Library
My library

+ Add to library

Contact us
24/7 Tech support | Rules regarding submitting

Send a message

Your tickets

Profile

Linux.Siggen.7648

Added to the Dr.Web virus database: 2024-06-15

Virus description added:

Technical Information

Malicious functions:
Removes itself
Substitutes application name for:
  • (null)
Kills the following processes:
  • bash
Network activity:
Awaits incoming connections on ports:
  • 0.0.0.0:9999
Establishes connection:
  • 8.#.8.8:53
Sends data to the following servers:
  • 18#.##.114.35:37215
  • 13#.###.206.111:37215
  • 94.##.222.193:37215
  • 12#.###.63.171:37215
  • 10#.##7.71.89:37215
  • 37.##.235.94:37215
  • 15#.##3.87.50:37215
  • 12#.###.52.228:37215
  • 51.###.103.51:37215
  • 37.##.202.78:37215
  • 15#.###.149.133:37215
  • 37.###.60.28:37215
  • 41.##.4.8:37215
  • 18#.###.34.180:37215
  • 13#.###.29.113:37215
  • 10#.###.147.231:37215
  • 22#.##.44.215:37215
  • 22#.###.211.65:37215
  • 19#.###.211.58:37215
  • 19#.###.138.244:37215
  • 16#.##.78.3:37215
  • 37.###.46.233:37215
  • 19#.##.58.125:37215
  • 19#.###.61.130:37215
  • 16#.###.177.224:37215
  • 45.###.74.87:37215
  • 37.#.#53.141:37215
  • 31.###.186.217:37215
  • 13#.###.207.76:37215
  • 13#.##.239.22:37215
  • 18#.###.216.124:37215
  • 18#.###.93.203:37215
  • 12#.##.170.47:37215
  • 94.###.167.200:37215
  • 22#.###.16.245:37215
  • 37.###.144.99:37215
  • 18#.##7.240.3:37215
  • 12#.###.178.188:37215
  • 19#.###.243.23:37215
  • 41.###.161.181:37215
  • 94.###.219.110:37215
  • 94.###.120.189:37215
  • 22#.###.67.108:37215
  • 45.##.130.97:37215
  • 19#.##.225.21:37215
  • 22#.###.241.116:37215
  • 15#.###.53.245:37215
  • 13#.###.90.160:37215
  • 13#.##.61.92:37215
  • 37.###.100.135:37215
  • 15#.##.133.171:37215
  • 18#.#.190.103:37215
  • 18#.##.69.82:37215
  • 12#.##.139.165:37215
  • 12#.##.52.112:37215
  • 18#.##.217.191:37215
  • 45.###.154.63:37215
  • 12#.##.203.106:37215
  • 31.##.54.253:37215
  • 18#.###.222.43:37215
  • 15#.##7.58.21:37215
  • 18#.###.64.196:37215
  • 15#.###.25.205:37215
  • 18#.##.90.97:37215
  • 19#.###.229.238:37215
  • 31.##.238.86:37215
  • 12#.###.62.118:37215
  • 15#.###.251.71:37215
  • 22#.##.187.229:37215
  • 94.##.137.185:37215
  • 13#.##.178.18:37215
  • 19#.###.146.222:37215
  • 31.###.156.251:37215
  • 37.##.250.100:37215
  • 22#.###.199.202:37215
  • 10#.###.183.188:37215
  • 18#.###.222.186:37215
  • 18#.##.72.228:37215
  • 18#.##0.58.45:37215
  • 41.###.152.3:37215
  • 41.###.165.187:37215
  • 37.##.142.49:37215
  • 13#.###.194.157:37215
  • 19#.###.235.213:37215
  • 19#.###.12.243:37215
  • 12#.##6.92.67:37215
  • 19#.##.107.101:37215
  • 18#.###.171.179:37215
  • 31.##.25.93:37215
  • 94.###.186.213:37215
  • 15#.###.10.225:37215
  • 94.#.#98.185:37215
  • 19#.##.218.35:37215
  • 37.#.3.43:37215
  • 10#.##.92.247:37215
  • 19#.##.233.153:37215
  • 15#.###.229.41:37215
  • 19#.###.146.154:37215
  • 41.###.56.11:37215
  • 94.##.176.109:37215
  • 10#.###.90.183:37215
  • 18#.###.196.39:37215
  • 18#.###.134.70:37215
  • 18#.##.211.101:37215
  • 12#.##.17.98:37215
  • 22#.###.144.117:37215
  • 31.###.142.159:37215
  • 19#.###.126.141:37215
  • 41.###.81.253:37215
  • 94.###.188.81:37215
  • 45.##.198.112:37215
  • 31.###.95.103:37215
  • 13#.###.42.233:37215
  • 19#.###.255.58:37215
  • 12#.##.7.131:37215
  • 10#.##.147.91:37215
  • 15#.###.67.119:37215
  • 12#.###.189.55:37215
  • 15#.###.246.12:37215
  • 15#.##.157.106:37215
  • 37.##.206.244:37215
