MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 09898756f3e900900093fe4890680734f41ece38362912f4da2a3994a12a833e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



XorDDoS


Vendor detections: 10


Intelligence 10 IOCs YARA 9 File information Comments

SHA256 hash: 09898756f3e900900093fe4890680734f41ece38362912f4da2a3994a12a833e
SHA3-384 hash: 5a795f30d4d2daf71a97c850463163d09b5122b0632403de87d949663fafc4043962926d80ca167d8d5ae0dc80081af9
SHA1 hash: 951e404d13747f567bd8d81d9170b832f64b28ce
MD5 hash: a3bb9946d21a1e3a9eaebc752d0e0db7
humanhash: tennessee-video-uncle-johnny
File name:p.txt
Download: download sample
Signature XorDDoS
File size:548'616 bytes
First seen:2025-08-22 05:53:09 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 12288:4Ufrcn+vwK5ripVU4tdZ1pNL/pVbzf66ySjQn36Eoj:/fUywKQ7Fb1pNL/p5ffjQn36Eu
TLSH T1A4C45C56E383E2F7C82705B0134BF7BF4620B6359461CD86B7989D5AB9338F22A4D352
telfhash t12ab138722e7558f8b7f08402425a7620ce39e027259439b71ef2b454f7f2c429b6ad7a
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter abuse_ch
Tags:elf XorDDoS

Intelligence


File Origin
# of uploads :
1
# of downloads :
35
Origin country :
DE DE
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Collects information on the RAM
Collects information on the CPU
Runs as daemon
Changes owner for a written file
Receives data from a server
Launching a process
Creating a process from a recently created file
DNS request
Manages services
Creating a file
Sends data to a server
Connection attempt
Collects information on the network activity
Deletes a system binary file
Creates or modifies files in /cron to set up autorun
Writes files to system directory
Deleting of the original file
Creates or modifies files in /init.d to set up autorun
Creates or modifies symbolic links in /init.d to set up autorun
Verdict:
Unknown
Threat level:
  0/10
Confidence:
100%
Tags:
gcc threat
Status:
terminated
Behavior Graph:
%3 guuid=749f0db6-1b00-0000-5e99-e0a69e0c0000 pid=3230 /usr/bin/sudo guuid=d273c7b7-1b00-0000-5e99-e0a6a00c0000 pid=3232 /tmp/sample.bin guuid=749f0db6-1b00-0000-5e99-e0a69e0c0000 pid=3230->guuid=d273c7b7-1b00-0000-5e99-e0a6a00c0000 pid=3232 execve guuid=8fc1f8b7-1b00-0000-5e99-e0a6a10c0000 pid=3233 /tmp/sample.bin delete-file write-config write-file zombie guuid=d273c7b7-1b00-0000-5e99-e0a6a00c0000 pid=3232->guuid=8fc1f8b7-1b00-0000-5e99-e0a6a10c0000 pid=3233 clone guuid=50a552b8-1b00-0000-5e99-e0a6a20c0000 pid=3234 /tmp/sample.bin guuid=8fc1f8b7-1b00-0000-5e99-e0a6a10c0000 pid=3233->guuid=50a552b8-1b00-0000-5e99-e0a6a20c0000 pid=3234 clone guuid=ce4860b8-1b00-0000-5e99-e0a6a40c0000 pid=3236 /tmp/sample.bin guuid=8fc1f8b7-1b00-0000-5e99-e0a6a10c0000 pid=3233->guuid=ce4860b8-1b00-0000-5e99-e0a6a40c0000 pid=3236 clone guuid=4a59bab8-1b00-0000-5e99-e0a6a60c0000 pid=3238 /usr/bin/dash guuid=8fc1f8b7-1b00-0000-5e99-e0a6a10c0000 pid=3233->guuid=4a59bab8-1b00-0000-5e99-e0a6a60c0000 pid=3238 execve guuid=8fc1f8b7-1b00-0000-5e99-e0a6a10c0000 pid=3241 /tmp/sample.bin write-file zombie guuid=8fc1f8b7-1b00-0000-5e99-e0a6a10c0000 pid=3233->guuid=8fc1f8b7-1b00-0000-5e99-e0a6a10c0000 pid=3241 clone guuid=8fc1f8b7-1b00-0000-5e99-e0a6a10c0000 pid=3242 /tmp/sample.bin dns net send-data write-file zombie guuid=8fc1f8b7-1b00-0000-5e99-e0a6a10c0000 pid=3233->guuid=8fc1f8b7-1b00-0000-5e99-e0a6a10c0000 pid=3242 clone guuid=8fc1f8b7-1b00-0000-5e99-e0a6a10c0000 pid=3243 /tmp/sample.bin net zombie guuid=8fc1f8b7-1b00-0000-5e99-e0a6a10c0000 pid=3233->guuid=8fc1f8b7-1b00-0000-5e99-e0a6a10c0000 pid=3243 clone guuid=d37e1ee6-1c00-0000-5e99-e0a6510f0000 pid=3921 /tmp/sample.bin guuid=8fc1f8b7-1b00-0000-5e99-e0a6a10c0000 pid=3233->guuid=d37e1ee6-1c00-0000-5e99-e0a6510f0000 pid=3921 clone guuid=e18a48e6-1c00-0000-5e99-e0a6550f0000 pid=3925 /tmp/sample.bin guuid=8fc1f8b7-1b00-0000-5e99-e0a6a10c0000 pid=3233->guuid=e18a48e6-1c00-0000-5e99-e0a6550f0000 pid=3925 clone guuid=a6b46be6-1c00-0000-5e99-e0a6580f0000 pid=3928 /tmp/sample.bin guuid=8fc1f8b7-1b00-0000-5e99-e0a6a10c0000 pid=3233->guuid=a6b46be6-1c00-0000-5e99-e0a6580f0000 pid=3928 clone guuid=687981e6-1c00-0000-5e99-e0a65a0f0000 pid=3930 /tmp/sample.bin guuid=8fc1f8b7-1b00-0000-5e99-e0a6a10c0000 pid=3233->guuid=687981e6-1c00-0000-5e99-e0a65a0f0000 pid=3930 clone guuid=96ada7e7-1c00-0000-5e99-e0a65e0f0000 pid=3934 /tmp/sample.bin guuid=8fc1f8b7-1b00-0000-5e99-e0a6a10c0000 pid=3233->guuid=96ada7e7-1c00-0000-5e99-e0a65e0f0000 pid=3934 clone guuid=b6e74314-1e00-0000-5e99-e0a6f8120000 pid=4856 /tmp/sample.bin guuid=8fc1f8b7-1b00-0000-5e99-e0a6a10c0000 pid=3233->guuid=b6e74314-1e00-0000-5e99-e0a6f8120000 pid=4856 clone guuid=5af28314-1e00-0000-5e99-e0a6fb120000 pid=4859 /tmp/sample.bin guuid=8fc1f8b7-1b00-0000-5e99-e0a6a10c0000 pid=3233->guuid=5af28314-1e00-0000-5e99-e0a6fb120000 pid=4859 clone guuid=01c2b514-1e00-0000-5e99-e0a6fd120000 pid=4861 /tmp/sample.bin guuid=8fc1f8b7-1b00-0000-5e99-e0a6a10c0000 pid=3233->guuid=01c2b514-1e00-0000-5e99-e0a6fd120000 pid=4861 clone guuid=2ccc9515-1e00-0000-5e99-e0a603130000 pid=4867 /tmp/sample.bin guuid=8fc1f8b7-1b00-0000-5e99-e0a6a10c0000 pid=3233->guuid=2ccc9515-1e00-0000-5e99-e0a603130000 pid=4867 clone guuid=7594ed15-1e00-0000-5e99-e0a606130000 pid=4870 /tmp/sample.bin guuid=8fc1f8b7-1b00-0000-5e99-e0a6a10c0000 pid=3233->guuid=7594ed15-1e00-0000-5e99-e0a606130000 pid=4870 clone guuid=26ca4c42-1f00-0000-5e99-e0a6ab140000 pid=5291 /tmp/sample.bin