A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #11513  by wildman424
 Thu Feb 09, 2012 4:57 am
New Linux Rootkit ??? :x
A member of my staff just found this thing, its the tarball of source code, complete with make file. Supposedly its new and chkrootkit and rkhunter isn't detecting it yet.
KBeast (Kernel Beast) 2012 is a Linux rootkit that hides the loadable kernel module, hides files and directories, hides processes, hides sockets and connections, performs keystroke logging, has anti-kill functionality and more.
password protected
(11.57 KiB) Downloaded 70 times
To prevent it from being compiled & spread I will supply the password only to researchers by request, just pm me here or at VT
 #11521  by AaLl86
 Thu Feb 09, 2012 8:41 am
Hi!
Thank you for sample! But by the way (and moderator has to tell me if I am wrong) I'm not completely agree on your pwd policy.
I think that all registered members of KernelMode.info should be able to open virus sample archive... Is for this matter that many researcher like me love this board.
In my opinion you have to provide archive password without the need to send you a mail...

Regards,
Andrea
wildman424 wrote:New Linux Rootkit ??? :x
A member of my staff just found this thing, its the tarball of source code, complete with make file. Supposedly its new and chkrootkit and rkhunter isn't detecting it yet.
KBeast (Kernel Beast) 2012 is a Linux rootkit that hides the loadable kernel module, hides files and directories, hides processes, hides sockets and connections, performs keystroke logging, has anti-kill functionality and more.
ipsecs-kbeast-v1.7z
To prevent it from being compiled & spread I will supply the password only to researchers by request, just pm me here or at VT
 #11525  by EP_X0FF
 Thu Feb 09, 2012 11:37 am
There are only common posting rules available here. It's user right - decide how exactly he want to share malware sample. However it is obvious - there is no need to add additional access requirements to the stuff which already available for free (and as in this case on it's own site which can be found by simple googling in 5 sec).