マイライブラリ
マイライブラリ

+ マイライブラリに追加

電話

お問い合わせ履歴

電話(英語)

+7 (495) 789-45-86

Profile

Linux.Siggen.4185

Added to the Dr.Web virus database: 2021-08-18

Virus description added:

Technical Information

Malicious functions:
Launches itself as a daemon
Substitutes application name for:
  • mAwUAoZUu7cCjqvZVRTHUpux
Network activity:
Awaits incoming connections on ports:
  • 0.0.0.0:23
Establishes connection:
  • 8.#.8.8:53
  • 10#.###.136.150:37009
  • 25#.###.255.255:37009
Attacks using a special dictionary (brute-force technique) via the Telnet protocol.
Sends data to the following servers:
  • 14.##.103.36:23
  • 61.###.46.213:23
  • 13#.##8.149.6:23
  • 81.##.190.215:23
  • 17#.##.163.144:23
  • 12.###.163.144:23
  • 87.##.157.230:23
  • 18#.##8.230.150:23
  • 64.###.143.164:23
  • 12#.#2.35.87:23
  • 17#.#2.222.1:23
  • 11#.##3.42.92:23
  • 40.###.75.178:23
  • 37.###.247.238:23
  • 15#.##.104.64:23
  • 16#.##9.237.80:23
  • 15#.#.25.233:23
  • 19#.##.237.194:23
  • 88.###.123.156:23
  • 12#.##5.129.76:23
  • 68.###.173.138:23
  • 76.###.51.173:23
  • 17.##.186.152:23
  • 18#.##5.195.157:23
  • 18#.##4.57.108:23
  • 45.##8.53.2:23
  • 88.#.184.143:23
  • 89.###.45.105:23
  • 12#.##7.53.36:23
  • 16#.##3.238.199:23
  • 32.###.153.154:23
  • 18#.##7.132.44:23
  • 48.##.170.84:23
  • 20#.##2.53.177:23
  • 24.##7.18.30:23
  • 84.##.127.13:23
  • 14#.##.227.184:23
  • 17#.##2.41.212:23
  • 14#.#.100.102:23
  • 12#.##9.84.73:23
  • 16.###.15.118:23
  • 10#.##7.54.85:23
  • 19#.##9.22.218:23
  • 20#.##2.21.23:23
  • 71.###.242.19:23
  • 66.##1.34.93:23
  • 99.##1.3.188:23
  • 66.###.116.94:23
  • 64.###.43.135:23
  • 60.###.20.125:23
  • 59.##.199.218:23
  • 47.##.71.75:23
  • 62.##.141.59:23
  • 10#.##6.204.15:23
  • 99.##2.6.15:23
  • 88.##.213.7:23
  • 16#.##.63.116:23
  • 14#.##.129.49:23
  • 21#.##.121.219:23
  • 8.###.222.175:23
  • 24.##.112.192:23
  • 17#.##1.8.158:23
  • 21#.#1.98.2:23
  • 18#.##6.244.177:23
  • 22#.##3.125.201:23
  • 23.###.17.240:23
  • 12#.##1.168.132:23
  • 16#.##0.140.138:23
  • 20#.##3.116.137:23
  • 19#.##.86.211:23
  • 17#.##.225.114:23
  • 18#.#2.50.50:23
  • 18#.##2.179.162:23
  • 16#.##6.125.203:23
  • 18#.##5.218.138:23
  • 92.###.192.149:23
  • 81.###.208.162:23
  • 73.##2.75.47:23
  • 11#.#7.8.218:23
  • 74.##.227.146:23
  • 46.##.175.243:23
  • 14#.##9.191.132:23
  • 12#.##2.90.119:23
  • 44.##1.1.13:23
  • 13#.##7.18.218:23
  • 10#.##6.209.208:23
  • 48.###.105.163:23
  • 21#.##5.186.103:23
  • 12#.##6.228.60:23
  • 27.##.190.81:23
  • 17#.##7.34.204:23

Curing recommendations


Linux

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Free trial

One month (no registration) or three months (registration and renewal discount)

Download Dr.Web

Download by serial number