Mi biblioteca
Mi biblioteca

+ Añadir a la biblioteca

Soporte
Soporte 24 horas | Normas de contactar

Sus solicitudes

Perfil

Linux.Siggen.502

Added to the Dr.Web virus database: 2018-03-30

Virus description added:

Technical Information

Malicious functions:
Modifies firewall settings:
  • iptables -I INPUT -p udp -m udp --dport 39898 -j ACCEPT
Performs operations with the file system:
Deletes files:
  • <SAMPLE_FULL_PATH>"
Network activity:
Awaits incoming connections on ports:
  • 0.0.0.0:39898
Establishes connection:
  • 8.#.8.8:53
  • [:##]:39898
  • 127.0.0.1:39898
  • 17#.#.23.20:80
  • 11#.##.221.223:80
  • 14#.#11.7.14:80
  • 20#.##6.91.69:80
  • 20#.#.198.227:80
  • 14#.##5.181.114:80
  • 21#.##0.197.21:80
HTTP GET requests:
  • http://##.##3.79.23/
Sends data to the following servers:
  • 60.###.253.65:8588
  • 19#.##.207.36:80
  • 17#.#.23.20:80
  • 18#.##3.163.1:80
  • 16#.##.129.14:80
  • 46.#.166.237:80
  • 13#.##.147.21:80
  • 63.###.146.36:80
  • 18#.##6.106.213:80
  • 23.##.150.241:80
  • 22#.##.14.159:80
  • 24.##.10.215:80
  • 67.##.242.16:80
  • 95.##0.43.63:80
  • 63.###.117.58:80
  • 53.###.235.133:80
  • 22#.##3.127.124:80
  • 15#.##1.232.102:80
  • 11#.##.221.223:80
  • 50.###.13.220:80
  • 46.##.38.156:80
  • 19#.##7.137.170:80
  • 17#.#.60.234:80
  • 17.##.169.14:80
  • 76.###.59.105:80
  • 11#.##.80.166:80
  • 14#.##.46.106:80
  • 51.###.95.134:80
  • 19#.##4.61.162:80
  • 44.##7.10.60:80
  • 16#.##1.122.130:80
  • 13#.##4.213.88:80
  • 19#.##.161.192:80
  • 20#.##1.241.194:80
  • 20#.##.239.47:80
  • 15#.##1.1.136:80
  • 5.##.194.91:80
  • 13#.##6.188.9:80
  • 18#.##7.254.22:80
  • 14#.##9.122.79:80
  • 96.###.119.141:80
  • 12#.##6.28.161:80
  • 39.##.94.74:80
  • 41.###.200.49:80
  • 16#.#.93.127:80
  • 16#.##.76.122:80
  • 21#.##9.206.161:80
  • 87.###.218.78:80
  • 76.##.202.35:80
  • 13.##.219.123:80
  • 18#.##6.105.61:80
  • 12.##.222.215:80
  • 37.###.135.16:80
  • 16#.##2.9.130:80
  • 53.###.120.202:80
  • 65.###.202.231:80
  • 14#.#11.7.14:80
  • 20#.##6.91.69:80
  • 18#.##0.231.59:80
  • 15#.##8.255.85:80
  • 18#.##0.121.69:80
  • 12#.##.71.197:80
  • 15#.##1.183.6:80
  • 34.###.71.197:80
  • 16#.#.234.236:80
  • 43.###.38.183:80
  • 19#.#4.32.89:80
  • 40.###.134.240:80
  • 2.###.102.89:80
  • 20#.##.37.122:80
  • 98.##2.97.43:80
  • 44.###.119.107:80
  • 13#.##.204.18:80
  • 18#.##3.200.141:80
  • 10#.##2.207.217:80
  • 92.##6.240.0:80
  • 14#.##3.201.109:80
  • 15#.##6.148.209:80
  • 10#.##9.232.168:80
  • 11#.##.116.250:80
  • 62.###.106.174:80
  • 34.##.108.158:80
  • 10#.##.137.126:80
  • 98.##1.48.9:80
  • 15#.##8.244.30:80
  • 13#.##0.251.203:80
  • 12#.##.144.52:80
  • 90.###.190.26:80
  • 11#.##5.128.103:80
  • 66.##1.89.33:80
  • 17.#.176.161:80
  • 12#.##7.38.218:80
  • 16#.##9.204.239:80
  • 37.##.215.141:80
  • 20#.#.154.131:80
  • 22#.##9.166.51:80
  • 36.###.198.116:80
  • 17#.#.225.178:80
  • 12#.##8.9.203:80
  • 34.##8.6.180:80
  • 16#.##9.82.83:80
  • 52.###.106.90:80
  • 17#.##8.153.163:80
  • 87.##.237.190:80
  • 20#.##.83.220:80
  • 95.###.198.104:80
  • 20#.##.34.113:80
  • 14#.##5.181.114:80
  • 15#.#1.206.7:80
  • 19#.##6.62.170:80
  • 12#.##3.53.147:80
  • 12#.##3.171.156:80
  • 16#.##6.35.116:80
  • 19#.#1.58.9:80
  • 10#.#3.134.1:80
  • 17#.##9.171.204:80
  • 94.###.226.209:80
  • 20#.#.198.227:80
  • 21#.##.185.32:80
  • 15#.##6.48.148:80
  • 11#.##2.131.37:80
  • 21#.##0.197.21:80
  • 13#.#00.45.4:80
  • 10#.#6.97.63:80
  • 4.#.#05.135:80
  • 5.##.69.237:80
  • 18#.##.56.179:80
  • 84.###.239.184:80
  • 64.##.2.66:80
  • 84.###.201.144:80
  • 16#.##.41.181:80
  • 66.###.74.142:80
  • 63.###.242.173:80
  • 46.###.61.183:80
  • 21#.##.125.174:80
  • 19#.##4.19.58:80
  • 12#.##.138.145:80
  • 91.##6.11.83:80
  • 16#.##5.75.30:80
  • 17#.##8.99.42:80
  • 15#.#2.2.214:80
  • 13#.##.181.141:80
  • 19#.##3.129.226:80
  • 12#.##6.42.183:80
  • 17#.##1.236.158:80
  • 84.##5.149.9:80
  • 4.##.215.127:80
  • 21#.##8.164.143:80
  • 12#.##1.86.40:80
  • 18#.##6.92.156:80
  • 17#.#1.64.39:80
  • 74.##.187.162:80
  • 76.###.29.199:80
  • 11#.##4.42.161:80
  • 90.##4.7.203:80
  • 15#.#5.43.71:80
  • 10#.##1.24.194:80
  • 17#.##.137.186:80
  • 13#.#.251.6:80
  • 15#.##4.224.213:80
  • 13#.##5.240.85:80
  • 16#.##.43.133:80
  • 12#.##.91.224:80
  • 87.###.196.107:80
  • 19#.##5.101.149:80
  • 19#.##5.0.255:80
  • 19#.##8.214.0:80
  • <LOCAL_GATE>:80

Curing recommendations


Linux

After booting up, run a full scan of all disk partitions with Dr.Web Anti-virus for Linux.

Free trial

One month (no registration) or three months (registration and renewal discount)

Download Dr.Web

Download by serial number