Linux malware from 186.33.90.247:56701

Type: sh (executable)

  • Packed with UPX
    image

Identificators:

Bytes:


p_info has 12 bits

read more: https://vcodispot.com/corrupted-upx-packed-elf-repair/

Source Code begin:

  • begin unpacking please wait a moment

Identificators:
Mozi BotNet

Tools:
Processing: Fixer.exe…
Processing: upx.exe…
Processing: HxD.exe…
Processing: HxD.ini…
Processing: mozitools.py…

Tutorial:
https://kn0wledge.fr/projects/mozitools/

Modules:
pip install elasticsearch
pip install bencodepy
pip install pytest
pip install secrets

Usage:
mozitools.py -d -f “Mozi File” -o “Output File”