MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 10e43894490d98a91f3d409a83d984556d619e91782333033ad3d7fb1b9def8b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



XorDDoS


Vendor detections: 10


Intelligence 10 IOCs YARA 9 File information Comments

SHA256 hash: 10e43894490d98a91f3d409a83d984556d619e91782333033ad3d7fb1b9def8b
SHA3-384 hash: 73a0ec49a214ab9458949c87fb17bb05eb1f5fc18cbaf65808a397d676b40ee748647cbd36537e8d68cbacb9fa1dc5fd
SHA1 hash: 73fd434aafab8fc390d07f981b13f26fefbf83b7
MD5 hash: 49597f30f671c6a2d8657aad728b9d5e
humanhash: crazy-kitten-item-coffee
File name:p.txt
Download: download sample
Signature XorDDoS
File size:548'616 bytes
First seen:2025-08-24 18:16:00 UTC
Last seen:2025-10-25 02:52:40 UTC
File type: elf
MIME type:application/x-executable
ssdeep 12288:4Ufrcn+vwK5ripVU4tdZ1pNL/pVbzh66ySjQn36Eoj:/fUywKQ7Fb1pNL/p5hfjQn36Eu
TLSH T19AC45C56E383E2F7C82705B0134BF7BF4620B6359461CD86B7989D5AB9338F22A4D352
telfhash t12ab138722e7558f8b7f08402425a7620ce39e027259439b71ef2b454f7f2c429b6ad7a
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter abuse_ch
Tags:elf XorDDoS

Intelligence


File Origin
# of uploads :
4
# of downloads :
29
Origin country :
DE DE
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Collects information on the RAM
Manages services
Sends data to a server
DNS request
Collects information on the CPU
Runs as daemon
Connection attempt
Creating a process from a recently created file
Receives data from a server
Creating a file
Collects information on the network activity
Launching a process
Changes owner for a written file
Deletes a system binary file
Creates or modifies files in /cron to set up autorun
Writes files to system directory
Deleting of the original file
Creates or modifies symbolic links in /init.d to set up autorun
Creates or modifies files in /init.d to set up autorun
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
gcc masquerade threat
Status:
terminated
Behavior Graph:
%3 guuid=7aa65ef4-1800-0000-c16d-e35652140000 pid=5202 /usr/bin/sudo guuid=f4db5bf6-1800-0000-c16d-e35653140000 pid=5203 /tmp/sample.bin guuid=7aa65ef4-1800-0000-c16d-e35652140000 pid=5202->guuid=f4db5bf6-1800-0000-c16d-e35653140000 pid=5203 execve guuid=09098ef6-1800-0000-c16d-e35654140000 pid=5204 /tmp/sample.bin delete-file write-config write-file zombie guuid=f4db5bf6-1800-0000-c16d-e35653140000 pid=5203->guuid=09098ef6-1800-0000-c16d-e35654140000 pid=5204 clone guuid=da81d5f7-1800-0000-c16d-e35655140000 pid=5205 /tmp/sample.bin guuid=09098ef6-1800-0000-c16d-e35654140000 pid=5204->guuid=da81d5f7-1800-0000-c16d-e35655140000 pid=5205 clone guuid=989f10f8-1800-0000-c16d-e35657140000 pid=5207 /tmp/sample.bin guuid=09098ef6-1800-0000-c16d-e35654140000 pid=5204->guuid=989f10f8-1800-0000-c16d-e35657140000 pid=5207 clone guuid=ab7c36f8-1800-0000-c16d-e35659140000 pid=5209 /usr/bin/dash guuid=09098ef6-1800-0000-c16d-e35654140000 pid=5204->guuid=ab7c36f8-1800-0000-c16d-e35659140000 pid=5209 execve guuid=09098ef6-1800-0000-c16d-e35654140000 pid=5213 /tmp/sample.bin write-file zombie guuid=09098ef6-1800-0000-c16d-e35654140000 pid=5204->guuid=09098ef6-1800-0000-c16d-e35654140000 pid=5213 clone guuid=09098ef6-1800-0000-c16d-e35654140000 pid=5214 /tmp/sample.bin dns net send-data write-file zombie guuid=09098ef6-1800-0000-c16d-e35654140000 pid=5204->guuid=09098ef6-1800-0000-c16d-e35654140000 pid=5214 clone guuid=09098ef6-1800-0000-c16d-e35654140000 pid=5215 /tmp/sample.bin net zombie guuid=09098ef6-1800-0000-c16d-e35654140000 pid=5204->guuid=09098ef6-1800-0000-c16d-e35654140000 pid=5215 clone guuid=efb14445-1a00-0000-c16d-e35686140000 pid=5254 /tmp/sample.bin guuid=09098ef6-1800-0000-c16d-e35654140000 pid=5204->guuid=efb14445-1a00-0000-c16d-e35686140000 pid=5254 clone guuid=9e419d45-1a00-0000-c16d-e35688140000 pid=5256 /tmp/sample.bin guuid=09098ef6-1800-0000-c16d-e35654140000 pid=5204->guuid=9e419d45-1a00-0000-c16d-e35688140000 pid=5256 clone guuid=05fd2f46-1a00-0000-c16d-e3568a140000 pid=5258 /tmp/sample.bin guuid=09098ef6-1800-0000-c16d-e35654140000 pid=5204->guuid=05fd2f46-1a00-0000-c16d-e3568a140000 pid=5258 clone guuid=23974847-1a00-0000-c16d-e3568c140000 pid=5260 /tmp/sample.bin guuid=09098ef6-1800-0000-c16d-e35654140000 pid=5204->guuid=23974847-1a00-0000-c16d-e3568c140000 pid=5260 clone guuid=e12aaa48-1a00-0000-c16d-e3568e140000 pid=5262 /tmp/sample.bin guuid=09098ef6-1800-0000-c16d-e35654140000 pid=5204->guuid=e12aaa48-1a00-0000-c16d-e3568e140000 pid=5262 clone guuid=22fd8a76-1b00-0000-c16d-e356b5140000 pid=5301 /tmp/sample.bin guuid=09098ef6-1800-0000-c16d-e35654140000 pid=5204->guuid=22fd8a76-1b00-0000-c16d-e356b5140000 pid=5301 clone