MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 007dd96c39a9136151071b5a3bc52956a9842c5dc1e7d3f7e98eecc3b76d520e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



XorDDoS


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 007dd96c39a9136151071b5a3bc52956a9842c5dc1e7d3f7e98eecc3b76d520e
SHA3-384 hash: 2d151bb9ebb25dbff870f4927b70fb55f823100b79ff801de23963c65f09a7e0f90b7d22cccc9d751395cba2f0819854
SHA1 hash: 8ff1c672eac7094ac22b191db8a94b881856161a
MD5 hash: 7f05ed85278e87dc25c2fd86ed83f5eb
humanhash: colorado-music-hot-solar
File name:p.sh
Download: download sample
Signature XorDDoS
File size:1'255 bytes
First seen:2025-09-04 09:35:38 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 24:fN7PvB3RqzZ5fFT6mtypsmo39LKGvkRexV5O:V7hhuZ5FT6mtyGms9LKGvkReVM
TLSH T142210A9950F924A075CE893F909D5E4C5FC63D924818120C63DFFFF8C06916875C8334
Magika shell
Reporter abuse_ch
Tags:sh XorDDoS
URLMalware sample (SHA256 hash)SignatureTags
http://23.160.56.115/p.txt5fefeaf30b8cd96607ee013a771c619d2bcba75e294f57e98ba86e8b40e51090 XorDDoSelf geofenced ua-wget USA x86 Xorddos
http://23.160.56.115/r.txtn/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
44
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Unknown
File Type:
ps1
First seen:
2025-09-04T07:22:00Z UTC
Last seen:
2025-09-04T07:22:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=c5a488b2-1600-0000-e7f9-cda9350c0000 pid=3125 /usr/bin/sudo guuid=243da4b4-1600-0000-e7f9-cda93c0c0000 pid=3132 /tmp/sample.bin guuid=c5a488b2-1600-0000-e7f9-cda9350c0000 pid=3125->guuid=243da4b4-1600-0000-e7f9-cda93c0c0000 pid=3132 execve guuid=2d81e6b4-1600-0000-e7f9-cda93d0c0000 pid=3133 /usr/bin/curl net send-data write-file guuid=243da4b4-1600-0000-e7f9-cda93c0c0000 pid=3132->guuid=2d81e6b4-1600-0000-e7f9-cda93d0c0000 pid=3133 execve guuid=84757bf0-1600-0000-e7f9-cda9810c0000 pid=3201 /usr/bin/chmod guuid=243da4b4-1600-0000-e7f9-cda93c0c0000 pid=3132->guuid=84757bf0-1600-0000-e7f9-cda9810c0000 pid=3201 execve guuid=dfda39f1-1600-0000-e7f9-cda9820c0000 pid=3202 /usr/bin/ygljglkjgfg0 guuid=243da4b4-1600-0000-e7f9-cda93c0c0000 pid=3132->guuid=dfda39f1-1600-0000-e7f9-cda9820c0000 pid=3202 execve guuid=336a95f1-1600-0000-e7f9-cda9840c0000 pid=3204 /usr/bin/wget net send-data write-file guuid=243da4b4-1600-0000-e7f9-cda93c0c0000 pid=3132->guuid=336a95f1-1600-0000-e7f9-cda9840c0000 pid=3204 execve guuid=1ece232e-1700-0000-e7f9-cda9e10c0000 pid=3297 /usr/bin/chmod guuid=243da4b4-1600-0000-e7f9-cda93c0c0000 pid=3132->guuid=1ece232e-1700-0000-e7f9-cda9e10c0000 pid=3297 execve guuid=01779f2e-1700-0000-e7f9-cda9e30c0000 pid=3299 /usr/bin/ygljglkjgfg1 guuid=243da4b4-1600-0000-e7f9-cda93c0c0000 pid=3132->guuid=01779f2e-1700-0000-e7f9-cda9e30c0000 pid=3299 execve guuid=4b7d7e2f-1700-0000-e7f9-cda9e80c0000 pid=3304 /usr/bin/chmod guuid=243da4b4-1600-0000-e7f9-cda93c0c0000 pid=3132->guuid=4b7d7e2f-1700-0000-e7f9-cda9e80c0000 pid=3304 execve guuid=96108930-1700-0000-e7f9-cda9ec0c0000 pid=3308 /usr/bin/dash guuid=243da4b4-1600-0000-e7f9-cda93c0c0000 pid=3132->guuid=96108930-1700-0000-e7f9-cda9ec0c0000 pid=3308 clone guuid=06309130-1700-0000-e7f9-cda9ed0c0000 pid=3309 /usr/bin/sleep guuid=243da4b4-1600-0000-e7f9-cda93c0c0000 pid=3132->guuid=06309130-1700-0000-e7f9-cda9ed0c0000 pid=3309 execve guuid=caafefa8-1700-0000-e7f9-cda9d50d0000 pid=3541 /usr/bin/wget net send-data guuid=243da4b4-1600-0000-e7f9-cda93c0c0000 pid=3132->guuid=caafefa8-1700-0000-e7f9-cda9d50d0000 pid=3541 execve guuid=afceceb9-1700-0000-e7f9-cda9f30d0000 pid=3571 /usr/bin/chmod guuid=243da4b4-1600-0000-e7f9-cda93c0c0000 pid=3132->guuid=afceceb9-1700-0000-e7f9-cda9f30d0000 pid=3571 execve guuid=c61b47ba-1700-0000-e7f9-cda9f50d0000 pid=3573 /usr/bin/sdf3fslsdf13 guuid=243da4b4-1600-0000-e7f9-cda93c0c0000 pid=3132->guuid=c61b47ba-1700-0000-e7f9-cda9f50d0000 pid=3573 execve guuid=ac0d80bb-1700-0000-e7f9-cda9f90d0000 pid=3577 /usr/bin/chmod guuid=243da4b4-1600-0000-e7f9-cda93c0c0000 pid=3132->guuid=ac0d80bb-1700-0000-e7f9-cda9f90d0000 pid=3577 execve guuid=8dfef1bb-1700-0000-e7f9-cda9fb0d0000 pid=3579 /usr/bin/dash guuid=243da4b4-1600-0000-e7f9-cda93c0c0000 pid=3132->guuid=8dfef1bb-1700-0000-e7f9-cda9fb0d0000 pid=3579 clone guuid=61370bbc-1700-0000-e7f9-cda9fc0d0000 pid=3580 /usr/bin/curl net send-data write-file guuid=243da4b4-1600-0000-e7f9-cda93c0c0000 pid=3132->guuid=61370bbc-1700-0000-e7f9-cda9fc0d0000 pid=3580 execve guuid=b260e6cd-1700-0000-e7f9-cda9200e0000 pid=3616 /usr/bin/chmod guuid=243da4b4-1600-0000-e7f9-cda93c0c0000 pid=3132->guuid=b260e6cd-1700-0000-e7f9-cda9200e0000 pid=3616 execve guuid=4a9564ce-1700-0000-e7f9-cda9230e0000 pid=3619 /usr/bin/sdf3fslsdf15 guuid=243da4b4-1600-0000-e7f9-cda93c0c0000 pid=3132->guuid=4a9564ce-1700-0000-e7f9-cda9230e0000 pid=3619 execve guuid=544cc9ce-1700-0000-e7f9-cda9240e0000 pid=3620 /usr/bin/sleep guuid=243da4b4-1600-0000-e7f9-cda93c0c0000 pid=3132->guuid=544cc9ce-1700-0000-e7f9-cda9240e0000 pid=3620 execve guuid=25019646-1800-0000-e7f9-cda95b0f0000 pid=3931 /usr/bin/mv guuid=243da4b4-1600-0000-e7f9-cda93c0c0000 pid=3132->guuid=25019646-1800-0000-e7f9-cda95b0f0000 pid=3931 execve guuid=e6b54c52-1800-0000-e7f9-cda9620f0000 pid=3938 /usr/bin/mv guuid=243da4b4-1600-0000-e7f9-cda93c0c0000 pid=3132->guuid=e6b54c52-1800-0000-e7f9-cda9620f0000 pid=3938 execve guuid=55336253-1800-0000-e7f9-cda9640f0000 pid=3940 /usr/bin/cat guuid=243da4b4-1600-0000-e7f9-cda93c0c0000 pid=3132->guuid=55336253-1800-0000-e7f9-cda9640f0000 