guuid=8fc1f8b7-1b00-0000-5e99-e0a6a10c0000 pid=3233->guuid=26ca4c42-1f00-0000-5e99-e0a6ab140000 pid=5291 clone guuid=45469342-1f00-0000-5e99-e0a6ad140000 pid=5293 /tmp/sample.bin guuid=8fc1f8b7-1b00-0000-5e99-e0a6a10c0000 pid=3233->guuid=45469342-1f00-0000-5e99-e0a6ad140000 pid=5293 clone guuid=5ca1ce42-1f00-0000-5e99-e0a6af140000 pid=5295 /tmp/sample.bin guuid=8fc1f8b7-1b00-0000-5e99-e0a6a10c0000 pid=3233->guuid=5ca1ce42-1f00-0000-5e99-e0a6af140000 pid=5295 clone guuid=aa110c43-1f00-0000-5e99-e0a6b1140000 pid=5297 /tmp/sample.bin guuid=8fc1f8b7-1b00-0000-5e99-e0a6a10c0000 pid=3233->guuid=aa110c43-1f00-0000-5e99-e0a6b1140000 pid=5297 clone guuid=66421b44-1f00-0000-5e99-e0a6b3140000 pid=5299 /tmp/sample.bin guuid=8fc1f8b7-1b00-0000-5e99-e0a6a10c0000 pid=3233->guuid=66421b44-1f00-0000-5e99-e0a6b3140000 pid=5299 clone guuid=a8865f70-2000-0000-5e99-e0a6c2140000 pid=5314 /tmp/sample.bin guuid=8fc1f8b7-1b00-0000-5e99-e0a6a10c0000 pid=3233->guuid=a8865f70-2000-0000-5e99-e0a6c2140000 pid=5314 clone guuid=b6ee7b70-2000-0000-5e99-e0a6c4140000 pid=5316 /tmp/sample.bin guuid=8fc1f8b7-1b00-0000-5e99-e0a6a10c0000 pid=3233->guuid=b6ee7b70-2000-0000-5e99-e0a6c4140000 pid=5316 clone guuid=31899b70-2000-0000-5e99-e0a6c6140000 pid=5318 /tmp/sample.bin guuid=8fc1f8b7-1b00-0000-5e99-e0a6a10c0000 pid=3233->guuid=31899b70-2000-0000-5e99-e0a6c6140000 pid=5318 clone guuid=d134b070-2000-0000-5e99-e0a6c8140000 pid=5320 /tmp/sample.bin guuid=8fc1f8b7-1b00-0000-5e99-e0a6a10c0000 pid=3233->guuid=d134b070-2000-0000-5e99-e0a6c8140000 pid=5320 clone guuid=d907ec70-2000-0000-5e99-e0a6ca140000 pid=5322 /tmp/sample.bin guuid=8fc1f8b7-1b00-0000-5e99-e0a6a10c0000 pid=3233->guuid=d907ec70-2000-0000-5e99-e0a6ca140000 pid=5322 clone guuid=08b8b19d-2100-0000-5e99-e0a6f0140000 pid=5360 /tmp/sample.bin guuid=8fc1f8b7-1b00-0000-5e99-e0a6a10c0000 pid=3233->guuid=08b8b19d-2100-0000-5e99-e0a6f0140000 pid=5360 clone guuid=73d7ed9d-2100-0000-5e99-e0a6f2140000 pid=5362 /tmp/sample.bin guuid=8fc1f8b7-1b00-0000-5e99-e0a6a10c0000 pid=3233->guuid=73d7ed9d-2100-0000-5e99-e0a6f2140000 pid=5362 clone guuid=bd4e2a9e-2100-0000-5e99-e0a6f4140000 pid=5364 /tmp/sample.bin guuid=8fc1f8b7-1b00-0000-5e99-e0a6a10c0000 pid=3233->guuid=bd4e2a9e-2100-0000-5e99-e0a6f4140000 pid=5364 clone guuid=bbf4579e-2100-0000-5e99-e0a6f6140000 pid=5366 /tmp/sample.bin guuid=8fc1f8b7-1b00-0000-5e99-e0a6a10c0000 pid=3233->guuid=bbf4579e-2100-0000-5e99-e0a6f6140000 pid=5366 clone guuid=5a317e9e-2100-0000-5e99-e0a6f8140000 pid=5368 /tmp/sample.bin guuid=8fc1f8b7-1b00-0000-5e99-e0a6a10c0000 pid=3233->guuid=5a317e9e-2100-0000-5e99-e0a6f8140000 pid=5368 clone guuid=902adccb-2200-0000-5e99-e0a6ff140000 pid=5375 /tmp/sample.bin guuid=8fc1f8b7-1b00-0000-5e99-e0a6a10c0000 pid=3233->guuid=902adccb-2200-0000-5e99-e0a6ff140000 pid=5375 clone guuid=d97411cc-2200-0000-5e99-e0a601150000 pid=5377 /tmp/sample.bin guuid=8fc1f8b7-1b00-0000-5e99-e0a6a10c0000 pid=3233->guuid=d97411cc-2200-0000-5e99-e0a601150000 pid=5377 clone guuid=aa2c3fcc-2200-0000-5e99-e0a603150000 pid=5379 /tmp/sample.bin guuid=8fc1f8b7-1b00-0000-5e99-e0a6a10c0000 pid=3233->guuid=aa2c3fcc-2200-0000-5e99-e0a603150000 pid=5379 clone guuid=3b266acc-2200-0000-5e99-e0a605150000 pid=5381 /tmp/sample.bin guuid=8fc1f8b7-1b00-0000-5e99-e0a6a10c0000 pid=3233->guuid=3b266acc-2200-0000-5e99-e0a605150000 pid=5381 clone guuid=e36998cc-2200-0000-5e99-e0a607150000 pid=5383 /tmp/sample.bin guuid=8fc1f8b7-1b00-0000-5e99-e0a6a10c0000 pid=3233->guuid=e36998cc-2200-0000-5e99-e0a607150000 pid=5383 clone guuid=884d96f8-2300-0000-5e99-e0a60e150000 pid=5390 /tmp/sample.bin guuid=8fc1f8b7-1b00-0000-5e99-e0a6a10c0000 pid=3233->guuid=884d96f8-2300-0000-5e99-e0a60e150000 pid=5390 clone guuid=bb55c2f8-2300-0000-5e99-e0a610150000 pid=5392 /tmp/sample.bin guuid=8fc1f8b7-1b00-0000-5e99-e0a6a10c0000 pid=3233->guuid=bb55c2f8-2300-0000-5e99-e0a610150000 pid=5392 clone guuid=297ff3f8-2300-0000-5e99-e0a612150000 pid=5394 /tmp/sample.bin guuid=8fc1f8b7-1b00-0000-5e99-e0a6a10c0000 pid=3233->guuid=297ff3f8-2300-0000-5e99-e0a612150000 pid=5394 clone guuid=727d1af9-2300-0000-5e99-e0a614150000 pid=5396 /tmp/sample.bin guuid=8fc1f8b7-1b00-0000-5e99-e0a6a10c0000 pid=3233->guuid=727d1af9-2300-0000-5e99-e0a614150000 pid=5396 clone guuid=517640f9-2300-0000-5e99-e0a616150000 pid=5398 /tmp/sample.bin guuid=8fc1f8b7-1b00-0000-5e99-e0a6a10c0000 pid=3233->guuid=517640f9-2300-0000-5e99-e0a616150000 pid=5398 clone guuid=31316e26-2500-0000-5e99-e0a61d150000 pid=5405 /tmp/sample.bin guuid=8fc1f8b7-1b00-0000-5e99-e0a6a10c0000 pid=3233->guuid=31316e26-2500-0000-5e99-e0a61d150000 pid=5405 clone guuid=182d9b26-2500-0000-5e99-e0a61f150000 pid=5407 /tmp/sample.bin guuid=8fc1f8b7-1b00-0000-5e99-e0a6a10c0000 pid=3233->guuid=182d9b26-2500-0000-5e99-e0a61f150000 pid=5407 clone guuid=7f8acd26-2500-0000-5e99-e0a621150000 pid=5409 /tmp/sample.bin guuid=8fc1f8b7-1b00-0000-5e99-e0a6a10c0000 pid=3233->guuid=7f8acd26-2500-0000-5e99-e0a621150000 pid=5409 clone guuid=0c84f426-2500-0000-5e99-e0a623150000 pid=5411 /tmp/sample.bin guuid=8fc1f8b7-1b00-0000-5e99-e0a6a10c0000 pid=3233->guuid=0c84f426-2500-0000-5e99-e0a623150000 pid=5411 clone guuid=d7a91e27-2500-0000-5e99-e0a625150000 pid=5413 /tmp/sample.bin guuid=8fc1f8b7-1b00-0000-5e99-e0a6a10c0000 pid=3233->guuid=d7a91e27-2500-0000-5e99-e0a625150000 pid=5413 clone guuid=99ac3d54-2600-0000-5e99-e0a62c150000 pid=5420 /tmp/sample.bin guuid=8fc1f8b7-1b00-0000-5e99-e0a6a10c0000 