Library
My library

+ Add to library

Contact us
24/7 Tech support | Rules regarding submitting

Send a message

Your tickets

Profile

Linux.Siggen.7929

Added to the Dr.Web virus database: 2024-08-14

Virus description added:

Technical Information

Malicious functions:
Launches itself as a daemon
Substitutes application name for:
  • /sbin/init
Performs operations with the file system:
Creates or modifies files:
  • /tmp/tmux-0/dirtest
  • /tmp/systemd-private-f0fd406c1a484a80879a20681d9207ef-logrotate.service-Jao6af/dirtest
  • /tmp/systemd-private-f0fd406c1a484a80879a20681d9207ef-logrotate.service-Jao6af/tmp/dirtest
  • /tmp/systemd-private-f0fd406c1a484a80879a20681d9207ef-systemd-timesyncd.service-FRmAYg/dirtest
  • /tmp/systemd-private-f0fd406c1a484a80879a20681d9207ef-systemd-timesyncd.service-FRmAYg/tmp/dirtest
  • /tmp/systemd-private-f0fd406c1a484a80879a20681d9207ef-systemd-logind.service-6pffCf/dirtest
  • /tmp/systemd-private-f0fd406c1a484a80879a20681d9207ef-systemd-logind.service-6pffCf/tmp/dirtest
  • /var/opt/dirtest
  • /var/backups/dirtest
  • /run/dirtest
  • /run/docker/dirtest
  • /run/containerd/dirtest
  • /run/sshd/dirtest
  • /run/dbus/dirtest
  • /run/user/dirtest
  • /run/sudo/dirtest
  • /run/sendsigs.omit.d/dirtest
  • /dev/shm/dirtest
  • /run/console-setup/dirtest
  • /run/network/dirtest
  • /run/log/dirtest
  • /run/tmpfiles.d/dirtest
  • /run/mount/dirtest
  • /run/credentials/dirtest
  • /run/systemd/dirtest
  • /run/lock/dirtest
  • /run/udev/dirtest
  • /run/initramfs/dirtest
  • /var/tmp/dirtest
  • /var/tmp/systemd-private-f0fd406c1a484a80879a20681d9207ef-systemd-timesyncd.service-rlMSmi/dirtest
  • /var/tmp/systemd-private-f0fd406c1a484a80879a20681d9207ef-logrotate.service-05VSbg/dirtest
  • /var/tmp/systemd-private-f0fd406c1a484a80879a20681d9207ef-systemd-logind.service-4ZZQFi/dirtest
  • /var/spool/dirtest
  • /var/spool/cron/dirtest
  • /var/mail/dirtest
  • /var/spool/rsyslog/dirtest
  • /run/lock/subsys/dirtest
  • /var/local/dirtest
  • /var/lib/dirtest
  • /var/lib/dbus/dirtest
  • /var/lib/misc/dirtest
  • /var/lib/vim/dirtest
  • /var/lib/grub/dirtest
  • /var/lib/aspell/dirtest
  • /var/lib/containerd/dirtest
  • /var/lib/dpkg/dirtest
  • /var/lib/emacsen-common/dirtest
  • /var/lib/python/dirtest
  • /var/lib/systemd/dirtest
  • /var/lib/sudo/dirtest
  • /var/lib/polkit-1/dirtest
  • /var/lib/dhcp/dirtest
  • /var/lib/pam/dirtest
  • /var/lib/dictionaries-common/dirtest
  • /var/lib/man-db/dirtest
  • /var/lib/logrotate/dirtest
  • /var/lib/os-prober/dirtest
  • /var/lib/apt/dirtest
  • /var/lib/docker/dirtest
  • /var/lib/ucf/dirtest
  • /var/lib/git/dirtest
  • /var/lib/ispell/dirtest
  • /var/lib/private/dirtest
  • /var/log/dirtest
  • /var/log/journal/dirtest
  • /var/log/apt/dirtest
  • /var/log/runit/dirtest
  • /var/log/installer/dirtest
  • /var/log/private/dirtest
  • /var/cache/dirtest
  • /var/cache/apparmor/dirtest
  • /var/cache/dictionaries-common/dirtest
  • /var/cache/man/dirtest
  • /var/cache/apt/dirtest
  • /var/cache/ldconfig/dirtest
  • /var/cache/debconf/dirtest
  • /var/cache/private/dirtest
  • /dev/dri/dirtest
  • /dev/dri/by-path/dirtest
  • /dev/snd/dirtest