pid=3940 execve guuid=f632fd53-1800-0000-e7f9-cda9680f0000 pid=3944 /usr/bin/cat guuid=243da4b4-1600-0000-e7f9-cda93c0c0000 pid=3132->guuid=f632fd53-1800-0000-e7f9-cda9680f0000 pid=3944 execve guuid=c11b8254-1800-0000-e7f9-cda96a0f0000 pid=3946 /usr/bin/cat guuid=243da4b4-1600-0000-e7f9-cda93c0c0000 pid=3132->guuid=c11b8254-1800-0000-e7f9-cda96a0f0000 pid=3946 execve guuid=2533f254-1800-0000-e7f9-cda96b0f0000 pid=3947 /usr/bin/cat guuid=243da4b4-1600-0000-e7f9-cda93c0c0000 pid=3132->guuid=2533f254-1800-0000-e7f9-cda96b0f0000 pid=3947 execve guuid=fd407e55-1800-0000-e7f9-cda96e0f0000 pid=3950 /usr/bin/cat guuid=243da4b4-1600-0000-e7f9-cda93c0c0000 pid=3132->guuid=fd407e55-1800-0000-e7f9-cda96e0f0000 pid=3950 execve guuid=d6a51356-1800-0000-e7f9-cda9710f0000 pid=3953 /usr/bin/cat guuid=243da4b4-1600-0000-e7f9-cda93c0c0000 pid=3132->guuid=d6a51356-1800-0000-e7f9-cda9710f0000 pid=3953 execve guuid=0c859f56-1800-0000-e7f9-cda9720f0000 pid=3954 /usr/bin/cat guuid=243da4b4-1600-0000-e7f9-cda93c0c0000 pid=3132->guuid=0c859f56-1800-0000-e7f9-cda9720f0000 pid=3954 execve guuid=44673b57-1800-0000-e7f9-cda9750f0000 pid=3957 /usr/bin/cat guuid=243da4b4-1600-0000-e7f9-cda93c0c0000 pid=3132->guuid=44673b57-1800-0000-e7f9-cda9750f0000 pid=3957 execve guuid=1a0ab357-1800-0000-e7f9-cda9770f0000 pid=3959 /usr/bin/cat guuid=243da4b4-1600-0000-e7f9-cda93c0c0000 pid=3132->guuid=1a0ab357-1800-0000-e7f9-cda9770f0000 pid=3959 execve guuid=c9252458-1800-0000-e7f9-cda9790f0000 pid=3961 /usr/bin/cat guuid=243da4b4-1600-0000-e7f9-cda93c0c0000 pid=3132->guuid=c9252458-1800-0000-e7f9-cda9790f0000 pid=3961 execve guuid=0a789358-1800-0000-e7f9-cda97b0f0000 pid=3963 /usr/bin/cat guuid=243da4b4-1600-0000-e7f9-cda93c0c0000 pid=3132->guuid=0a789358-1800-0000-e7f9-cda97b0f0000 pid=3963 execve guuid=6d930259-1800-0000-e7f9-cda97d0f0000 pid=3965 /usr/bin/cat guuid=243da4b4-1600-0000-e7f9-cda93c0c0000 pid=3132->guuid=6d930259-1800-0000-e7f9-cda97d0f0000 pid=3965 execve guuid=9e107259-1800-0000-e7f9-cda97f0f0000 pid=3967 /usr/bin/cat guuid=243da4b4-1600-0000-e7f9-cda93c0c0000 pid=3132->guuid=9e107259-1800-0000-e7f9-cda97f0f0000 pid=3967 execve guuid=05355169-1800-0000-e7f9-cda98a0f0000 pid=3978 /usr/bin/cat guuid=243da4b4-1600-0000-e7f9-cda93c0c0000 pid=3132->guuid=05355169-1800-0000-e7f9-cda98a0f0000 pid=3978 execve guuid=1ee5496a-1800-0000-e7f9-cda98e0f0000 pid=3982 /usr/bin/cat guuid=243da4b4-1600-0000-e7f9-cda93c0c0000 pid=3132->guuid=1ee5496a-1800-0000-e7f9-cda98e0f0000 pid=3982 execve guuid=5817c36a-1800-0000-e7f9-cda98f0f0000 pid=3983 /usr/bin/cat guuid=243da4b4-1600-0000-e7f9-cda93c0c0000 pid=3132->guuid=5817c36a-1800-0000-e7f9-cda98f0f0000 pid=3983 execve guuid=eb6a456b-1800-0000-e7f9-cda9910f0000 pid=3985 /usr/bin/ls guuid=243da4b4-1600-0000-e7f9-cda93c0c0000 pid=3132->guuid=eb6a456b-1800-0000-e7f9-cda9910f0000 pid=3985 execve 916ccbc0-3acd-51f4-84b1-312e6c807f13 23.160.56.115:80 guuid=2d81e6b4-1600-0000-e7f9-cda93d0c0000 pid=3133->916ccbc0-3acd-51f4-84b1-312e6c807f13 send: 82B guuid=353b85f1-1600-0000-e7f9-cda9830c0000 pid=3203 /usr/bin/ygljglkjgfg0 delete-file write-config write-file zombie guuid=dfda39f1-1600-0000-e7f9-cda9820c0000 pid=3202->guuid=353b85f1-1600-0000-e7f9-cda9830c0000 pid=3203 clone guuid=afa5caf1-1600-0000-e7f9-cda9850c0000 pid=3205 /usr/bin/ygljglkjgfg0 guuid=353b85f1-1600-0000-e7f9-cda9830c0000 pid=3203->guuid=afa5caf1-1600-0000-e7f9-cda9850c0000 pid=3205 clone guuid=1a6a6bf2-1600-0000-e7f9-cda9870c0000 pid=3207 /usr/bin/ygljglkjgfg0 guuid=353b85f1-1600-0000-e7f9-cda9830c0000 pid=3203->guuid=1a6a6bf2-1600-0000-e7f9-cda9870c0000 pid=3207 clone guuid=747a03f3-1600-0000-e7f9-cda9890c0000 pid=3209 /usr/bin/dash guuid=353b85f1-1600-0000-e7f9-cda9830c0000 pid=3203->guuid=747a03f3-1600-0000-e7f9-cda9890c0000 pid=3209 execve guuid=353b85f1-1600-0000-e7f9-cda9830c0000 pid=3211 /usr/bin/ygljglkjgfg0 write-file zombie guuid=353b85f1-1600-0000-e7f9-cda9830c0000 pid=3203->guuid=353b85f1-1600-0000-e7f9-cda9830c0000 pid=3211 clone guuid=353b85f1-1600-0000-e7f9-cda9830c0000 pid=3212 /usr/bin/ygljglkjgfg0 dns net send-data write-file zombie guuid=353b85f1-1600-0000-e7f9-cda9830c0000 pid=3203->guuid=353b85f1-1600-0000-e7f9-cda9830c0000 pid=3212 clone guuid=353b85f1-1600-0000-e7f9-cda9830c0000 pid=3213 /usr/bin/ygljglkjgfg0 net zombie guuid=353b85f1-1600-0000-e7f9-cda9830c0000 pid=3203->guuid=353b85f1-1600-0000-e7f9-cda9830c0000 pid=3213 clone guuid=74282f23-1800-0000-e7f9-cda9ea0e0000 pid=3818 /usr/bin/ygljglkjgfg0 guuid=353b85f1-1600-0000-e7f9-cda9830c0000 pid=3203->guuid=74282f23-1800-0000-e7f9-cda9ea0e0000 pid=3818 clone guuid=f3295e23-1800-0000-e7f9-cda9ed0e0000 pid=3821 /usr/bin/ygljglkjgfg0 guuid=353b85f1-1600-0000-e7f9-cda9830c0000 pid=3203->guuid=f3295e23-1800-0000-e7f9-cda9ed0e0000 pid=3821 clone guuid=b9c97423-1800-0000-e7f9-cda9f00e0000 pid=3824 /usr/bin/ygljglkjgfg0 guuid=353b85f1-1600-0000-e7f9-cda9830c0000 pid=3203->guuid=b9c97423-1800-0000-e7f9-cda9f00e0000 pid=3824 clone guuid=0c649b23-1800-0000-e7f9-cda9f20e0000 pid=3826 /usr/bin/ygljglkjgfg0 guuid=353b85f1-1600-0000-e7f9-cda9830c0000 pid=3203->guuid=0c649b23-1800-0000-e7f9-cda9f20e0000 pid=3826 clone guuid=34902424-1800-0000-e7f9-cda9f60e0000 pid=3830 /usr/bin/ygljglkjgfg0 guuid=353b85f1-1600-0000-e7f9-cda9830c0000 pid=3203->guuid=34902424-1800-0000-e7f9-cda9f60e0000 pid=3830 clone guuid=592e7051-1900-0000-e7f9-cda9aa110000 pid=4522 /usr/bin/ygljglkjgfg0 guuid=353b85f1-1600-0000-e7f9-cda9830c0000 