Investigation of Linux.Mirai Trojan family
u97CXm
u97CXm
Create successful ePaper yourself
Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.
27<br />
27<br />
setsid();<br />
sleep(time);<br />
kill(v6, 9); //kills his child after $time seconds<br />
exit(0);<br />
}<br />
}<br />
}<br />
}else{//parent waiting for children death<br />
LOBYTE(v6) = __libc_waitpid(pid_children, &status, 0);<br />
}<br />
Command handlers<br />
.text:08048190 cmd15 proc near ; CODE XREF: cmd15j<br />
.text:08048190<br />
fillCmdHandlers+27Ao<br />
.text:08048190 jmp short cmd15<br />
.text:08048190 cmd15<br />
.text:08048190<br />
endp<br />
; DATA XREF:<br />
.text:08048190 ;<br />
-------------------------------------------------------------------------<br />
--<br />
.text:08048192<br />
.text:080481A0<br />
align 10h<br />
.text:080481A0 ; =============== S U B R O U T I N E<br />
=======================================<br />
.text:080481A0<br />
.text:080481A0 ; Attributes: noreturn<br />
.text:080481A0<br />
.text:080481A0 cmd16 proc near ; CODE XREF: cmd16j<br />
.text:080481A0<br />
fillCmdHandlers+2B4o<br />
.text:080481A0 jmp short cmd16<br />
.text:080481A0 cmd16<br />
.text:080481A0<br />
endp<br />
; DATA XREF:<br />
.text:080481A0 ;<br />
-------------------------------------------------------------------------<br />
--<br />
.text:080481A2<br />
align 10h