Linux.Siggen.2186
Added to the Dr.Web virus database:
2019-10-03
Virus description added:
2019-10-03
Technical Information
Malicious functions:
Removes itself
Substitutes application name for:
- apMMpew8HuQM2t6lveW1bMjAd1jMWBauAQ6y1CjttjnwMwBy1AWnA2jjCMpjQlbKdAoN1eWKM3rN4aW1K7xpjtAlp11yKj3vNXxjxKtKjaAWpAHQbuajNv1KWoAK3pov3yjtt1AKybRbAxKao4MV4Co8AMWl1A8jKjNjNpwoalpArwlWNnnrCjcVab71KK7eowByeBAntQAvpjv1wMRd4veuVtvwpWA3V6x4jdM2B1j712QW8aw13CpBHvAlQa1QtQ1nnWttoWNAA7vbtKapp3AxloVayKvdR1paAAvupuQpWAMxwlrVAAQaW8oj8j2jKd6oKjQK61AQlreuHAjoawvCNAWtBjKAWj1tnjWAcAR2ljNjW4wj71AbAwKVBp6l2tcM4A8H1ejnVatVpoAjK6ldo6XavBaWR6W1CaWoQdAo3oNAjuAWvjt8AKjXj1pyrNcoadaKjA1toaauMoQnAK4anw6aoNaKoHaXKRMyX87e7A8NNeKuaWAvoKRAMwBHvWbCWr1A4dwNeynodWetp14K1jwjoA2aupMbjjMQCwxaw161WtAaKApWWAK1bjrnCAWppMpyMKBKAxAWHAu1VBnAnN1MyyrwojNMjwMjMw1NNwAaACadMd7AKAMWpAlewxj8VwAtVaacoQMyoCuRvK71oKAy6olKVna4KAuelXtBK3KAaa4oAuKQjKwbpp87bNCoANAbCwQaR16vRp31prjArblRlwtd3jQA2lvp1altM1bvv1MpvQbjaAAlAdearRxjMMrNpXvcRjdN11BW6CadNX1ooXAa1Koe1BNyQAQ1dAwxnvdM4ApKtnaaAKAewjoa1WMWp1tbWWa1yMtyv14AWpA2MWVdKejr6oVtllHdNxrtrvN7p7No7MMAN[rkmodule] [run.sh][PPID:0x217] [sleep][PID:0x21b] do_filp_open. Filename: "/usr/lib/locale/locale-archive"
Network activity:
Awaits incoming connections on ports:
Establishes connection:
- 8.#.8.8:53
- 5.#.##.205:34255
Attacks using a special dictionary (brute-force technique) via the Telnet protocol.
DNS ASK:
Sends data to the following servers:
- 20.##.7.200:23
- 11#.#.156.242:23
- 22#.##7.221.157:23
- 13#.##5.21.114:23
- 82.###.235.105:23
- 18#.##2.104.143:23
- 74.###.24.136:23
- 17#.##.43.131:23
- 98.##.167.81:23
- 37.##3.80.37:23
- 20#.##3.170.195:23
- 92.##.178.36:23
- 61.###.126.237:23
- 45.##.180.152:23
- 66.##6.11.75:23
- 13#.##7.163.224:23
- 10#.##7.133.62:23
- 19#.##.110.234:23
- 15#.##.112.141:23
- 17#.##0.123.114:23
- 12#.##6.88.236:23
- 13#.##6.104.6:23
- 45.##6.58.58:23
- 13#.##9.7.121:23
- 11#.##6.53.245:23
- 75.###.242.198:23
- 13#.##.239.138:23
- 18#.##4.41.245:23
- 10#.##.49.138:23
- 19#.#.46.165:23
- 20#.##7.115.111:23
- 13#.##3.121.23:23
- 19#.##8.249.154:23
- 41.###.252.38:23
- 32.###.166.57:23
- 16#.##.255.145:23
- 18#.##8.123.21:23
- 10#.##.153.100:23
- 63.##.74.229:23
- 97.###.44.189:23
- 11#.##1.242.79:23
- 10#.##5.74.128:23
- 77.###.149.69:23
- 79.##.83.20:23
- 18.###.112.203:23
- 15#.##7.196.47:23
- 19#.##3.106.34:23
- 22#.##.46.147:23
- 18#.##7.25.64:23
- 57.##7.38.65:23
- 18.###.104.204:23
- 17#.##.174.219:23
- 53.###.16.145:23
- 46.###.124.59:23
- 72.#.216.100:23
- 74.##3.240.3:23
- 48.##.108.160:23
- 10#.##0.64.114:23
- 81.##8.82.17:23
- 13#.##3.52.183:23
- 18#.##.216.245:23
- 14#.##5.117.244:23
- 19#.##.177.133:23
- 68.##.211.97:23
- 21#.##3.203.9:23
- 13#.##.33.129:23
- 61.###.176.41:23
- 53.##.90.17:23
- 51.##.211.82:23
- 11#.##.39.255:23
- 99.##.76.60:23
- 15#.##6.110.103:23
- 31.###.219.169:23
- 14.###.225.112:23
- 22#.##7.112.253:23
- 12#.##5.222.152:23
- 61.##.225.154:23
- 89.##.151.152:23
- 38.###.28.200:23
- 37.#.157.43:23
- 27.###.177.76:23
- 18.##.91.16:23
- 39.###.43.128:23
- 89.##.30.183:23
- 95.###.103.54:23
- 81.##.176.125:23
- 65.##.75.90:23
- 15#.##.20.192:23
- 15#.##2.176.50:23
- 19#.##9.154.61:23
- 11#.##.187.44:23
- 82.#.137.232:23
- 81.##.168.17:23
- 18#.##5.134.91:23
- 95.##.61.183:23
- 17.###.196.179:23
- 21#.##3.83.237:23
- 84.###.125.173:23
- 12#.##.217.36:23
Curing recommendations
Linux
Free trial
One month (no registration) or three months (registration and renewal discount)
このウェブサイトを継続して訪問する場合、訪問者に関する統計データを収集するためのCookieファイルおよび他のテクノロジーを弊社が利用することに同意したものとします。詳細