マイライブラリ
マイライブラリ

+ マイライブラリに追加

電話

お問い合わせ履歴

電話(英語)

+7 (495) 789-45-86

Profile

Linux.Siggen.7088

Added to the Dr.Web virus database: 2024-04-18

Virus description added:

Technical Information

Malicious functions:
Removes itself
Launches itself as a daemon
Substitutes application name for:
  • ke61vlh868hoaalnlkb1
Performs process tracing:
  • swapper/0
Kills system processes:
  • sshd
Kills the following processes:
  • systemd-timesyn
  • run.sh
  • dash
  • bash
  • ke61vlh868hoaal
  • systemd
Network activity:
Awaits incoming connections on ports:
  • 127.0.0.1:8345
Establishes connection:
  • 8.#.8.8:53
  • 1.#.0.1:53
  • 87.###.7.66:35342
  • 18#.##1.61.24:53
  • 94.##.114.254:53
  • 19#.##.144.87:53
  • 91.###.137.37:53
  • 51.##.149.139:53
Sends data to the following servers:
  • 19#.###.143.100:37215
  • 41.###.77.118:37215
  • 15#.###.237.100:37215
  • 19#.###.116.172:37215
  • 41.#.#36.184:37215
  • 41.##.73.41:37215
  • 15#.#.202.114:37215
  • 14#.###.140.184:37215
  • 18#.#.70.189:37215
  • 15#.###.123.102:37215
  • 15#.###.239.239:37215
  • 41.###.217.90:37215
  • 13#.##2.7.67:37215
  • 93.###.93.168:37215
  • 15#.###.118.50:37215
  • 15#.###.109.184:37215
  • 14#.###.216.157:37215
  • 62.###.130.221:37215
  • 14#.##.251.136:37215
  • 15#.###.155.30:37215
  • 15#.###.177.250:37215
  • 15#.##.7.242:37215
  • 15#.#.226.239:37215
  • 15#.###.238.40:37215
  • 19#.###.30.254:37215
  • 41.#.#52.6:37215
  • 19#.###.112.161:37215
  • 19#.###.105.255:37215
  • 41.###.40.49:37215
  • 71.##.150.158:37215
  • 15#.##5.65.92:37215
  • 19#.###.156.174:37215
  • 19#.###.206.122:37215
  • 41.###.29.232:37215
  • 15#.##2.50.75:37215
  • 72.##.30.207:37215
  • 18#.###.46.173:37215
  • 18#.###.235.191:37215
  • 27.###.74.11:37215
  • 21#.##.44.61:37215
  • 19#.##.225.212:37215
  • 41.##.96.182:37215
  • 41.###.216.132:37215
  • 19#.##.22.195:37215
  • 15#.##5.186.1:37215
  • 41.###.60.229:37215
  • 19#.##1.5.191:37215
  • 41.##.124.78:37215
  • 34.###.69.173:37215
  • 20#.###.91.205:37215
  • 15#.##.129.202:37215
  • 15#.##.145.63:37215
  • 19#.###.47.180:37215
  • 15#.###.121.77:37215
  • 19#.##.21.124:37215
  • 15#.##.45.198:37215
  • 20.###.111.45:37215
  • 41.###.123.199:37215
  • 41.##.183.218:37215
  • 10#.##0.3.193:37215
  • 41.##.106.40:37215
  • 15#.##.110.191:37215
  • 15#.#.220.133:37215
  • 15#.##.104.231:37215
  • 18.##.56.99:37215
  • 41.###.112.14:37215
  • 19#.###.190.77:37215
  • 19#.###.127.99:37215
  • 13#.##6.7.92:37215
  • 19#.##.35.107:37215
  • 15#.###.180.150:37215
  • 15#.##9.4.93:37215
  • 10#.###.55.173:37215
  • 19#.###.174.158:37215
  • 19#.###.139.100:37215
  • 16#.###.78.221:37215
  • 19#.##1.47.56:37215
  • 19#.###.34.132:37215
  • 19#.###.119.219:37215
  • 15#.###.46.251:37215
  • 19#.###.209.126:37215
  • 5.##.#30.220:37215
  • 19#.##.165.45:37215
