Re: another rootkit - one more file (fwd)

From: Michal Zalewski (lcamtufat_private)
Date: Mon Jun 04 2001 - 05:42:52 PDT

  • Next message: Fernando Cardoso: "RE: another rootkit - one more file (fwd)"

    Alvin told me it might be good to forward it to INCIDENTS. There are my
    comments on the binaries of this rootkit I got from him - you might want
    to check if you have one already ;-):
    
    - The rootkit itself is called 'ManiaC r00tkit' (how pathetic). We
      were not able to find it anywhere on the net (searching for filenames
      and such), so I presume it is pretty new,
    
    - It consists of a sniffer, few trivial backdoors, DoS tools, bnc
      IRC bouncer, setuid shell and so on. It uses Ava/Adore kernel module to
      hide itself, and replaces few binaries, modifies one rc script - it
      is not too advanced,
    
    - Rootkit installation script:
    
      echo "Copiando os arquivos necess.rios."
    
      This sounds like Portuguese or so, which probably tells us about
      its origins.
    
    - It removes few patterns from logfiles. That would be: 200.195.86.*,
      200.248.162.*, 200.195.121.*, 200.243.17.*, netdados.com.br,
      usinet.com.br - I presume these are networks attacker used for
      defacements (how smart to put them in the script in this form!),
    
    - It sends information about machine to tuiqoitu039t09q3at_private,
      bnadfjg9023at_private, t391u9t0qit@end-war.com, mki62969oat_private
      One of these mailboxes is still working (bigfoot.com, others are
      provided as a decay or so),
    
    - pt07 and mailrc binaries are backdoors. Listening on 56789/tcp, with
      password "include.h", it hides under the name of "klogd":
    
      Trying 0.0.0.0...
      Connected to 0.
      Escape character is '^]'.
      include.h
    
      Bem Vindo MaNiAc 31337 a sua makina!
      Voce Tem o controle! =)
    
      bash: no job control in this shell
      bash-2.01#
    
      Once again, I haven't seen any mention of this backdoor port anywhere.
    
    Hope that helps,
    -- 
    _____________________________________________________
    Michal Zalewski [lcamtufat_private] [security]
    [http://lcamtuf.coredump.cx] <=-=> bash$ :(){ :|:&};:
    =-=> Did you know that clones never use mirrors? <=-=
    



    This archive was generated by hypermail 2b30 : Mon Jun 04 2001 - 07:26:22 PDT