pid=3203->guuid=592e7051-1900-0000-e7f9-cda9aa110000 pid=4522 clone guuid=cd4f9d51-1900-0000-e7f9-cda9ae110000 pid=4526 /usr/bin/ygljglkjgfg0 guuid=353b85f1-1600-0000-e7f9-cda9830c0000 pid=3203->guuid=cd4f9d51-1900-0000-e7f9-cda9ae110000 pid=4526 clone guuid=66c7b451-1900-0000-e7f9-cda9b0110000 pid=4528 /usr/bin/ygljglkjgfg0 guuid=353b85f1-1600-0000-e7f9-cda9830c0000 pid=3203->guuid=66c7b451-1900-0000-e7f9-cda9b0110000 pid=4528 clone guuid=d124dd51-1900-0000-e7f9-cda9b3110000 pid=4531 /usr/bin/ygljglkjgfg0 guuid=353b85f1-1600-0000-e7f9-cda9830c0000 pid=3203->guuid=d124dd51-1900-0000-e7f9-cda9b3110000 pid=4531 clone guuid=9de3c352-1900-0000-e7f9-cda9bc110000 pid=4540 /usr/bin/ygljglkjgfg0 guuid=353b85f1-1600-0000-e7f9-cda9830c0000 pid=3203->guuid=9de3c352-1900-0000-e7f9-cda9bc110000 pid=4540 clone guuid=c5673c80-1a00-0000-e7f9-cda973140000 pid=5235 /usr/bin/ygljglkjgfg0 guuid=353b85f1-1600-0000-e7f9-cda9830c0000 pid=3203->guuid=c5673c80-1a00-0000-e7f9-cda973140000 pid=5235 clone guuid=4ea85a80-1a00-0000-e7f9-cda975140000 pid=5237 /usr/bin/ygljglkjgfg0 guuid=353b85f1-1600-0000-e7f9-cda9830c0000 pid=3203->guuid=4ea85a80-1a00-0000-e7f9-cda975140000 pid=5237 clone guuid=294b7680-1a00-0000-e7f9-cda977140000 pid=5239 /usr/bin/ygljglkjgfg0 guuid=353b85f1-1600-0000-e7f9-cda9830c0000 pid=3203->guuid=294b7680-1a00-0000-e7f9-cda977140000 pid=5239 clone guuid=82fb8a80-1a00-0000-e7f9-cda979140000 pid=5241 /usr/bin/ygljglkjgfg0 guuid=353b85f1-1600-0000-e7f9-cda9830c0000 pid=3203->guuid=82fb8a80-1a00-0000-e7f9-cda979140000 pid=5241 clone guuid=5f8cc280-1a00-0000-e7f9-cda97b140000 pid=5243 /usr/bin/ygljglkjgfg0 guuid=353b85f1-1600-0000-e7f9-cda9830c0000 pid=3203->guuid=5f8cc280-1a00-0000-e7f9-cda97b140000 pid=5243 clone guuid=cf9535ae-1b00-0000-e7f9-cda9d6140000 pid=5334 /usr/bin/ygljglkjgfg0 guuid=353b85f1-1600-0000-e7f9-cda9830c0000 pid=3203->guuid=cf9535ae-1b00-0000-e7f9-cda9d6140000 pid=5334 clone guuid=eeac73ae-1b00-0000-e7f9-cda9d8140000 pid=5336 /usr/bin/ygljglkjgfg0 guuid=353b85f1-1600-0000-e7f9-cda9830c0000 pid=3203->guuid=eeac73ae-1b00-0000-e7f9-cda9d8140000 pid=5336 clone guuid=9a6afdae-1b00-0000-e7f9-cda9da140000 pid=5338 /usr/bin/ygljglkjgfg0 guuid=353b85f1-1600-0000-e7f9-cda9830c0000 pid=3203->guuid=9a6afdae-1b00-0000-e7f9-cda9da140000 pid=5338 clone guuid=8cdf2faf-1b00-0000-e7f9-cda9dc140000 pid=5340 /usr/bin/ygljglkjgfg0 guuid=353b85f1-1600-0000-e7f9-cda9830c0000 pid=3203->guuid=8cdf2faf-1b00-0000-e7f9-cda9dc140000 pid=5340 clone guuid=bb5046b3-1b00-0000-e7f9-cda9de140000 pid=5342 /usr/bin/ygljglkjgfg0 guuid=353b85f1-1600-0000-e7f9-cda9830c0000 pid=3203->guuid=bb5046b3-1b00-0000-e7f9-cda9de140000 pid=5342 clone guuid=2de6c3ec-1c00-0000-e7f9-cda905150000 pid=5381 /usr/bin/ygljglkjgfg0 guuid=353b85f1-1600-0000-e7f9-cda9830c0000 pid=3203->guuid=2de6c3ec-1c00-0000-e7f9-cda905150000 pid=5381 clone guuid=d188f4ec-1c00-0000-e7f9-cda907150000 pid=5383 /usr/bin/ygljglkjgfg0 guuid=353b85f1-1600-0000-e7f9-cda9830c0000 pid=3203->guuid=d188f4ec-1c00-0000-e7f9-cda907150000 pid=5383 clone guuid=5f5824ed-1c00-0000-e7f9-cda909150000 pid=5385 /usr/bin/ygljglkjgfg0 guuid=353b85f1-1600-0000-e7f9-cda9830c0000 pid=3203->guuid=5f5824ed-1c00-0000-e7f9-cda909150000 pid=5385 clone guuid=248a54ed-1c00-0000-e7f9-cda90b150000 pid=5387 /usr/bin/ygljglkjgfg0 guuid=353b85f1-1600-0000-e7f9-cda9830c0000 pid=3203->guuid=248a54ed-1c00-0000-e7f9-cda90b150000 pid=5387 clone guuid=88d479ed-1c00-0000-e7f9-cda90d150000 pid=5389 /usr/bin/ygljglkjgfg0 guuid=353b85f1-1600-0000-e7f9-cda9830c0000 pid=3203->guuid=88d479ed-1c00-0000-e7f9-cda90d150000 pid=5389 clone guuid=774e6b1a-1e00-0000-e7f9-cda914150000 pid=5396 /usr/bin/ygljglkjgfg0 guuid=353b85f1-1600-0000-e7f9-cda9830c0000 pid=3203->guuid=774e6b1a-1e00-0000-e7f9-cda914150000 pid=5396 clone guuid=419fa01a-1e00-0000-e7f9-cda916150000 pid=5398 /usr/bin/ygljglkjgfg0 guuid=353b85f1-1600-0000-e7f9-cda9830c0000 pid=3203->guuid=419fa01a-1e00-0000-e7f9-cda916150000 pid=5398 clone guuid=da4ee01a-1e00-0000-e7f9-cda918150000 pid=5400 /usr/bin/ygljglkjgfg0 guuid=353b85f1-1600-0000-e7f9-cda9830c0000 pid=3203->guuid=da4ee01a-1e00-0000-e7f9-cda918150000 pid=5400 clone guuid=aa262f1b-1e00-0000-e7f9-cda91a150000 pid=5402 /usr/bin/ygljglkjgfg0 guuid=353b85f1-1600-0000-e7f9-cda9830c0000 pid=3203->guuid=aa262f1b-1e00-0000-e7f9-cda91a150000 pid=5402 clone guuid=8fa9801b-1e00-0000-e7f9-cda91c150000 pid=5404 /usr/bin/ygljglkjgfg0 guuid=353b85f1-1600-0000-e7f9-cda9830c0000 pid=3203->guuid=8fa9801b-1e00-0000-e7f9-cda91c150000 pid=5404 clone guuid=d5af1e48-1f00-0000-e7f9-cda923150000 pid=5411 /usr/bin/ygljglkjgfg0 guuid=353b85f1-1600-0000-e7f9-cda9830c0000 pid=3203->guuid=d5af1e48-1f00-0000-e7f9-cda923150000 pid=5411 clone guuid=6be06348-1f00-0000-e7f9-cda925150000 pid=5413 /usr/bin/ygljglkjgfg0 guuid=353b85f1-1600-0000-e7f9-cda9830c0000 pid=3203->guuid=6be06348-1f00-0000-e7f9-cda925150000 pid=5413 clone guuid=2afe9448-1f00-0000-e7f9-cda927150000 pid=5415 /usr/bin/ygljglkjgfg0 guuid=353b85f1-1600-0000-e7f9-cda9830c0000 pid=3203->guuid=2afe9448-1f00-0000-e7f9-cda927150000 pid=5415 clone guuid=85f6bd48-1f00-0000-e7f9-cda929150000 pid=5417 /usr/bin/ygljglkjgfg0 guuid=353b85f1-1600-0000-e7f9-cda9830c0000 pid=3203->guuid=85f6bd48-1f00-0000-e7f9-cda929150000 pid=5417 clone guuid=ff78e948-1f00-0000-e7f9-cda92b150000 pid=5419 /usr/bin/ygljglkjgfg0 guuid=353b85f1-1600-0000-e7f9-cda9830c0000 pid=3203->guuid=ff78e948-1f00-0000-e7f9-cda92b150000 