guuid=8f57b976-1b00-0000-c16d-e356b7140000 pid=5303 /tmp/sample.bin guuid=09098ef6-1800-0000-c16d-e35654140000 pid=5204->guuid=8f57b976-1b00-0000-c16d-e356b7140000 pid=5303 clone guuid=5f6fee76-1b00-0000-c16d-e356b9140000 pid=5305 /tmp/sample.bin guuid=09098ef6-1800-0000-c16d-e35654140000 pid=5204->guuid=5f6fee76-1b00-0000-c16d-e356b9140000 pid=5305 clone guuid=25e41a77-1b00-0000-c16d-e356bb140000 pid=5307 /tmp/sample.bin guuid=09098ef6-1800-0000-c16d-e35654140000 pid=5204->guuid=25e41a77-1b00-0000-c16d-e356bb140000 pid=5307 clone guuid=c5c54077-1b00-0000-c16d-e356bd140000 pid=5309 /tmp/sample.bin guuid=09098ef6-1800-0000-c16d-e35654140000 pid=5204->guuid=c5c54077-1b00-0000-c16d-e356bd140000 pid=5309 clone guuid=29be68a4-1c00-0000-c16d-e356c4140000 pid=5316 /tmp/sample.bin guuid=09098ef6-1800-0000-c16d-e35654140000 pid=5204->guuid=29be68a4-1c00-0000-c16d-e356c4140000 pid=5316 clone guuid=635a8fa4-1c00-0000-c16d-e356c6140000 pid=5318 /tmp/sample.bin guuid=09098ef6-1800-0000-c16d-e35654140000 pid=5204->guuid=635a8fa4-1c00-0000-c16d-e356c6140000 pid=5318 clone guuid=cef8b3a4-1c00-0000-c16d-e356c8140000 pid=5320 /tmp/sample.bin guuid=09098ef6-1800-0000-c16d-e35654140000 pid=5204->guuid=cef8b3a4-1c00-0000-c16d-e356c8140000 pid=5320 clone guuid=8db9d3a4-1c00-0000-c16d-e356ca140000 pid=5322 /tmp/sample.bin guuid=09098ef6-1800-0000-c16d-e35654140000 pid=5204->guuid=8db9d3a4-1c00-0000-c16d-e356ca140000 pid=5322 clone guuid=c4baeaa4-1c00-0000-c16d-e356cc140000 pid=5324 /tmp/sample.bin guuid=09098ef6-1800-0000-c16d-e35654140000 pid=5204->guuid=c4baeaa4-1c00-0000-c16d-e356cc140000 pid=5324 clone guuid=6ae6d9d1-1d00-0000-c16d-e356d3140000 pid=5331 /tmp/sample.bin guuid=09098ef6-1800-0000-c16d-e35654140000 pid=5204->guuid=6ae6d9d1-1d00-0000-c16d-e356d3140000 pid=5331 clone guuid=30820fd2-1d00-0000-c16d-e356d5140000 pid=5333 /tmp/sample.bin guuid=09098ef6-1800-0000-c16d-e35654140000 pid=5204->guuid=30820fd2-1d00-0000-c16d-e356d5140000 pid=5333 clone guuid=f01f3dd2-1d00-0000-c16d-e356d7140000 pid=5335 /tmp/sample.bin guuid=09098ef6-1800-0000-c16d-e35654140000 pid=5204->guuid=f01f3dd2-1d00-0000-c16d-e356d7140000 pid=5335 clone guuid=9aa763d2-1d00-0000-c16d-e356d9140000 pid=5337 /tmp/sample.bin guuid=09098ef6-1800-0000-c16d-e35654140000 pid=5204->guuid=9aa763d2-1d00-0000-c16d-e356d9140000 pid=5337 clone guuid=f7658cd2-1d00-0000-c16d-e356db140000 pid=5339 /tmp/sample.bin guuid=09098ef6-1800-0000-c16d-e35654140000 pid=5204->guuid=f7658cd2-1d00-0000-c16d-e356db140000 pid=5339 clone guuid=857f0c00-1f00-0000-c16d-e356e2140000 pid=5346 /tmp/sample.bin guuid=09098ef6-1800-0000-c16d-e35654140000 pid=5204->guuid=857f0c00-1f00-0000-c16d-e356e2140000 pid=5346 clone guuid=59233d00-1f00-0000-c16d-e356e4140000 pid=5348 /tmp/sample.bin guuid=09098ef6-1800-0000-c16d-e35654140000 pid=5204->guuid=59233d00-1f00-0000-c16d-e356e4140000 pid=5348 clone guuid=80398200-1f00-0000-c16d-e356e6140000 pid=5350 /tmp/sample.bin guuid=09098ef6-1800-0000-c16d-e35654140000 pid=5204->guuid=80398200-1f00-0000-c16d-e356e6140000 pid=5350 clone guuid=56a6b100-1f00-0000-c16d-e356e8140000 pid=5352 /tmp/sample.bin guuid=09098ef6-1800-0000-c16d-e35654140000 pid=5204->guuid=56a6b100-1f00-0000-c16d-e356e8140000 pid=5352 clone guuid=fc60dd00-1f00-0000-c16d-e356ea140000 pid=5354 /tmp/sample.bin guuid=09098ef6-1800-0000-c16d-e35654140000 pid=5204->guuid=fc60dd00-1f00-0000-c16d-e356ea140000 pid=5354 clone guuid=8a3a8035-2000-0000-c16d-e356f1140000 pid=5361 /tmp/sample.bin guuid=09098ef6-1800-0000-c16d-e35654140000 pid=5204->guuid=8a3a8035-2000-0000-c16d-e356f1140000 pid=5361 clone guuid=7501b435-2000-0000-c16d-e356f3140000 pid=5363 /tmp/sample.bin guuid=09098ef6-1800-0000-c16d-e35654140000 pid=5204->guuid=7501b435-2000-0000-c16d-e356f3140000 pid=5363 clone guuid=2325ee35-2000-0000-c16d-e356f5140000 pid=5365 /tmp/sample.bin guuid=09098ef6-1800-0000-c16d-e35654140000 pid=5204->guuid=2325ee35-2000-0000-c16d-e356f5140000 pid=5365 clone guuid=0fd81736-2000-0000-c16d-e356f7140000 pid=5367 /tmp/sample.bin guuid=09098ef6-1800-0000-c16d-e35654140000 pid=5204->guuid=0fd81736-2000-0000-c16d-e356f7140000 pid=5367 clone guuid=f9a03e36-2000-0000-c16d-e356f9140000 pid=5369 /tmp/sample.bin guuid=09098ef6-1800-0000-c16d-e35654140000 pid=5204->guuid=f9a03e36-2000-0000-c16d-e356f9140000 pid=5369 clone guuid=5397196b-2100-0000-c16d-e35600150000 pid=5376 /tmp/sample.bin guuid=09098ef6-1800-0000-c16d-e35654140000 pid=5204->guuid=5397196b-2100-0000-c16d-e35600150000 pid=5376 clone guuid=adea506b-2100-0000-c16d-e35602150000 pid=5378 /tmp/sample.bin guuid=09098ef6-1800-0000-c16d-e35654140000 pid=5204->guuid=adea506b-2100-0000-c16d-e35602150000 pid=5378 