DDoS木马-Tsunami家族样本分析

<title></title>
D D
o
S
¨NBSP;
-
T
s u n
a
m
i
l i
nux
D D
o
S
IRC
D D
o
S
T
sun
a
m
i
D D
o
S
2013
使
⼿
T C P
U
D P
DNS
h
t t p s
://
g i
t
h
u
b
.
c
o m
/
S
o
ldie
/
COLE
-
O
-
b
o t n
e
t s
/
b l
o
b
/
aec
534
acbf
9 7 8 9 4 5 1
f
009129
e f a a
1
e c
7 6 0 9 7 3
e
2
e
/
V
i
rus
P
ack
/
f
3 4
c
5
c
2 7
b
.
c
3 . 1
E L F
h a i d
r
a g
o n
2 0 2 2 - 1 1 - 0 6
14: 48
3 . 2

A
T
i
m
e
PPID
I D
B
IRC
C
352
i
p
3 7 6
m
a c
433
/
u s r
/
dic
t
/
w o r
d
s
422
3 6 7
PRI
V
M S G
i
r
c
访
/
usr
/
b i
n
/
x x
h
SSH
d d
o s
P I N G
P O N G
J O I N
K I C K
N I C K
3 . 3
 DD
o
S
T
s u n
a
m
i
A C K F L O O D
P
a
n
S
Y
N F L O O D
D
o s
U
D P F L O O D
U
n
k
n o w n
S P O O F S
I P
D I S A B L E
E N A B L E
GET
u r
l
c
p u
i
686
x
8 6
线
8 0
V
E R S I O N
B
Y
E B
Y
E A L L
d d
o s
I R C
i
r
c
C H G S E R
V
H
e l
p
N I C K
G E T S P O O F S
E N A B L E
D D
o
S
3 . 4 .
3 . 4 . 1
 CC
IRC
器地址
T
s u n
a
m
i
C C
3 . 4 . 2
线
V
i
rus
T
o t
a l
1 5
h a
s
h
s
3 . 5
3 . 5 . 1
m u m
a
ELF
E L F
3 . 5 . 2
/
t
e
m p
/ .
s s
h
样本未
使
访
i d
3 . 5 . 3
线
2
7
间间隔
s o
c k e
t
s o
c k e
t
b
u
f f e
r
3 . 5 . 4
3 . 5 . 4 . 1
3 5 2
i
p
n
i c k
i
p
I P
i
p
i
p
3 . 5 . 4 . 1
3 7 6
422
线
3 . 5 . 4 . 3
433
n
ick
3 . 5 . 4 . 4
P R I
V
MSG
r
e
pons
e
DDOS
T
sun
a
m
i
P
a
n
D
o s
U
n
K
n o w n
D D O S
3 . 5 . 5
D D O S
3 . 5 . 5 . 1
A C K
-
P
U
S H
A C K
-
P
U
S H
T C P
-
ack
3 . 5 . 5 . 2
S
Y
N
S
Y
N
T C P
⼿
S
Y
N
T C P
S
Y
N
S
Y
N
-
A C K
A C K
S
Y
N
-
A C K
A C K
s y n
s y n
3 . 5 . 5 . 3
U
D P
U
D P
U
D P
(
1500
)
u
d
p
3 . 5 . 5 . 3
(
0
x
2 4 0 0
)
4 . 1
I O C
F
i l e
M D
5
c f
6
c b
2 5 6 2 4 8 7 4 4 2 4
a f
47 011
a
7
d d
131
b
4
F
i l e
S H A
1
1
d
0
d
2
d e
612
c
4 7 3
f c
4
c
7 5
e d
5
d
61952
f
8
e
4
a d
7 3 8 4
c
F
i l e
S H A
2 5 6
6
f
1 4
afb
1 4
e
198
f c
3 6
f f
839
b
0 9 0 7 7
edb
2
f b
5
a
5 5
d c
9
c
2 9
c
9
edcd
590
7 5
d
4825 5332
H
o s t
p w n
.
p w n
d
n s
.
p w
i
p
1 6 8 . 2 3 5 . 9 5 . 1 0 4
4 . 2
Y
a
r
a
rule muma_unpack {
   meta:
      description = "Tsunami:RAT&DDOS_BOT"
      muma_unpack_hash1 = "4410b1cd507926071378c0c470fa98aff12ed4b59ec00766fef8847c72397c26"
      muma_hash1 = "6f14afb14e198fc36ff839b09077edb2fb5a55dc9c29c9edcd59075d48255332"
   strings:
      $x1 = "NOTICE %s :PAN  = An advanced syn flooder that will kill most network drivers" fullword ascii
      $x2 = "NOTICE %s :SH = Executes a command" fullword ascii
      $x3 = "NOTICE %s :GET = Downloads a file off the web and saves it onto the hd" fullword ascii