pid=5419 clone guuid=f9c61d77-2000-0000-e7f9-cda932150000 pid=5426 /usr/bin/ygljglkjgfg0 guuid=353b85f1-1600-0000-e7f9-cda9830c0000 pid=3203->guuid=f9c61d77-2000-0000-e7f9-cda932150000 pid=5426 clone guuid=30924977-2000-0000-e7f9-cda934150000 pid=5428 /usr/bin/ygljglkjgfg0 guuid=353b85f1-1600-0000-e7f9-cda9830c0000 pid=3203->guuid=30924977-2000-0000-e7f9-cda934150000 pid=5428 clone guuid=8b2e6d77-2000-0000-e7f9-cda936150000 pid=5430 /usr/bin/ygljglkjgfg0 guuid=353b85f1-1600-0000-e7f9-cda9830c0000 pid=3203->guuid=8b2e6d77-2000-0000-e7f9-cda936150000 pid=5430 clone guuid=6f9c8877-2000-0000-e7f9-cda938150000 pid=5432 /usr/bin/ygljglkjgfg0 guuid=353b85f1-1600-0000-e7f9-cda9830c0000 pid=3203->guuid=6f9c8877-2000-0000-e7f9-cda938150000 pid=5432 clone guuid=6c33a177-2000-0000-e7f9-cda93a150000 pid=5434 /usr/bin/ygljglkjgfg0 guuid=353b85f1-1600-0000-e7f9-cda9830c0000 pid=3203->guuid=6c33a177-2000-0000-e7f9-cda93a150000 pid=5434 clone guuid=972a33a5-2100-0000-e7f9-cda941150000 pid=5441 /usr/bin/ygljglkjgfg0 guuid=353b85f1-1600-0000-e7f9-cda9830c0000 pid=3203->guuid=972a33a5-2100-0000-e7f9-cda941150000 pid=5441 clone guuid=2ff565a5-2100-0000-e7f9-cda943150000 pid=5443 /usr/bin/ygljglkjgfg0 guuid=353b85f1-1600-0000-e7f9-cda9830c0000 pid=3203->guuid=2ff565a5-2100-0000-e7f9-cda943150000 pid=5443 clone guuid=a5729aa5-2100-0000-e7f9-cda945150000 pid=5445 /usr/bin/ygljglkjgfg0 guuid=353b85f1-1600-0000-e7f9-cda9830c0000 pid=3203->guuid=a5729aa5-2100-0000-e7f9-cda945150000 pid=5445 clone guuid=762ec4a5-2100-0000-e7f9-cda947150000 pid=5447 /usr/bin/ygljglkjgfg0 guuid=353b85f1-1600-0000-e7f9-cda9830c0000 pid=3203->guuid=762ec4a5-2100-0000-e7f9-cda947150000 pid=5447 clone guuid=5357f2a5-2100-0000-e7f9-cda949150000 pid=5449 /usr/bin/ygljglkjgfg0 guuid=353b85f1-1600-0000-e7f9-cda9830c0000 pid=3203->guuid=5357f2a5-2100-0000-e7f9-cda949150000 pid=5449 clone guuid=0a2391dd-2200-0000-e7f9-cda950150000 pid=5456 /usr/bin/ygljglkjgfg0 guuid=353b85f1-1600-0000-e7f9-cda9830c0000 pid=3203->guuid=0a2391dd-2200-0000-e7f9-cda950150000 pid=5456 clone guuid=f7aacadd-2200-0000-e7f9-cda952150000 pid=5458 /usr/bin/ygljglkjgfg0 guuid=353b85f1-1600-0000-e7f9-cda9830c0000 pid=3203->guuid=f7aacadd-2200-0000-e7f9-cda952150000 pid=5458 clone guuid=9370fddd-2200-0000-e7f9-cda954150000 pid=5460 /usr/bin/ygljglkjgfg0 guuid=353b85f1-1600-0000-e7f9-cda9830c0000 pid=3203->guuid=9370fddd-2200-0000-e7f9-cda954150000 pid=5460 clone guuid=f36226de-2200-0000-e7f9-cda956150000 pid=5462 /usr/bin/ygljglkjgfg0 guuid=353b85f1-1600-0000-e7f9-cda9830c0000 pid=3203->guuid=f36226de-2200-0000-e7f9-cda956150000 pid=5462 clone guuid=271750de-2200-0000-e7f9-cda958150000 pid=5464 /usr/bin/ygljglkjgfg0 guuid=353b85f1-1600-0000-e7f9-cda9830c0000 pid=3203->guuid=271750de-2200-0000-e7f9-cda958150000 pid=5464 clone guuid=777dcc14-2400-0000-e7f9-cda95f150000 pid=5471 /usr/bin/ygljglkjgfg0 guuid=353b85f1-1600-0000-e7f9-cda9830c0000 pid=3203->guuid=777dcc14-2400-0000-e7f9-cda95f150000 pid=5471 clone guuid=b6cffe14-2400-0000-e7f9-cda961150000 pid=5473 /usr/bin/ygljglkjgfg0 guuid=353b85f1-1600-0000-e7f9-cda9830c0000 pid=3203->guuid=b6cffe14-2400-0000-e7f9-cda961150000 pid=5473 clone guuid=35ea2f15-2400-0000-e7f9-cda963150000 pid=5475 /usr/bin/ygljglkjgfg0 guuid=353b85f1-1600-0000-e7f9-cda9830c0000 pid=3203->guuid=35ea2f15-2400-0000-e7f9-cda963150000 pid=5475 clone guuid=28b35415-2400-0000-e7f9-cda965150000 pid=5477 /usr/bin/ygljglkjgfg0 guuid=353b85f1-1600-0000-e7f9-cda9830c0000 pid=3203->guuid=28b35415-2400-0000-e7f9-cda965150000 pid=5477 clone guuid=412b7615-2400-0000-e7f9-cda967150000 pid=5479 /usr/bin/ygljglkjgfg0 guuid=353b85f1-1600-0000-e7f9-cda9830c0000 pid=3203->guuid=412b7615-2400-0000-e7f9-cda967150000 pid=5479 clone guuid=336a95f1-1600-0000-e7f9-cda9840c0000 pid=3204->916ccbc0-3acd-51f4-84b1-312e6c807f13 send: 133B guuid=17c4e4f1-1600-0000-e7f9-cda9860c0000 pid=3206 /usr/bin/ygljglkjgfg0 guuid=afa5caf1-1600-0000-e7f9-cda9850c0000 pid=3205->guuid=17c4e4f1-1600-0000-e7f9-cda9860c0000 pid=3206 clone guuid=2483e7f2-1600-0000-e7f9-cda9880c0000 pid=3208 /usr/sbin/update-rc.d zombie guuid=1a6a6bf2-1600-0000-e7f9-cda9870c0000 pid=3207->guuid=2483e7f2-1600-0000-e7f9-cda9880c0000 pid=3208 execve guuid=7325bafc-1600-0000-e7f9-cda98e0c0000 pid=3214 /usr/bin/systemctl guuid=2483e7f2-1600-0000-e7f9-cda9880c0000 pid=3208->guuid=7325bafc-1600-0000-e7f9-cda98e0c0000 pid=3214 execve guuid=78fb56f4-1600-0000-e7f9-cda98a0c0000 pid=3210 /usr/bin/sed guuid=747a03f3-1600-0000-e7f9-cda9890c0000 pid=3209->guuid=78fb56f4-1600-0000-e7f9-cda98a0c0000 pid=3210 execve f8f8f150-6705-5c6d-b135-03a0b4165a8e 0.0.0.0:1529 guuid=353b85f1-1600-0000-e7f9-cda9830c0000 pid=3212->f8f8f150-6705-5c6d-b135-03a0b4165a8e con ec143f60-91e6-5225-ae7f-e225cad41951 zz.vvbb321.com:1529 guuid=353b85f1-1600-0000-e7f9-cda9830c0000 pid=3212->ec143f60-91e6-5225-ae7f-e225cad41951 send: 4548B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=353b85f1-1600-0000-e7f9-cda9830c0000 pid=3212->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 96B b4bf20d4-f7c8-5c24-8830-c23364537aa4 8.8.4.4:53 guuid=353b85f1-1600-0000-e7f9-cda9830c0000 pid=3212->b4bf20d4-f7c8-5c24-8830-c23364537aa4 send: 64B 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=353b85f1-1600-0000-e7f9-cda9830c0000 pid=3212->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 64B 87f248b3-21f7-50eb-a2c7-cb35eca5cc17 0.0.0.0:80 guuid=353b85f1-1600-0000-e7f9-cda9830c0000 