A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #26778  by unixfreaxjp
 Mon Sep 21, 2015 12:09 pm
Linux/Elknot packed/stripped "freeBSD" version is the hot version left of the elknot in market now.
Just aim this assembly process for get into cnc of the ELF malware Linux/Elknot packed/stripped "freeBSD" version.
I even automated it.. lolling the builder :roll:
Image
*) do this well, and you'll see the double cnc extracted - kudos to mockers who laugh
 #26780  by unixfreaxjp
 Mon Sep 21, 2015 12:33 pm
ChinaZ gangs using a shellshock:
Image
A panel:
Image
A CNC:
Image
↑all in US.. using payload of Linux/Elknot (packed/stripped)
Second CNC:
Image
haha :P ..unusued..

Sample: https://www.virustotal.com/en/file/d95c ... /analysis/
( Who is these "Cornel"?? :lol: get a new name of a "well-known" Elknot?? :roll: )
Image
Attachments
7z/infected
(1.02 MiB) Downloaded 43 times