Linux.Siggen.7307
Added to the Dr.Web virus database:
2024-05-01
Virus description added:
2024-05-01
Technical Information
Malicious functions:
Removes itself
Launches itself as a daemon
Substitutes application name for:
Kills system processes:
Kills the following processes:
- systemd
- systemd-journal
- systemd-udevd
- rpcbind
- rpc.statd
- rpc.idmapd
- cron
- atd
- systemd-logind
- dbus-daemon
- rsyslogd
- agetty
- mouseemu
- exim4
- dhclient
- lockfile-remove
- run.sh
- tmux
- bash
- sleep
- mc56lrs6i5spp5w
- systemd-cgroups
- systemctl
Network activity:
Awaits incoming connections on ports:
Establishes connection:
- 8.#.8.8:53
- 18#.##1.61.24:53
- 21#.##.149.14:35342
- 91.###.137.37:53
- 51.##.149.139:53
DNS ASK:
- se######.rebirth-network.su
Sends data to the following servers:
- 41.##.54.126:37215
- 19#.##3.39.9:37215
- 41.###.106.246:37215
- 15#.##.222.121:37215
- 31.###.159.133:37215
- 18#.##1.61.24:53
- 15#.###.151.35:37215
- 20#.##7.240.2:37215
- 19#.##.229.71:37215
- 41.##.11.124:37215
- 15#.###.36.205:37215
- 41.###.175.232:37215
- 87.###.211.11:37215
- 41.###.83.46:37215
- 15#.##4.39.12:37215
- 15#.###.153.168:37215
- 19#.###.187.174:37215
- 19#.##.117.31:37215
- 15#.##7.7.179:37215
- 19#.##.238.29:37215
- 19#.###.208.74:37215
- 20#.###.233.173:37215
- 15#.##.149.137:37215
- 21#.##.212.70:37215
- 41.#.#37.16:37215
- 69.##.3.179:37215
- 15#.##9.43.84:37215
- 19#.###.58.173:37215
- 16#.###.135.203:37215
- 49.###.176.84:37215
- 41.###.209.6:37215
- 94.##.168.17:37215
- 41.##.239.114:37215
- 12#.###.138.183:37215
- 19#.##.191.45:37215
- 16#.##.235.45:37215
- 41.###.227.195:37215
- 15#.###.70.179:37215
- 19#.###.32.123:37215
- 13#.###.227.141:37215
- 19#.##.107.137:37215
- 15#.###.22.139:37215
- 19#.###.182.17:37215
- 15#.##.112.34:37215
- 15#.##3.5.121:37215
- 15#.##8.40.77:37215
- 92.###.154.43:37215
- 19#.##.205.204:37215
- 41.#.#.104:37215
- 14#.##.88.96:37215
- 15#.###.238.31:37215
- 44.#.#32.121:37215
- 16#.##.29.255:37215
- 19#.##.109.59:37215
- 13#.##.211.63:37215
- 19#.###.169.45:37215
- 19#.##.248.155:37215
- 41.###.5.181:37215
- 19#.##8.58.18:37215
- 19#.###.241.150:37215
- 41.##.103.167:37215
- 41.##.236.62:37215
- 41.##.151.144:37215
- 41.###.22.75:37215
- 91.###.137.37:53
- 51.##.149.139:53
- 8.#.8.8:53
Receives data from the following servers:
- 18#.##1.61.24:53
- 51.##.149.139:53
- 8.#.8.8:53
Curing recommendations
Linux
Free trial
One month (no registration) or three months (registration and renewal discount)
このウェブサイトを継続して訪問する場合、訪問者に関する統計データを収集するためのCookieファイルおよび他のテクノロジーを弊社が利用することに同意したものとします。詳細