pid=3213->87f248b3-21f7-50eb-a2c7-cb35eca5cc17 con guuid=9719742f-1700-0000-e7f9-cda9e70c0000 pid=3303 /usr/bin/ygljglkjgfg1 delete-file zombie guuid=01779f2e-1700-0000-e7f9-cda9e30c0000 pid=3299->guuid=9719742f-1700-0000-e7f9-cda9e70c0000 pid=3303 clone guuid=caafefa8-1700-0000-e7f9-cda9d50d0000 pid=3541->916ccbc0-3acd-51f4-84b1-312e6c807f13 send: 133B guuid=61370bbc-1700-0000-e7f9-cda9fc0d0000 pid=3580->916ccbc0-3acd-51f4-84b1-312e6c807f13 send: 82B guuid=cfb24423-1800-0000-e7f9-cda9eb0e0000 pid=3819 /usr/bin/umurlgxkgy zombie guuid=74282f23-1800-0000-e7f9-cda9ea0e0000 pid=3818->guuid=cfb24423-1800-0000-e7f9-cda9eb0e0000 pid=3819 execve guuid=25db8327-1800-0000-e7f9-cda9040f0000 pid=3844 /usr/bin/umurlgxkgy zombie guuid=cfb24423-1800-0000-e7f9-cda9eb0e0000 pid=3819->guuid=25db8327-1800-0000-e7f9-cda9040f0000 pid=3844 clone guuid=b2db6523-1800-0000-e7f9-cda9ee0e0000 pid=3822 /usr/bin/umurlgxkgy zombie guuid=f3295e23-1800-0000-e7f9-cda9ed0e0000 pid=3821->guuid=b2db6523-1800-0000-e7f9-cda9ee0e0000 pid=3822 execve guuid=c0f8fc26-1800-0000-e7f9-cda9000f0000 pid=3840 /usr/bin/umurlgxkgy zombie guuid=b2db6523-1800-0000-e7f9-cda9ee0e0000 pid=3822->guuid=c0f8fc26-1800-0000-e7f9-cda9000f0000 pid=3840 clone guuid=86d88023-1800-0000-e7f9-cda9f10e0000 pid=3825 /usr/bin/umurlgxkgy zombie guuid=b9c97423-1800-0000-e7f9-cda9f00e0000 pid=3824->guuid=86d88023-1800-0000-e7f9-cda9f10e0000 pid=3825 execve guuid=6ae32429-1800-0000-e7f9-cda90f0f0000 pid=3855 /usr/bin/umurlgxkgy zombie guuid=86d88023-1800-0000-e7f9-cda9f10e0000 pid=3825->guuid=6ae32429-1800-0000-e7f9-cda90f0f0000 pid=3855 clone guuid=d72f0c24-1800-0000-e7f9-cda9f50e0000 pid=3829 /usr/bin/umurlgxkgy zombie guuid=0c649b23-1800-0000-e7f9-cda9f20e0000 pid=3826->guuid=d72f0c24-1800-0000-e7f9-cda9f50e0000 pid=3829 execve guuid=f5c0012a-1800-0000-e7f9-cda9140f0000 pid=3860 /usr/bin/umurlgxkgy zombie guuid=d72f0c24-1800-0000-e7f9-cda9f50e0000 pid=3829->guuid=f5c0012a-1800-0000-e7f9-cda9140f0000 pid=3860 clone guuid=91bc9424-1800-0000-e7f9-cda9f80e0000 pid=3832 /usr/bin/umurlgxkgy zombie guuid=34902424-1800-0000-e7f9-cda9f60e0000 pid=3830->guuid=91bc9424-1800-0000-e7f9-cda9f80e0000 pid=3832 execve guuid=911a3128-1800-0000-e7f9-cda9070f0000 pid=3847 /usr/bin/umurlgxkgy zombie guuid=91bc9424-1800-0000-e7f9-cda9f80e0000 pid=3832->guuid=911a3128-1800-0000-e7f9-cda9070f0000 pid=3847 clone guuid=48fc7851-1900-0000-e7f9-cda9ac110000 pid=4524 /usr/bin/jwpuuuoraj zombie guuid=592e7051-1900-0000-e7f9-cda9aa110000 pid=4522->guuid=48fc7851-1900-0000-e7f9-cda9ac110000 pid=4524 execve guuid=b4206e56-1900-0000-e7f9-cda9cb110000 pid=4555 /usr/bin/jwpuuuoraj zombie guuid=48fc7851-1900-0000-e7f9-cda9ac110000 pid=4524->guuid=b4206e56-1900-0000-e7f9-cda9cb110000 pid=4555 clone guuid=2d6ea351-1900-0000-e7f9-cda9af110000 pid=4527 /usr/bin/jwpuuuoraj zombie guuid=cd4f9d51-1900-0000-e7f9-cda9ae110000 pid=4526->guuid=2d6ea351-1900-0000-e7f9-cda9af110000 pid=4527 execve guuid=b2ce7b56-1900-0000-e7f9-cda9cc110000 pid=4556 /usr/bin/jwpuuuoraj zombie guuid=2d6ea351-1900-0000-e7f9-cda9af110000 pid=4527->guuid=b2ce7b56-1900-0000-e7f9-cda9cc110000 pid=4556 clone guuid=0da8c251-1900-0000-e7f9-cda9b1110000 pid=4529 /usr/bin/jwpuuuoraj zombie guuid=66c7b451-1900-0000-e7f9-cda9b0110000 pid=4528->guuid=0da8c251-1900-0000-e7f9-cda9b1110000 pid=4529 execve guuid=18f5b154-1900-0000-e7f9-cda9c6110000 pid=4550 /usr/bin/jwpuuuoraj zombie guuid=0da8c251-1900-0000-e7f9-cda9b1110000 pid=4529->guuid=18f5b154-1900-0000-e7f9-cda9c6110000 pid=4550 clone guuid=89ffab52-1900-0000-e7f9-cda9b8110000 pid=4536 /usr/bin/jwpuuuoraj zombie guuid=d124dd51-1900-0000-e7f9-cda9b3110000 pid=4531->guuid=89ffab52-1900-0000-e7f9-cda9b8110000 pid=4536 execve guuid=8c546359-1900-0000-e7f9-cda9d5110000 pid=4565 /usr/bin/jwpuuuoraj zombie guuid=89ffab52-1900-0000-e7f9-cda9b8110000 pid=4536->guuid=8c546359-1900-0000-e7f9-cda9d5110000 pid=4565 clone guuid=0bf80c54-1900-0000-e7f9-cda9c3110000 pid=4547 /usr/bin/jwpuuuoraj zombie guuid=9de3c352-1900-0000-e7f9-cda9bc110000 pid=4540->guuid=0bf80c54-1900-0000-e7f9-cda9c3110000 pid=4547 execve guuid=97333257-1900-0000-e7f9-cda9ce110000 pid=4558 /usr/bin/jwpuuuoraj zombie guuid=0bf80c54-1900-0000-e7f9-cda9c3110000 pid=4547->guuid=97333257-1900-0000-e7f9-cda9ce110000 pid=4558 clone guuid=71ae4680-1a00-0000-e7f9-cda974140000 pid=5236 /usr/bin/cjvtehootr zombie guuid=c5673c80-1a00-0000-e7f9-cda973140000 pid=5235->guuid=71ae4680-1a00-0000-e7f9-cda974140000 pid=5236 execve guuid=b1193383-1a00-0000-e7f9-cda983140000 pid=5251 /usr/bin/cjvtehootr zombie guuid=71ae4680-1a00-0000-e7f9-cda974140000 pid=5236->guuid=b1193383-1a00-0000-e7f9-cda983140000 pid=5251 clone guuid=4f596480-1a00-0000-e7f9-cda976140000 pid=5238 /usr/bin/cjvtehootr zombie guuid=4ea85a80-1a00-0000-e7f9-cda975140000 pid=5237->guuid=4f596480-1a00-0000-e7f9-cda976140000 pid=5238 execve guuid=ad031b85-1a00-0000-e7f9-cda98a140000 pid=5258 /usr/bin/cjvtehootr zombie guuid=4f596480-1a00-0000-e7f9-cda976140000 pid=5238->guuid=ad031b85-1a00-0000-e7f9-cda98a140000 pid=5258 clone guuid=78387d80-1a00-0000-e7f9-cda978140000 pid=5240 /usr/bin/cjvtehootr zombie guuid=294b7680-1a00-0000-e7f9-cda977140000 pid=5239->guuid=78387d80-1a00-0000-e7f9-cda978140000 pid=5240 execve guuid=d3fc3485-1a00-0000-e7f9-cda98b140000 pid=5259 /usr/bin/cjvtehootr zombie guuid=78387d80-1a00-0000-e7f9-cda978140000 pid=5240->guuid=d3fc3485-1a00-0000-e7f9-cda98b140000 pid=5259 clone guuid=6f5bb580-1a00-0000-e7f9-cda97a140000 