MAL_LNX_LinaDoor_Rootkit_May22
Description
Detects LinaDoor Linux Rootkit
Query · yara
strings:
$s1 = "/dev/net/.../rootkit_/" ascii
$s2 = "did_exec" ascii fullword
$s3 = "rh_reserved_tp_target" ascii fullword
$s4 = "HIDDEN_SERVICES" ascii fullword
$s5 = "bypass_udp_ports" ascii fullword
$s6 = "DoBypassIP" ascii fullword
$op1 = { 74 2a 4c 89 ef e8 00 00 00 00 48 89 da 4c 29 e2 48 01 c2 31 c0 4c 39 f2 }
$op2 = { e8 00 00 00 00 48 89 da 4c 29 e2 48 01 c2 31 c0 4c 39 f2 48 0f 46 c3 5b }
$op3 = { 48 89 c3 74 2a 4c 89 ef e8 00 00 00 00 48 89 da 4c 29 e2 48 01 c2 31 c0 }
$op4 = { 4c 29 e2 48 01 c2 31 c0 4c 39 f2 48 0f 46 c3 5b 41 5c 41 5d }
$fp1 = "/wgsyncdaemon.pid"
condition:
uint16(0) == 0x457f and
filesize < 2000KB and 2 of them
and not 1 of ($fp*)
or 4 of them