Skip to content

Malware

PITHOOK

According to Mandiant, PITHOOK hooks the accept and accept4 functions within the web process by modifying the PLT.

According to Mandiant, PITHOOK hooks the accept and accept4 functions within the web process by modifying the PLT. When PITHOOK receives a buffer matching the predefined magic byte sequence, it will duplicate the socket and forward it to PITSTOP over the Unix domain socket /data/runtime/cockpit/wd.fd.


Family metadata imported from Malpedia (Fraunhofer FKIE).