pid=5242 /usr/bin/cjvtehootr zombie guuid=82fb8a80-1a00-0000-e7f9-cda979140000 pid=5241->guuid=6f5bb580-1a00-0000-e7f9-cda97a140000 pid=5242 execve guuid=8db36685-1a00-0000-e7f9-cda98c140000 pid=5260 /usr/bin/cjvtehootr zombie guuid=6f5bb580-1a00-0000-e7f9-cda97a140000 pid=5242->guuid=8db36685-1a00-0000-e7f9-cda98c140000 pid=5260 clone guuid=3161e080-1a00-0000-e7f9-cda97d140000 pid=5245 /usr/bin/cjvtehootr zombie guuid=5f8cc280-1a00-0000-e7f9-cda97b140000 pid=5243->guuid=3161e080-1a00-0000-e7f9-cda97d140000 pid=5245 execve guuid=cb03a786-1a00-0000-e7f9-cda98f140000 pid=5263 /usr/bin/cjvtehootr zombie guuid=3161e080-1a00-0000-e7f9-cda97d140000 pid=5245->guuid=cb03a786-1a00-0000-e7f9-cda98f140000 pid=5263 clone guuid=02fe56ae-1b00-0000-e7f9-cda9d7140000 pid=5335 /usr/bin/gxnpemnwgl zombie guuid=cf9535ae-1b00-0000-e7f9-cda9d6140000 pid=5334->guuid=02fe56ae-1b00-0000-e7f9-cda9d7140000 pid=5335 execve guuid=e20fa2b5-1b00-0000-e7f9-cda9df140000 pid=5343 /usr/bin/gxnpemnwgl zombie guuid=02fe56ae-1b00-0000-e7f9-cda9d7140000 pid=5335->guuid=e20fa2b5-1b00-0000-e7f9-cda9df140000 pid=5343 clone guuid=a9ddd7ae-1b00-0000-e7f9-cda9d9140000 pid=5337 /usr/bin/gxnpemnwgl zombie guuid=eeac73ae-1b00-0000-e7f9-cda9d8140000 pid=5336->guuid=a9ddd7ae-1b00-0000-e7f9-cda9d9140000 pid=5337 execve guuid=6b24e4b6-1b00-0000-e7f9-cda9e0140000 pid=5344 /usr/bin/gxnpemnwgl zombie guuid=a9ddd7ae-1b00-0000-e7f9-cda9d9140000 pid=5337->guuid=6b24e4b6-1b00-0000-e7f9-cda9e0140000 pid=5344 clone guuid=77e214af-1b00-0000-e7f9-cda9db140000 pid=5339 /usr/bin/gxnpemnwgl zombie guuid=9a6afdae-1b00-0000-e7f9-cda9da140000 pid=5338->guuid=77e214af-1b00-0000-e7f9-cda9db140000 pid=5339 execve guuid=ae95e6bc-1b00-0000-e7f9-cda9e2140000 pid=5346 /usr/bin/gxnpemnwgl zombie guuid=77e214af-1b00-0000-e7f9-cda9db140000 pid=5339->guuid=ae95e6bc-1b00-0000-e7f9-cda9e2140000 pid=5346 clone guuid=9b3821b3-1b00-0000-e7f9-cda9dd140000 pid=5341 /usr/bin/gxnpemnwgl zombie guuid=8cdf2faf-1b00-0000-e7f9-cda9dc140000 pid=5340->guuid=9b3821b3-1b00-0000-e7f9-cda9dd140000 pid=5341 execve guuid=0ce993bf-1b00-0000-e7f9-cda9e4140000 pid=5348 /usr/bin/gxnpemnwgl zombie guuid=9b3821b3-1b00-0000-e7f9-cda9dd140000 pid=5341->guuid=0ce993bf-1b00-0000-e7f9-cda9e4140000 pid=5348 clone guuid=f83248b7-1b00-0000-e7f9-cda9e1140000 pid=5345 /usr/bin/gxnpemnwgl zombie guuid=bb5046b3-1b00-0000-e7f9-cda9de140000 pid=5342->guuid=f83248b7-1b00-0000-e7f9-cda9e1140000 pid=5345 execve guuid=74e85ebd-1b00-0000-e7f9-cda9e3140000 pid=5347 /usr/bin/gxnpemnwgl zombie guuid=f83248b7-1b00-0000-e7f9-cda9e1140000 pid=5345->guuid=74e85ebd-1b00-0000-e7f9-cda9e3140000 pid=5347 clone guuid=af2bdaec-1c00-0000-e7f9-cda906150000 pid=5382 /usr/bin/wocijtvxpf zombie guuid=2de6c3ec-1c00-0000-e7f9-cda905150000 pid=5381->guuid=af2bdaec-1c00-0000-e7f9-cda906150000 pid=5382 execve guuid=48c35cf1-1c00-0000-e7f9-cda910150000 pid=5392 /usr/bin/wocijtvxpf zombie guuid=af2bdaec-1c00-0000-e7f9-cda906150000 pid=5382->guuid=48c35cf1-1c00-0000-e7f9-cda910150000 pid=5392 clone guuid=bf4a02ed-1c00-0000-e7f9-cda908150000 pid=5384 /usr/bin/wocijtvxpf zombie guuid=d188f4ec-1c00-0000-e7f9-cda907150000 pid=5383->guuid=bf4a02ed-1c00-0000-e7f9-cda908150000 pid=5384 execve guuid=111bcdf0-1c00-0000-e7f9-cda90f150000 pid=5391 /usr/bin/wocijtvxpf zombie guuid=bf4a02ed-1c00-0000-e7f9-cda908150000 pid=5384->guuid=111bcdf0-1c00-0000-e7f9-cda90f150000 pid=5391 clone guuid=a59337ed-1c00-0000-e7f9-cda90a150000 pid=5386 /usr/bin/wocijtvxpf zombie guuid=5f5824ed-1c00-0000-e7f9-cda909150000 pid=5385->guuid=a59337ed-1c00-0000-e7f9-cda90a150000 pid=5386 execve guuid=df907af1-1c00-0000-e7f9-cda911150000 pid=5393 /usr/bin/wocijtvxpf zombie guuid=a59337ed-1c00-0000-e7f9-cda90a150000 pid=5386->guuid=df907af1-1c00-0000-e7f9-cda911150000 pid=5393 clone guuid=e71562ed-1c00-0000-e7f9-cda90c150000 pid=5388 /usr/bin/wocijtvxpf zombie guuid=248a54ed-1c00-0000-e7f9-cda90b150000 pid=5387->guuid=e71562ed-1c00-0000-e7f9-cda90c150000 pid=5388 execve guuid=ee89d9f1-1c00-0000-e7f9-cda912150000 pid=5394 /usr/bin/wocijtvxpf zombie guuid=e71562ed-1c00-0000-e7f9-cda90c150000 pid=5388->guuid=ee89d9f1-1c00-0000-e7f9-cda912150000 pid=5394 clone guuid=64c109ee-1c00-0000-e7f9-cda90e150000 pid=5390 /usr/bin/wocijtvxpf zombie guuid=88d479ed-1c00-0000-e7f9-cda90d150000 pid=5389->guuid=64c109ee-1c00-0000-e7f9-cda90e150000 pid=5390 execve guuid=7d0184f2-1c00-0000-e7f9-cda913150000 pid=5395 /usr/bin/wocijtvxpf zombie guuid=64c109ee-1c00-0000-e7f9-cda90e150000 pid=5390->guuid=7d0184f2-1c00-0000-e7f9-cda913150000 pid=5395 clone guuid=49fd7f1a-1e00-0000-e7f9-cda915150000 pid=5397 /usr/bin/efunuuozpi zombie guuid=774e6b1a-1e00-0000-e7f9-cda914150000 pid=5396->guuid=49fd7f1a-1e00-0000-e7f9-cda915150000 pid=5397 execve guuid=8846451e-1e00-0000-e7f9-cda91e150000 pid=5406 /usr/bin/efunuuozpi zombie guuid=49fd7f1a-1e00-0000-e7f9-cda915150000 pid=5397->guuid=8846451e-1e00-0000-e7f9-cda91e150000 pid=5406 clone guuid=7ef8bb1a-1e00-0000-e7f9-cda917150000 pid=5399 /usr/bin/efunuuozpi zombie guuid=419fa01a-1e00-0000-e7f9-cda916150000 pid=5398->guuid=7ef8bb1a-1e00-0000-e7f9-cda917150000 pid=5399 execve guuid=ab6e3d1f-1e00-0000-e7f9-cda91f150000 pid=5407 /usr/bin/efunuuozpi zombie guuid=7ef8bb1a-1e00-0000-e7f9-cda917150000 pid=5399->guuid=ab6e3d1f-1e00-0000-e7f9-cda91f150000 pid=5407 clone guuid=6244fe1a-1e00-0000-e7f9-cda919150000 pid=5401 /usr/bin/efunuuozpi zombie guuid=da4ee01a-1e00-0000-e7f9-cda918150000 