  • 19#.##.124.192:37215
  • 78.###.176.168:37215
  • 19#.##.53.174:37215
  • 15#.##.141.152:37215
  • 41.##.141.174:37215
  • 15#.##.61.229:37215
  • 15#.###.114.79:37215
  • 15#.###.144.201:37215
  • 15#.##5.188.3:37215
  • 41.###.235.35:37215
  • 15#.##.120.234:37215
  • 41.##.252.1:37215
  • 41.###.124.232:37215
  • 19#.###.255.209:37215
  • 15#.##.47.0:37215
  • 19#.###.199.254:37215
  • 41.##.93.158:37215
  • 15#.##9.54.47:37215
  • 15#.###.173.203:37215
  • 41.##.66.132:37215
  • 19#.##.156.172:37215
  • 17#.#.144.72:37215
  • 19#.##.60.4:37215
  • 15#.###.251.241:37215
  • 19#.###.146.103:37215
  • 15#.##4.204.7:37215
  • 54.###.58.149:37215
  • 40.###.122.218:37215
  • 19#.##2.81.20:37215
  • 19#.###.125.138:37215
  • 41.###.84.48:37215
  • 19#.###.171.146:37215
  • 15#.###.224.191:37215
  • 19#.###.82.110:37215
  • 41.###.125.62:37215
  • 60.###.64.133:37215
  • 21#.##.80.249:37215
  • 15#.###.66.118:37215
  • 19#.##.117.209:37215
  • 19#.###.123.61:37215
  • 15#.##.118.151:37215
  • 18#.###.156.80:37215
  • 19#.###.163.186:37215
  • 41.###.117.56:37215
  • 95.###.20.11:37215
  • 41.##.139.79:37215
  • 11#.###.133.96:37215
  • 19#.##.247.61:37215
  • 15#.###.235.119:37215
  • 19#.###.10.122:37215
  • 15#.###.119.83:37215
  • 27.##.243.13:37215
  • 15#.##1.92.44:37215
  • 19#.#.203.184:37215
  • 15#.##.179.218:37215
  • 19#.#.220.191:37215
  • 19#.###.248.207:37215
  • 19#.##.164.204:37215
  • 19#.##.21.224:37215
  • 14#.#.222.11:37215
  • 19#.##.204.71:37215
  • 15#.###.216.151:37215
  • 15#.###.120.71:37215
  • 15#.##.27.214:37215
  • 53.###.232.140:37215
  • 15#.###.157.89:37215
  • 41.##.171.130:37215
  • 41.###.30.228:37215
  • 41.###.174.225:37215
  • 15#.###.150.246:37215
  • 41.##.179.24:37215
  • 19#.###.176.46:37215
  • 19#.##.102.110:37215
  • 41.###.1.107:37215
  • 19#.##.18.227:37215
  • 41.###.176.239:37215
  • 19#.###.224.169:37215
  • 15#.##5.37.12:37215
  • 19#.##.199.236:37215
  • 19#.##.95.133:37215
  • 34.###.239.216:37215
  • 15#.###.164.92:37215
  • 15#.##3.84.62:37215
  • 15#.##.33.184:37215
  • 73.##.125.22:37215
  • 19#.###.116.123:37215
  • 82.###.82.14:37215
  • 41.###.62.204:37215
  • 41.##.160.71:37215
  • 15#.##.208.113:37215
  • 20#.##.38.49:37215
  • 15#.###.226.160:37215
  • 15#.#.3.105:37215
  • 41.###.113.130:37215
  • 41.##.199.8:37215
  • 41.###.235.79:37215
  • 15#.###.150.255:37215
  • 15#.###.46.174:37215
  • 41.###.137.253:37215
  • 15#.###.130.135:37215
  • 18.##.103.190:37215
  • 15#.###.46.106:37215
  • 41.###.110.11:37215
  • 41.#.#7.233:37215
  • 13#.##.47.55:37215
  • 19#.##.198.68:37215
  • 0.0.0.0

Curing recommendations


Linux

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Free trial

One month (no registration) or three months (registration and renewal discount)

Download Dr.Web

Download by serial number