pid=3233->guuid=99ac3d54-2600-0000-5e99-e0a62c150000 pid=5420 clone guuid=7c847f54-2600-0000-5e99-e0a62e150000 pid=5422 /tmp/sample.bin guuid=8fc1f8b7-1b00-0000-5e99-e0a6a10c0000 pid=3233->guuid=7c847f54-2600-0000-5e99-e0a62e150000 pid=5422 clone guuid=220fb754-2600-0000-5e99-e0a630150000 pid=5424 /tmp/sample.bin guuid=8fc1f8b7-1b00-0000-5e99-e0a6a10c0000 pid=3233->guuid=220fb754-2600-0000-5e99-e0a630150000 pid=5424 clone guuid=5009e754-2600-0000-5e99-e0a632150000 pid=5426 /tmp/sample.bin guuid=8fc1f8b7-1b00-0000-5e99-e0a6a10c0000 pid=3233->guuid=5009e754-2600-0000-5e99-e0a632150000 pid=5426 clone guuid=0a420855-2600-0000-5e99-e0a634150000 pid=5428 /tmp/sample.bin guuid=8fc1f8b7-1b00-0000-5e99-e0a6a10c0000 pid=3233->guuid=0a420855-2600-0000-5e99-e0a634150000 pid=5428 clone guuid=aaea1e81-2700-0000-5e99-e0a63b150000 pid=5435 /tmp/sample.bin guuid=8fc1f8b7-1b00-0000-5e99-e0a6a10c0000 pid=3233->guuid=aaea1e81-2700-0000-5e99-e0a63b150000 pid=5435 clone guuid=8f213981-2700-0000-5e99-e0a63d150000 pid=5437 /tmp/sample.bin guuid=8fc1f8b7-1b00-0000-5e99-e0a6a10c0000 pid=3233->guuid=8f213981-2700-0000-5e99-e0a63d150000 pid=5437 clone guuid=f3175a81-2700-0000-5e99-e0a63f150000 pid=5439 /tmp/sample.bin guuid=8fc1f8b7-1b00-0000-5e99-e0a6a10c0000 pid=3233->guuid=f3175a81-2700-0000-5e99-e0a63f150000 pid=5439 clone guuid=7ea86e81-2700-0000-5e99-e0a641150000 pid=5441 /tmp/sample.bin guuid=8fc1f8b7-1b00-0000-5e99-e0a6a10c0000 pid=3233->guuid=7ea86e81-2700-0000-5e99-e0a641150000 pid=5441 clone guuid=d02d8181-2700-0000-5e99-e0a643150000 pid=5443 /tmp/sample.bin guuid=8fc1f8b7-1b00-0000-5e99-e0a6a10c0000 pid=3233->guuid=d02d8181-2700-0000-5e99-e0a643150000 pid=5443 clone guuid=3986ddae-2800-0000-5e99-e0a64a150000 pid=5450 /tmp/sample.bin guuid=8fc1f8b7-1b00-0000-5e99-e0a6a10c0000 pid=3233->guuid=3986ddae-2800-0000-5e99-e0a64a150000 pid=5450 clone guuid=e5f6ffae-2800-0000-5e99-e0a64c150000 pid=5452 /tmp/sample.bin guuid=8fc1f8b7-1b00-0000-5e99-e0a6a10c0000 pid=3233->guuid=e5f6ffae-2800-0000-5e99-e0a64c150000 pid=5452 clone guuid=0a5225af-2800-0000-5e99-e0a64e150000 pid=5454 /tmp/sample.bin guuid=8fc1f8b7-1b00-0000-5e99-e0a6a10c0000 pid=3233->guuid=0a5225af-2800-0000-5e99-e0a64e150000 pid=5454 clone guuid=5d3f3baf-2800-0000-5e99-e0a650150000 pid=5456 /tmp/sample.bin guuid=8fc1f8b7-1b00-0000-5e99-e0a6a10c0000 pid=3233->guuid=5d3f3baf-2800-0000-5e99-e0a650150000 pid=5456 clone guuid=2d8e4caf-2800-0000-5e99-e0a652150000 pid=5458 /tmp/sample.bin guuid=8fc1f8b7-1b00-0000-5e99-e0a6a10c0000 pid=3233->guuid=2d8e4caf-2800-0000-5e99-e0a652150000 pid=5458 clone guuid=acb004db-2900-0000-5e99-e0a663150000 pid=5475 /tmp/sample.bin guuid=8fc1f8b7-1b00-0000-5e99-e0a6a10c0000 pid=3233->guuid=acb004db-2900-0000-5e99-e0a663150000 pid=5475 clone guuid=89a81fdb-2900-0000-5e99-e0a665150000 pid=5477 /tmp/sample.bin guuid=8fc1f8b7-1b00-0000-5e99-e0a6a10c0000 pid=3233->guuid=89a81fdb-2900-0000-5e99-e0a665150000 pid=5477 clone guuid=19b138db-2900-0000-5e99-e0a667150000 pid=5479 /tmp/sample.bin guuid=8fc1f8b7-1b00-0000-5e99-e0a6a10c0000 pid=3233->guuid=19b138db-2900-0000-5e99-e0a667150000 pid=5479 clone guuid=254b4edb-2900-0000-5e99-e0a669150000 pid=5481 /tmp/sample.bin guuid=8fc1f8b7-1b00-0000-5e99-e0a6a10c0000 pid=3233->guuid=254b4edb-2900-0000-5e99-e0a669150000 pid=5481 clone guuid=2bcc60db-2900-0000-5e99-e0a66b150000 pid=5483 /tmp/sample.bin guuid=8fc1f8b7-1b00-0000-5e99-e0a6a10c0000 pid=3233->guuid=2bcc60db-2900-0000-5e99-e0a66b150000 pid=5483 clone guuid=41dc58b8-1b00-0000-5e99-e0a6a30c0000 pid=3235 /tmp/sample.bin guuid=50a552b8-1b00-0000-5e99-e0a6a20c0000 pid=3234->guuid=41dc58b8-1b00-0000-5e99-e0a6a30c0000 pid=3235 clone guuid=3c8581b8-1b00-0000-5e99-e0a6a50c0000 pid=3237 /usr/sbin/update-rc.d zombie guuid=ce4860b8-1b00-0000-5e99-e0a6a40c0000 pid=3236->guuid=3c8581b8-1b00-0000-5e99-e0a6a50c0000 pid=3237 execve guuid=f7f506c2-1b00-0000-5e99-e0a6b10c0000 pid=3249 /usr/bin/systemctl guuid=3c8581b8-1b00-0000-5e99-e0a6a50c0000 pid=3237->guuid=f7f506c2-1b00-0000-5e99-e0a6b10c0000 pid=3249 execve guuid=eace3eb9-1b00-0000-5e99-e0a6a70c0000 pid=3239 /usr/bin/sed guuid=4a59bab8-1b00-0000-5e99-e0a6a60c0000 pid=3238->guuid=eace3eb9-1b00-0000-5e99-e0a6a70c0000 pid=3239 execve c68d1fe9-5408-5c6b-aaca-7f7052cd4748 0.0.0.0:1526 guuid=8fc1f8b7-1b00-0000-5e99-e0a6a10c0000 pid=3242->c68d1fe9-5408-5c6b-aaca-7f7052cd4748 con 14b982e0-9390-5251-8c19-7fc0b951ace2 jj.vvbb321.com:1526 guuid=8fc1f8b7-1b00-0000-5e99-e0a6a10c0000 pid=3242->14b982e0-9390-5251-8c19-7fc0b951ace2 send: 4548B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=8fc1f8b7-1b00-0000-5e99-e0a6a10c0000 pid=3242->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 96B b4bf20d4-f7c8-5c24-8830-c23364537aa4 8.8.4.4:53 guuid=8fc1f8b7-1b00-0000-5e99-e0a6a10c0000 pid=3242->b4bf20d4-f7c8-5c24-8830-c23364537aa4 send: 64B 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=8fc1f8b7-1b00-0000-5e99-e0a6a10c0000 pid=3242->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 64B 87f248b3-21f7-50eb-a2c7-cb35eca5cc17 0.0.0.0:80 guuid=8fc1f8b7-1b00-0000-5e99-e0a6a10c0000 pid=3243->87f248b3-21f7-50eb-a2c7-cb35eca5cc17 con guuid=60db2de6-1c00-0000-5e99-e0a6520f0000 pid=3922 /usr/bin/crlkvlpehv zombie guuid=d37e1ee6-1c00-0000-5e99-e0a6510f0000 pid=3921->guuid=60db2de6-1c00-0000-5e99-e0a6520f0000 pid=3922 execve guuid=003e36eb-1c00-0000-5e99-e0a66c0f0000 pid=3948 /usr/bin/crlkvlpehv zombie