pid=5400->guuid=6244fe1a-1e00-0000-e7f9-cda919150000 pid=5401 execve guuid=444c4e1f-1e00-0000-e7f9-cda920150000 pid=5408 /usr/bin/efunuuozpi zombie guuid=6244fe1a-1e00-0000-e7f9-cda919150000 pid=5401->guuid=444c4e1f-1e00-0000-e7f9-cda920150000 pid=5408 clone guuid=9b6c461b-1e00-0000-e7f9-cda91b150000 pid=5403 /usr/bin/efunuuozpi zombie guuid=aa262f1b-1e00-0000-e7f9-cda91a150000 pid=5402->guuid=9b6c461b-1e00-0000-e7f9-cda91b150000 pid=5403 execve guuid=ec8e991f-1e00-0000-e7f9-cda921150000 pid=5409 /usr/bin/efunuuozpi zombie guuid=9b6c461b-1e00-0000-e7f9-cda91b150000 pid=5403->guuid=ec8e991f-1e00-0000-e7f9-cda921150000 pid=5409 clone guuid=2231941b-1e00-0000-e7f9-cda91d150000 pid=5405 /usr/bin/efunuuozpi zombie guuid=8fa9801b-1e00-0000-e7f9-cda91c150000 pid=5404->guuid=2231941b-1e00-0000-e7f9-cda91d150000 pid=5405 execve guuid=1c79ce1f-1e00-0000-e7f9-cda922150000 pid=5410 /usr/bin/efunuuozpi zombie guuid=2231941b-1e00-0000-e7f9-cda91d150000 pid=5405->guuid=1c79ce1f-1e00-0000-e7f9-cda922150000 pid=5410 clone guuid=6ad93448-1f00-0000-e7f9-cda924150000 pid=5412 /usr/bin/itqjuevhlk zombie guuid=d5af1e48-1f00-0000-e7f9-cda923150000 pid=5411->guuid=6ad93448-1f00-0000-e7f9-cda924150000 pid=5412 execve guuid=1894d24c-1f00-0000-e7f9-cda92e150000 pid=5422 /usr/bin/itqjuevhlk zombie guuid=6ad93448-1f00-0000-e7f9-cda924150000 pid=5412->guuid=1894d24c-1f00-0000-e7f9-cda92e150000 pid=5422 clone guuid=7a837448-1f00-0000-e7f9-cda926150000 pid=5414 /usr/bin/itqjuevhlk zombie guuid=6be06348-1f00-0000-e7f9-cda925150000 pid=5413->guuid=7a837448-1f00-0000-e7f9-cda926150000 pid=5414 execve guuid=1972d24c-1f00-0000-e7f9-cda92d150000 pid=5421 /usr/bin/itqjuevhlk zombie guuid=7a837448-1f00-0000-e7f9-cda926150000 pid=5414->guuid=1972d24c-1f00-0000-e7f9-cda92d150000 pid=5421 clone guuid=5ee9a148-1f00-0000-e7f9-cda928150000 pid=5416 /usr/bin/itqjuevhlk zombie guuid=2afe9448-1f00-0000-e7f9-cda927150000 pid=5415->guuid=5ee9a148-1f00-0000-e7f9-cda928150000 pid=5416 execve guuid=3309fd4d-1f00-0000-e7f9-cda930150000 pid=5424 /usr/bin/itqjuevhlk zombie guuid=5ee9a148-1f00-0000-e7f9-cda928150000 pid=5416->guuid=3309fd4d-1f00-0000-e7f9-cda930150000 pid=5424 clone guuid=77c2ce48-1f00-0000-e7f9-cda92a150000 pid=5418 /usr/bin/itqjuevhlk zombie guuid=85f6bd48-1f00-0000-e7f9-cda929150000 pid=5417->guuid=77c2ce48-1f00-0000-e7f9-cda92a150000 pid=5418 execve guuid=0c62604d-1f00-0000-e7f9-cda92f150000 pid=5423 /usr/bin/itqjuevhlk zombie guuid=77c2ce48-1f00-0000-e7f9-cda92a150000 pid=5418->guuid=0c62604d-1f00-0000-e7f9-cda92f150000 pid=5423 clone guuid=b8af7a49-1f00-0000-e7f9-cda92c150000 pid=5420 /usr/bin/itqjuevhlk zombie guuid=ff78e948-1f00-0000-e7f9-cda92b150000 pid=5419->guuid=b8af7a49-1f00-0000-e7f9-cda92c150000 pid=5420 execve guuid=d1e3394e-1f00-0000-e7f9-cda931150000 pid=5425 /usr/bin/itqjuevhlk zombie guuid=b8af7a49-1f00-0000-e7f9-cda92c150000 pid=5420->guuid=d1e3394e-1f00-0000-e7f9-cda931150000 pid=5425 clone guuid=064f2c77-2000-0000-e7f9-cda933150000 pid=5427 /usr/bin/mfcjibhaav zombie guuid=f9c61d77-2000-0000-e7f9-cda932150000 pid=5426->guuid=064f2c77-2000-0000-e7f9-cda933150000 pid=5427 execve guuid=bb57137b-2000-0000-e7f9-cda93e150000 pid=5438 /usr/bin/mfcjibhaav zombie guuid=064f2c77-2000-0000-e7f9-cda933150000 pid=5427->guuid=bb57137b-2000-0000-e7f9-cda93e150000 pid=5438 clone guuid=bab55677-2000-0000-e7f9-cda935150000 pid=5429 /usr/bin/mfcjibhaav zombie guuid=30924977-2000-0000-e7f9-cda934150000 pid=5428->guuid=bab55677-2000-0000-e7f9-cda935150000 pid=5429 execve guuid=9d64687a-2000-0000-e7f9-cda93d150000 pid=5437 /usr/bin/mfcjibhaav zombie guuid=bab55677-2000-0000-e7f9-cda935150000 pid=5429->guuid=9d64687a-2000-0000-e7f9-cda93d150000 pid=5437 clone guuid=ce657677-2000-0000-e7f9-cda937150000 pid=5431 /usr/bin/mfcjibhaav zombie guuid=8b2e6d77-2000-0000-e7f9-cda936150000 pid=5430->guuid=ce657677-2000-0000-e7f9-cda937150000 pid=5431 execve guuid=6274627b-2000-0000-e7f9-cda93f150000 pid=5439 /usr/bin/mfcjibhaav zombie guuid=ce657677-2000-0000-e7f9-cda937150000 pid=5431->guuid=6274627b-2000-0000-e7f9-cda93f150000 pid=5439 clone guuid=613f9277-2000-0000-e7f9-cda939150000 pid=5433 /usr/bin/mfcjibhaav zombie guuid=6f9c8877-2000-0000-e7f9-cda938150000 pid=5432->guuid=613f9277-2000-0000-e7f9-cda939150000 pid=5433 execve guuid=5ca7447a-2000-0000-e7f9-cda93c150000 pid=5436 /usr/bin/mfcjibhaav zombie guuid=613f9277-2000-0000-e7f9-cda939150000 pid=5433->guuid=5ca7447a-2000-0000-e7f9-cda93c150000 pid=5436 clone guuid=4e5d7b78-2000-0000-e7f9-cda93b150000 pid=5435 /usr/bin/mfcjibhaav zombie guuid=6c33a177-2000-0000-e7f9-cda93a150000 pid=5434->guuid=4e5d7b78-2000-0000-e7f9-cda93b150000 pid=5435 execve guuid=a868ca7b-2000-0000-e7f9-cda940150000 pid=5440 /usr/bin/mfcjibhaav zombie guuid=4e5d7b78-2000-0000-e7f9-cda93b150000 pid=5435->guuid=a868ca7b-2000-0000-e7f9-cda940150000 pid=5440 clone guuid=286442a5-2100-0000-e7f9-cda942150000 pid=5442 /usr/bin/nwgkklsvmn zombie guuid=972a33a5-2100-0000-e7f9-cda941150000 pid=5441->guuid=286442a5-2100-0000-e7f9-cda942150000 pid=5442 execve guuid=1fc7bfa9-2100-0000-e7f9-cda94d150000 pid=5453 /usr/bin/nwgkklsvmn zombie guuid=286442a5-2100-0000-e7f9-cda942150000 pid=5442->guuid=1fc7bfa9-2100-0000-e7f9-cda94d150000 pid=5453 clone guuid=077f77a5-2100-0000-e7f9-cda944150000 pid=5444 /usr/bin/nwgkklsvmn zombie guuid=2ff565a5-2100-0000-e7f9-cda943150000 pid=5443->guuid=077f77a5-2100-0000-e7f9-cda944150000 pid=5444 execve guuid=caaa64aa-2100-0000-e7f9-cda94e150000 pid=5454 /usr/bin/nwgkklsvmn zombie guuid=077f77a5-2100-0000-e7f9-cda944150000 pid=5444->guuid=caaa64aa-2100-0000-e7f9-cda94e150000 pid=5454 clone guuid=a54aa9a5-2100-0000-e7f9-cda946150000 pid=5446 /usr/bin/nwgkklsvmn zombie guuid=a5729aa5-2100-0000-e7f9-cda945150000 pid=5445->guuid=a54aa9a5-2100-0000-e7f9-cda946150000 pid=5446 execve guuid=1e7384a9-2100-0000-e7f9-cda94b150000 pid=5451 /usr/bin/nwgkklsvmn zombie guuid=a54aa9a5-2100-0000-e7f9-cda946150000 pid=5446->guuid=1e7384a9-2100-0000-e7f9-cda94b150000 pid=5451 clone guuid=986fd9a5-2100-0000-e7f9-cda948150000 pid=5448 /usr/bin/nwgkklsvmn zombie guuid=762ec4a5-2100-0000-e7f9-cda947150000 pid=5447->guuid=986fd9a5-2100-0000-e7f9-cda948150000 pid=5448 execve guuid=1c6b2bab-2100-0000-e7f9-cda94f150000 pid=5455 /usr/bin/nwgkklsvmn zombie guuid=986fd9a5-2100-0000-e7f9-cda948150000 pid=5448->guuid=1c6b2bab-2100-0000-e7f9-cda94f150000 pid=5455 clone guuid=f40f04a6-2100-0000-e7f9-cda94a150000 pid=5450 /usr/bin/nwgkklsvmn zombie guuid=5357f2a5-2100-0000-e7f9-cda949150000 pid=5449->guuid=f40f04a6-2100-0000-e7f9-cda94a150000 pid=5450 execve guuid=a4caa3a9-2100-0000-e7f9-cda94c150000 pid=5452 /usr/bin/nwgkklsvmn zombie guuid=f40f04a6-2100-0000-e7f9-cda94a150000 pid=5450->guuid=a4caa3a9-2100-0000-e7f9-cda94c150000 pid=5452 clone guuid=3bb6a5dd-2200-0000-e7f9-cda951150000 pid=5457 /usr/bin/zokkbxhbfg zombie guuid=0a2391dd-2200-0000-e7f9-cda950150000 pid=5456->guuid=3bb6a5dd-2200-0000-e7f9-cda951150000 pid=5457 execve guuid=2e0029e2-2200-0000-e7f9-cda95a150000 pid=5466 /usr/bin/zokkbxhbfg zombie guuid=3bb6a5dd-2200-0000-e7f9-cda951150000 pid=5457->guuid=2e0029e2-2200-0000-e7f9-cda95a150000 pid=5466 clone guuid=8484dadd-2200-0000-e7f9-cda953150000 pid=5459 /usr/bin/zokkbxhbfg zombie guuid=f7aacadd-2200-0000-e7f9-cda952150000 pid=5458->guuid=8484dadd-2200-0000-e7f9-cda953150000 pid=5459 execve guuid=1a7c8be2-2200-0000-e7f9-cda95b150000 pid=5467 /usr/bin/zokkbxhbfg zombie guuid=8484dadd-2200-0000-e7f9-cda953150000 pid=5459->guuid=1a7c8be2-2200-0000-e7f9-cda95b150000 pid=5467 clone guuid=f3330cde-2200-0000-e7f9-cda955150000 pid=5461 /usr/bin/zokkbxhbfg zombie guuid=9370fddd-2200-0000-e7f9-cda954150000 pid=5460->guuid=f3330cde-2200-0000-e7f9-cda955150000 pid=5461 execve guuid=d34d59e3-2200-0000-e7f9-cda95d150000 pid=5469 /usr/bin/zokkbxhbfg zombie guuid=f3330cde-2200-0000-e7f9-cda955150000 pid=5461->guuid=d34d59e3-2200-0000-e7f9-cda95d150000 pid=5469 clone guuid=fdcb39de-2200-0000-e7f9-cda957150000 pid=5463 /usr/bin/zokkbxhbfg zombie guuid=f36226de-2200-0000-e7f9-cda956150000 pid=5462->guuid=fdcb39de-2200-0000-e7f9-cda957150000 pid=5463 execve guuid=8ea9c8e2-2200-0000-e7f9-cda95c150000 pid=5468 /usr/bin/zokkbxhbfg zombie guuid=fdcb39de-2200-0000-e7f9-cda957150000 pid=5463->guuid=8ea9c8e2-2200-0000-e7f9-cda95c150000 pid=5468 clone guuid=a2adeade-2200-0000-e7f9-cda959150000 pid=5465 /usr/bin/zokkbxhbfg zombie guuid=271750de-2200-0000-e7f9-cda958150000 pid=5464->guuid=a2adeade-2200-0000-e7f9-cda959150000 pid=5465 execve guuid=985225e4-2200-0000-e7f9-cda95e150000 pid=5470 /usr/bin/zokkbxhbfg zombie guuid=a2adeade-2200-0000-e7f9-cda959150000 pid=5465->guuid=985225e4-2200-0000-e7f9-cda95e150000 pid=5470 clone guuid=5862de14-2400-0000-e7f9-cda960150000 pid=5472 /usr/bin/yshfjoxeba zombie guuid=777dcc14-2400-0000-e7f9-cda95f150000 pid=5471->guuid=5862de14-2400-0000-e7f9-cda960150000 pid=5472 execve guuid=daa1eb18-2400-0000-e7f9-cda969150000 pid=5481 /usr/bin/yshfjoxeba zombie guuid=5862de14-2400-0000-e7f9-cda960150000 pid=5472->guuid=daa1eb18-2400-0000-e7f9-cda969150000 pid=5481 clone guuid=87ad1315-2400-0000-e7f9-cda962150000 pid=5474 /usr/bin/yshfjoxeba zombie guuid=b6cffe14-2400-0000-e7f9-cda961150000 pid=5473->guuid=87ad1315-2400-0000-e7f9-cda962150000 pid=5474 execve guuid=4c0ef518-2400-0000-e7f9-cda96a150000 pid=5482 /usr/bin/yshfjoxeba zombie guuid=87ad1315-2400-0000-e7f9-cda962150000 pid=5474->guuid=4c0ef518-2400-0000-e7f9-cda96a150000 pid=5482 clone guuid=83e33a15-2400-0000-e7f9-cda964150000 pid=5476 /usr/bin/yshfjoxeba zombie guuid=35ea2f15-2400-0000-e7f9-cda963150000 pid=5475->guuid=83e33a15-2400-0000-e7f9-cda964150000 pid=5476 execve guuid=e5a9491a-2400-0000-e7f9-cda96c150000 pid=5484 /usr/bin/yshfjoxeba zombie guuid=83e33a15-2400-0000-e7f9-cda964150000 pid=5476->guuid=e5a9491a-2400-0000-e7f9-cda96c150000 pid=5484 clone guuid=35a46015-2400-0000-e7f9-cda966150000 pid=5478 /usr/bin/yshfjoxeba zombie guuid=28b35415-2400-0000-e7f9-cda965150000 pid=5477->guuid=35a46015-2400-0000-e7f9-cda966150000 pid=5478 execve guuid=17e1341a-2400-0000-e7f9-cda96b150000 pid=5483 /usr/bin/yshfjoxeba zombie guuid=35a46015-2400-0000-e7f9-cda966150000 pid=5478->guuid=17e1341a-2400-0000-e7f9-cda96b150000 pid=5483 clone guuid=06531716-2400-0000-e7f9-cda968150000 pid=5480 /usr/bin/yshfjoxeba zombie guuid=412b7615-2400-0000-e7f9-cda967150000 pid=5479->guuid=06531716-2400-0000-e7f9-cda968150000 pid=5480 execve guuid=1331e51a-2400-0000-e7f9-cda96d150000 pid=5485 /usr/bin/yshfjoxeba zombie guuid=06531716-2400-0000-e7f9-cda968150000 pid=5480->guuid=1331e51a-2400-0000-e7f9-cda96d150000 pid=5485 clone
Threat name:
Script.Trojan.Multiverze
Status:
Malicious
First seen:
2025-09-04 09:09:52 UTC
File Type:
Text (Shell)
AV detection:
9 of 24 (37.50%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

XorDDoS

sh 007dd96c39a9136151071b5a3bc52956a9842c5dc1e7d3f7e98eecc3b76d520e

(this sample)

  
Delivery method
Distributed via web download

Comments