マイライブラリ
マイライブラリ

+ マイライブラリに追加

電話

お問い合わせ履歴

電話(英語)

+7 (495) 789-45-86

Profile

Linux.Siggen.7152

Added to the Dr.Web virus database: 2024-04-18

Virus description added:

Technical Information

Malicious functions:
Launches itself as a daemon
Substitutes application name for:
  • e28081
Kills the following processes:
  • systemd
  • kthreadd
  • ksoftirqd/0
  • kworker/0:0
  • kworker/0:0H
  • watchdog/0
  • khelper
  • kdevtmpfs
  • netns
  • khungtaskd
  • writeback
  • ksmd
  • crypto
  • kintegrityd
  • bioset
  • kblockd
  • kswapd0
  • fsnotify_mark
  • kthrotld
  • ipv6_addrconf
  • deferwq
  • kworker/u2:1
  • kpsmoused
  • scsi_eh_0
  • scsi_tmf_0
  • kworker/0:1H
  • kworker/u2:2
  • jbd2/sda1-8
  • ext4-rsv-conver
  • kauditd
  • kworker/0:3
  • systemd-journal
  • systemd-udevd
  • rpciod
  • nfsiod
  • systemd-logind
  • kworker/0:1
  • dhclient
  • lockfile-touch
  • 9bc2fd2a
  • systemd-cgroups
Network activity:
Awaits incoming connections on ports:
  • 127.0.0.1:33337
  • 0.0.0.0:23951
Establishes connection:
  • 8.#.8.8:53
  • 45.###.232.208:33335
  • 13#.###.169.191:26507
Attacks using a special dictionary (brute-force technique) via the Telnet protocol.
DNS ASK:
  • ro##me.xyz
Sends data to the following servers:
  • 45.###.232.208:33335
  • 13#.###.169.191:26507
  • 22#.##1.112.213:23
  • 15#.##.203.200:23
  • 71.###.144.58:23
  • 15#.##.166.166:23
  • 17#.##2.51.10:23
  • 14#.##4.79.165:23
  • 89.##.73.46:23
  • 16#.##0.189.205:23
  • 17#.#2.70.91:23
  • 13.###.214.145:23
  • 41.###.211.216:23
  • 13#.##4.211.176:23
  • 4.#.#05.141:23
  • 37.##0.85.34:23
  • 54.###.40.151:23
  • 13#.##3.23.100:23
  • 14#.##8.5.129:23
  • 12.###.136.88:23
  • 57.##.237.221:23
  • 22#.##.246.149:23
  • 20#.##.241.64:23
  • 12.##2.15.39:23
  • 21#.##6.253.158:23
  • 16#.##1.180.140:23
  • 15#.##.17.124:23
  • 51.###.16.129:23
  • 15#.##.142.129:23
  • 35.##.180.174:23
  • 12#.##2.218.140:23
  • 18#.##4.82.170:23
  • 17#.##.109.22:23
  • 33.##.196.136:23
  • 17.###.196.204:23
  • 48.#.93.180:23
  • 74.###.185.244:23
  • 17.###.99.118:23
  • 24#.##2.164.98:23
  • 5.##.49.56:23
  • 25#.##6.135.73:23
  • 7.###.173.33:23
  • 16#.##.166.220:23
  • 87.###.205.239:23
  • 38.###.247.138:23
  • 26.###.137.161:23
  • 12#.##9.140.18:23
  • 11#.##.191.34:23
  • 12#.##.221.83:23
  • 15#.##1.104.196:23
  • 20#.##.245.61:23
  • 35.##0.215.3:23
  • 17.##.209.210:23
  • 14#.##4.252.245:23
  • 23#.##7.181.2:23
  • 65.##4.42.76:23
  • 17#.##0.55.206:23
  • 13#.##6.22.159:23
  • 16#.##2.116.145:23
  • 22#.##9.74.156:23
  • 12.##.134.224:23
  • 23#.##3.59.129:23
  • 18#.##4.15.40:23
  • 22#.#4.26.23:23
  • 37.###.245.103:23
  • 25#.##0.7.129:23
  • 21#.##7.61.151:23
  • 14#.##4.235.245:23
  • 21#.##6.158.137:23
  • 23#.##6.188.91:23
  • 23#.##.151.217:23
  • 16#.##9.0.198:23
  • 11#.##.236.168:23
  • 75.##8.174.8:23
