Техническая информация
- /usr/bin/curl
- /bin/bash <SAMPLE_FULL_PATH> -c exec '<SAMPLE_FULL_PATH>' \"$@\" <SAMPLE_FULL_PATH>
- <SAMPLE_FULL_PATH>
- /bin/bash <SAMPLE_FULL_PATH> -c
- sleep 3
- mv /usr/bin/curl /usr/bin/JK
- cat
- chmod 777 /usr/bin/curl /usr/bin/JK
- sleep 5
- /usr/bin/curl
- /tmp/sh-thd-814704947
- /tmp/sh-thd-814704947