guuid=60db2de6-1c00-0000-5e99-e0a6520f0000 pid=3922->guuid=003e36eb-1c00-0000-5e99-e0a66c0f0000 pid=3948 clone guuid=db6a55e6-1c00-0000-5e99-e0a6570f0000 pid=3927 /usr/bin/crlkvlpehv zombie guuid=e18a48e6-1c00-0000-5e99-e0a6550f0000 pid=3925->guuid=db6a55e6-1c00-0000-5e99-e0a6570f0000 pid=3927 execve guuid=6c4318ed-1c00-0000-5e99-e0a6710f0000 pid=3953 /usr/bin/crlkvlpehv zombie guuid=db6a55e6-1c00-0000-5e99-e0a6570f0000 pid=3927->guuid=6c4318ed-1c00-0000-5e99-e0a6710f0000 pid=3953 clone guuid=80b973e6-1c00-0000-5e99-e0a6590f0000 pid=3929 /usr/bin/crlkvlpehv zombie guuid=a6b46be6-1c00-0000-5e99-e0a6580f0000 pid=3928->guuid=80b973e6-1c00-0000-5e99-e0a6590f0000 pid=3929 execve guuid=bd0949eb-1c00-0000-5e99-e0a66d0f0000 pid=3949 /usr/bin/crlkvlpehv zombie guuid=80b973e6-1c00-0000-5e99-e0a6590f0000 pid=3929->guuid=bd0949eb-1c00-0000-5e99-e0a66d0f0000 pid=3949 clone guuid=653596e7-1c00-0000-5e99-e0a65c0f0000 pid=3932 /usr/bin/crlkvlpehv zombie guuid=687981e6-1c00-0000-5e99-e0a65a0f0000 pid=3930->guuid=653596e7-1c00-0000-5e99-e0a65c0f0000 pid=3932 execve guuid=81a564ec-1c00-0000-5e99-e0a6700f0000 pid=3952 /usr/bin/crlkvlpehv zombie guuid=653596e7-1c00-0000-5e99-e0a65c0f0000 pid=3932->guuid=81a564ec-1c00-0000-5e99-e0a6700f0000 pid=3952 clone guuid=18cbaae8-1c00-0000-5e99-e0a6620f0000 pid=3938 /usr/bin/crlkvlpehv zombie guuid=96ada7e7-1c00-0000-5e99-e0a65e0f0000 pid=3934->guuid=18cbaae8-1c00-0000-5e99-e0a6620f0000 pid=3938 execve guuid=ae2a03ee-1c00-0000-5e99-e0a6720f0000 pid=3954 /usr/bin/crlkvlpehv zombie guuid=18cbaae8-1c00-0000-5e99-e0a6620f0000 pid=3938->guuid=ae2a03ee-1c00-0000-5e99-e0a6720f0000 pid=3954 clone guuid=91ea5c14-1e00-0000-5e99-e0a6f9120000 pid=4857 /usr/bin/xzuaceqlab zombie guuid=b6e74314-1e00-0000-5e99-e0a6f8120000 pid=4856->guuid=91ea5c14-1e00-0000-5e99-e0a6f9120000 pid=4857 execve guuid=ababf117-1e00-0000-5e99-e0a60f130000 pid=4879 /usr/bin/xzuaceqlab zombie guuid=91ea5c14-1e00-0000-5e99-e0a6f9120000 pid=4857->guuid=ababf117-1e00-0000-5e99-e0a60f130000 pid=4879 clone guuid=1d399214-1e00-0000-5e99-e0a6fc120000 pid=4860 /usr/bin/xzuaceqlab zombie guuid=5af28314-1e00-0000-5e99-e0a6fb120000 pid=4859->guuid=1d399214-1e00-0000-5e99-e0a6fc120000 pid=4860 execve guuid=96619518-1e00-0000-5e99-e0a611130000 pid=4881 /usr/bin/xzuaceqlab zombie guuid=1d399214-1e00-0000-5e99-e0a6fc120000 pid=4860->guuid=96619518-1e00-0000-5e99-e0a611130000 pid=4881 clone guuid=e46b7315-1e00-0000-5e99-e0a601130000 pid=4865 /usr/bin/xzuaceqlab zombie guuid=01c2b514-1e00-0000-5e99-e0a6fd120000 pid=4861->guuid=e46b7315-1e00-0000-5e99-e0a601130000 pid=4865 execve guuid=05018d1d-1e00-0000-5e99-e0a626130000 pid=4902 /usr/bin/xzuaceqlab zombie guuid=e46b7315-1e00-0000-5e99-e0a601130000 pid=4865->guuid=05018d1d-1e00-0000-5e99-e0a626130000 pid=4902 clone guuid=24efcb15-1e00-0000-5e99-e0a605130000 pid=4869 /usr/bin/xzuaceqlab zombie guuid=2ccc9515-1e00-0000-5e99-e0a603130000 pid=4867->guuid=24efcb15-1e00-0000-5e99-e0a605130000 pid=4869 execve guuid=894b8019-1e00-0000-5e99-e0a616130000 pid=4886 /usr/bin/xzuaceqlab zombie guuid=24efcb15-1e00-0000-5e99-e0a605130000 pid=4869->guuid=894b8019-1e00-0000-5e99-e0a616130000 pid=4886 clone guuid=8f2d6616-1e00-0000-5e99-e0a608130000 pid=4872 /usr/bin/xzuaceqlab zombie guuid=7594ed15-1e00-0000-5e99-e0a606130000 pid=4870->guuid=8f2d6616-1e00-0000-5e99-e0a608130000 pid=4872 execve guuid=5683f81c-1e00-0000-5e99-e0a623130000 pid=4899 /usr/bin/xzuaceqlab zombie guuid=8f2d6616-1e00-0000-5e99-e0a608130000 pid=4872->guuid=5683f81c-1e00-0000-5e99-e0a623130000 pid=4899 clone guuid=9e226c42-1f00-0000-5e99-e0a6ac140000 pid=5292 /usr/bin/vnljlphrre zombie guuid=26ca4c42-1f00-0000-5e99-e0a6ab140000 pid=5291->guuid=9e226c42-1f00-0000-5e99-e0a6ac140000 pid=5292 execve guuid=7b9c3546-1f00-0000-5e99-e0a6b5140000 pid=5301 /usr/bin/vnljlphrre zombie guuid=9e226c42-1f00-0000-5e99-e0a6ac140000 pid=5292->guuid=7b9c3546-1f00-0000-5e99-e0a6b5140000 pid=5301 clone guuid=b03fb042-1f00-0000-5e99-e0a6ae140000 pid=5294 /usr/bin/vnljlphrre zombie guuid=45469342-1f00-0000-5e99-e0a6ad140000 pid=5293->guuid=b03fb042-1f00-0000-5e99-e0a6ae140000 pid=5294 execve guuid=77f44247-1f00-0000-5e99-e0a6b6140000 pid=5302 /usr/bin/vnljlphrre zombie guuid=b03fb042-1f00-0000-5e99-e0a6ae140000 pid=5294->guuid=77f44247-1f00-0000-5e99-e0a6b6140000 pid=5302 clone guuid=0b7edf42-1f00-0000-5e99-e0a6b0140000 pid=5296 /usr/bin/vnljlphrre zombie guuid=5ca1ce42-1f00-0000-5e99-e0a6af140000 pid=5295->guuid=0b7edf42-1f00-0000-5e99-e0a6b0140000 pid=5296 execve guuid=e2f3e247-1f00-0000-5e99-e0a6b7140000 pid=5303 /usr/bin/vnljlphrre zombie guuid=0b7edf42-1f00-0000-5e99-e0a6b0140000 pid=5296->guuid=e2f3e247-1f00-0000-5e99-e0a6b7140000 pid=5303 clone guuid=fb739843-1f00-0000-5e99-e0a6b2140000 pid=5298 /usr/bin/vnljlphrre zombie guuid=aa110c43-1f00-0000-5e99-e0a6b1140000 pid=5297->guuid=fb739843-1f00-0000-5e99-e0a6b2140000 pid=5298 execve guuid=cf12a448-1f00-0000-5e99-e0a6b8140000 pid=5304 /usr/bin/vnljlphrre zombie guuid=fb739843-1f00-0000-5e99-e0a6b2140000 pid=5298->guuid=cf12a448-1f00-0000-5e99-e0a6b8140000 pid=5304 clone guuid=ea429644-1f00-0000-5e99-e0a6b4140000 pid=5300 /usr/bin/vnljlphrre zombie guuid=66421b44-1f00-0000-5e99-e0a6b3140000 pid=5299->guuid=ea429644-1f00-0000-5e99-e0a6b4140000 pid=5300 execve guuid=709ea249-1f00-0000-5e99-e0a6b9140000 pid=5305 /usr/bin/vnljlphrre zombie guuid=ea429644-1f00-0000-5e99-e0a6b4140000 pid=5300->guuid=709ea249-1f00-0000-5e99-e0a6b9140000 