clone guuid=9e7c7f6b-2100-0000-c16d-e35604150000 pid=5380 /tmp/sample.bin guuid=09098ef6-1800-0000-c16d-e35654140000 pid=5204->guuid=9e7c7f6b-2100-0000-c16d-e35604150000 pid=5380 clone guuid=8a83a36b-2100-0000-c16d-e35606150000 pid=5382 /tmp/sample.bin guuid=09098ef6-1800-0000-c16d-e35654140000 pid=5204->guuid=8a83a36b-2100-0000-c16d-e35606150000 pid=5382 clone guuid=e82fcc6b-2100-0000-c16d-e35608150000 pid=5384 /tmp/sample.bin guuid=09098ef6-1800-0000-c16d-e35654140000 pid=5204->guuid=e82fcc6b-2100-0000-c16d-e35608150000 pid=5384 clone guuid=da6d60b0-2200-0000-c16d-e3560f150000 pid=5391 /tmp/sample.bin guuid=09098ef6-1800-0000-c16d-e35654140000 pid=5204->guuid=da6d60b0-2200-0000-c16d-e3560f150000 pid=5391 clone guuid=0dabb0b0-2200-0000-c16d-e35611150000 pid=5393 /tmp/sample.bin guuid=09098ef6-1800-0000-c16d-e35654140000 pid=5204->guuid=0dabb0b0-2200-0000-c16d-e35611150000 pid=5393 clone guuid=72e8e4b0-2200-0000-c16d-e35613150000 pid=5395 /tmp/sample.bin guuid=09098ef6-1800-0000-c16d-e35654140000 pid=5204->guuid=72e8e4b0-2200-0000-c16d-e35613150000 pid=5395 clone guuid=37190cb1-2200-0000-c16d-e35615150000 pid=5397 /tmp/sample.bin guuid=09098ef6-1800-0000-c16d-e35654140000 pid=5204->guuid=37190cb1-2200-0000-c16d-e35615150000 pid=5397 clone guuid=6c8c35b1-2200-0000-c16d-e35617150000 pid=5399 /tmp/sample.bin guuid=09098ef6-1800-0000-c16d-e35654140000 pid=5204->guuid=6c8c35b1-2200-0000-c16d-e35617150000 pid=5399 clone guuid=9f2b78e1-2300-0000-c16d-e3561e150000 pid=5406 /tmp/sample.bin guuid=09098ef6-1800-0000-c16d-e35654140000 pid=5204->guuid=9f2b78e1-2300-0000-c16d-e3561e150000 pid=5406 clone guuid=f5f2a9e1-2300-0000-c16d-e35620150000 pid=5408 /tmp/sample.bin guuid=09098ef6-1800-0000-c16d-e35654140000 pid=5204->guuid=f5f2a9e1-2300-0000-c16d-e35620150000 pid=5408 clone guuid=b35fdee1-2300-0000-c16d-e35622150000 pid=5410 /tmp/sample.bin guuid=09098ef6-1800-0000-c16d-e35654140000 pid=5204->guuid=b35fdee1-2300-0000-c16d-e35622150000 pid=5410 clone guuid=f64b0ce2-2300-0000-c16d-e35624150000 pid=5412 /tmp/sample.bin guuid=09098ef6-1800-0000-c16d-e35654140000 pid=5204->guuid=f64b0ce2-2300-0000-c16d-e35624150000 pid=5412 clone guuid=8ef130e2-2300-0000-c16d-e35626150000 pid=5414 /tmp/sample.bin guuid=09098ef6-1800-0000-c16d-e35654140000 pid=5204->guuid=8ef130e2-2300-0000-c16d-e35626150000 pid=5414 clone guuid=bf3a880f-2500-0000-c16d-e3562d150000 pid=5421 /tmp/sample.bin guuid=09098ef6-1800-0000-c16d-e35654140000 pid=5204->guuid=bf3a880f-2500-0000-c16d-e3562d150000 pid=5421 clone guuid=d11ebe0f-2500-0000-c16d-e3562f150000 pid=5423 /tmp/sample.bin guuid=09098ef6-1800-0000-c16d-e35654140000 pid=5204->guuid=d11ebe0f-2500-0000-c16d-e3562f150000 pid=5423 clone guuid=546bf00f-2500-0000-c16d-e35631150000 pid=5425 /tmp/sample.bin guuid=09098ef6-1800-0000-c16d-e35654140000 pid=5204->guuid=546bf00f-2500-0000-c16d-e35631150000 pid=5425 clone guuid=a7311910-2500-0000-c16d-e35633150000 pid=5427 /tmp/sample.bin guuid=09098ef6-1800-0000-c16d-e35654140000 pid=5204->guuid=a7311910-2500-0000-c16d-e35633150000 pid=5427 clone guuid=f9884210-2500-0000-c16d-e35635150000 pid=5429 /tmp/sample.bin guuid=09098ef6-1800-0000-c16d-e35654140000 pid=5204->guuid=f9884210-2500-0000-c16d-e35635150000 pid=5429 clone guuid=27387e3d-2600-0000-c16d-e3563c150000 pid=5436 /tmp/sample.bin guuid=09098ef6-1800-0000-c16d-e35654140000 pid=5204->guuid=27387e3d-2600-0000-c16d-e3563c150000 pid=5436 clone guuid=4213c23d-2600-0000-c16d-e3563e150000 pid=5438 /tmp/sample.bin guuid=09098ef6-1800-0000-c16d-e35654140000 pid=5204->guuid=4213c23d-2600-0000-c16d-e3563e150000 pid=5438 clone guuid=786ef13d-2600-0000-c16d-e35640150000 pid=5440 /tmp/sample.bin guuid=09098ef6-1800-0000-c16d-e35654140000 pid=5204->guuid=786ef13d-2600-0000-c16d-e35640150000 pid=5440 clone guuid=538c233e-2600-0000-c16d-e35642150000 pid=5442 /tmp/sample.bin guuid=09098ef6-1800-0000-c16d-e35654140000 pid=5204->guuid=538c233e-2600-0000-c16d-e35642150000 pid=5442 clone guuid=e8844e3e-2600-0000-c16d-e35644150000 pid=5444 /tmp/sample.bin guuid=09098ef6-1800-0000-c16d-e35654140000 pid=5204->guuid=e8844e3e-2600-0000-c16d-e35644150000 pid=5444 clone guuid=95f6e0f7-1800-0000-c16d-e35656140000 pid=5206 /tmp/sample.bin guuid=da81d5f7-1800-0000-c16d-e35655140000 pid=5205->guuid=95f6e0f7-1800-0000-c16d-e35656140000 pid=5206 clone guuid=1b2027f8-1800-0000-c16d-e35658140000 pid=5208 /usr/sbin/update-rc.d zombie guuid=989f10f8-1800-0000-c16d-e35657140000 pid=5207->guuid=1b2027f8-1800-0000-c16d-e35658140000 pid=5208 execve guuid=523bbd01-1900-0000-c16d-e35669140000 pid=5225 /usr/bin/systemctl guuid=1b2027f8-1800-0000-c16d-e35658140000 pid=5208->guuid=523bbd01-1900-0000-c16d-e35669140000 