{"id":11208,"date":"2017-02-16T18:37:24","date_gmt":"2017-02-16T18:37:24","guid":{"rendered":"https:\/\/evosec.eu\/?p=11208"},"modified":"2017-02-16T18:37:24","modified_gmt":"2017-02-16T18:37:24","slug":"iot-malware-advances","status":"publish","type":"post","link":"https:\/\/evosec.eu\/ru\/iot-malware-advances\/","title":{"rendered":"IoT Malware advances"},"content":{"rendered":"<p>A new strain (as long as December 2016 can be called new) has been spotted on GitHub that combines both a standard telnet scanner and also MIRAI. <\/p>\n<p>It has been uploaded here:<a href=\"https:\/\/github.com\/geo93033\/u\">https:\/\/github.com\/geo93033\/u<\/a>.<\/p>\n<p>In the header(s) you can find some credentials:<\/p>\n<blockquote><p>Xmpp: b1nary@nigge.rs<br \/>\nTwitter: @P2PBOTNET<br \/>\nInstragram: @Rebirth.c<br \/>\nSkype: b1narythag0d<\/p><\/blockquote>\n<p>and<\/p>\n<blockquote><p>\nSkype: uriede<br \/>\nXMPP: Crypt@nigge.rs<br \/>\nChanges:<br \/>\nMade Date: 7-30-16<\/p><\/blockquote>\n<p>And also a &#171;nice&#187; notice:<\/p>\n<blockquote><p>\/*<br \/>\nRebirth Is an ongoing project, that will have many builds, and updates.<br \/>\nThis Client is being constantly worked on.<br \/>\nAnyone that bought Rebirth Legitly will have access to the builds, and updates.<br \/>\nFor anyone that leeches, or leaks, well fuck you.<br \/>\n*\/<\/p><\/blockquote>\n<hr \/>\n<p>Besides that, you can also find several names of the ELF binaries used by this (or other) infections, as well as the architectures they are designed for:<\/p>\n<blockquote><p>\t&#171;jackmymips&#187;,<br \/>\n\t&#171;jackmymips64&#187;,<br \/>\n\t&#171;jackmymipsel&#187;,<br \/>\n\t&#171;jackmysh2eb&#187;,<br \/>\n\t&#171;jackmysh2elf&#187;,<br \/>\n\t&#171;jackmysh4&#187;,<br \/>\n\t&#171;jackmyx86&#187;,<br \/>\n\t&#171;jackmyarmv5&#187;,<br \/>\n\t&#171;jackmyarmv4tl&#187;,<br \/>\n\t&#171;jackmyarmv4&#187;,<br \/>\n\t&#171;jackmyarmv6&#187;,<br \/>\n\t&#171;jackmyi686&#187;,<br \/>\n\t&#171;jackmypowerpc&#187;,<br \/>\n\t&#171;jackmypowerpc440fp&#187;,<br \/>\n\t&#171;jackmyi586&#187;,<br \/>\n\t&#171;jackmym68k&#187;,<br \/>\n\t&#171;jackmysparc&#187;,<\/p><\/blockquote>\n<blockquote><p>\t&#171;hackmymips&#187;,<br \/>\n\t&#171;hackmymipsel&#187;,<br \/>\n\t&#171;hackmysh4&#187;,<br \/>\n\t&#171;hackmyx86&#187;,<br \/>\n\t&#171;hackmyarmv6&#187;,<br \/>\n\t&#171;hackmyi686&#187;,<br \/>\n\t&#171;hackmypowerpc&#187;,<br \/>\n\t&#171;hackmyi586&#187;,<br \/>\n\t&#171;hackmym68k&#187;,<br \/>\n\t&#171;hackmysparc&#187;,<\/p><\/blockquote>\n<blockquote><p>\t&#171;busyboxterrorist&#187;,<br \/>\n\t&#171;DFhxdhdf&#187;,<br \/>\n\t&#171;dvrHelper&#187;,<br \/>\n\t&#171;FDFDHFC&#187;,<br \/>\n\t&#171;FEUB&#187;,<br \/>\n\t&#171;FTUdftui&#187;,<br \/>\n\t&#171;GHfjfgvj&#187;,<\/p><\/blockquote>\n<blockquote><p>\t&#171;jhUOH&#187;,<br \/>\n\t&#171;JIPJIPJj&#187;,<br \/>\n\t&#171;JIPJuipjh&#187;,<br \/>\n\t&#171;kmyx86_64&#187;,    \/\/<- Kami?