pid=5305 clone guuid=db5a6a70-2000-0000-5e99-e0a6c3140000 pid=5315 /usr/bin/vigcpbezza zombie guuid=a8865f70-2000-0000-5e99-e0a6c2140000 pid=5314->guuid=db5a6a70-2000-0000-5e99-e0a6c3140000 pid=5315 execve guuid=dd07ea74-2000-0000-5e99-e0a6d4140000 pid=5332 /usr/bin/vigcpbezza zombie guuid=db5a6a70-2000-0000-5e99-e0a6c3140000 pid=5315->guuid=dd07ea74-2000-0000-5e99-e0a6d4140000 pid=5332 clone guuid=9cd78770-2000-0000-5e99-e0a6c5140000 pid=5317 /usr/bin/vigcpbezza zombie guuid=b6ee7b70-2000-0000-5e99-e0a6c4140000 pid=5316->guuid=9cd78770-2000-0000-5e99-e0a6c5140000 pid=5317 execve guuid=a3d9a273-2000-0000-5e99-e0a6d1140000 pid=5329 /usr/bin/vigcpbezza zombie guuid=9cd78770-2000-0000-5e99-e0a6c5140000 pid=5317->guuid=a3d9a273-2000-0000-5e99-e0a6d1140000 pid=5329 clone guuid=587ba370-2000-0000-5e99-e0a6c7140000 pid=5319 /usr/bin/vigcpbezza zombie guuid=31899b70-2000-0000-5e99-e0a6c6140000 pid=5318->guuid=587ba370-2000-0000-5e99-e0a6c7140000 pid=5319 execve guuid=eb4b0975-2000-0000-5e99-e0a6d5140000 pid=5333 /usr/bin/vigcpbezza zombie guuid=587ba370-2000-0000-5e99-e0a6c7140000 pid=5319->guuid=eb4b0975-2000-0000-5e99-e0a6d5140000 pid=5333 clone guuid=8098dd70-2000-0000-5e99-e0a6c9140000 pid=5321 /usr/bin/vigcpbezza zombie guuid=d134b070-2000-0000-5e99-e0a6c8140000 pid=5320->guuid=8098dd70-2000-0000-5e99-e0a6c9140000 pid=5321 execve guuid=7c98b474-2000-0000-5e99-e0a6d3140000 pid=5331 /usr/bin/vigcpbezza zombie guuid=8098dd70-2000-0000-5e99-e0a6c9140000 pid=5321->guuid=7c98b474-2000-0000-5e99-e0a6d3140000 pid=5331 clone guuid=7da12371-2000-0000-5e99-e0a6cc140000 pid=5324 /usr/bin/vigcpbezza zombie guuid=d907ec70-2000-0000-5e99-e0a6ca140000 pid=5322->guuid=7da12371-2000-0000-5e99-e0a6cc140000 pid=5324 execve guuid=df764f74-2000-0000-5e99-e0a6d2140000 pid=5330 /usr/bin/vigcpbezza zombie guuid=7da12371-2000-0000-5e99-e0a6cc140000 pid=5324->guuid=df764f74-2000-0000-5e99-e0a6d2140000 pid=5330 clone guuid=6326c49d-2100-0000-5e99-e0a6f1140000 pid=5361 /usr/bin/srmssazabu zombie guuid=08b8b19d-2100-0000-5e99-e0a6f0140000 pid=5360->guuid=6326c49d-2100-0000-5e99-e0a6f1140000 pid=5361 execve guuid=6df3c7a1-2100-0000-5e99-e0a6fa140000 pid=5370 /usr/bin/srmssazabu zombie guuid=6326c49d-2100-0000-5e99-e0a6f1140000 pid=5361->guuid=6df3c7a1-2100-0000-5e99-e0a6fa140000 pid=5370 clone guuid=2e02ff9d-2100-0000-5e99-e0a6f3140000 pid=5363 /usr/bin/srmssazabu zombie guuid=73d7ed9d-2100-0000-5e99-e0a6f2140000 pid=5362->guuid=2e02ff9d-2100-0000-5e99-e0a6f3140000 pid=5363 execve guuid=1f3ef4a1-2100-0000-5e99-e0a6fb140000 pid=5371 /usr/bin/srmssazabu zombie guuid=2e02ff9d-2100-0000-5e99-e0a6f3140000 pid=5363->guuid=1f3ef4a1-2100-0000-5e99-e0a6fb140000 pid=5371 clone guuid=60843d9e-2100-0000-5e99-e0a6f5140000 pid=5365 /usr/bin/srmssazabu zombie guuid=bd4e2a9e-2100-0000-5e99-e0a6f4140000 pid=5364->guuid=60843d9e-2100-0000-5e99-e0a6f5140000 pid=5365 execve guuid=826cd0a2-2100-0000-5e99-e0a6fd140000 pid=5373 /usr/bin/srmssazabu zombie guuid=60843d9e-2100-0000-5e99-e0a6f5140000 pid=5365->guuid=826cd0a2-2100-0000-5e99-e0a6fd140000 pid=5373 clone guuid=b330639e-2100-0000-5e99-e0a6f7140000 pid=5367 /usr/bin/srmssazabu zombie guuid=bbf4579e-2100-0000-5e99-e0a6f6140000 pid=5366->guuid=b330639e-2100-0000-5e99-e0a6f7140000 pid=5367 execve guuid=de6701a2-2100-0000-5e99-e0a6fc140000 pid=5372 /usr/bin/srmssazabu zombie guuid=b330639e-2100-0000-5e99-e0a6f7140000 pid=5367->guuid=de6701a2-2100-0000-5e99-e0a6fc140000 pid=5372 clone guuid=54cf349f-2100-0000-5e99-e0a6f9140000 pid=5369 /usr/bin/srmssazabu zombie guuid=5a317e9e-2100-0000-5e99-e0a6f8140000 pid=5368->guuid=54cf349f-2100-0000-5e99-e0a6f9140000 pid=5369 execve guuid=eae327a3-2100-0000-5e99-e0a6fe140000 pid=5374 /usr/bin/srmssazabu zombie guuid=54cf349f-2100-0000-5e99-e0a6f9140000 pid=5369->guuid=eae327a3-2100-0000-5e99-e0a6fe140000 pid=5374 clone guuid=9fdaf2cb-2200-0000-5e99-e0a600150000 pid=5376 /usr/bin/dihtgrseqc zombie guuid=902adccb-2200-0000-5e99-e0a6ff140000 pid=5375->guuid=9fdaf2cb-2200-0000-5e99-e0a600150000 pid=5376 execve guuid=b2d420d0-2200-0000-5e99-e0a60a150000 pid=5386 /usr/bin/dihtgrseqc zombie guuid=9fdaf2cb-2200-0000-5e99-e0a600150000 pid=5376->guuid=b2d420d0-2200-0000-5e99-e0a60a150000 pid=5386 clone guuid=3b7f20cc-2200-0000-5e99-e0a602150000 pid=5378 /usr/bin/dihtgrseqc zombie guuid=d97411cc-2200-0000-5e99-e0a601150000 pid=5377->guuid=3b7f20cc-2200-0000-5e99-e0a602150000 pid=5378 execve guuid=904fa3cf-2200-0000-5e99-e0a609150000 pid=5385 /usr/bin/dihtgrseqc zombie guuid=3b7f20cc-2200-0000-5e99-e0a602150000 pid=5378->guuid=904fa3cf-2200-0000-5e99-e0a609150000 pid=5385 clone guuid=422c52cc-2200-0000-5e99-e0a604150000 pid=5380 /usr/bin/dihtgrseqc zombie guuid=aa2c3fcc-2200-0000-5e99-e0a603150000 pid=5379->guuid=422c52cc-2200-0000-5e99-e0a604150000 pid=5380 execve guuid=22e428d1-2200-0000-5e99-e0a60c150000 pid=5388 /usr/bin/dihtgrseqc zombie guuid=422c52cc-2200-0000-5e99-e0a604150000 pid=5380->guuid=22e428d1-2200-0000-5e99-e0a60c150000 pid=5388 clone guuid=8eca77cc-2200-0000-5e99-e0a606150000 pid=5382 /usr/bin/dihtgrseqc zombie guuid=3b266acc-2200-0000-5e99-e0a605150000 pid=5381->guuid=8eca77cc-2200-0000-5e99-e0a606150000 pid=5382 execve guuid=10ba4ed0-2200-0000-5e99-e0a60b150000 pid=5387 /usr/bin/dihtgrseqc zombie guuid=8eca77cc-2200-0000-5e99-e0a606150000 pid=5382->guuid=10ba4ed0-2200-0000-5e99-e0a60b150000 pid=5387 clone guuid=01194ecd-2200-0000-5e99-e0a608150000 