03.10.2016 Views

Investigation of Linux.Mirai Trojan family

u97CXm

u97CXm

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

27<br />

27<br />

setsid();<br />

sleep(time);<br />

kill(v6, 9); //kills his child after $time seconds<br />

exit(0);<br />

}<br />

}<br />

}<br />

}else{//parent waiting for children death<br />

LOBYTE(v6) = __libc_waitpid(pid_children, &status, 0);<br />

}<br />

Command handlers<br />

.text:08048190 cmd15 proc near ; CODE XREF: cmd15j<br />

.text:08048190<br />

fillCmdHandlers+27Ao<br />

.text:08048190 jmp short cmd15<br />

.text:08048190 cmd15<br />

.text:08048190<br />

endp<br />

; DATA XREF:<br />

.text:08048190 ;<br />

-------------------------------------------------------------------------<br />

--<br />

.text:08048192<br />

.text:080481A0<br />

align 10h<br />

.text:080481A0 ; =============== S U B R O U T I N E<br />

=======================================<br />

.text:080481A0<br />

.text:080481A0 ; Attributes: noreturn<br />

.text:080481A0<br />

.text:080481A0 cmd16 proc near ; CODE XREF: cmd16j<br />

.text:080481A0<br />

fillCmdHandlers+2B4o<br />

.text:080481A0 jmp short cmd16<br />

.text:080481A0 cmd16<br />

.text:080481A0<br />

endp<br />

; DATA XREF:<br />

.text:080481A0 ;<br />

-------------------------------------------------------------------------<br />

--<br />

.text:080481A2<br />

align 10h

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!