Library
My library

+ Add to library

Profile

Linux.Siggen.3532

Added to the Dr.Web virus database: 2021-01-24

Virus description added:

Technical Information

Malicious functions:
Launches itself as a daemon
Substitutes application name for:
  • sshd
Modifies firewall settings:
  • iptables -I INPUT -p tcp --destination-port 56595 -j ACCEPT
  • iptables -I OUTPUT -p tcp --source-port 56595 -j ACCEPT
  • iptables -I PREROUTING -t nat -p tcp --destination-port 56595 -j ACCEPT
  • iptables -I INPUT -p tcp --destination-port 22 -j DROP
Launches processes:
  • sh -c killall -9 telnetd utelnetd scfgmgr
  • sh -c iptables -I INPUT -p tcp --destination-port 56595 -j ACCEPT
  • sh -c iptables -I OUTPUT -p tcp --source-port 56595 -j ACCEPT
  • sh -c iptables -I PREROUTING -t nat -p tcp --destination-port 56595 -j ACCEPT
  • sh -c iptables -I INPUT -p tcp --destination-port 22 -j DROP
  • sh -c iptables -I INPUT -p tcp --destination-port 23 -j DROP
Attempts to kill the following processes:
  • killall -9 telnetd utelnetd scfgmgr
Performs operations with the file system:
Creates or modifies files:
  • /proc/self/oom_score_adj
  • /proc/531/oom_score_adj
  • /root/.ips
Network activity:
Awaits incoming connections on ports:
  • 127.0.0.1:14737
  • 0.0.0.0:33445
  • 0.0.0.0:56595
Establishes connection:
  • 8.#.8.8:53
  • 85.##.77.35:5555
  • 27.##.117.49:8080
  • 13#.##.169.63:60001
  • 85.###.192.127:8080
  • 20#.###.225.203:8081
  • 12.##.108.206:8081
  • 15#.##3.241.81:8181
  • 61.###.100.239:8081
  • 17#.###.178.75:52869
  • 10#.##3.92.149:8080
  • 21#.##.163.65:8181
  • 79.##.7.67:49152
  • 16#.##8.51.212:80
  • 11#.##2.254.168:80
  • 31.##1.86.14:80
  • 18#.##.46.124:80
  • 15#.##9.1.35:37215
  • 13#.##.151.117:80
  • 53.###.222.123:8080
  • 55.##.123.200:80
  • 10#.###.202.247:8080
  • 21#.##.69.161:37215
  • 38.###.135.226:60001
  • 11#.##.217.56:49152
  • 19#.#.37.70:80
  • 18#.#8.22.10:81
  • 73.###.114.45:8443
  • 18#.###.115.164:8080
  • 19#.##3.28.116:80
  • 19#.##7.169.1:80
  • 18#.#5.131.8:81
  • 17#.##.184.176:7574
  • 22#.###.159.245:8080
  • 21#.##7.240.156:80
  • 44.##.216.112:8080
  • 91.###.215.228:60001
  • 21#.###.19.171:52869
  • 70.###.173.81:8443
  • 14#.##0.199.94:7574
  • 99.##1.65.54:80
  • 17#.##2.137.7:80
  • 19#.##.145.218:5555
  • 36.###.60.26:8081
  • 21#.##9.213.80:8443
  • 11#.###.110.167:60001
  • 97.##.15.29:80
  • 16#.###.203.92:37215
  • 55.###.4.190:8081
  • 15#.##5.92.70:81
  • 10#.##9.24.129:8181
  • 13#.##.91.233:8080
  • 21.#.#82.72:5555
  • 19#.##7.5.141:8080
  • 63.###.149.71:8443
  • 20#.##.65.169:8080
  • 66.##.157.44:49152
  • 15#.#32.32.9:80
  • 14#.##.131.200:7574
  • 18#.###.108.227:7574
  • 15#.###.46.189:37215
  • 15#.##1.1.155:80
  • 16#.##9.11.91:80
  • 77.###.242.109:80
  • 19#.##1.104.97:8081
  • 51.##.231.37:52869