  • 31.##.254.153:37215
  • 94.##.114.82:37215
  • 41.##.98.229:37215
  • 15#.##.185.147:37215
  • 14#.##.58.93:37215
  • 94.###.21.175:37215
  • 12#.###.162.219:37215
  • 41.##.121.233:37215
  • 37.###.242.108:37215
  • 22#.###.76.133:37215
  • 37.###.51.200:37215
  • 75.##.20.50:37215
  • 41.###.130.95:37215
  • 37.###.177.150:37215
  • 31.###.15.29:37215
  • 15#.#.180.111:37215
  • 18#.##.93.226:37215
  • 37.###.100.152:37215
  • 15#.###.217.84:37215
  • 10#.###.241.53:37215
  • 31.###.166.56:37215
  • 18#.###.187.249:37215
  • 31.###.108.20:37215
  • 45.##.34.61:37215
  • 18#.##.137.161:37215
  • 19#.##.251.175:37215
  • 22#.##.226.155:37215
  • 12#.###.61.110:37215
  • 15#.##4.37.71:37215
  • 15#.##.96.24:37215
  • 18#.##6.72.86:37215
  • 22#.###.146.233:37215
  • 15#.##4.9.59:37215
  • 19#.##1.17.8:37215
  • 31.###.239.222:37215
  • 13#.##.221.203:37215
  • 18#.##.238.22:37215
  • 12#.###.235.120:37215
  • 12#.###.110.12:37215
  • 45.##.1.107:37215
  • 10#.##3.84.77:37215
  • 94.###.75.155:37215
  • 19#.###.36.170:37215
  • 19#.###.168.192:37215
  • 22#.###.190.246:37215
  • 94.###.177.185:37215
  • 12#.###.52.197:37215
  • 18#.##.162.244:37215
  • 22#.##.238.142:37215
  • 10#.##.215.41:37215
  • 15#.###.104.225:37215
  • 15#.###.106.40:37215
  • 11#.##.92.33:37215
  • 31.###.156.71:37215
  • 45.###.166.190:37215
  • 15#.##.198.184:37215
  • 94.##.108.98:37215
  • 18#.###.19.159:37215
  • 13#.##9.50.1:37215
  • 37.##.8.106:37215
  • 18#.##5.8.209:37215
  • 12#.##.39.184:37215
  • 12#.###.239.78:37215
  • 18#.###.162.47:37215
  • 15#.##.26.167:37215
  • 37.###.12.119:37215
  • 19#.##.53.237:37215
  • 12#.##5.48.70:37215
  • 10#.##.166.65:37215
  • 41.##.154.123:37215
  • 15#.##.210.108:37215
  • 94.##.169.88:37215
  • 37.###.138.62:37215
  • 18#.##.206.20:37215
  • 18#.###.172.86:37215
  • 18#.##.88.100:37215
  • 19#.###.195.162:37215
  • 18#.###.113.126:37215
  • 13#.###.198.33:37215
  • 19#.###.210.222:37215
  • 45.###.250.227:37215
  • 18#.###.142.69:37215
  • 94.###.38.21:37215
  • 37.###.93.129:37215
  • 10#.###.125.61:37215
  • 15#.##6.44.1:37215
  • 19#.###.235.232:37215
  • 37.##.105.166:37215
  • 45.##.10.191:37215
  • 18#.###.86.244:37215
  • 31.##.62.186:37215
  • 22#.###.231.76:37215
  • 19#.###.115.45:37215
  • 15#.##.57.211:37215
  • 12#.###.246.68:37215
  • 18#.##1.90.35:37215
  • 22#.##.11.176:37215
  • 18#.##.223.239:37215
  • 19#.##.73.255:37215
  • 18#.###.85.144:37215
  • 18#.##.81.111:37215
  • 31.##.48.231:37215
  • 31.##.144.24:37215
  • 10#.##.116.223:37215
  • 45.##.130.197:37215
  • 37.##.64.161:37215
  • 10#.###.146.76:37215
  • 12#.##.89.117:37215
  • 15#.##.121.116:37215
  • 94.##.195.152:37215
  • 15#.##5.25.34:37215
  • 15#.##.140.84:37215
  • 19#.###.172.130:37215
  • 12#.##.193.56:37215
  • 37.###.131.65:37215
  • 41.###.227.230:37215
  • 18#.###.55.208:37215
  • 18#.##.64.21:37215
  • 19#.###.115.191:37215
  • 13#.###.161.64:37215
  • 22#.##3.71.22:37215
  • 45.###.7.47:37215
  • 75.###.252.77:37215
  • 19#.##.24.208:37215
  • 94.###.136.230:37215
  • 15#.##.89.169:37215
  • 12#.###.237.126:37215
  • 18#.##.9.238:37215
  • 31.##.66.32:37215
  • 18#.##.62.38:37215
  • 13#.###.196.150:37215
  • 41.##.58.146:37215
  • 12#.##.237.188:37215
  • 12#.###.185.46:37215
  • 18#.###.100.102:37215

Curing recommendations


Linux

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Free trial

One month (no registration) or three months (registration and renewal discount)

Download Dr.Web

Download by serial number