pid=5225 execve guuid=01d376f9-1800-0000-c16d-e3565a140000 pid=5210 /usr/bin/sed guuid=ab7c36f8-1800-0000-c16d-e35659140000 pid=5209->guuid=01d376f9-1800-0000-c16d-e3565a140000 pid=5210 execve c1c79644-7013-50a6-b5ad-39fff83e9e87 0.0.0.0:1528 guuid=09098ef6-1800-0000-c16d-e35654140000 pid=5214->c1c79644-7013-50a6-b5ad-39fff83e9e87 con 2e58f97a-e0f5-59ea-89bb-17ac33083ffe ll.vvbb321.com:1528 guuid=09098ef6-1800-0000-c16d-e35654140000 pid=5214->2e58f97a-e0f5-59ea-89bb-17ac33083ffe con dc6b7799-62ee-5243-a778-07ceb943277c ll.xxcc789.com:1528 guuid=09098ef6-1800-0000-c16d-e35654140000 pid=5214->dc6b7799-62ee-5243-a778-07ceb943277c con dbb9e30d-0f30-5f57-ad15-8f8f639c3a74 ll.aass654.com:1528 guuid=09098ef6-1800-0000-c16d-e35654140000 pid=5214->dbb9e30d-0f30-5f57-ad15-8f8f639c3a74 con 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=09098ef6-1800-0000-c16d-e35654140000 pid=5214->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 256B b4bf20d4-f7c8-5c24-8830-c23364537aa4 8.8.4.4:53 guuid=09098ef6-1800-0000-c16d-e35654140000 pid=5214->b4bf20d4-f7c8-5c24-8830-c23364537aa4 send: 128B 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=09098ef6-1800-0000-c16d-e35654140000 pid=5214->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 128B 87f248b3-21f7-50eb-a2c7-cb35eca5cc17 0.0.0.0:80 guuid=09098ef6-1800-0000-c16d-e35654140000 pid=5215->87f248b3-21f7-50eb-a2c7-cb35eca5cc17 con guuid=653a6945-1a00-0000-c16d-e35687140000 pid=5255 /usr/bin/qekuwotmdm zombie guuid=efb14445-1a00-0000-c16d-e35686140000 pid=5254->guuid=653a6945-1a00-0000-c16d-e35687140000 pid=5255 execve guuid=a12c9250-1a00-0000-c16d-e35691140000 pid=5265 /usr/bin/qekuwotmdm zombie guuid=653a6945-1a00-0000-c16d-e35687140000 pid=5255->guuid=a12c9250-1a00-0000-c16d-e35691140000 pid=5265 clone guuid=7ca0e445-1a00-0000-c16d-e35689140000 pid=5257 /usr/bin/qekuwotmdm zombie guuid=9e419d45-1a00-0000-c16d-e35688140000 pid=5256->guuid=7ca0e445-1a00-0000-c16d-e35689140000 pid=5257 execve guuid=050c5954-1a00-0000-c16d-e35692140000 pid=5266 /usr/bin/qekuwotmdm zombie guuid=7ca0e445-1a00-0000-c16d-e35689140000 pid=5257->guuid=050c5954-1a00-0000-c16d-e35692140000 pid=5266 clone guuid=91348846-1a00-0000-c16d-e3568b140000 pid=5259 /usr/bin/qekuwotmdm zombie guuid=05fd2f46-1a00-0000-c16d-e3568a140000 pid=5258->guuid=91348846-1a00-0000-c16d-e3568b140000 pid=5259 execve guuid=fc91644d-1a00-0000-c16d-e35690140000 pid=5264 /usr/bin/qekuwotmdm guuid=91348846-1a00-0000-c16d-e3568b140000 pid=5259->guuid=fc91644d-1a00-0000-c16d-e35690140000 pid=5264 clone guuid=4e244648-1a00-0000-c16d-e3568d140000 pid=5261 /usr/bin/qekuwotmdm zombie guuid=23974847-1a00-0000-c16d-e3568c140000 pid=5260->guuid=4e244648-1a00-0000-c16d-e3568d140000 pid=5261 execve guuid=a6db0955-1a00-0000-c16d-e35694140000 pid=5268 /usr/bin/qekuwotmdm zombie guuid=4e244648-1a00-0000-c16d-e3568d140000 pid=5261->guuid=a6db0955-1a00-0000-c16d-e35694140000 pid=5268 clone guuid=663fdf49-1a00-0000-c16d-e3568f140000 pid=5263 /usr/bin/qekuwotmdm zombie guuid=e12aaa48-1a00-0000-c16d-e3568e140000 pid=5262->guuid=663fdf49-1a00-0000-c16d-e3568f140000 pid=5263 execve guuid=4be18d54-1a00-0000-c16d-e35693140000 pid=5267 /usr/bin/qekuwotmdm zombie guuid=663fdf49-1a00-0000-c16d-e3568f140000 pid=5263->guuid=4be18d54-1a00-0000-c16d-e35693140000 pid=5267 clone guuid=03f19d76-1b00-0000-c16d-e356b6140000 pid=5302 /usr/bin/oiiqaqmfyt zombie guuid=22fd8a76-1b00-0000-c16d-e356b5140000 pid=5301->guuid=03f19d76-1b00-0000-c16d-e356b6140000 pid=5302 execve guuid=2fa9387a-1b00-0000-c16d-e356c0140000 pid=5312 /usr/bin/oiiqaqmfyt zombie guuid=03f19d76-1b00-0000-c16d-e356b6140000 pid=5302->guuid=2fa9387a-1b00-0000-c16d-e356c0140000 pid=5312 clone guuid=f4b9cd76-1b00-0000-c16d-e356b8140000 pid=5304 /usr/bin/oiiqaqmfyt zombie guuid=8f57b976-1b00-0000-c16d-e356b7140000 pid=5303->guuid=f4b9cd76-1b00-0000-c16d-e356b8140000 pid=5304 execve guuid=4af27979-1b00-0000-c16d-e356bf140000 pid=5311 /usr/bin/oiiqaqmfyt zombie guuid=f4b9cd76-1b00-0000-c16d-e356b8140000 pid=5304->guuid=4af27979-1b00-0000-c16d-e356bf140000 pid=5311 clone guuid=24250377-1b00-0000-c16d-e356ba140000 pid=5306 /usr/bin/oiiqaqmfyt zombie guuid=5f6fee76-1b00-0000-c16d-e356b9140000 pid=5305->guuid=24250377-1b00-0000-c16d-e356ba140000 pid=5306 execve guuid=63170e7c-1b00-0000-c16d-e356c2140000 pid=5314 /usr/bin/oiiqaqmfyt zombie guuid=24250377-1b00-0000-c16d-e356ba140000 pid=5306->guuid=63170e7c-1b00-0000-c16d-e356c2140000 pid=5314 clone guuid=d3f32677-1b00-0000-c16d-e356bc140000 pid=5308 /usr/bin/oiiqaqmfyt zombie guuid=25e41a77-1b00-0000-c16d-e356bb140000 pid=5307->guuid=d3f32677-1b00-0000-c16d-e356bc140000 pid=5308 execve