Threat Cluster 150[.]241[.]65[.]250

Multi-architecture Linux and IoT malware staging, payload delivery, operator workspace exposure, and possible botnet recruitment.

Threat Cluster 150[.]241[.]65[.]250

This dossier was generated from passive acquisition and static analysis. Retrieved artifacts were preserved as unexecuted evidence. No login, exploitation, modification, deletion, or active interaction with the endpoint was performed.

Evidence Coverage

MetricValue
Root directory listing acquired1
Root-level artifacts preserved7
Text / configuration artifacts preserved5
Linux ELF binaries preserved2
Architecture-specific payloads listed but not fully acquired14
Directory descendants acquired0
PE candidates identified0
Credential / secret exposure indicators2 high-risk exposure locations
Dynamic execution performedNo
Acquisition completed within bounded limitsNo — larger transfers stalled and were stopped

Motivation & Objectives

Strategic Motivation

The endpoint appears to be an exposed Linux staging workspace supporting multi-architecture payload delivery. Its directory listing contains binaries named for multiple CPU architectures, while the acquired shell history records the use of temporary HTTP servers, wget, chmod +x, and direct execution of downloaded payloads.[2]

Operational Objectives

  • Multi-Architecture Payload Delivery: Hosting raul.* binaries and related Linux ELF files for x86, ARM, MIPS, PowerPC, SPARC, and other architectures.

  • Botnet or IoT Recruitment: Using architecture-specific binaries such as pito.*, raul.*, and bot.i686 for possible deployment to heterogeneous Linux and embedded systems.

  • Staging Infrastructure: Operating Python HTTP servers on ports 889 and 67 for file distribution.

  • Operator Workspace Management: Retaining shell history, scripts, screen-session commands, and downloaded tooling in a web-accessible directory.

  • Defense Evasion and Cleanup: Maintaining a VPS-cleaner script capable of killing processes and deleting artifacts from temporary directories and cron locations.

Inferred Target Profile

  • Linux servers and VPS instances

  • IoT and embedded devices

  • Internet-exposed edge systems

  • Hosts vulnerable to unauthorized payload download and execution

Key Operational Findings

  • Unauthenticated Python SimpleHTTP directory listing on port 889

  • Multi-architecture raul.* payload set exposed in the web root

  • bot and dropper Linux ELF binaries exposed and partially acquired

  • Shell history showing wget, curl, chmod +x, and direct execution

  • Historical retrieval and execution of pito.arm7, pito.x86, and bot.i686

  • Historical use of nc -nlvp 9001, indicating listener setup

  • VPS cleaner script capable of process termination and artifact deletion

  • Strong tradecraft overlap with the supplied 194[.]238[.]57[.]124 cluster

  • No direct evidence in this acquisition of successful victim compromise or current C2 activity

Credentials, Keys & Tokens (Redacted )

RiskTypeRedacted ValueSource / Layer
HighSSH material exposure[NOT ACQUIRED — .ssh/ DIRECTORY PUBLICLY LISTED]Root directory listing / L0
HighX11 authentication cookie[REDACTED_XAUTHORITY_COOKIE].Xauthority / L0
MediumShell-history credentials or operational secrets[NOT REPRODUCED].bash_history / L0

Verified Indicators

TypeDefanged Value / HashContextConfidence
Investigated Host150[.]241[.]65[.]250User-supplied investigated hostHigh (observed)
Service Endpoint150[.]241[.]65[.]250:889Unauthenticated HTTP directory listingHigh (observed)
Related Service Endpoint150[.]241[.]65[.]250:67Historical HTTP server referenced in .bash_historyHigh (historical)
Related IPv494[.]154[.]43[.]249Historical payload retrieval sourceMedium-to-high (historical)
Domainnode-32404[.]nodehost[.]ruHostname found in acquired .Xauthority stringsMedium (context required)
SHA-256118be4b076806c3d426507fa11cc0fffc40c62be51343aef8e82cc04d91330b6Acquired bot Linux ELFHigh (computed)
SHA-25679aebbbde524f8ec10d232ea48ed3c83068e5f96d8831c7f62820a36688e2550Acquired dropper Linux ELFHigh (computed)
Filename Patternraul.*Architecture-specific payload family listed at rootHigh (observed)
Filename Patternpito.*Payload family referenced in shell history and related dossierHigh (historical/correlated)
Filenamebot.i686Historical download and execution targetHigh (historical)
Filenamepito.arm7Historical download and execution targetHigh (historical)
Filenamepito.x86Historical execution targetHigh (historical)