<\/p><\/blockquote>\n<blockquote><p>\t&#171;TwoFacearmv61&#187;,<br \/>\n\t&#171;TwoFacei586&#187;,<br \/>\n\t&#171;TwoFacei686&#187;,<br \/>\n\t&#171;TwoFacem86k&#187;,<br \/>\n\t&#171;TwoFacemips&#187;,<br \/>\n\t&#171;TwoFacemipsel&#187;,<br \/>\n\t&#171;TwoFacepowerpc&#187;,<br \/>\n\t&#171;TwoFacesh4&#187;,<br \/>\n\t&#171;TwoFacesparc&#187;,<br \/>\n\t&#171;TwoFacex86_64&#187;,<\/p><\/blockquote>\n<p>and others&#8230;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A new strain (as long as December 2016 can be called new) has been spotted on GitHub that combines both a standard telnet scanner and also MIRAI. It has been uploaded here:https:\/\/github.com\/geo93033\/u. In the header(s) you can find some credentials: Xmpp: b1nary@nigge.rs Twitter: @P2PBOTNET Instragram: @Rebirth.c Skype: b1narythag0d and Skype: &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[98,932,947,99],"tags":[74,60,981],"class_list":["post-11208","post","type-post","status-publish","format-standard","hentry","category-iot-newsupdates","category-iot-security","category-it-security","category-it-security-newsupdates","tag-iot","tag-malware","tag-mirai"],"translation":{"provider":"WPGlobus","version":"3.0.2","language":"ru","enabled_languages":["en","da","de","es","fi","fr","it","hu","nl","no","pl","pt","ru","sv"],"languages":{"en":{"title":true,"content":true,"excerpt":false},"da":{"title":false,"content":false,"excerpt":false},"de":{"title":false,"content":false,"excerpt":false},"es":{"title":false,"content":false,"excerpt":false},"fi":{"title":false,"content":false,"excerpt":false},"fr":{"title":false,"content":false,"excerpt":false},"it":{"title":false,"content":false,"excerpt":false},"hu":{"title":false,"content":false,"excerpt":false},"nl":{"title":false,"content":false,"excerpt":false},"no":{"title":false,"content":false,"excerpt":false},"pl":{"title":false,"content":false,"excerpt":false},"pt":{"title":false,"content":false,"excerpt":false},"ru":{"title":false,"content":false,"excerpt":false},"sv":{"title":false,"content":false,"excerpt":false}}},"_links":{"self":[{"href":"https:\/\/evosec.eu\/ru\/wp-json\/wp\/v2\/posts\/11208","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/evosec.eu\/ru\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/evosec.eu\/ru\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/evosec.eu\/ru\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/evosec.eu\/ru\/wp-json\/wp\/v2\/comments?post=11208"}],"version-history":[{"count":1,"href":"https:\/\/evosec.eu\/ru\/wp-json\/wp\/v2\/posts\/11208\/revisions"}],"predecessor-version":[{"id":11209,"href":"https:\/\/evosec.eu\/ru\/wp-json\/wp\/v2\/posts\/11208\/revisions\/11209"}],"wp:attachment":[{"href":"https:\/\/evosec.eu\/ru\/wp-json\/wp\/v2\/media?parent=11208"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/evosec.eu\/ru\/wp-json\/wp\/v2\/categories?post=11208"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/evosec.eu\/ru\/wp-json\/wp\/v2\/tags?post=11208"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}