guuid=5e0c837b-1b00-0000-c16d-e356c1140000 pid=5313 /usr/bin/oiiqaqmfyt zombie guuid=d3f32677-1b00-0000-c16d-e356bc140000 pid=5308->guuid=5e0c837b-1b00-0000-c16d-e356c1140000 pid=5313 clone guuid=99abf977-1b00-0000-c16d-e356be140000 pid=5310 /usr/bin/oiiqaqmfyt zombie guuid=c5c54077-1b00-0000-c16d-e356bd140000 pid=5309->guuid=99abf977-1b00-0000-c16d-e356be140000 pid=5310 execve guuid=9bdf3a7c-1b00-0000-c16d-e356c3140000 pid=5315 /usr/bin/oiiqaqmfyt zombie guuid=99abf977-1b00-0000-c16d-e356be140000 pid=5310->guuid=9bdf3a7c-1b00-0000-c16d-e356c3140000 pid=5315 clone guuid=947377a4-1c00-0000-c16d-e356c5140000 pid=5317 /usr/bin/uvcfpioxkg zombie guuid=29be68a4-1c00-0000-c16d-e356c4140000 pid=5316->guuid=947377a4-1c00-0000-c16d-e356c5140000 pid=5317 execve guuid=98b452a7-1c00-0000-c16d-e356ce140000 pid=5326 /usr/bin/uvcfpioxkg zombie guuid=947377a4-1c00-0000-c16d-e356c5140000 pid=5317->guuid=98b452a7-1c00-0000-c16d-e356ce140000 pid=5326 clone guuid=bb7e9ca4-1c00-0000-c16d-e356c7140000 pid=5319 /usr/bin/uvcfpioxkg zombie guuid=635a8fa4-1c00-0000-c16d-e356c6140000 pid=5318->guuid=bb7e9ca4-1c00-0000-c16d-e356c7140000 pid=5319 execve guuid=4c2767a7-1c00-0000-c16d-e356cf140000 pid=5327 /usr/bin/uvcfpioxkg zombie guuid=bb7e9ca4-1c00-0000-c16d-e356c7140000 pid=5319->guuid=4c2767a7-1c00-0000-c16d-e356cf140000 pid=5327 clone guuid=7e30bea4-1c00-0000-c16d-e356c9140000 pid=5321 /usr/bin/uvcfpioxkg zombie guuid=cef8b3a4-1c00-0000-c16d-e356c8140000 pid=5320->guuid=7e30bea4-1c00-0000-c16d-e356c9140000 pid=5321 execve guuid=b870d1a8-1c00-0000-c16d-e356d1140000 pid=5329 /usr/bin/uvcfpioxkg zombie guuid=7e30bea4-1c00-0000-c16d-e356c9140000 pid=5321->guuid=b870d1a8-1c00-0000-c16d-e356d1140000 pid=5329 clone guuid=b5dedba4-1c00-0000-c16d-e356cb140000 pid=5323 /usr/bin/uvcfpioxkg zombie guuid=8db9d3a4-1c00-0000-c16d-e356ca140000 pid=5322->guuid=b5dedba4-1c00-0000-c16d-e356cb140000 pid=5323 execve guuid=d24d9ca8-1c00-0000-c16d-e356d0140000 pid=5328 /usr/bin/uvcfpioxkg zombie guuid=b5dedba4-1c00-0000-c16d-e356cb140000 pid=5323->guuid=d24d9ca8-1c00-0000-c16d-e356d0140000 pid=5328 clone guuid=0a8f50a5-1c00-0000-c16d-e356cd140000 pid=5325 /usr/bin/uvcfpioxkg zombie guuid=c4baeaa4-1c00-0000-c16d-e356cc140000 pid=5324->guuid=0a8f50a5-1c00-0000-c16d-e356cd140000 pid=5325 execve guuid=32f662a9-1c00-0000-c16d-e356d2140000 pid=5330 /usr/bin/uvcfpioxkg zombie guuid=0a8f50a5-1c00-0000-c16d-e356cd140000 pid=5325->guuid=32f662a9-1c00-0000-c16d-e356d2140000 pid=5330 clone guuid=759febd1-1d00-0000-c16d-e356d4140000 pid=5332 /usr/bin/jcfconmshx zombie guuid=6ae6d9d1-1d00-0000-c16d-e356d3140000 pid=5331->guuid=759febd1-1d00-0000-c16d-e356d4140000 pid=5332 execve guuid=c203cdd5-1d00-0000-c16d-e356dd140000 pid=5341 /usr/bin/jcfconmshx zombie guuid=759febd1-1d00-0000-c16d-e356d4140000 pid=5332->guuid=c203cdd5-1d00-0000-c16d-e356dd140000 pid=5341 clone guuid=fe101ed2-1d00-0000-c16d-e356d6140000 pid=5334 /usr/bin/jcfconmshx zombie guuid=30820fd2-1d00-0000-c16d-e356d5140000 pid=5333->guuid=fe101ed2-1d00-0000-c16d-e356d6140000 pid=5334 execve guuid=cdc6f4d5-1d00-0000-c16d-e356de140000 pid=5342 /usr/bin/jcfconmshx zombie guuid=fe101ed2-1d00-0000-c16d-e356d6140000 pid=5334->guuid=cdc6f4d5-1d00-0000-c16d-e356de140000 pid=5342 clone guuid=72ff4ad2-1d00-0000-c16d-e356d8140000 pid=5336 /usr/bin/jcfconmshx zombie guuid=f01f3dd2-1d00-0000-c16d-e356d7140000 pid=5335->guuid=72ff4ad2-1d00-0000-c16d-e356d8140000 pid=5336 execve guuid=5e894bd7-1d00-0000-c16d-e356e0140000 pid=5344 /usr/bin/jcfconmshx zombie guuid=72ff4ad2-1d00-0000-c16d-e356d8140000 pid=5336->guuid=5e894bd7-1d00-0000-c16d-e356e0140000 pid=5344 clone guuid=9cf974d2-1d00-0000-c16d-e356da140000 pid=5338 /usr/bin/jcfconmshx zombie guuid=9aa763d2-1d00-0000-c16d-e356d9140000 pid=5337->guuid=9cf974d2-1d00-0000-c16d-e356da140000 pid=5338 execve guuid=b9cf6fd6-1d00-0000-c16d-e356df140000 pid=5343 /usr/bin/jcfconmshx zombie guuid=9cf974d2-1d00-0000-c16d-e356da140000 pid=5338->guuid=b9cf6fd6-1d00-0000-c16d-e356df140000 pid=5343 clone guuid=06b342d3-1d00-0000-c16d-e356dc140000 pid=5340 /usr/bin/jcfconmshx zombie guuid=f7658cd2-1d00-0000-c16d-e356db140000 pid=5339->guuid=06b342d3-1d00-0000-c16d-e356dc140000 pid=5340 execve guuid=726614d8-1d00-0000-c16d-e356e1140000 pid=5345 /usr/bin/jcfconmshx zombie guuid=06b342d3-1d00-0000-c16d-e356dc140000 pid=5340->guuid=726614d8-1d00-0000-c16d-e356e1140000 pid=5345 clone guuid=576d1f00-1f00-0000-c16d-e356e3140000 pid=5347 /usr/bin/ivkjnbgure zombie guuid=857f0c00-1f00-0000-c16d-e356e2140000 pid=5346->guuid=576d1f00-1f00-0000-c16d-e356e3140000 pid=5347 execve guuid=cfc2ac03-1f00-0000-c16d-e356ec140000 pid=5356 /usr/bin/ivkjnbgure zombie