New uploaded ELknot compiled in dynamic (non-static) libs linked ELF for x32 and x64
This version is a small in design, threaded but not forked (read: spawn)
https://www.virustotal.com/en/file/dba0 ... 414256488/
https://www.virustotal.com/en/file/e3f3 ... /analysis/
The ELF is callback to hardcoded hostname
before connected to
Code: Select all222.186.21.55:8000
sa_family=AF_INET, sin_port=htons(8000), sin_addr=inet_addr("222.186.21.55")
38.72.114.63 is US based IP belong to Chinese entity:
Code: Select all38.72.114.63||174 | 38.72.112.0/21 | COGENT-174 | US | - | SHENZHEN YI YUN NETWORK TECHNOLOGY CO LTD
And 222.186.21.55 is in China:
Code: Select all222.186.21.55||23650 | 222.186.21.0/24 | CHINANET-JS-AS | CN | CHINATELECOM.COM.CN | CHINANET JIANGSU PROVINCE NETWORK
for them who trust more in PCAP than to reversers:
The domain registry information, it's in PDR, just in case I copied info for the law enforcement to follow:
Code: Select all Domain Name: LQ4444.COM
Registrar: PDR LTD. D/B/A PUBLICDOMAINREGISTRY.COM
Whois Server: whois.PublicDomainRegistry.com
Referral URL: http://www.PublicDomainRegistry.com
Name Server: F1G1NS1.DNSPOD.NET
Name Server: F1G1NS2.DNSPOD.NET
Status: clientTransferProhibited
Updated Date: 30-jun-2014
Creation Date: 07-jun-2013
Expiration Date: 07-jun-2015
>>> Last update of whois database: Sat, 25 Oct 2014 17:47:37 GMT <<<
Domain Name: LQ4444.COM
Registry Domain ID:
Registrar WHOIS Server: whois.publicdomainregistry.com
Registrar URL: www.publicdomainregistry.com
Updated Date: 2014-08-29T03:31:51Z
Creation Date: 2013-06-07T17:41:50Z
Registrar Registration Expiration Date: 2015-06-07T17:41:50Z
Registrar: PDR Ltd. d/b/a PublicDomainRegistry.com
Registrar IANA ID: 303
Registrar Abuse Contact Email: abuse-contact@publicdomainregistry.com
Registrar Abuse Contact Phone: +1-2013775952
Domain Status: clientTransferProhibited
Registry Registrant ID: PP-SP-001
Registrant Name: Domain Admin
Registrant Organization: Privacy Protection Service INC d/b/a PrivacyProtect.org
Registrant Street: C/O ID#10760, PO Box 16 Note - Visit PrivacyProtect.org to contact the domain owner/operator Note - Visit PrivacyProtect.org to contact the domain owner/operator
Registrant City: Nobby Beach
Registrant State/Province: Queensland
Registrant Postal Code: QLD 4218
Registrant Country: AU
Registrant Phone: +45.36946676
Registrant Phone Ext:
Registrant Fax:
Registrant Fax Ext:
Registrant Email: contact@privacyprotect.org
Registry Admin ID: PP-SP-001
We'll see some crying moronz soon :lol:
#MalwareMustDie!