Linux.Siggen.1468
Added to the Dr.Web virus database:
2019-02-28
Virus description added:
2019-02-28
Technical Information
Malicious functions:
Removes itself
Launches itself as a daemon
Substitutes application name for:
Network activity:
Awaits incoming connections on ports:
Establishes connection:
- 8.#.8.8:53
- 8.#.4.4:53
- 18#.##.138.13:6592
DNS ASK:
- xa########.ukrainianhorseriding.com
Sends data to the following servers:
- 24#.##2.218.19:5555
- 14#.##.223.195:5555
- 10#.##.252.251:5555
- 11#.##0.246.40:5555
- 17.##.185.172:5555
- 15#.##.116.10:5555
- 17#.##1.140.63:5555
- 20#.##.93.203:5555
- 19#.##.226.53:5555
- 18#.##4.80.63:5555
- 17#.##.124.47:5555
- 15#.#.202.3:5555
- 23#.##.58.7:5555
- 16#.##5.146.45:5555
- 14#.##4.97.150:5555
- 89.###.115.147:5555
- 55.##.128.15:5555
- 10#.##.39.61:5555
- 20#.##8.152.44:5555
- 73.###.139.91:5555
- 13#.###.252.253:5555
- 13#.##8.32.72:5555
- 20#.##4.196.71:5555
- 58.##.148.78:5555
- 98.##.34.62:5555
- 50.##.137.152:5555
- 13#.##5.56.25:5555
- 16#.###.213.105:5555
- 16#.##8.44.232:5555
- 24#.###.138.207:5555
- 11#.##8.63.194:5555
- 11#.##.21.132:5555
- 56.##.91.24:5555
- 32.##.0.91:5555
- 21#.##9.62.51:5555
- 15#.##3.78.195:5555
- 64.###.227.25:5555
- 87.###.151.148:5555
- 15#.##.196.2:5555
- 19#.##1.122.71:5555
- 24#.##3.208.86:5555
- 18#.###.182.254:5555
- 28.##.79.222:5555
- 77.##.156.102:5555
- 11#.##.50.171:5555
- 79.#.#43.116:5555
- 23.###.170.235:5555
- 63.##.182.237:5555
- 62.##.64.189:5555
- 21.###.5.221:5555
- 11#.##5.87.108:5555
- 22.###.133.182:5555
- 19#.##6.59.18:5555
- 11#.###.103.166:5555
- 24.###.148.50:5555
- 24#.###.171.108:5555
- 13#.##.238.177:5555
- 76.##.253.84:5555
- 20#.##6.80.23:5555
- 63.#.#26.180:5555
- 13#.#.6.94:5555
- 67.###.96.81:5555
- 21#.##0.36.234:5555
- 47.###.150.119:5555
- 12#.###.227.196:5555
Curing recommendations
Linux
Free trial
One month (no registration) or three months (registration and renewal discount)
このウェブサイトを継続して訪問する場合、訪問者に関する統計データを収集するためのCookieファイルおよび他のテクノロジーを弊社が利用することに同意したものとします。詳細