8.180.60:23
  • 10#.##4.222.205:23
  • 35.##.53.213:23
  • 14#.##.229.111:23
  • 13#.##4.82.134:23
  • 78.###.236.160:23
  • 10#.#77.31.2:23
  • 11#.##.102.243:23
  • 72.###.114.194:23
  • 27.##.13.149:23
  • 16#.##7.147.49:23
  • 17#.##3.104.208:23
  • 11#.##5.197.185:23
  • 15#.##7.205.177:23
  • 17#.##3.53.90:23
  • 22#.##3.153.79:23
  • 17#.##6.100.11:23
  • 13#.##3.112.148:23
  • 81.#.4.12:23
  • 11#.##.91.148:23
  • 11#.##.42.195:23
  • 93.##8.81.56:23
  • 16#.##0.75.20:23
  • 37.###.143.106:23
  • 88.###.88.120:23
  • 17#.##5.211.41:23
  • 21#.##.86.237:23
Receives data from the following servers:
  • 94.###.83.102:1114

Curing recommendations


Linux

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Free trial

One month (no registration) or three months (registration and renewal discount)

Download Dr.Web

Download by serial number