Windows LNK Findings

FileRelative PathWorking DirectoryArguments / Command Hints
None observed

PE Candidates

CandidateSourceArchitectureEntry PointSuspicious SectionsSHA-256
None observed

Linux ELF Candidates

CandidateSourceArchitectureStatic observationsSHA-256
botRoot-level acquisitionx86-64Statically linked; debug information present; not stripped118be4b076806c3d426507fa11cc0fffc40c62be51343aef8e82cc04d91330b6
dropperRoot-level acquisitionx86-64Dynamically linked; anomalous section-header offset reported by file parser; strings include /proc/self/mountinfo and Go runtime indicators79aebbbde524f8ec10d232ea48ed3c83068e5f96d8831c7f62820a36688e2550
raul.*Root directory listingMultiple architecturesListed but not fully acquired in bounded passNot available

Deep Technical Threat Analysis

1. Executive Technical Assessment

The endpoint is best assessed as high-confidence hostile or malicious staging infrastructure. The direct evidence is an unauthenticated directory listing containing operational files and multiple architecture-specific binaries, reinforced by shell-history records of payload retrieval and execution.[2]

The evidence supports a staging and distribution role. It does not prove that every file is malicious, that a victim was compromised, or that the service remained active after acquisition.

2. Artifact Inventory

ArtifactTypeSizeSHA-256Notes
.bash_historyShell history24,794 bytesPreserved in acquisition manifestContains payload retrieval, execution, listener, and cleanup commands.
.bashrcShell configuration3,106 bytesPreserved in acquisition manifestStandard configuration observed; retain for timeline analysis.
.lesshstHistory file20 bytesPreserved in acquisition manifestNo substantive command content observed.
.profileShell profile161 bytesPreserved in acquisition manifestStandard profile content observed.
.XauthorityX11 authentication data204 bytesPreserved in acquisition manifestContains X11 cookie marker and hostname; treat as sensitive.
botLinux ELF binary1,822,880 bytes118be4b076806c3d426507fa11cc0fffc40c62be51343aef8e82cc04d91330b6x86-64, statically linked, debug information present.
dropperLinux ELF binary2,097,152 bytes acquired79aebbbde524f8ec10d232ea48ed3c83068e5f96d8831c7f62820a36688e2550x86-64, dynamically linked; parser reported malformed section-header offset.
raul.*Linux ELF payload familyNot acquiredNot availableFourteen architecture-labelled files listed in root index.
exploit.py, test1.py, test2.pyPython scriptsNot acquiredNot availableListed in root index; require authorized static acquisition.

3. Script Behaviors

3.1 .bash_history

The history records the following operational behavior:

BehaviorEvidenceAssessment
Temporary HTTP stagingscreen python3 -m http.server 889 and port 67Deliberate file-serving activity.
Payload retrievalwget and curl commandsIngress tool transfer and staging.
Payload executionchmod +x followed by ./pito.arm7, ./pito.x86, and ./bot.i686Historical execution attempts; success not established.
Listener setupnc -nlvp 9001Possible inbound control or transfer listener; intent unconfirmed.
CleanupVPS cleaner scriptProcess killing, temporary-file deletion, and crontab removal capability.

3.2 VPS Cleaner Script

The shell history contains a script labelled “VPS CLEANER (killer-based ).” Its documented logic scans processes, scores suspicious characteristics, issues kill -9, deletes executable or hidden files from /tmp, /var/tmp, /dev/shm, /mnt, and /run, and removes user crontabs and /etc/cron.d/*.[2]

This demonstrates indicator-removal and defensive-disruption capability. The current evidence does not establish whether the cleaner was executed, when it was executed, or what systems it affected.