pid=5384 /usr/bin/dihtgrseqc zombie guuid=e36998cc-2200-0000-5e99-e0a607150000 pid=5383->guuid=01194ecd-2200-0000-5e99-e0a608150000 pid=5384 execve guuid=de452fd2-2200-0000-5e99-e0a60d150000 pid=5389 /usr/bin/dihtgrseqc zombie guuid=01194ecd-2200-0000-5e99-e0a608150000 pid=5384->guuid=de452fd2-2200-0000-5e99-e0a60d150000 pid=5389 clone guuid=e0caa8f8-2300-0000-5e99-e0a60f150000 pid=5391 /usr/bin/hpqzcynesi zombie guuid=884d96f8-2300-0000-5e99-e0a60e150000 pid=5390->guuid=e0caa8f8-2300-0000-5e99-e0a60f150000 pid=5391 execve guuid=07800cfd-2300-0000-5e99-e0a619150000 pid=5401 /usr/bin/hpqzcynesi zombie guuid=e0caa8f8-2300-0000-5e99-e0a60f150000 pid=5391->guuid=07800cfd-2300-0000-5e99-e0a619150000 pid=5401 clone guuid=8731cff8-2300-0000-5e99-e0a611150000 pid=5393 /usr/bin/hpqzcynesi zombie guuid=bb55c2f8-2300-0000-5e99-e0a610150000 pid=5392->guuid=8731cff8-2300-0000-5e99-e0a611150000 pid=5393 execve guuid=fb86ddfc-2300-0000-5e99-e0a618150000 pid=5400 /usr/bin/hpqzcynesi zombie guuid=8731cff8-2300-0000-5e99-e0a611150000 pid=5393->guuid=fb86ddfc-2300-0000-5e99-e0a618150000 pid=5400 clone guuid=eb7ffff8-2300-0000-5e99-e0a613150000 pid=5395 /usr/bin/hpqzcynesi zombie guuid=297ff3f8-2300-0000-5e99-e0a612150000 pid=5394->guuid=eb7ffff8-2300-0000-5e99-e0a613150000 pid=5395 execve guuid=ca3d2ffd-2300-0000-5e99-e0a61a150000 pid=5402 /usr/bin/hpqzcynesi zombie guuid=eb7ffff8-2300-0000-5e99-e0a613150000 pid=5395->guuid=ca3d2ffd-2300-0000-5e99-e0a61a150000 pid=5402 clone guuid=100c28f9-2300-0000-5e99-e0a615150000 pid=5397 /usr/bin/hpqzcynesi zombie guuid=727d1af9-2300-0000-5e99-e0a614150000 pid=5396->guuid=100c28f9-2300-0000-5e99-e0a615150000 pid=5397 execve guuid=b76626fe-2300-0000-5e99-e0a61b150000 pid=5403 /usr/bin/hpqzcynesi zombie guuid=100c28f9-2300-0000-5e99-e0a615150000 pid=5397->guuid=b76626fe-2300-0000-5e99-e0a61b150000 pid=5403 clone guuid=a87ceef9-2300-0000-5e99-e0a617150000 pid=5399 /usr/bin/hpqzcynesi zombie guuid=517640f9-2300-0000-5e99-e0a616150000 pid=5398->guuid=a87ceef9-2300-0000-5e99-e0a617150000 pid=5399 execve guuid=aefae4fe-2300-0000-5e99-e0a61c150000 pid=5404 /usr/bin/hpqzcynesi zombie guuid=a87ceef9-2300-0000-5e99-e0a617150000 pid=5399->guuid=aefae4fe-2300-0000-5e99-e0a61c150000 pid=5404 clone guuid=671d7b26-2500-0000-5e99-e0a61e150000 pid=5406 /usr/bin/whxwzzbdmc zombie guuid=31316e26-2500-0000-5e99-e0a61d150000 pid=5405->guuid=671d7b26-2500-0000-5e99-e0a61e150000 pid=5406 execve guuid=beb7112a-2500-0000-5e99-e0a628150000 pid=5416 /usr/bin/whxwzzbdmc zombie guuid=671d7b26-2500-0000-5e99-e0a61e150000 pid=5406->guuid=beb7112a-2500-0000-5e99-e0a628150000 pid=5416 clone guuid=311ea626-2500-0000-5e99-e0a620150000 pid=5408 /usr/bin/whxwzzbdmc zombie guuid=182d9b26-2500-0000-5e99-e0a61f150000 pid=5407->guuid=311ea626-2500-0000-5e99-e0a620150000 pid=5408 execve guuid=69f00529-2500-0000-5e99-e0a627150000 pid=5415 /usr/bin/whxwzzbdmc zombie guuid=311ea626-2500-0000-5e99-e0a620150000 pid=5408->guuid=69f00529-2500-0000-5e99-e0a627150000 pid=5415 clone guuid=a550da26-2500-0000-5e99-e0a622150000 pid=5410 /usr/bin/whxwzzbdmc zombie guuid=7f8acd26-2500-0000-5e99-e0a621150000 pid=5409->guuid=a550da26-2500-0000-5e99-e0a622150000 pid=5410 execve guuid=284e742b-2500-0000-5e99-e0a62a150000 pid=5418 /usr/bin/whxwzzbdmc zombie guuid=a550da26-2500-0000-5e99-e0a622150000 pid=5410->guuid=284e742b-2500-0000-5e99-e0a62a150000 pid=5418 clone guuid=b6740627-2500-0000-5e99-e0a624150000 pid=5412 /usr/bin/whxwzzbdmc zombie guuid=0c84f426-2500-0000-5e99-e0a623150000 pid=5411->guuid=b6740627-2500-0000-5e99-e0a624150000 pid=5412 execve guuid=273c6b2b-2500-0000-5e99-e0a629150000 pid=5417 /usr/bin/whxwzzbdmc zombie guuid=b6740627-2500-0000-5e99-e0a624150000 pid=5412->guuid=273c6b2b-2500-0000-5e99-e0a629150000 pid=5417 clone guuid=dd43c727-2500-0000-5e99-e0a626150000 pid=5414 /usr/bin/whxwzzbdmc zombie guuid=d7a91e27-2500-0000-5e99-e0a625150000 pid=5413->guuid=dd43c727-2500-0000-5e99-e0a626150000 pid=5414 execve guuid=ec48d02b-2500-0000-5e99-e0a62b150000 pid=5419 /usr/bin/whxwzzbdmc zombie guuid=dd43c727-2500-0000-5e99-e0a626150000 pid=5414->guuid=ec48d02b-2500-0000-5e99-e0a62b150000 pid=5419 clone guuid=fe245854-2600-0000-5e99-e0a62d150000 pid=5421 /usr/bin/ufqigqsxkj zombie guuid=99ac3d54-2600-0000-5e99-e0a62c150000 pid=5420->guuid=fe245854-2600-0000-5e99-e0a62d150000 pid=5421 execve guuid=17872958-2600-0000-5e99-e0a638150000 pid=5432 /usr/bin/ufqigqsxkj zombie guuid=fe245854-2600-0000-5e99-e0a62d150000 pid=5421->guuid=17872958-2600-0000-5e99-e0a638150000 pid=5432 clone guuid=781c9254-2600-0000-5e99-e0a62f150000 pid=5423 /usr/bin/ufqigqsxkj zombie guuid=7c847f54-2600-0000-5e99-e0a62e150000 pid=5422->guuid=781c9254-2600-0000-5e99-e0a62f150000 pid=5423 execve guuid=96d4c157-2600-0000-5e99-e0a636150000 pid=5430 /usr/bin/ufqigqsxkj zombie guuid=781c9254-2600-0000-5e99-e0a62f150000 pid=5423->guuid=96d4c157-2600-0000-5e99-e0a636150000 pid=5430 clone guuid=2db1c254-2600-0000-5e99-e0a631150000 pid=5425 /usr/bin/ufqigqsxkj zombie guuid=220fb754-2600-0000-5e99-e0a630150000 pid=5424->guuid=2db1c254-2600-0000-5e99-e0a631150000 pid=5425 execve guuid=6a074259-2600-0000-5e99-e0a639150000 pid=5433 /usr/bin/ufqigqsxkj zombie guuid=2db1c254-2600-0000-5e99-e0a631150000 pid=5425->guuid=6a074259-2600-0000-5e99-e0a639150000 pid=5433 clone guuid=ff6aef54-2600-0000-5e99-e0a633150000 pid=5427 /usr/bin/ufqigqsxkj zombie guuid=5009e754-2600-0000-5e99-e0a632150000 