-
Notifications
You must be signed in to change notification settings - Fork 2.1k
Open
Description
It appears 'watcher' is a headless packet sniffer used for spying.
The first few lines makes calls to /lib64/ld-linux-x86-64.so.2 to find a process ID; next it makes a call to libc.so.6 where it opens up some sort of connection, either to localhost or to a remote server (further disassembly required).
this program was probably written in 2002 or so (judging by the glibc version), definitely before 2011 as libc.so.6 stopped being hard-coded after that afaik.
The strings that give it away as a sniffer are:
monitor_type
set_prismhdr
forceprismheader
forceprism
prismhdr
rfmontx
monitor
Atavic, postfix, MisterAlex95, mscalindt and TheNpcNoob
Metadata
Metadata
Assignees
Labels
No labels