4. Network Indicators

Indicator IDURL / EndpointAssociated Evidence
NI-001hxxp://150[.]241[.]65[.]250:889/Direct passive acquisition.
NI-002hxxp://150[.]241[.]65[.]250:67/pito.arm7Historical command in .bash_history.
NI-003hxxp://94[.]154[.]43[.]249:233/gg11Historical command in .bash_history.
NI-004hxxp://94[.]154[.]43[.]249:82/BORRARYA.zipHistorical command in .bash_history.
NI-005hxxp://94[.]154[.]43[.]249:33/bots/bot.i686Historical command in .bash_history.
NI-006hxxp://94[.]154[.]43[.]249:98/botHistorical command in .bash_history.
NI-007/raul.*Architecture-specific files listed in root directory.
NI-008node-32404[.]nodehost[.]ruHostname observed in .Xauthority strings.

5. Cross-Cluster Correlation

The strongest correlation is with the supplied Threat Cluster 194[.]238[.]57[.]124 dossier. That dossier documents a pito.* multi-architecture payload family, gg11, dp.sh, the contextual IP 94[.]154[.]43[.]249, and port 889 staging.[3] The current endpoint independently exposes architecture-specific raul.* files and records historical use of pito.arm7, pito.x86, and bot.i686.[2]

CorrelationEvidenceConfidence
Shared multi-architecture staging modelraul.* root listing and pito.* / bot.i686 historyHigh
Shared related infrastructure94[.]154[.]43[.]249 appears in current history and supplied dossierMedium-to-high
Exact ownership or operator identityNo shared credentials, certificates, logs, or account evidenceNot established
Relationship to Windows Mythic/Adaptix clustersNo direct current-endpoint artifacts identifiedLow / unconfirmed

6. PE and LNK Assessment

No Windows PE candidates or LNK artifacts were identified in the bounded acquisition. The observed payload set is Linux ELF-oriented. This conclusion is limited because the listed Python scripts, raul.* files, directory descendants, and .ssh/ contents were not fully acquired.

7. Secrets and Sensitive Material

The public listing exposes .ssh/, shell history, and .Xauthority. These are sensitive locations even where the acquisition does not reveal a usable private key or token. The .Xauthority file contains an X11 cookie marker, and its value is intentionally omitted from this dossier.[2]

If the infrastructure belongs to the organization, all SSH keys, cookies, cloud credentials, API tokens, and credentials appearing in shell history should be treated as compromised and rotated through a trusted administrative path.

  1. Remove public access to the directory while preserving the host and web-server logs.

  2. Acquire a forensic image, volatile memory, process/socket state, cron and systemd state, and the complete .ssh/ directory under controlled evidence handling.

  3. Hunt for raul.*, pito.*, bot, dropper, gg11, dp.sh, wget, curl, chmod +x, screen, and nc -nlvp 9001 across Linux, IoT, and edge-device telemetry.

  4. Block or monitor 150[.]241[.]65[.]250, 94[.]154[.]43[.]249, and the historical service ports after validating business ownership and avoiding disruption to legitimate investigations.

  5. Rotate exposed SSH keys, X11 cookies, API tokens, passwords, and cloud credentials.

  6. Reverse-engineer bot, dropper, and the uncollected raul.* payloads in an isolated environment; do not execute them on production systems.

  7. Review historical authentication, firewall, DNS, proxy, and cloud-provider telemetry for connections to the listed infrastructure.

Conclusion

The endpoint at 150[.]241[.]65[.]250:889 was publicly exposing an operational Linux staging workspace. The combination of directory exposure, architecture-specific payload names, historical download-and-execute commands, and cleanup tooling indicates a serious infrastructure-security incident and a likely relationship to the supplied multi-architecture 194[.]238[.]57[.]124 cluster.

The evidence supports high-confidence classification as hostile staging infrastructure. It does not independently establish victim compromise, current command-and-control activity, persistence, or attribution to a named threat actor. Those questions require server logs, disk and memory acquisition, network telemetry, and analysis of the uncollected payloads.