pid=5426->guuid=ff6aef54-2600-0000-5e99-e0a633150000 pid=5427 execve guuid=ef5a0658-2600-0000-5e99-e0a637150000 pid=5431 /usr/bin/ufqigqsxkj zombie guuid=ff6aef54-2600-0000-5e99-e0a633150000 pid=5427->guuid=ef5a0658-2600-0000-5e99-e0a637150000 pid=5431 clone guuid=7833d655-2600-0000-5e99-e0a635150000 pid=5429 /usr/bin/ufqigqsxkj zombie guuid=0a420855-2600-0000-5e99-e0a634150000 pid=5428->guuid=7833d655-2600-0000-5e99-e0a635150000 pid=5429 execve guuid=7e99245a-2600-0000-5e99-e0a63a150000 pid=5434 /usr/bin/ufqigqsxkj zombie guuid=7833d655-2600-0000-5e99-e0a635150000 pid=5429->guuid=7e99245a-2600-0000-5e99-e0a63a150000 pid=5434 clone guuid=2a9c2881-2700-0000-5e99-e0a63c150000 pid=5436 /usr/bin/tmigvazzcc zombie guuid=aaea1e81-2700-0000-5e99-e0a63b150000 pid=5435->guuid=2a9c2881-2700-0000-5e99-e0a63c150000 pid=5436 execve guuid=ddd95584-2700-0000-5e99-e0a646150000 pid=5446 /usr/bin/tmigvazzcc zombie guuid=2a9c2881-2700-0000-5e99-e0a63c150000 pid=5436->guuid=ddd95584-2700-0000-5e99-e0a646150000 pid=5446 clone guuid=59ed4581-2700-0000-5e99-e0a63e150000 pid=5438 /usr/bin/tmigvazzcc zombie guuid=8f213981-2700-0000-5e99-e0a63d150000 pid=5437->guuid=59ed4581-2700-0000-5e99-e0a63e150000 pid=5438 execve guuid=70e4e983-2700-0000-5e99-e0a645150000 pid=5445 /usr/bin/tmigvazzcc zombie guuid=59ed4581-2700-0000-5e99-e0a63e150000 pid=5438->guuid=70e4e983-2700-0000-5e99-e0a645150000 pid=5445 clone guuid=d7a36281-2700-0000-5e99-e0a640150000 pid=5440 /usr/bin/tmigvazzcc zombie guuid=f3175a81-2700-0000-5e99-e0a63f150000 pid=5439->guuid=d7a36281-2700-0000-5e99-e0a640150000 pid=5440 execve guuid=e8406d85-2700-0000-5e99-e0a648150000 pid=5448 /usr/bin/tmigvazzcc zombie guuid=d7a36281-2700-0000-5e99-e0a640150000 pid=5440->guuid=e8406d85-2700-0000-5e99-e0a648150000 pid=5448 clone guuid=c8297481-2700-0000-5e99-e0a642150000 pid=5442 /usr/bin/tmigvazzcc zombie guuid=7ea86e81-2700-0000-5e99-e0a641150000 pid=5441->guuid=c8297481-2700-0000-5e99-e0a642150000 pid=5442 execve guuid=6eb76c85-2700-0000-5e99-e0a647150000 pid=5447 /usr/bin/tmigvazzcc zombie guuid=c8297481-2700-0000-5e99-e0a642150000 pid=5442->guuid=6eb76c85-2700-0000-5e99-e0a647150000 pid=5447 clone guuid=6ada3882-2700-0000-5e99-e0a644150000 pid=5444 /usr/bin/tmigvazzcc zombie guuid=d02d8181-2700-0000-5e99-e0a643150000 pid=5443->guuid=6ada3882-2700-0000-5e99-e0a644150000 pid=5444 execve guuid=98df5686-2700-0000-5e99-e0a649150000 pid=5449 /usr/bin/tmigvazzcc zombie guuid=6ada3882-2700-0000-5e99-e0a644150000 pid=5444->guuid=98df5686-2700-0000-5e99-e0a649150000 pid=5449 clone guuid=8613e9ae-2800-0000-5e99-e0a64b150000 pid=5451 /usr/bin/vepojevrqb zombie guuid=3986ddae-2800-0000-5e99-e0a64a150000 pid=5450->guuid=8613e9ae-2800-0000-5e99-e0a64b150000 pid=5451 execve guuid=cd5f4fb2-2800-0000-5e99-e0a654150000 pid=5460 /usr/bin/vepojevrqb zombie guuid=8613e9ae-2800-0000-5e99-e0a64b150000 pid=5451->guuid=cd5f4fb2-2800-0000-5e99-e0a654150000 pid=5460 clone guuid=90400baf-2800-0000-5e99-e0a64d150000 pid=5453 /usr/bin/vepojevrqb zombie guuid=e5f6ffae-2800-0000-5e99-e0a64c150000 pid=5452->guuid=90400baf-2800-0000-5e99-e0a64d150000 pid=5453 execve guuid=3d2643b3-2800-0000-5e99-e0a657150000 pid=5463 /usr/bin/vepojevrqb zombie guuid=90400baf-2800-0000-5e99-e0a64d150000 pid=5453->guuid=3d2643b3-2800-0000-5e99-e0a657150000 pid=5463 clone guuid=4cd42daf-2800-0000-5e99-e0a64f150000 pid=5455 /usr/bin/vepojevrqb zombie guuid=0a5225af-2800-0000-5e99-e0a64e150000 pid=5454->guuid=4cd42daf-2800-0000-5e99-e0a64f150000 pid=5455 execve guuid=4caf89b2-2800-0000-5e99-e0a655150000 pid=5461 /usr/bin/vepojevrqb zombie guuid=4cd42daf-2800-0000-5e99-e0a64f150000 pid=5455->guuid=4caf89b2-2800-0000-5e99-e0a655150000 pid=5461 clone guuid=3b7641af-2800-0000-5e99-e0a651150000 pid=5457 /usr/bin/vepojevrqb zombie guuid=5d3f3baf-2800-0000-5e99-e0a650150000 pid=5456->guuid=3b7641af-2800-0000-5e99-e0a651150000 pid=5457 execve guuid=3331bab2-2800-0000-5e99-e0a656150000 pid=5462 /usr/bin/vepojevrqb zombie guuid=3b7641af-2800-0000-5e99-e0a651150000 pid=5457->guuid=3331bab2-2800-0000-5e99-e0a656150000 pid=5462 clone guuid=1c8fd4af-2800-0000-5e99-e0a653150000 pid=5459 /usr/bin/vepojevrqb zombie guuid=2d8e4caf-2800-0000-5e99-e0a652150000 pid=5458->guuid=1c8fd4af-2800-0000-5e99-e0a653150000 pid=5459 execve guuid=0942c2b3-2800-0000-5e99-e0a658150000 pid=5464 /usr/bin/vepojevrqb zombie guuid=1c8fd4af-2800-0000-5e99-e0a653150000 pid=5459->guuid=0942c2b3-2800-0000-5e99-e0a658150000 pid=5464 clone guuid=f3b40edb-2900-0000-5e99-e0a664150000 pid=5476 /usr/bin/xvkovqhldy zombie guuid=acb004db-2900-0000-5e99-e0a663150000 pid=5475->guuid=f3b40edb-2900-0000-5e99-e0a664150000 pid=5476 execve guuid=6f5b9fdd-2900-0000-5e99-e0a66d150000 pid=5485 /usr/bin/xvkovqhldy zombie guuid=f3b40edb-2900-0000-5e99-e0a664150000 pid=5476->guuid=6f5b9fdd-2900-0000-5e99-e0a66d150000 pid=5485 clone guuid=686528db-2900-0000-5e99-e0a666150000 pid=5478 /usr/bin/xvkovqhldy zombie guuid=89a81fdb-2900-0000-5e99-e0a665150000 pid=5477->guuid=686528db-2900-0000-5e99-e0a666150000 pid=5478 execve guuid=1637aadd-2900-0000-5e99-e0a66e150000 pid=5486 /usr/bin/xvkovqhldy zombie guuid=686528db-2900-0000-5e99-e0a666150000 pid=5478->guuid=1637aadd-2900-0000-5e99-e0a66e150000 pid=5486 clone guuid=703a42db-2900-0000-5e99-e0a668150000 pid=5480 /usr/bin/xvkovqhldy zombie guuid=19b138db-2900-0000-5e99-e0a667150000 pid=5479->guuid=703a42db-2900-0000-5e99-e0a668150000 