T03 · Remote Payload Retrieval and Execution
- Location
run.sh:31- Finding
Unverified Native Binary Downloaded Through Mutable Third-Party Mirrors and Executed
- Content
View full analysis
/dev/null; then CDN_OK="$cdn_url" ``` ```bash local gh_release_base="https://github.com/${GITHUB_REPO}/releases/download/v${version}" if [[ "$use_cn" == "true" ]]; then base_url="https://cnb.cool/oneclickvirt/ecs/-/releases/download/v${version}" else if check_cdn 2>/dev/null && [[ -n "$CDN_OK" ]]; then base_url="${CDN_OK}${gh_release_base}" else base_url="$gh_release_base" fi fi ``` ```bash local download_url="${base_url}/${zip_name}" local tmp_zip tmp_zip=$(mktemp "${bin_dir}/${BINARY_NAME}_XXXXXX.zip") if ! http_get "$download_url" "$tmp_zip" 2>/dev/null; then rm -f "$tmp_zip" if [[ "$use_cn" == "true" ]]; then if check_cdn 2>/dev/null && [[ -n "$CDN_OK" ]]; then download_url="${CDN_OK}${gh_release_base}/${zip_name}" else download_url="${gh_release_base}/${zip_name}" fi else download_url="${gh_release_base}/${zip_name}" fi tmp_zip=$(mktemp "${bin_dir}/${BINARY_NAME}_XXXXXX.zip") http_get "$download_url" "$tmp_zip" \ || { rm -f "$tmp_zip"; _fatal "All download sources failed"; } fi extract_zip "$tmp_zip" "$bin_dir" rm -f "$tmp_zip" chmod +x "$bin_path" ``` ```bash "$binary" -menu=false "$@" || true ``` ### Technical Analysis The Skill retrieves a precompiled native executable at runtime and immediately executes it. The archive can be obtained through mutable third-party proxy domains rather than exclusivel ...[truncated 2271 chars]- Remediation
View remediation