guuid=576d1f00-1f00-0000-c16d-e356e3140000 pid=5347->guuid=cfc2ac03-1f00-0000-c16d-e356ec140000 pid=5356 clone guuid=3cc65400-1f00-0000-c16d-e356e5140000 pid=5349 /usr/bin/ivkjnbgure zombie guuid=59233d00-1f00-0000-c16d-e356e4140000 pid=5348->guuid=3cc65400-1f00-0000-c16d-e356e5140000 pid=5349 execve guuid=6bb60104-1f00-0000-c16d-e356ed140000 pid=5357 /usr/bin/ivkjnbgure zombie guuid=3cc65400-1f00-0000-c16d-e356e5140000 pid=5349->guuid=6bb60104-1f00-0000-c16d-e356ed140000 pid=5357 clone guuid=37139600-1f00-0000-c16d-e356e7140000 pid=5351 /usr/bin/ivkjnbgure zombie guuid=80398200-1f00-0000-c16d-e356e6140000 pid=5350->guuid=37139600-1f00-0000-c16d-e356e7140000 pid=5351 execve guuid=aef38b05-1f00-0000-c16d-e356ef140000 pid=5359 /usr/bin/ivkjnbgure zombie guuid=37139600-1f00-0000-c16d-e356e7140000 pid=5351->guuid=aef38b05-1f00-0000-c16d-e356ef140000 pid=5359 clone guuid=c5dec100-1f00-0000-c16d-e356e9140000 pid=5353 /usr/bin/ivkjnbgure zombie guuid=56a6b100-1f00-0000-c16d-e356e8140000 pid=5352->guuid=c5dec100-1f00-0000-c16d-e356e9140000 pid=5353 execve guuid=4fbe3604-1f00-0000-c16d-e356ee140000 pid=5358 /usr/bin/ivkjnbgure zombie guuid=c5dec100-1f00-0000-c16d-e356e9140000 pid=5353->guuid=4fbe3604-1f00-0000-c16d-e356ee140000 pid=5358 clone guuid=1118b901-1f00-0000-c16d-e356eb140000 pid=5355 /usr/bin/ivkjnbgure zombie guuid=fc60dd00-1f00-0000-c16d-e356ea140000 pid=5354->guuid=1118b901-1f00-0000-c16d-e356eb140000 pid=5355 execve guuid=c47c1406-1f00-0000-c16d-e356f0140000 pid=5360 /usr/bin/ivkjnbgure zombie guuid=1118b901-1f00-0000-c16d-e356eb140000 pid=5355->guuid=c47c1406-1f00-0000-c16d-e356f0140000 pid=5360 clone guuid=0d009335-2000-0000-c16d-e356f2140000 pid=5362 /usr/bin/dxeqoyoaed zombie guuid=8a3a8035-2000-0000-c16d-e356f1140000 pid=5361->guuid=0d009335-2000-0000-c16d-e356f2140000 pid=5362 execve guuid=5f589839-2000-0000-c16d-e356fb140000 pid=5371 /usr/bin/dxeqoyoaed zombie guuid=0d009335-2000-0000-c16d-e356f2140000 pid=5362->guuid=5f589839-2000-0000-c16d-e356fb140000 pid=5371 clone guuid=cd60cc35-2000-0000-c16d-e356f4140000 pid=5364 /usr/bin/dxeqoyoaed zombie guuid=7501b435-2000-0000-c16d-e356f3140000 pid=5363->guuid=cd60cc35-2000-0000-c16d-e356f4140000 pid=5364 execve guuid=8265a639-2000-0000-c16d-e356fc140000 pid=5372 /usr/bin/dxeqoyoaed zombie guuid=cd60cc35-2000-0000-c16d-e356f4140000 pid=5364->guuid=8265a639-2000-0000-c16d-e356fc140000 pid=5372 clone guuid=9275ff35-2000-0000-c16d-e356f6140000 pid=5366 /usr/bin/dxeqoyoaed zombie guuid=2325ee35-2000-0000-c16d-e356f5140000 pid=5365->guuid=9275ff35-2000-0000-c16d-e356f6140000 pid=5366 execve guuid=7bc5863b-2000-0000-c16d-e356ff140000 pid=5375 /usr/bin/dxeqoyoaed zombie guuid=9275ff35-2000-0000-c16d-e356f6140000 pid=5366->guuid=7bc5863b-2000-0000-c16d-e356ff140000 pid=5375 clone guuid=70af2336-2000-0000-c16d-e356f8140000 pid=5368 /usr/bin/dxeqoyoaed zombie guuid=0fd81736-2000-0000-c16d-e356f7140000 pid=5367->guuid=70af2336-2000-0000-c16d-e356f8140000 pid=5368 execve guuid=b656e339-2000-0000-c16d-e356fd140000 pid=5373 /usr/bin/dxeqoyoaed zombie guuid=70af2336-2000-0000-c16d-e356f8140000 pid=5368->guuid=b656e339-2000-0000-c16d-e356fd140000 pid=5373 clone guuid=646ef536-2000-0000-c16d-e356fa140000 pid=5370 /usr/bin/dxeqoyoaed zombie guuid=f9a03e36-2000-0000-c16d-e356f9140000 pid=5369->guuid=646ef536-2000-0000-c16d-e356fa140000 pid=5370 execve guuid=113c533b-2000-0000-c16d-e356fe140000 pid=5374 /usr/bin/dxeqoyoaed zombie guuid=646ef536-2000-0000-c16d-e356fa140000 pid=5370->guuid=113c533b-2000-0000-c16d-e356fe140000 pid=5374 clone guuid=3fad2a6b-2100-0000-c16d-e35601150000 pid=5377 /usr/bin/ccehqgosel zombie guuid=5397196b-2100-0000-c16d-e35600150000 pid=5376->guuid=3fad2a6b-2100-0000-c16d-e35601150000 pid=5377 execve guuid=834ffd6e-2100-0000-c16d-e3560a150000 pid=5386 /usr/bin/ccehqgosel zombie guuid=3fad2a6b-2100-0000-c16d-e35601150000 pid=5377->guuid=834ffd6e-2100-0000-c16d-e3560a150000 pid=5386 clone guuid=469d5f6b-2100-0000-c16d-e35603150000 pid=5379 /usr/bin/ccehqgosel zombie guuid=adea506b-2100-0000-c16d-e35602150000 pid=5378->guuid=469d5f6b-2100-0000-c16d-e35603150000 pid=5379 execve guuid=8c9d1a6f-2100-0000-c16d-e3560b150000 pid=5387 /usr/bin/ccehqgosel zombie guuid=469d5f6b-2100-0000-c16d-e35603150000 pid=5379->guuid=8c9d1a6f-2100-0000-c16d-e3560b150000 pid=5387 clone guuid=55cf8c6b-2100-0000-c16d-e35605150000 pid=5381 /usr/bin/ccehqgosel zombie guuid=9e7c7f6b-2100-0000-c16d-e35604150000 pid=5380->guuid=55cf8c6b-2100-0000-c16d-e35605150000 pid=5381 execve guuid=cf598570-2100-0000-c16d-e3560d150000 pid=5389 /usr/bin/ccehqgosel zombie guuid=55cf8c6b-2100-0000-c16d-e35605150000 pid=5381->guuid=cf598570-2100-0000-c16d-e3560d150000 