  • 20#.###.157.110:5555
  • 12.##.78.29:80
  • 49.###.40.204:60001
  • 13#.###.164.236:8080
  • 14#.##4.50.53:80
  • 82.###.52.109:81
  • 17#.##3.167.8:80
  • 50.###.117.9:5555
  • 62.##.125.109:80
  • 14#.##7.52.141:80
  • 16#.##1.27.245:8080
  • 64.##.94.237:80
  • 15#.##8.68.61:8080
  • 17#.##9.161.186:80
  • 5.###.171.203:8080
  • 21#.##3.59.24:80
  • 10#.###.175.106:8080
  • 18#.##8.205.20:8080
  • 16#.###.169.39:37215
  • 19#.##6.5.146:80
  • 14#.##2.152.25:8081
  • 56.###.157.224:7574
  • 96.###.12.252:8080
  • 15#.##0.121.254:80
  • 21#.###.175.238:8181
  • 81.###.19.180:60001
  • 10#.##5.48.202:8443
  • 15#.##1.253.7:8081
  • 21#.##.198.165:8443
  • 16#.##9.73.94:8080
  • 19#.###.180.148:8080
  • 19#.##0.99.224:80
  • 21#.##.179.142:8081
  • 13#.##.2.53:8080
  • 18#.###.141.211:8080
  • 93.##.122.88:8080
  • 49.##.155.111:37215
  • 68.###.122.22:81
  • 20#.##9.14.136:80
  • 20#.#.72.168:49152
  • 6.###.240.25:60001
  • 20#.###.118.234:8080
  • 21#.##.125.50:80
  • 16#.##.159.238:5555
  • 64.###.36.203:81
  • 62.###.125.24:8080
  • 15#.##.184.169:80
  • 12#.#1.64.88:80
  • 16#.##.220.79:37215
  • 95.###.44.16:5555
  • 20#.##0.135.141:80
  • 79.##.4.155:80
  • 13#.##3.91.230:80
  • 72.##.174.206:60001
  • 18#.##.68.177:60001
  • 20#.###.154.132:8080
  • 70.###.124.229:49152
  • 20.##.64.212:8081
  • 19#.##2.192.216:81
  • 12#.##.250.148:8080
  • 36.#.208.10:80
  • 15#.##1.50.247:8080
  • 15#.##.211.104:80
  • 18#.##.91.209:80
  • 49.###.121.244:8181
  • 16#.##6.254.36:8080
  • 21.###.235.167:8081
  • 82.###.130.43:80
  • 30.###.102.228:80
  • 96.###.4.41:8080
  • 91.###.134.193:8080
  • 13#.###.172.192:8181
  • 21#.###.206.244:5555
  • 15#.##0.59.230:80
  • 13#.##.43.113:8081
  • 11#.##8.9.250:7574
  • 12#.##.201.26:52869
  • 62.###.51.153:8443
  • 23.##.174.10:8080
  • 10#.##4.167.102:80
  • 18#.##7.150.10:7574
  • 12#.##3.65.196:7574
  • 15#.##.67.181:80
  • 67.###.245.161:8080
  • 76.###.189.199:37215
  • 94.##.201.86:8081
  • 13#.##1.44.15:80
  • 93.##.249.158:80
  • 56.##.21.68:7574
  • 87.##.205.37:7574
  • 95.###.144.56:52869
  • 11#.###.101.168:8080
  • 18#.##7.65.80:8080
  • 19#.##.252.196:80
  • 48.###.142.102:8080
  • 11#.##0.146.164:80
  • 9.##.82.135:80
  • 35.###.89.218:81
  • 10#.##5.71.252:80
  • 13#.##1.115.129:80
  • 15#.##5.62.4:8080
  • 16#.##.229.97:37215
  • 28.###.48.226:7574
  • 19#.###.35.212:60001
  • 11#.##8.105.113:80
  • 72.###.40.144:8181
  • 15#.##.103.202:8080
  • 18.##.241.155:8080
  • 19#.#.78.207:37215
  • 20#.##2.24.178:80
  • 15#.##.202.25:8080
  • 10#.###.134.182:8081
  • 4.###.160.72:80
  • 11#.##.24.54:8080
  • 70.##.194.72:8080
  • 81.###.32.203:8080
  • 6.###.214.178:60001
  • 51.##.116.226:80
  • 21.###.96.144:80
  • 20#.##.99.192:80
  • 58.###.134.104:80
  • 19#.##2.27.8:5555
  • 20#.#4.68.43:80
  • 11#.##3.189.96:80
  • 16#.##8.187.1:5555
