JavaScript support is required for our site to be fully operational in your browser.
Linux.Siggen.7742
Added to the Dr.Web virus database:
2024-07-05
Virus description added:
2024-07-05
Technical Information
Malicious functions:
Gets access to SSH keys
/root/.ssh/authorized_keys
Launches processes:
/usr/bin/cp -f <SAMPLE_FULL_PATH> /usr/bin/vwilnl
/usr/bin/python3.9 /usr/bin/python3 -Es /usr/bin/lsb_release
/usr/bin/chattr -i /tmp/nrinvj
/usr/bin/cp -f <SAMPLE_FULL_PATH> /usr/bin/uvhdjl
/usr/bin/cp -f <SAMPLE_FULL_PATH> /usr/bin/npgjpp
/usr/bin/chattr -i /root/.ssh/authorized_keys
/usr/bin/getconf CLK_TCK
Kills the following processes:
Performs operations with the file system:
Modifies file access rights:
Creates folders:
/var/lib/.mnon
/root/.ssh
Deletes folders:
Creates or modifies files:
/var/lib/.mnon/.local
/tmp/.X11-unix
/tmp/nrinvj
/usr/bin/uvhdjl
/usr/bin/npgjpp
/usr/bin/vwilnl
Deletes files:
Locks files:
/var/lib/.mnon/.local
/tmp/nrinvj
Network activity:
Establishes connection:
8.#.8.8:53
58.##.119.191:45569
11#.##.189.244:35327
21#.##9.32.10:53
20#.##.222.222:53
19#.#08.88.1:53
49.##.234.183:80
[2#####901:0:bbc3::]:9
34.##7.118.44:9
34.###.118.44:80
34.###.186.192:80
18#.###.166.148:37940
18#.##4.98.233:9
18#.##4.99.233:9
18#.##4.98.233:80
[2#######0:3037::6815:365b]:9
[2#######0:3030::ac43:a86a]:9
17#.##.168.106:9
10#.#1.54.91:9
17#.##.168.106:80
54.##.206.99:9
52.##3.236.3:9
99.##.7.149:9
54.##4.47.36:9
52.##.148.69:9
52.##0.17.94:9
54.##.206.99:80
10#.##.185.241:9
10#.##.184.241:9
10#.##.185.241:80
43.###.202.68:44164
10#.##.190.41:36492
42.###.136.96:35463
12#.#5.237.16:9
12#.#5.237.51:9
12#.##.237.16:80
[2#######0:3037::6815:365b]:80
[2#######0:3030::ac43:a86a]:80
10#.##.69.154:43511
12#.##8.190.84:8000
DNS ASK:
ns###.#kamaitech.net
ip##ho.net
ip##fo.io
ip##.#canhazip.com
ch#####.amazonaws.com
ap#.#pify.org
v4.#dent.me
if##nfig.me
if##nfig.co
o-#.###ddr.l.google.com
my##.#pendns.com
ns#.#oogle.com
re#####r1.opendns.com
wh####.akamai.net
wh#####yip.akamai.com
Sends data to the following servers:
19#.#08.88.1:53
20#.##.222.222:53
21#.##9.32.10:53
49.##.234.183:80
34.###.186.192:80
34.###.118.44:80
18#.##4.98.233:80
54.##.206.99:80
17#.##.168.106:80
10#.##.185.241:80
12#.##.237.16:80
Receives data from the following servers:
19#.#08.88.1:53
20#.##.222.222:53
21#.##9.32.10:53
49.##.234.183:80
34.###.186.192:80
34.###.118.44:80
18#.##4.98.233:80
54.##.206.99:80
17#.##.168.106:80
10#.##.185.241:80
12#.##.237.16:80
Other:
Collects CPU information
Collects information about network activity
Curing recommendations
Linux
Free trial
One month (no registration) or three months (registration and renewal discount)
Download Dr.Web for Android
Free three-month trial
All protection features available
Renew your trial license in AppGallery/on Google Pay
By continuing to use this website, you are consenting to Doctor Web’s use of cookies and other technologies related to the collection of visitor statistics. Learn more
OK