A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #29372  by tWiCe
 Thu Oct 06, 2016 12:13 pm
>91.185.190.172/bins/mirai.arm7

The server has been shutted down.

>We can see file on server what include ???

Dude, I've tried really hard, but I can't understand what do you mean...
 #29374  by tWiCe
 Thu Oct 06, 2016 12:41 pm
Okey, then it's just blocking requests from my ip. :)

>What hacker doing with this source .Insert in infected server.????????

A hacker would need to compile these sources into binary file before distributing it.

Of course, one may want to distribute it in source and compile it on thte target device, but nobody really do it nowdays.
 #29377  by tWiCe
 Thu Oct 06, 2016 3:09 pm
>But I don't see file where was call """Apache ""

huh? The link you provided has compiled binaries of downloaders and sources for downloader and mirai itself. Where you saw file called "apache" ?
 #29378  by ikolor
 Thu Oct 06, 2016 3:52 pm
I have seen it.But I don't remember where.I visited a lot of palace.
Yes you are right .The hacker don't need a lot of skills.But have to know how Linux works and has to know how make programing.C++ and different language.

Today some connection for some Russian modem.Any harm from my side .But telnet works.
Image
Image
Image