  • 17#.##7.191.229:23
  • 20.###.125.192:23
  • 41.###.168.34:23
  • 74.###.157.95:23
  • 23.###.69.136:23
  • 25#.##0.58.62:23
  • 20#.#1.7.172:23
  • 54.##0.21.32:23
  • 56.###.134.52:23
  • 21#.##.178.115:23
  • 10#.##3.230.156:23
  • 41.###.233.84:23
  • 21#.##.206.148:23
  • 38.##.134.157:23
  • 21#.##.48.185:23
  • 11#.##2.195.49:23
  • 13#.##1.227.96:23
  • 91.###.141.67:23
  • 56.##6.162.9:23
  • 12#.##.190.214:23
  • 16.###.85.170:23
  • 15#.##3.165.60:23
  • 14#.##3.80.218:23
  • 62.###.154.191:23
  • 10#.##1.135.123:23
  • 12#.##1.241.213:23
  • 85.###.167.147:23
  • 14#.##5.217.234:23
  • 43.###.127.252:23
  • 23#.##4.140.128:23
  • 14#.##.82.110:23
  • 20#.##7.128.201:23
  • 22#.##.68.104:23
  • 10#.##6.246.150:23
  • 17#.##.220.226:23
  • 15#.##.93.161:23
  • 58.##1.3.94:23
  • 92.###.114.215:23
  • 37.#.49.31:23
  • 16#.##.111.70:23
  • 23#.##.161.198:23
  • 7.###.212.135:23
  • 88.###.76.169:23
  • 18#.##0.42.182:23
  • 51.##.144.55:23
  • 11#.##.13.237:23
  • 14.###.237.195:23
  • 23#.##.143.223:23
  • 31.##.7.202:23
  • 98.##.125.86:23
  • 51.##.13.110:23
  • 14.##.136.115:23
  • 10#.#1.69.40:23
  • 16#.##4.148.197:23
  • 32.##1.29.65:23
  • 11#.##4.147.18:23
  • 15#.##2.103.104:23
  • 17#.##4.221.47:23
  • 18#.##.104.203:23
  • 12#.##8.57.37:23
  • 3.##.155.118:23
  • 23#.##0.246.98:23
  • 15#.##6.190.218:23
  • 12#.##6.5.168:23
  • 21#.##.85.160:23
  • 24#.##8.22.244:23
  • 18.##.2.238:23
  • 4.###.195.110:23
  • 87.###.255.244:23
  • 10#.##4.73.50:23
  • 99.##.57.97:23
  • 11#.##5.20.167:23
  • 18#.#9.10.15:23
  • 20#.##8.169.87:23
  • 15#.##7.182.111:23
  • 29.##1.85.48:23
  • 13#.##.196.187:23
  • 18#.##3.150.142:23
  • 18#.##7.12.200:23
  • 10#.##0.229.80:23
  • 88.#.183.79:23
  • 23#.##1.38.198:23
  • 14#.##5.238.4:23
  • 13#.##0.221.35:23
  • 18#.##6.36.71:23
  • 4.##.29.118:23
  • 20#.##.18.131:23
  • 74.###.151.227:23
  • 62.##.178.44:23
  • 19#.##7.57.115:23
  • 21#.##2.131.212:23
  • 15#.#2.90.68:23
  • 86.###.237.139:23
  • 66.##.20.108:23
  • 13#.#73.5.93:23
  • 96.##.137.144:23
  • 22#.##0.125.174:23
  • 27.#.208.183:23
  • 10#.##.158.42:23
  • 16#.##.122.198:23
  • 17.##.39.85:23
  • 11#.##.116.215:23
  • 24#.##3.59.56:23
  • 23.###.37.179:23
  • 14#.##1.114.70:23
  • 50.###.62.240:23
  • 10#.##5.133.23:23
  • 22.###.251.20:23
  • 12#.##.223.34:23
  • 24#.##.85.250:23
  • 22.#.26.102:23
  • 55.##.17.117:23
  • 17#.##9.242.117:23
  • 54.##2.2.179:23
  • 10#.##3.234.33:23
  • 18#.##6.145.252:23
  • 15#.##0.43.106:23
  • 14#.##5.213.112:23
  • 14#.##3.180.153:23
  • 62.###.91.242:23
  • 21#.##4.162.3:23
Receives data from the following servers:
  • 45.###.232.208:33335

Curing recommendations


Linux

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Free trial

One month (no registration) or three months (registration and renewal discount)

Download Dr.Web

Download by serial number