  • /dev/vfio/dirtest
  • /dev/mapper/dirtest
  • /dev/net/dirtest
  • /dev/mqueue/dirtest
  • /dev/hugepages/dirtest
  • /var/dirtest
Deletes files:
  • /tmp/tmux-0/dirtest
  • /tmp/systemd-private-f0fd406c1a484a80879a20681d9207ef-logrotate.service-Jao6af/dirtest
  • /tmp/systemd-private-f0fd406c1a484a80879a20681d9207ef-logrotate.service-Jao6af/tmp/dirtest
  • /tmp/systemd-private-f0fd406c1a484a80879a20681d9207ef-systemd-timesyncd.service-FRmAYg/dirtest
  • /tmp/systemd-private-f0fd406c1a484a80879a20681d9207ef-systemd-timesyncd.service-FRmAYg/tmp/dirtest
  • /tmp/systemd-private-f0fd406c1a484a80879a20681d9207ef-systemd-logind.service-6pffCf/dirtest
  • /tmp/systemd-private-f0fd406c1a484a80879a20681d9207ef-systemd-logind.service-6pffCf/tmp/dirtest
  • /var/opt/dirtest
  • /var/backups/dirtest
  • /dirtest
  • /docker/dirtest
  • /containerd/dirtest
  • /sshd/dirtest
  • /dbus/dirtest
  • /user/dirtest
  • /sudo/dirtest
  • /sendsigs.omit.d/dirtest
  • /console-setup/dirtest
  • /network/dirtest
  • /log/dirtest
  • /tmpfiles.d/dirtest
  • /mount/dirtest
  • /credentials/dirtest
  • /systemd/dirtest
  • /udev/dirtest
  • /initramfs/dirtest
  • /var/tmp/dirtest
  • /var/tmp/systemd-private-f0fd406c1a484a80879a20681d9207ef-systemd-timesyncd.service-rlMSmi/dirtest
  • /var/tmp/systemd-private-f0fd406c1a484a80879a20681d9207ef-logrotate.service-05VSbg/dirtest
  • /var/tmp/systemd-private-f0fd406c1a484a80879a20681d9207ef-systemd-logind.service-4ZZQFi/dirtest
  • /var/spool/dirtest
  • /var/spool/cron/dirtest
  • /var/mail/dirtest
  • /var/spool/rsyslog/dirtest
  • /subsys/dirtest
  • /var/local/dirtest
  • /var/lib/dirtest
  • /var/lib/dbus/dirtest
  • /var/lib/misc/dirtest
  • /var/lib/vim/dirtest
  • /var/lib/grub/dirtest
  • /var/lib/aspell/dirtest
  • /var/lib/containerd/dirtest
  • /var/lib/dpkg/dirtest
  • /var/lib/emacsen-common/dirtest
  • /var/lib/python/dirtest
  • /var/lib/systemd/dirtest
  • /var/lib/sudo/dirtest
  • /var/lib/polkit-1/dirtest
  • /var/lib/dhcp/dirtest
  • /var/lib/pam/dirtest
  • /var/lib/dictionaries-common/dirtest
  • /var/lib/man-db/dirtest
  • /var/lib/logrotate/dirtest
  • /var/lib/os-prober/dirtest
  • /var/lib/apt/dirtest
  • /var/lib/docker/dirtest
  • /var/lib/ucf/dirtest
  • /var/lib/git/dirtest
  • /var/lib/ispell/dirtest
  • /var/lib/private/dirtest
  • /var/log/dirtest
  • /var/log/journal/dirtest
  • /var/log/apt/dirtest
  • /var/log/runit/dirtest
  • /var/log/installer/dirtest
  • /var/log/private/dirtest
  • /var/cache/dirtest
  • /var/cache/apparmor/dirtest
  • /var/cache/dictionaries-common/dirtest
  • /var/cache/man/dirtest
  • /var/cache/apt/dirtest
  • /var/cache/ldconfig/dirtest
  • /var/cache/debconf/dirtest
  • /var/cache/private/dirtest
  • /dri/dirtest
  • /dri/by-path/dirtest
  • /snd/dirtest
  • /vfio/dirtest
  • /mapper/dirtest
  • /net/dirtest
  • /var/dirtest
Network activity:
Awaits incoming connections on ports:
  • 127.0.0.1:45242
Establishes connection:
  • 1.#.1.1:53

Curing recommendations


Linux

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Free trial

One month (no registration) or three months (registration and renewal discount)

Download Dr.Web

Download by serial number