Live data from Hacker News

RotaJakiro: A long live secret backdoor with 0 VT detection

blog.netlab.360.com

31–40 of 183 posts

Re: RotaJakiro: A long live secret backdoor with 0 VT detection

#31
post #9

This isn't my area of expertise but ... where did they find this? >On March 25, 2021, 360 NETLAB's BotMon system flagged a suspiciousELF file (MD5=64f6cfe44ba08b0babdd3904233c4857) with 0 VT detection, the sample communicates with 4 domains on TCP 443 (HTTPS), but the traffic is not of TLS/SSL. A close look at the sample revealed it to be a backdoor targeting Linux X64 systems, a family that has been around for at le…

BotMon is a "DDoS botnet C2 command tracking system". So I guess they're doing some kind of traffic analysis. https://ddosmon.net/faq doesn't say much.

"0 VT detection" means that no virus scan on VirusTotal detected it.

The ZDNet article is a little more informative with regard to the terms: https://www.zdnet.com/article/rotajakiro-a-linux-backdoor-th...

Re: RotaJakiro: A long live secret backdoor with 0 VT detection

#32
post #3

The obvious question not answered (but asked) in the article is: "Who put it there and why?" Surely this should be easily knowable?

Attribution of malware can be difficult and the lack of details like who was targeted and missing plugins don't leave enough information to guess who might have been interested in developing this.

Re: RotaJakiro: A long live secret backdoor with 0 VT detection

#36
post #9

This isn't my area of expertise but ... where did they find this? >On March 25, 2021, 360 NETLAB's BotMon system flagged a suspiciousELF file (MD5=64f6cfe44ba08b0babdd3904233c4857) with 0 VT detection, the sample communicates with 4 domains on TCP 443 (HTTPS), but the traffic is not of TLS/SSL. A close look at the sample revealed it to be a backdoor targeting Linux X64 systems, a family that has been around for at le…

The website this was posted in seems to be a company offering network monitoring tools. So they probably saw it in one of their customer's systems.

Re: RotaJakiro: A long live secret backdoor with 0 VT detection

#38
post #8

Earlier quoted context omitted.

The user (perhaps running as root) was tricked into installed it. It has nothing to do with the kernel installation. The file name is chosen by the attackers to look like a legit executable - systemd-daemon if installed as root, $HOME/.gvfsd/.profile/gvfsd-helper if installed without root privileges. That way victims who are looking at file names won't be alarmed because they look like an expected file e.g. hiding in…

This is completely off topic but I love the Caesar cipher implementation in your bio. What does HAL stand for?

IBM is HAL

Re: RotaJakiro: A long live secret backdoor with 0 VT detection

#39
post #28

Earlier quoted context omitted.

This is completely off topic but I love the Caesar cipher implementation in your bio. What does HAL stand for?

2001:ASO's villain is named HAL execute the cipher on it and see :)

The full name of the movie is “2001: A Space Odyssey”. It’s based on a novel by the great Arthur C. Clarke.
Post reply on HN