pid=5480 execve guuid=e648cede-2900-0000-5e99-e0a66f150000 pid=5487 /usr/bin/xvkovqhldy zombie guuid=703a42db-2900-0000-5e99-e0a668150000 pid=5480->guuid=e648cede-2900-0000-5e99-e0a66f150000 pid=5487 clone guuid=256855db-2900-0000-5e99-e0a66a150000 pid=5482 /usr/bin/xvkovqhldy zombie guuid=254b4edb-2900-0000-5e99-e0a669150000 pid=5481->guuid=256855db-2900-0000-5e99-e0a66a150000 pid=5482 execve guuid=8ebc12df-2900-0000-5e99-e0a670150000 pid=5488 /usr/bin/xvkovqhldy zombie guuid=256855db-2900-0000-5e99-e0a66a150000 pid=5482->guuid=8ebc12df-2900-0000-5e99-e0a670150000 pid=5488 clone guuid=f61cfedb-2900-0000-5e99-e0a66c150000 pid=5484 /usr/bin/xvkovqhldy zombie guuid=2bcc60db-2900-0000-5e99-e0a66b150000 pid=5483->guuid=f61cfedb-2900-0000-5e99-e0a66c150000 pid=5484 execve guuid=de24f7df-2900-0000-5e99-e0a671150000 pid=5489 /usr/bin/xvkovqhldy zombie guuid=f61cfedb-2900-0000-5e99-e0a66c150000 pid=5484->guuid=de24f7df-2900-0000-5e99-e0a671150000 pid=5489 clone
Result
Threat name:
XorDDoS
Detection:
malicious
Classification:
troj.evad
Score:
100 / 100
Signature
Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Drops files in suspicious directories
Found malware configuration
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Sample deletes itself
Sample tries to persist itself using cron
Sample tries to persist itself using System V runlevels
Suricata IDS alerts for network traffic
Yara detected XorDDoS Bot
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1762676 Sample: p.txt.elf Startdate: 22/08/2025 Architecture: LINUX Score: 100 72 jj.vvbb321.com 5.196.167.242, 1526, 36572 OVHFR France 2->72 74 jj.nnmm234.com 2->74 76 jj.jjkk567.com 2->76 78 Suricata IDS alerts for network traffic 2->78 80 Found malware configuration 2->80 82 Malicious sample detected (through community Yara rule) 2->82 84 4 other signatures 2->84 10 p.txt.elf 2->10         started        12 systemd snapd-env-generator 2->12         started        signatures3 process4 process5 14 p.txt.elf 10->14         started        file6 64 /usr/lib/libudev.so, ELF 14->64 dropped 66 /usr/bin/xmwgqdeveg, ELF 14->66 dropped 68 /usr/bin/wwelwlxvwq, ELF 14->68 dropped 70 16 other malicious files 14->70 dropped 92 Drops files in suspicious directories 14->92 94 Sample deletes itself 14->94 96 Sample tries to persist itself using cron 14->96 98 Sample tries to persist itself using System V runlevels 14->98 18 p.txt.elf sh 14->18         started        22 p.txt.elf 14->22         started        24 p.txt.elf 14->24         started        26 115 other processes 14->26 signatures7 process8 file9 62 /etc/crontab, ASCII 18->62 dropped 86 Sample tries to persist itself using cron 18->86 28 sh sed 18->28         started        31 p.txt.elf pmgfrdqfir 22->31         started        33 p.txt.elf pmgfrdqfir 24->33         started        35 p.txt.elf pmgfrdqfir 26->35         started        37 p.txt.elf pmgfrdqfir 26->37         started        39 p.txt.elf pmgfrdqfir 26->39         started        41 112 other processes 26->41 signatures10 process11 signatures12 90 Sample tries to persist itself using cron 28->90 43 pmgfrdqfir 31->43         started        46 pmgfrdqfir 33->46         started        48 pmgfrdqfir 35->48         started        50 pmgfrdqfir 37->50         started        52 pmgfrdqfir 39->52         started        54 prcymiiicq 41->54         started        56 prcymiiicq 41->56         started        58 prcymiiicq 41->58         started        60 103 other processes 41->60 process13 signatures14 88 Sample deletes itself 43->88
Threat name:
Linux.Network.Xorddos
Status:
Malicious
First seen:
2025-08-22 05:54:36 UTC
File Type:
ELF32 Little (Exe)
AV detection:
19 of 24 (79.17%)
Threat level:
  3/5
Result
Malware family:
xorddos
Score:
  10/10
Tags:
family:xorddos botnet discovery downloader execution linux persistence privilege_escalation rootkit
Behaviour
Reads runtime system information
Creates/modifies Cron job
Loads a kernel module
Writes memory of remote process
XorDDoS
XorDDoS payload
Xorddos family
Malware Config
C2 Extraction:
https://ww.aass654.com/config.rar
jj.aass654.com:1526
jj.xxcc789.com:1526
jj.vvbb321.com:1526
jj.jjkk567.com:1526
jj.nnmm234.com:1526
Verdict:
Malicious
Tags:
backdoor trojan xor_ddos Unix.Malware.Xorddos-9856891-0
YARA:
libgcc_backdoor Linux_Trojan_Xorddos_2aef46a6 Linux_Trojan_Xorddos_884cab60 MALWARE_Linux_XORDDoS
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:CP_AllMal_Detector
Author:DiegoAnalytics
Description:CrossPlatform All Malwares Detector: Detect PE, ELF, Mach-O, scripts, archives; overlay, obfuscation, encryption, spoofing, hiding, high entropy, network communication
Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:enterpriseapps2
Author:Tim Brown @timb_machine
Description:Enterprise apps
Rule name:F01_s1ckrule
Author:s1ckb017
Rule name:linux_generic_ipv6_catcher
Author:@_lubiedo
Description:ELF samples using IPv6 addresses
Rule name:Linux_Trojan_Xorddos_2aef46a6
Author:Elastic Security
Rule name:MALWARE_Linux_XORDDoS
Author:ditekSHen
Description:Detects XORDDoS
Rule name:NET
Author:malware-lu
Rule name:unixredflags3
Author:Tim Brown @timb_machine
Description:Hunts for UNIX red flags

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

XorDDoS

elf 09898756f3e900900093fe4890680734f41ece38362912f4da2a3994a12a833e

(this sample)

  
Delivery method
Distributed via web download

Comments