マイライブラリ
マイライブラリ

+ マイライブラリに追加

電話

お問い合わせ履歴

電話(英語)

+7 (495) 789-45-86

Profile

Linux.Siggen.2186

Added to the Dr.Web virus database: 2019-10-03

Virus description added:

Technical Information

Malicious functions:
Removes itself
Substitutes application name for:
  • apMMpew8HuQM2t6lveW1bMjAd1jMWBauAQ6y1CjttjnwMwBy1AWnA2jjCMpjQlbKdAoN1eWKM3rN4aW1K7xpjtAlp11yKj3vNXxjxKtKjaAWpAHQbuajNv1KWoAK3pov3yjtt1AKybRbAxKao4MV4Co8AMWl1A8jKjNjNpwoalpArwlWNnnrCjcVab71KK7eowByeBAntQAvpjv1wMRd4veuVtvwpWA3V6x4jdM2B1j712QW8aw13CpBHvAlQa1QtQ1nnWttoWNAA7vbtKapp3AxloVayKvdR1paAAvupuQpWAMxwlrVAAQaW8oj8j2jKd6oKjQK61AQlreuHAjoawvCNAWtBjKAWj1tnjWAcAR2ljNjW4wj71AbAwKVBp6l2tcM4A8H1ejnVatVpoAjK6ldo6XavBaWR6W1CaWoQdAo3oNAjuAWvjt8AKjXj1pyrNcoadaKjA1toaauMoQnAK4anw6aoNaKoHaXKRMyX87e7A8NNeKuaWAvoKRAMwBHvWbCWr1A4dwNeynodWetp14K1jwjoA2aupMbjjMQCwxaw161WtAaKApWWAK1bjrnCAWppMpyMKBKAxAWHAu1VBnAnN1MyyrwojNMjwMjMw1NNwAaACadMd7AKAMWpAlewxj8VwAtVaacoQMyoCuRvK71oKAy6olKVna4KAuelXtBK3KAaa4oAuKQjKwbpp87bNCoANAbCwQaR16vRp31prjArblRlwtd3jQA2lvp1altM1bvv1MpvQbjaAAlAdearRxjMMrNpXvcRjdN11BW6CadNX1ooXAa1Koe1BNyQAQ1dAwxnvdM4ApKtnaaAKAewjoa1WMWp1tbWWa1yMtyv14AWpA2MWVdKejr6oVtllHdNxrtrvN7p7No7MMAN[rkmodule] [run.sh][PPID:0x217] [sleep][PID:0x21b] do_filp_open. Filename: "/usr/lib/locale/locale-archive"
Network activity:
Awaits incoming connections on ports:
  • 19#.###.200.50:56242
Establishes connection:
  • 8.#.8.8:53
  • 5.#.##.205:34255
Attacks using a special dictionary (brute-force technique) via the Telnet protocol.
DNS ASK:
  • sk##ine.wtf
Sends data to the following servers:
  • 20.##.7.200:23
  • 11#.#.156.242:23
  • 22#.##7.221.157:23
  • 13#.##5.21.114:23
  • 82.###.235.105:23
  • 18#.##2.104.143:23
  • 74.###.24.136:23
  • 17#.##.43.131:23
  • 98.##.167.81:23
  • 37.##3.80.37:23
  • 20#.##3.170.195:23
  • 92.##.178.36:23
  • 61.###.126.237:23
  • 45.##.180.152:23
  • 66.##6.11.75:23
  • 13#.##7.163.224:23
  • 10#.##7.133.62:23
  • 19#.##.110.234:23
  • 15#.##.112.141:23
  • 17#.##0.123.114:23
  • 12#.##6.88.236:23
  • 13#.##6.104.6:23
  • 45.##6.58.58:23
  • 13#.##9.7.121:23
  • 11#.##6.53.245:23
  • 75.###.242.198:23
  • 13#.##.239.138:23
  • 18#.##4.41.245:23
  • 10#.##.49.138:23
  • 19#.#.46.165:23
  • 20#.##7.115.111:23
  • 13#.##3.121.23:23
  • 19#.##8.249.154:23
  • 41.###.252.38:23
  • 32.###.166.57:23
  • 16#.##.255.145:23
  • 18#.##8.123.21:23
  • 10#.##.153.100:23
  • 63.##.74.229:23
  • 97.###.44.189:23
  • 11#.##1.242.79:23
  • 10#.##5.74.128:23
  • 77.###.149.69:23
  • 79.##.83.20:23
  • 18.###.112.203:23
  • 15#.##7.196.47:23
  • 19#.##3.106.34:23
  • 22#.##.46.147:23
  • 18#.##7.25.64:23
  • 57.##7.38.65:23
  • 18.###.104.204:23
  • 17#.##.174.219:23
  • 53.###.16.145:23
  • 46.###.124.59:23
  • 72.#.216.100:23
  • 74.##3.240.3:23
  • 48.##.108.160:23
  • 10#.##0.64.114:23
  • 81.##8.82.17:23
  • 13#.##3.52.183:23
  • 18#.##.216.245:23
  • 14#.##5.117.244:23
  • 19#.##.177.133:23
  • 68.##.211.97:23
  • 21#.##3.203.9:23
  • 13#.##.33.129:23
  • 61.###.176.41:23
  • 53.##.90.17:23
  • 51.##.211.82:23
  • 11#.##.39.255:23
  • 99.##.76.60:23
  • 15#.##6.110.103:23
  • 31.###.219.169:23
  • 14.###.225.112:23
  • 22#.##7.112.253:23
  • 12#.##5.222.152:23
  • 61.##.225.154:23
  • 89.##.151.152:23
  • 38.###.28.200:23
  • 37.#.157.43:23
  • 27.###.177.76:23
  • 18.##.91.16:23
  • 39.###.43.128:23
  • 89.##.30.183:23
  • 95.###.103.54:23
  • 81.##.176.125:23
  • 65.##.75.90:23
  • 15#.##.20.192:23
  • 15#.##2.176.50:23
  • 19#.##9.154.61:23
  • 11#.##.187.44:23
  • 82.#.137.232:23
  • 81.##.168.17:23
  • 18#.##5.134.91:23
  • 95.##.61.183:23
  • 17.###.196.179:23
  • 21#.##3.83.237:23
  • 84.###.125.173:23
  • 12#.##.217.36:23

Curing recommendations


Linux

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Free trial

One month (no registration) or three months (registration and renewal discount)

Download Dr.Web

Download by serial number