• DDoS木马-Tsunami家族样本分析


    D D
    o
    S
    ¨NBSP;
    -
    T
    s u n
    a
    m
    i
    l i
    nux
    D D
    o
    S
    IRC
    D D
    o
    S
    T
    sun
    a
    m
    i
    D D
    o
    S
    2013
    使
    ⼿
    T C P
    U
    D P
    DNS
    h
    t t p s
    ://
    g i
    t
    h
    u
    b
    .
    c
    o m
    /
    S
    o
    ldie
    /
    COLE
    -
    O
    -
    b
    o t n
    e
    t s
    /
    b l
    o
    b
    /
    aec
    534
    acbf
    9 7 8 9 4 5 1
    f
    009129
    e f a a
    1
    e c
    7 6 0 9 7 3
    e
    2
    e
    /
    V
    i
    rus
    P
    ack
    /
    f
    3 4
    c
    5
    c
    2 7
    b
    .
    c
    3 . 1
    E L F
    h a i d
    r
    a g
    o n
    2 0 2 2 - 1 1 - 0 6
    14: 48
    3 . 2
    
    A
    T
    i
    m
    e
    PPID
    I D
    B
    IRC
    C
    352
    i
    p
    3 7 6
    m
    a c
    433
    /
    u s r
    /
    dic
    t
    /
    w o r
    d
    s
    422
    3 6 7
    PRI
    V
    M S G
    i
    r
    c
    访
    /
    usr
    /
    b i
    n
    /
    x x
    h
    SSH
    d d
    o s
    P I N G
    P O N G
    J O I N
    K I C K
    N I C K
    3 . 3
     DD
    o
    S
    T
    s u n
    a
    m
    i
    A C K F L O O D
    P
    a
    n
    S
    Y
    N F L O O D
    D
    o s
    U
    D P F L O O D
    U
    n
    k
    n o w n
    S P O O F S
    I P
    D I S A B L E
    E N A B L E
    GET
    u r
    l
    c
    p u
    i
    686
    x
    8 6
    线
    8 0
    V
    E R S I O N
    B
    Y
    E B
    Y
    E A L L
    d d
    o s
    I R C
    i
    r
    c
    C H G S E R
    V
    H
    e l
    p
    N I C K
    G E T S P O O F S
    E N A B L E
    D D
    o
    S
    3 . 4 .
    3 . 4 . 1
     CC
    IRC
    器地址
    T
    s u n
    a
    m
    i
    C C
    3 . 4 . 2
    线
    V
    i
    rus
    T
    o t
    a l
    1 5
    h a
    s
    h
    s
    3 . 5
    3 . 5 . 1
    m u m
    a
    ELF
    E L F
    3 . 5 . 2
    /
    t
    e
    m p
    / .
    s s
    h
    样本未
    使
    访
    i d
    3 . 5 . 3
    线
    2
    7
    间间隔
    s o
    c k e
    t
    s o
    c k e
    t
    b
    u
    f f e
    r
    3 . 5 . 4
    3 . 5 . 4 . 1
    3 5 2
    i
    p
    n
    i c k
    i
    p
    I P
    i
    p
    i
    p
    3 . 5 . 4 . 1
    3 7 6
    422
    线
    3 . 5 . 4 . 3
    433
    n
    ick
    3 . 5 . 4 . 4
    P R I
    V
    MSG
    r
    e
    pons
    e
    DDOS
    T
    sun
    a
    m
    i
    P
    a
    n
    D
    o s
    U
    n
    K
    n o w n
    D D O S
    3 . 5 . 5
    D D O S
    3 . 5 . 5 . 1
    A C K
    -
    P
    U
    S H
    A C K
    -
    P
    U
    S H
    T C P
    -
    ack
    3 . 5 . 5 . 2
    S
    Y
    N
    S
    Y
    N
    T C P
    ⼿
    S
    Y
    N
    T C P
    S
    Y
    N
    S
    Y
    N
    -
    A C K
    A C K
    S
    Y
    N
    -
    A C K
    A C K
    s y n
    s y n
    3 . 5 . 5 . 3
    U
    D P
    U
    D P
    U
    D P
    (
    1500
    )
    u
    d
    p
    3 . 5 . 5 . 3
    (
    0
    x
    2 4 0 0
    )
    4 . 1
    I O C
    F
    i l e
    M D
    5
    c f
    6
    c b
    2 5 6 2 4 8 7 4 4 2 4
    a f
    47 011
    a
    7
    d d
    131
    b
    4
    F
    i l e
    S H A
    1
    1
    d
    0
    d
    2
    d e
    612
    c
    4 7 3
    f c
    4
    c
    7 5
    e d
    5
    d
    61952
    f
    8
    e
    4
    a d
    7 3 8 4
    c
    F
    i l e
    S H A
    2 5 6
    6
    f
    1 4
    afb
    1 4
    e
    198
    f c
    3 6
    f f
    839
    b
    0 9 0 7 7
    edb
    2
    f b
    5
    a
    5 5
    d c
    9
    c
    2 9
    c
    9
    edcd
    590
    7 5
    d
    4825 5332
    H
    o s t
    p w n
    .
