マイライブラリ
マイライブラリ

+ マイライブラリに追加

電話

お問い合わせ履歴

電話(英語)

+7 (495) 789-45-86

Profile

Linux.Siggen.7184

Added to the Dr.Web virus database: 2024-04-19

Virus description added:

Technical Information

Malicious functions:
Launches itself as a daemon
Substitutes application name for:
  • e28081
Kills the following processes:
  • rpcbind
  • rpc.statd
  • rpc.idmapd
  • cron
  • dbus-daemon
  • rsyslogd
  • agetty
  • lockfile-touch
  • run.sh
  • sleep
  • stub.sh
  • tee
Network activity:
Awaits incoming connections on ports:
  • 127.0.0.1:33337
Establishes connection:
  • 8.#.8.8:53
  • 45.###.232.208:33335
Attacks using a special dictionary (brute-force technique) via the Telnet protocol.
DNS ASK:
  • ro##me.xyz
Sends data to the following servers:
  • 45.###.232.208:33335
  • 14#.##4.175.117:23
  • 75.##4.2.11:23
  • 24#.#.40.30:23
  • 11.###.215.116:23
  • 36.##2.90.87:23
  • 15#.##.54.140:23
  • 13#.##.231.28:23
  • 17#.##9.247.169:23
  • 66.###.56.127:23
  • 53.###.172.160:23
  • 13#.#.184.52:23
  • 30.###.82.217:23
  • 14#.##5.135.211:23
  • 25#.##.78.197:23
  • 73.###.245.52:23
  • 28.###.212.147:23
  • 18#.#.204.96:23
  • 68.##.25.101:23
  • 51.###.129.212:23
  • 23#.##7.128.64:23
  • 24#.##3.220.74:23
  • 11#.##7.83.135:23
  • 21#.##7.75.213:23
  • 55.###.100.67:23
  • 13#.##1.14.62:23
  • 13#.##7.34.133:23
  • 17#.##9.83.104:23
  • 25#.##1.52.68:23
  • 27.##.177.118:23
  • 23#.##2.181.38:23
  • 5.###.82.16:23
  • 18#.##.55.191:23
  • 29.###.89.254:23
  • 38.##.55.138:23
  • 98.###.65.194:23
  • 19#.##6.203.162:23
  • 19#.##.169.19:23
  • 24#.##0.18.205:23
  • 13#.##.120.225:23
  • 14#.#9.75.63:23
  • 6.###.78.75:23
  • 98.###.241.113:23
  • 44.##.230.117:23
  • 11#.##6.5.144:23
  • 18#.##.96.184:23
  • 11#.##.149.120:23
  • 23#.##2.170.227:23
  • 14#.##9.70.132:23
  • 22#.##6.233.133:23
  • 98.###.252.55:23
  • 24#.##2.16.216:23
  • 19#.##7.142.163:23
  • 13#.#.226.201:23
  • 18#.##5.119.127:23
  • 30.###.94.246:23
  • 42.##.92.130:23
  • 24#.##.158.100:23
  • 63.##.187.103:23
  • 22#.##0.11.157:23
  • 16#.##8.204.10:23
  • 11#.##0.104.227:23
  • 91.##4.64.46:23
  • 28.###.126.144:23
  • 74.##.56.254:23
  • 19#.##5.12.41:23
  • 17#.#7.20.94:23
  • 19#.##1.14.97:23
  • 21#.##0.240.30:23
  • 20#.#1.73.2:23
  • 11#.#5.62.93:23
  • 69.##.251.185:23
  • 31.##.162.122:23
  • 6.##.7.210:23
  • 16#.##6.13.176:23
  • 10#.##.30.129:23
  • 14#.##9.227.123:23
  • 20#.##9.88.191:23
Receives data from the following servers:
  • 45.###.232.208:33335

Curing recommendations


Linux

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Free trial

One month (no registration) or three months (registration and renewal discount)

Download Dr.Web

Download by serial number