Linux/LuaBot
Linux/LuaBot
"Malware Must Die" released a great analysis on a new Linux bot, written in Lua.
http://blog.malwaremustdie.org/2016/09/ ... uabot.html
http://blog.malwaremustdie.org/2016/09/ ... uabot.html
- Xylitol
- Global Moderator
- Posts: 1671
- Joined: Sat Apr 10, 2010 5:54 pm
- Location: Seireitei, Soul Society
- Contact:
Re: Linux/LuaBot
In attachment
https://www.virustotal.com/en/file/e1f6 ... 473235583/
https://www.virustotal.com/en/file/0206 ... 473235583/
https://www.virustotal.com/en/file/e1f6 ... 473235583/
https://www.virustotal.com/en/file/0206 ... 473235583/
You do not have the required permissions to view the files attached to this post.
Re: Linux/LuaBot
i unpacked lua script.
sign gzip )
sign gzip )
Code: Select all
.00102018: 1F 8B 08 00-4E BD AC 57-00 03 AC 3C-6B 73 E3 46
You do not have the required permissions to view the files attached to this post.
- Xylitol
- Global Moderator
- Posts: 1671
- Joined: Sat Apr 10, 2010 5:54 pm
- Location: Seireitei, Soul Society
- Contact:
Re: Linux/LuaBot
LuaBot: Malware targeting cable modems ~ https://w00tsec.blogspot.com/2016/09/lu ... odems.html
Re: Linux/LuaBot
This bot has evolved a lot since, does anyone have a fresh samples?
Report: https://vms.drweb.com/virus/?_is=2&i=15330288
Sandbox: https://detux.org/report.php?sha256=948 ... aa60c1f345
Report: https://vms.drweb.com/virus/?_is=2&i=15330288
Sandbox: https://detux.org/report.php?sha256=948 ... aa60c1f345
- Xylitol
- Global Moderator
- Posts: 1671
- Joined: Sat Apr 10, 2010 5:54 pm
- Location: Seireitei, Soul Society
- Contact:
Re: Linux/LuaBot
Files from dr.web article you mentioned
You do not have the required permissions to view the files attached to this post.
Re: Linux/LuaBot
Thank you very much Xylitol, any chance to obtain these samples?
Code: Select all
5deb17c660de9d449675ab32048756ed
c867d00e4ed65a4ae91ee65ee00271c7
4b8c0ec8b36c6bf679b3afcc6f54442a
889100a188a42369fd93e7010f7c654b
061b03f8911c41ad18f417223840bce0
- Xylitol
- Global Moderator
- Posts: 1671
- Joined: Sat Apr 10, 2010 5:54 pm
- Location: Seireitei, Soul Society
- Contact:
Re: Linux/LuaBot
voila
You do not have the required permissions to view the files attached to this post.