    p w n
    d
    n s
    .
    p w
    i
    p
    1 6 8 . 2 3 5 . 9 5 . 1 0 4
    4 . 2
    Y
    a
    r
    a
    1. rule muma_unpack {
    2. meta:
    3. description = "Tsunami:RAT&DDOS_BOT"
    4. muma_unpack_hash1 = "4410b1cd507926071378c0c470fa98aff12ed4b59ec00766fef8847c72397c26"
    5. muma_hash1 = "6f14afb14e198fc36ff839b09077edb2fb5a55dc9c29c9edcd59075d48255332"
    6. strings:
    7. $x1 = "NOTICE %s :PAN = An advanced syn flooder that will kill most network drivers" fullword ascii
    8. $x2 = "NOTICE %s :SH = Executes a command" fullword ascii
    9. $x3 = "NOTICE %s :GET = Downloads a file off the web and saves it onto the hd" fullword ascii
    10. $x4 = "NOTICE %s :UDP = A udp flooder" fullword ascii
    11. $x5 = "NOTICE %s :UNKNOWN = Another non-spoof udp flooder" fullword ascii
    12. $s6 = "NOTICE %s :TSUNAMI = Special packeter that wont be blocked by most firewalls" fullword ascii
    13. $s7 = "NOTICE %s :PAN " fullword ascii
    14. $s8 = "NOTICE %s :UDP " fullword ascii
    15. $s9 = "User-Agent: Mozilla/4.75 [en] (X11; U; Linux 2.2.16-3 i686)" fullword ascii
    16. $s10 = "src/process/execve.c" fullword ascii
    17. $s11 = "NOTICE %s :UNKNOWN" fullword ascii
    18. $s12 = "NOTICE %s :TSUNAMI" fullword ascii
    19. $s13 = "NOTICE %s :IRC = Sends this command to the server" fullword ascii
    20. $s14 = "src/process/posix_spawn_file_actions_adddup2.c" fullword ascii
    21. $s15 = "src/process/posix_spawn_file_actions_destroy.c" fullword ascii
    22. $s16 = "src/process/posix_spawn_file_actions_init.c" fullword ascii
    23. $s17 = "NOTICE %s :Spoofs: %d.%d.%d.%d - %d.%d.%d.%d" fullword ascii
    24. $s18 = "NOTICE %s :Password too long! > 254" fullword ascii
    25. $s19 = "NOTICE %s :Password correct." fullword ascii
    26. $s20 = "src/process/posix_spawn.c" fullword ascii
    27. $y1 = "gent.Mozilla/4.75" fullword ascii
    28. $y2 = "PROT_EXEC|PROT_WRITE failed." fullword ascii
    29. $y3 = "Id: UPX 3.95 Copyright (C) 1996-2018 the UPX Team. All Rights Reserved. $" fullword ascii
    30. $y4 = "NOTICE %s :Unable to comply." fullword ascii
    31. $y5 = "Q USERID" fullword ascii
    32. $y6 = "ooo.User" fullword ascii
    33. $y7 = "KILL " fullword ascii
    34. $y8 = "no- wi&-FbZ" fullword ascii
    35. $y9 = "" fullword ascii
    36. $y10 = ",7V{ -" fullword ascii
    37. $y11 = "? -[Bo&" fullword ascii
    38. $y12 = "O9/JHTTP/1.0" fullword ascii
    39. $y13 = "liheek" fullword ascii
    40. $y14 = "assifyl" fullword ascii
    41. $y15 = "DEH_FRAME_" fullword ascii
    42. $y16 = "%HTF%3" fullword ascii
    43. $y17 = "toupbr" fullword ascii
    44. $y18 = "%DKz%H" fullword ascii
    45. $y19 = "uvbful" fullword ascii
    46. $y20 = "1-2%S " fullword ascii
    47. condition:
    48. ( uint16(0) == 0x457f and filesize < 2000KB and ( 1 of (x*) and 4 of (s*) ) ) or
    49. ( uint16(0) == 0x457f and filesize < 600KB and ( 8 of (y*) ) ) or
    50. ( all of them )
    51. }
  • 相关阅读:
    AI修复1950正年轻的他们;2022阿里天池冠军方案[1/1149];计算机优秀课程大集锦;贝叶斯统计课程资料;前沿论文 | ShowMeAI资讯日报
    springboot项目启动时获取所有的api接口
    百度指数 Cipher-Text、百度翻译 Acs-Token 逆向分析
    【如何学习CAN总线测试】——OSEK网络管理测试
    更灵活的 serverless framework 配置文件
    在Ubuntu 20.04搭建最小实验环境
    Flink Yarn Per Job - RM启动SlotManager
    awk命令实例
    1018 锤子剪刀布
    【Python21天学习挑战赛】-爬虫(B站)程序示例
  • 原文地址:https://blog.csdn.net/sinat_35360663/article/details/127719004