      $x4 = "NOTICE %s :UDP = A udp flooder" fullword ascii
      $x5 = "NOTICE %s :UNKNOWN = Another non-spoof udp flooder" fullword ascii
      $s6 = "NOTICE %s :TSUNAMI  = Special packeter that wont be blocked by most firewalls" fullword ascii
      $s7 = "NOTICE %s :PAN   " fullword ascii
      $s8 = "NOTICE %s :UDP   " fullword ascii
      $s9 = "User-Agent: Mozilla/4.75 [en] (X11; U; Linux 2.2.16-3 i686)" fullword ascii
      $s10 = "src/process/execve.c" fullword ascii
      $s11 = "NOTICE %s :UNKNOWN" fullword ascii
      $s12 = "NOTICE %s :TSUNAMI" fullword ascii
      $s13 = "NOTICE %s :IRC  = Sends this command to the server" fullword ascii
      $s14 = "src/process/posix_spawn_file_actions_adddup2.c" fullword ascii
      $s15 = "src/process/posix_spawn_file_actions_destroy.c" fullword ascii
      $s16 = "src/process/posix_spawn_file_actions_init.c" fullword ascii
      $s17 = "NOTICE %s :Spoofs: %d.%d.%d.%d - %d.%d.%d.%d" fullword ascii
      $s18 = "NOTICE %s :Password too long! > 254" fullword ascii
      $s19 = "NOTICE %s :Password correct." fullword ascii
      $s20 = "src/process/posix_spawn.c" fullword ascii
      $y1 = "gent.Mozilla/4.75" fullword ascii
      $y2 = "PROT_EXEC|PROT_WRITE failed." fullword ascii
      $y3 = "Id: UPX 3.95 Copyright (C) 1996-2018 the UPX Team. All Rights Reserved. $" fullword ascii
      $y4 = "NOTICE %s :Unable to comply." fullword ascii
      $y5 = "Q USERID" fullword ascii
      $y6 = "ooo.User" fullword ascii
      $y7 = "KILL  " fullword ascii
      $y8 = "no- wi&-FbZ" fullword ascii
      $y9 = "" fullword ascii
      $y10 = ",7V{ -" fullword ascii
      $y11 = "? -[Bo&" fullword ascii
      $y12 = "O9/JHTTP/1.0" fullword ascii
      $y13 = "liheek" fullword ascii
      $y14 = "assifyl" fullword ascii
      $y15 = "DEH_FRAME_" fullword ascii
      $y16 = "%HTF%3" fullword ascii
      $y17 = "toupbr" fullword ascii
      $y18 = "%DKz%H" fullword ascii
      $y19 = "uvbful" fullword ascii
      $y20 = "1-2%S " fullword ascii

   condition:
( uint16(0) == 0x457f and filesize < 2000KB and ( 1 of (x*) and 4 of (s*) ) ) or
( uint16(0) == 0x457f and filesize < 600KB and ( 8 of (y*) ) ) or 
( all of them )
}
  • 0
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 打赏
    打赏
  • 0
    评论

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包

打赏作者

C-haidragon

你的鼓励将是我创作的最大动力

¥1 ¥2 ¥4 ¥6 ¥10 ¥20
扫码支付:¥1
获取中
扫码支付

您的余额不足,请更换扫码支付或充值

打赏作者

实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值