Library
My library

+ Add to library

Profile

Linux.Siggen.1438

Added to the Dr.Web virus database: 2019-02-21

Virus description added:

Technical Information

Malicious functions:
Launches itself as a daemon
Kills system processes:
  • sshd
Kills the following processes:
  • <SAMPLE>
Network activity:
Awaits incoming connections on ports:
  • 127.0.0.1:57886
Establishes connection:
  • 8.#.8.8:53
  • 68.###.157.144:37212
Attacks using a special dictionary (brute-force technique) via the Telnet protocol.
Sends data to the following servers:
  • 19#.##2.29.98:37215
  • 19#.##.46.98:37215
  • 15#.###.254.189:37215
  • 19#.###.17.101:37215
  • 41.###.9.125:37215
  • 19#.##.226.210:37215
  • 19#.##.44.101:37215
  • 15#.###.50.245:37215
  • 15#.##.131.36:37215
  • 19#.#.9.34:37215
  • 41.###.162.215:37215
  • 19#.###.94.251:37215
  • 41.##.89.46:37215
  • 19#.##.15.132:37215
  • 41.###.22.112:37215
  • 19#.##.240.168:37215
  • 15#.##.55.186:37215
  • 15#.###.167.226:37215
  • 19#.###.234.38:37215
  • 19#.###.160.151:37215
  • 41.###.155.89:37215
  • 41.##.123.126:37215
  • 15#.###.145.158:37215
  • 15#.###.82.102:37215
  • 41.##.60.176:37215
  • 41.###.86.35:37215
  • 41.###.181.228:37215
  • 19#.##.12.202:37215
  • 68.###.157.144:37212
  • 19#.##.137.66:37215
  • 19#.##.35.166:37215
  • 41.##.131.123:37215
  • 15#.###.193.17:37215
  • 15#.##.38.220:37215
  • 15#.###.222.162:37215
  • 41.###.48.122:37215
  • 15#.##3.53.49:37215
  • 19#.##.51.123:37215
  • 19#.#.252.230:37215
  • 19#.###.230.235:37215
  • 19#.###.212.38:37215
  • 15#.##.246.132:37215
  • 15#.##.137.4:37215
  • 15#.###.251.187:37215
  • 41.###.173.249:37215
  • 41.###.63.32:37215
  • 19#.###.80.116:37215
  • 41.###.189.43:37215
  • 41.##.228.123:37215
  • 41.###.159.189:37215
  • 15#.##.129.50:37215
  • 41.###.194.58:37215
  • 19#.##1.49.64:37215
  • 19#.###.124.49:37215
  • 41.###.27.10:37215
  • 41.##.198.209:37215
  • 15#.###.81.174:37215
  • 41.###.240.182:37215
  • 41.###.146.212:37215
  • 19#.##1.223.7:37215
  • 19#.##.225.51:37215
  • 15#.###.162.16:37215
  • 15#.###.140.147:37215
  • 41.###.202.138:37215
  • 15#.##.174.61:37215
  • 41.##.189.59:37215
  • 41.###.70.133:37215
  • 19#.###.223.92:37215
  • 15#.###.129.120:37215
  • 19#.###.139.218:37215
  • 41.##.226.220:37215
  • 15#.###.158.162:37215
  • 15#.#.93.100:37215
  • 15#.##.27.224:37215
  • 15#.###.53.188:37215
  • 41.###.111.94:37215
  • 15#.##.97.6:37215
  • 41.##.16.74:37215
  • 41.###.121.32:37215
  • 15#.###.58.190:37215
  • 41.##.1.132:37215
  • 19#.###.62.100:37215
  • 15#.###.26.210:37215
  • 15#.##.47.101:37215
  • 41.###.115.162:37215
  • 41.##.202.3:37215
  • 15#.#.1.146:37215
  • 15#.###.213.96:37215
  • 41.###.40.232:37215
  • 41.###.231.81:37215
  • 19#.##.3.9:37215
  • 15#.###.93.112:37215
  • 15#.###.83.122:37215
  • 41.##.216.76:37215
  • 15#.###.43.212:37215
  • 19#.##.71.34:37215
  • 19#.###.204.26:37215
  • 19#.##.20.232:37215
  • 15#.###.145.103:37215
  • 15#.##.228.111:37215
  • 41.###.250.72:37215
  • 15#.###.28.253:37215
  • 19#.###.200.156:37215
  • 41.##.176.71:37215
  • 19#.#.91.107:37215
  • 41.###.77.206:37215
  • 15#.###.42.244:37215
  • 41.###.244.68:37215
  • 41.##.112.181:37215
  • 15#.###.215.184:37215
  • 15#.###.129.191:37215
  • 19#.###.99.226:37215
  • 41.##.52.85:37215
  • 19#.###.62.222:37215
  • 41.#.#49.225:37215
  • 41.###.246.182:37215
  • 19#.##.245.146:37215
  • 15#.##.211.226:37215
  • 41.###.208.199:37215
  • 19#.##0.70.48:37215
  • 41.###.136.75:37215
  • 19#.##7.8.189:37215
  • 15#.##.77.186:37215
  • 15#.###.64.179:37215
  • 19#.###.200.223:37215
  • 15#.###.134.183:37215
  • 41.##.8.15:37215
  • 15#.###.152.235:37215
  • 41.###.42.238:37215
  • 15#.#.150.208:37215
  • 19#.##.255.126:37215
  • 15#.###.169.59:37215
  • 19#.##.93.224:37215
  • 41.###.226.31:37215
  • 15#.##9.9.14:37215
  • 15#.###.172.123:37215
  • 41.###.189.10:37215
  • 19#.##.200.46:37215
  • 41.##.18.104:37215
  • 41.##.117.202:37215
  • 41.##.118.197:37215
  • 19#.##.61.107:37215
  • 15#.###.154.120:37215
  • 41.###.160.213:37215
  • 41.##.101.134:37215
  • 15#.###.220.43:37215
  • 41.###.156.225:37215
  • 15#.##0.3.255:37215
  • 15#.###.99.234:37215
  • 19#.##.233.36:37215
  • 41.###.108.192:37215
  • 19#.##.176.208:37215
  • 15#.###.201.65:37215
Receives data from the following servers:
  • 68.###.157.144:37212

Curing recommendations


Linux

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Free trial

One month (no registration) or three months (registration and renewal discount)

Download Dr.Web

Download by serial number