  • 11#.#.124.195:80
  • 18#.##.129.72:80
  • 74.##8.91.18:80
  • 14#.##3.53.28:8080
  • 74.#.#1.187:8081
  • 53.##.101.20:80
  • 18#.##.236.125:8081
  • 12#.##.107.165:8080
  • 10#.##6.119.39:80
  • 95.##.95.127:8081
  • 13#.###.165.199:8080
  • 12#.##.95.6:5555
  • 14#.#.38.2:80
  • 15#.##5.59.107:80
  • 17#.##.105.39:80
  • 73.###.167.176:81
  • 11#.##.160.188:80
  • 52.###.221.62:81
  • 12#.##2.35.250:8080
  • 22.##4.0.118:80
  • 80.##.22.27:80
  • 16#.##7.56.33:60001
  • 13.###.148.88:60001
  • 94.##2.128.2:80
  • 66.###.129.104:80
  • 87.##.115.69:8080
  • 12#.##5.70.224:80
  • 15#.###.234.152:8081
  • 12#.##.73.130:52869
  • 17#.##2.23.235:7574
  • 15#.###.101.119:8081
  • 18#.##0.36.104:8080
  • 16#.##9.236.47:8081
  • 81.###.78.100:7574
  • 21#.##1.153.197:80
  • 12#.#.54.102:49152
  • 18#.###.138.126:8080
  • 21#.##6.64.120:80
  • 60.###.250.75:8081
  • 19#.###.190.61:52869
  • 21#.##1.73.249:80
  • 18#.##.107.176:8181
  • 20#.##.196.58:8081
  • 76.###.218.5:5555
  • 15#.##1.3.107:5555
  • 13#.###.230.246:49152
  • 40.###.115.171:8080
  • 11#.##7.98.103:8080
  • 18#.##.75.5:8081
  • 13#.##7.106.223:80
  • 15#.##4.235.186:80
  • 69.##.203.237:8080
  • 15#.#.46.117:8080
  • 11#.###.136.216:8081
  • 10#.##1.36.139:8080
  • 25.###.239.65:8080
  • 21#.##.22.22:60001
  • 61.##.244.4:8181
  • 72.###.237.99:8443
  • 19#.##.117.71:5555
  • 20#.###.236.170:8080
  • 2.###.168.35:7574
  • 14#.##.77.13:8081
  • 33.###.254.87:80
  • 46.###.145.80:8081
  • 2.##.178.6:80
  • 74.###.117.124:8081
  • 14#.##.131.187:81
  • 11.###.74.217:37215
  • 41.###.85.35:8443
  • 38.###.205.77:8443
  • 12#.##7.229.114:80
  • 21#.##6.232.72:81
  • 16#.###.135.204:8080
  • 16#.##.153.95:8081
  • 20#.##1.64.225:7574
  • 23.###.220.217:60001
  • 10#.###.52.158:37215
  • 21#.##8.75.42:81
  • 14#.##8.1.167:49152
  • 11#.##6.169.8:52869
  • 15#.#45.5.74:80
  • 88.##.136.207:80
  • 61.###.228.108:80
  • 20#.##.231.138:8081
  • 92.##.73.61:80
  • 41.###.119.219:80
  • 42.###.132.72:49152
  • 18#.##.167.35:8080
  • 54.##.207.171:49152
  • 13#.##7.29.131:8081
  • 29.###.50.224:80
  • 54.###.99.200:8181
  • 9.###.240.180:80
  • 93.###.130.56:80
  • 70.###.70.104:52869
  • 20#.###.110.202:49152
  • 21#.#.99.170:80
  • 51.###.103.179:8080
  • 14#.##6.51.234:8080
  • 20#.##9.212.12:8080
  • 72.###.34.233:8443
  • 77.##.96.22:8081
  • 18#.##8.1.195:80
  • 74.###.1.33:8081
  • 12#.##7.163.92:8443
  • 11#.##.251.197:8080
  • 45.##7.201.6:80
  • 17#.##.247.176:80
  • 18#.###.186.189:8080
  • 29.##.128.15:5555
  • 17#.##4.33.14:81
  • 10#.###.68.150:49152
  • 1.###.35.141:8080
  • 94.##.211.237:37215
  • 21#.##4.188.169:80
  • 15#.##7.11.157:81
  • 21#.##7.174.186:80
  • 15#.#6.50.36:81
  • 18#.##.133.60:80
  • 14#.##2.126.125:80
  • 19#.##.147.91:80
  • 89.##.35.20:80
  • 14#.##7.194.30:80
  • 12#.##7.71.97:8080
  • 27.###.132.236:8080
  • 19.###.188.127:8443
  • 62.#.36.216:80
  • 21#.#.121.67:37215
  • 15#.##1.0.245:80
  • 14#.##3.167.13:8080
  • 15#.##4.89.107:8080
  • 70.###.247.132:80
  • 12#.##.143.140:8080
  • 90.##.45.149:8080
  • 16#.##3.213.113:80
  • 15#.##.177.226:8080
  • 21#.##1.48.80:80
  • 67.##.148.237:8080
  • 8.###.176.202:8080
  • 12#.##.239.43:80
  • 81.##.0.234:49152
  • 20#.###.118.113:8080
  • 13#.###.106.103:8080
  • 11.##.32.35:80
  • 76.##.224.95:80
  • 13#.##.89.0:8080
  • 14#.##.232.173:8080
  • 18#.##.14.136:8443
  • 11#.##7.74.27:8080
  • 12.##.67.123:80
  • 70.#.26.70:8081
  • 22.##.218.113:8081
  • 88.###.216.211:80
  • 19#.##.225.203:8181
  • 12#.#6.33.59:80
  • 23.##.4.113:81
  • 20#.##.187.223:8080
  • 12#.##.191.134:80
  • 10#.###.133.106:8080
  • 24.##.164.253:8080
  • 32.###.26.116:80
  • 13#.##.136.130:49152
  • 10#.##3.28.172:8080
  • 4.##.#4.182:49152
  • 46.###.127.129:8081
  • 13#.##.217.68:8081
  • 20#.##1.12.162:8181
  • 10#.#.25.7:8081
  • 18#.###.144.218:7574
  • 20#.###.119.193:8080
  • 11#.##.109.253:8080
  • 68.###.17.246:8080
  • 17#.##4.151.143:80
  • 35.###.49.251:80
  • 45.###.70.163:8080
  • 20#.##1.101.76:80
  • 10#.##8.81.242:80
  • 61.##.135.153:8080
  • 16#.##4.110.149:80
  • 12#.##4.133.168:80
  • 20#.##7.136.78:8080
  • 18#.###.150.109:49152
  • 16#.###.115.235:8080
  • 18#.##2.82.248:8080
  • 91.###.190.151:80
  • 14#.##1.254.212:80
  • 45.###.152.197:8080
  • 13.###.249.4:8181
  • 94.###.244.131:80
  • 14#.###.98.180:49152
  • 88.###.108.227:8080
  • 45.##.26.23:80
  • 10#.##6.35.24:8081
  • 27.###.243.145:80
  • 18.###.210.110:81
  • 20#.##.62.206:80
  • 66.##.204.156:8080
  • 19#.##.166.172:80
  • 14#.##.200.230:8181
  • 18#.###.25.211:52869
  • 82.###.172.180:80
  • 20#.##.234.175:5555
  • 15#.##0.246.7:8080
  • 58.###.238.111:81
  • 60.###.181.252:80
  • 15#.##.198.153:8081
  • 11#.##.90.81:8081
  • 49.###.179.105:8080
  • 49.###.98.188:80
  • 68.###.81.126:80
  • 58.###.224.19:80
  • 10#.##.50.124:8080
  • 66.###.164.242:37215
  • 17#.###.173.166:8081
  • 52.###.32.82:37215
  • 19#.##.222.81:37215
  • 14#.##7.38.91:80
  • 20#.##9.234.186:81
  • 18#.##.195.127:80
  • 23.###.45.211:80
  • 11#.##1.42.187:8080
  • 21.##.59.49:37215
  • 18#.##.166.107:80
Attacks using a special dictionary (brute-force technique) via the Telnet protocol.
Sends data to the following servers:
  • 23#.###.255.250:1900
  • 10#.##6.109.219:23
  • 18#.##2.121.177:23
  • 10#.##0.176.100:23
  • 22#.##0.30.13:23
  • 72.###.199.144:23
  • 14#.##.185.68:23
  • 2.###.41.41:23
  • 18#.##.142.214:23
  • 17#.##7.180.111:23

Curing recommendations


Linux

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Free trial

One month (no registration) or three months (registration and renewal discount)

Download Dr.Web

Download by serial number