pid=5389 clone guuid=48dcb56b-2100-0000-c16d-e35607150000 pid=5383 /usr/bin/ccehqgosel zombie guuid=8a83a36b-2100-0000-c16d-e35606150000 pid=5382->guuid=48dcb56b-2100-0000-c16d-e35607150000 pid=5383 execve guuid=6d29556f-2100-0000-c16d-e3560c150000 pid=5388 /usr/bin/ccehqgosel zombie guuid=48dcb56b-2100-0000-c16d-e35607150000 pid=5383->guuid=6d29556f-2100-0000-c16d-e3560c150000 pid=5388 clone guuid=d1016b6c-2100-0000-c16d-e35609150000 pid=5385 /usr/bin/ccehqgosel zombie guuid=e82fcc6b-2100-0000-c16d-e35608150000 pid=5384->guuid=d1016b6c-2100-0000-c16d-e35609150000 pid=5385 execve guuid=07edbc70-2100-0000-c16d-e3560e150000 pid=5390 /usr/bin/ccehqgosel zombie guuid=d1016b6c-2100-0000-c16d-e35609150000 pid=5385->guuid=07edbc70-2100-0000-c16d-e3560e150000 pid=5390 clone guuid=cc7782b0-2200-0000-c16d-e35610150000 pid=5392 /usr/bin/xwkrjkivrb zombie guuid=da6d60b0-2200-0000-c16d-e3560f150000 pid=5391->guuid=cc7782b0-2200-0000-c16d-e35610150000 pid=5392 execve guuid=bf71f1b4-2200-0000-c16d-e3561b150000 pid=5403 /usr/bin/xwkrjkivrb zombie guuid=cc7782b0-2200-0000-c16d-e35610150000 pid=5392->guuid=bf71f1b4-2200-0000-c16d-e3561b150000 pid=5403 clone guuid=17abc1b0-2200-0000-c16d-e35612150000 pid=5394 /usr/bin/xwkrjkivrb zombie guuid=0dabb0b0-2200-0000-c16d-e35611150000 pid=5393->guuid=17abc1b0-2200-0000-c16d-e35612150000 pid=5394 execve guuid=79e641b4-2200-0000-c16d-e35619150000 pid=5401 /usr/bin/xwkrjkivrb zombie guuid=17abc1b0-2200-0000-c16d-e35612150000 pid=5394->guuid=79e641b4-2200-0000-c16d-e35619150000 pid=5401 clone guuid=2b46f2b0-2200-0000-c16d-e35614150000 pid=5396 /usr/bin/xwkrjkivrb zombie guuid=72e8e4b0-2200-0000-c16d-e35613150000 pid=5395->guuid=2b46f2b0-2200-0000-c16d-e35614150000 pid=5396 execve guuid=d91bcfb5-2200-0000-c16d-e3561c150000 pid=5404 /usr/bin/xwkrjkivrb zombie guuid=2b46f2b0-2200-0000-c16d-e35614150000 pid=5396->guuid=d91bcfb5-2200-0000-c16d-e3561c150000 pid=5404 clone guuid=fec917b1-2200-0000-c16d-e35616150000 pid=5398 /usr/bin/xwkrjkivrb zombie guuid=37190cb1-2200-0000-c16d-e35615150000 pid=5397->guuid=fec917b1-2200-0000-c16d-e35616150000 pid=5398 execve guuid=687dcdb4-2200-0000-c16d-e3561a150000 pid=5402 /usr/bin/xwkrjkivrb zombie guuid=fec917b1-2200-0000-c16d-e35616150000 pid=5398->guuid=687dcdb4-2200-0000-c16d-e3561a150000 pid=5402 clone guuid=b9ffdcb1-2200-0000-c16d-e35618150000 pid=5400 /usr/bin/xwkrjkivrb zombie guuid=6c8c35b1-2200-0000-c16d-e35617150000 pid=5399->guuid=b9ffdcb1-2200-0000-c16d-e35618150000 pid=5400 execve guuid=53b158b6-2200-0000-c16d-e3561d150000 pid=5405 /usr/bin/xwkrjkivrb zombie guuid=b9ffdcb1-2200-0000-c16d-e35618150000 pid=5400->guuid=53b158b6-2200-0000-c16d-e3561d150000 pid=5405 clone guuid=dec288e1-2300-0000-c16d-e3561f150000 pid=5407 /usr/bin/nqlbktxnvf zombie guuid=9f2b78e1-2300-0000-c16d-e3561e150000 pid=5406->guuid=dec288e1-2300-0000-c16d-e3561f150000 pid=5407 execve guuid=28e07fe5-2300-0000-c16d-e35629150000 pid=5417 /usr/bin/nqlbktxnvf zombie guuid=dec288e1-2300-0000-c16d-e3561f150000 pid=5407->guuid=28e07fe5-2300-0000-c16d-e35629150000 pid=5417 clone guuid=2a6ebce1-2300-0000-c16d-e35621150000 pid=5409 /usr/bin/nqlbktxnvf zombie guuid=f5f2a9e1-2300-0000-c16d-e35620150000 pid=5408->guuid=2a6ebce1-2300-0000-c16d-e35621150000 pid=5409 execve guuid=0a514fe5-2300-0000-c16d-e35628150000 pid=5416 /usr/bin/nqlbktxnvf zombie guuid=2a6ebce1-2300-0000-c16d-e35621150000 pid=5409->guuid=0a514fe5-2300-0000-c16d-e35628150000 pid=5416 clone guuid=dc1eede1-2300-0000-c16d-e35623150000 pid=5411 /usr/bin/nqlbktxnvf zombie guuid=b35fdee1-2300-0000-c16d-e35622150000 pid=5410->guuid=dc1eede1-2300-0000-c16d-e35623150000 pid=5411 execve guuid=c321a8e6-2300-0000-c16d-e3562b150000 pid=5419 /usr/bin/nqlbktxnvf zombie guuid=dc1eede1-2300-0000-c16d-e35623150000 pid=5411->guuid=c321a8e6-2300-0000-c16d-e3562b150000 pid=5419 clone guuid=089f19e2-2300-0000-c16d-e35625150000 pid=5413 /usr/bin/nqlbktxnvf zombie guuid=f64b0ce2-2300-0000-c16d-e35624150000 pid=5412->guuid=089f19e2-2300-0000-c16d-e35625150000 pid=5413 execve guuid=888e33e6-2300-0000-c16d-e3562a150000 pid=5418 /usr/bin/nqlbktxnvf zombie guuid=089f19e2-2300-0000-c16d-e35625150000 pid=5413->guuid=888e33e6-2300-0000-c16d-e3562a150000 pid=5418 clone guuid=29e804e3-2300-0000-c16d-e35627150000 pid=5415 /usr/bin/nqlbktxnvf zombie guuid=8ef130e2-2300-0000-c16d-e35626150000 pid=5414->guuid=29e804e3-2300-0000-c16d-e35627150000 pid=5415 execve guuid=7f3168e7-2300-0000-c16d-e3562c150000 pid=5420 /usr/bin/nqlbktxnvf zombie guuid=29e804e3-2300-0000-c16d-e35627150000 pid=5415->guuid=7f3168e7-2300-0000-c16d-e3562c150000 pid=5420 clone guuid=38739a0f-2500-0000-c16d-e3562e150000 pid=5422 /usr/bin/bthfpsjzac zombie guuid=bf3a880f-2500-0000-c16d-e3562d150000 pid=5421->guuid=38739a0f-2500-0000-c16d-e3562e150000 pid=5422 execve guuid=bb877d12-2500-0000-c16d-e35637150000 pid=5431 /usr/bin/bthfpsjzac zombie guuid=38739a0f-2500-0000-c16d-e3562e150000 pid=5422->guuid=bb877d12-2500-0000-c16d-e35637150000 pid=5431 clone guuid=a0e7cd0f-2500-0000-c16d-e35630150000 pid=5424 /usr/bin/bthfpsjzac zombie guuid=d11ebe0f-2500-0000-c16d-e3562f150000 pid=5423->guuid=a0e7cd0f-2500-0000-c16d-e35630150000 pid=5424 execve guuid=5a9e9c12-2500-0000-c16d-e35638150000 pid=5432 /usr/bin/bthfpsjzac zombie guuid=a0e7cd0f-2500-0000-c16d-e35630150000 pid=5424->guuid=5a9e9c12-2500-0000-c16d-e35638150000 pid=5432 clone guuid=f38cff0f-2500-0000-c16d-e35632150000 pid=5426 /usr/bin/bthfpsjzac zombie guuid=546bf00f-2500-0000-c16d-e35631150000 pid=5425->guuid=f38cff0f-2500-0000-c16d-e35632150000 pid=5426 execve guuid=08d3a514-2500-0000-c16d-e35639150000 pid=5433 /usr/bin/bthfpsjzac zombie guuid=f38cff0f-2500-0000-c16d-e35632150000 pid=5426->guuid=08d3a514-2500-0000-c16d-e35639150000 pid=5433 clone guuid=1be92a10-2500-0000-c16d-e35634150000 pid=5428 /usr/bin/bthfpsjzac zombie guuid=a7311910-2500-0000-c16d-e35633150000 pid=5427->guuid=1be92a10-2500-0000-c16d-e35634150000 pid=5428 execve guuid=fe86dc14-2500-0000-c16d-e3563a150000 pid=5434 /usr/bin/bthfpsjzac zombie guuid=1be92a10-2500-0000-c16d-e35634150000 pid=5428->guuid=fe86dc14-2500-0000-c16d-e3563a150000 pid=5434 clone guuid=50a4df10-2500-0000-c16d-e35636150000 pid=5430 /usr/bin/bthfpsjzac zombie guuid=f9884210-2500-0000-c16d-e35635150000 pid=5429->guuid=50a4df10-2500-0000-c16d-e35636150000 pid=5430 execve guuid=b9bb5715-2500-0000-c16d-e3563b150000 pid=5435 /usr/bin/bthfpsjzac zombie guuid=50a4df10-2500-0000-c16d-e35636150000 pid=5430->guuid=b9bb5715-2500-0000-c16d-e3563b150000 pid=5435 clone guuid=a01e963d-2600-0000-c16d-e3563d150000 pid=5437 /usr/bin/wanyubghvs zombie guuid=27387e3d-2600-0000-c16d-e3563c150000 pid=5436->guuid=a01e963d-2600-0000-c16d-e3563d150000 pid=5437 execve guuid=032d8c41-2600-0000-c16d-e35646150000 pid=5446 /usr/bin/wanyubghvs zombie guuid=a01e963d-2600-0000-c16d-e3563d150000 pid=5437->guuid=032d8c41-2600-0000-c16d-e35646150000 pid=5446 clone guuid=da41d33d-2600-0000-c16d-e3563f150000 pid=5439 /usr/bin/wanyubghvs zombie guuid=4213c23d-2600-0000-c16d-e3563e150000 pid=5438->guuid=da41d33d-2600-0000-c16d-e3563f150000 pid=5439 execve guuid=73c8f242-2600-0000-c16d-e35649150000 pid=5449 /usr/bin/wanyubghvs zombie guuid=da41d33d-2600-0000-c16d-e3563f150000 pid=5439->guuid=73c8f242-2600-0000-c16d-e35649150000 pid=5449 clone guuid=7662063e-2600-0000-c16d-e35641150000 pid=5441 /usr/bin/wanyubghvs zombie guuid=786ef13d-2600-0000-c16d-e35640150000 pid=5440->guuid=7662063e-2600-0000-c16d-e35641150000 pid=5441 execve guuid=4054b642-2600-0000-c16d-e35648150000 pid=5448 /usr/bin/wanyubghvs zombie guuid=7662063e-2600-0000-c16d-e35641150000 pid=5441->guuid=4054b642-2600-0000-c16d-e35648150000 pid=5448 clone guuid=640f353e-2600-0000-c16d-e35643150000 pid=5443 /usr/bin/wanyubghvs zombie guuid=538c233e-2600-0000-c16d-e35642150000 pid=5442->guuid=640f353e-2600-0000-c16d-e35643150000 pid=5443 execve guuid=d1228942-2600-0000-c16d-e35647150000 pid=5447 /usr/bin/wanyubghvs zombie guuid=640f353e-2600-0000-c16d-e35643150000 pid=5443->guuid=d1228942-2600-0000-c16d-e35647150000 pid=5447 clone guuid=ba66f23e-2600-0000-c16d-e35645150000 pid=5445 /usr/bin/wanyubghvs zombie guuid=e8844e3e-2600-0000-c16d-e35644150000 pid=5444->guuid=ba66f23e-2600-0000-c16d-e35645150000 pid=5445 execve guuid=a4928843-2600-0000-c16d-e3564a150000 pid=5450 /usr/bin/wanyubghvs zombie guuid=ba66f23e-2600-0000-c16d-e35645150000 pid=5445->guuid=a4928843-2600-0000-c16d-e3564a150000 pid=5450 clone
Result
Threat name:
XorDDoS
Detection:
malicious
Classification:
troj.evad
Score:
100 / 100
Signature
Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Drops files in suspicious directories
Found malware configuration
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Sample deletes itself
Sample tries to persist itself using cron
Sample tries to persist itself using System V runlevels
Suricata IDS alerts for network traffic
Yara detected XorDDoS Bot
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1764047 Sample: p.txt.elf Startdate: 24/08/2025 Architecture: LINUX Score: 100 72 ll.vvbb321.com 5.196.167.240, 1528, 38448 OVHFR France 2->72 74 ll.nnmm234.com 2->74 76 2 other IPs or domains 2->76 78 Suricata IDS alerts for network traffic 2->78 80 Found malware configuration 2->80 82 Malicious sample detected (through community Yara rule) 2->82 84 4 other signatures 2->84 10 p.txt.elf 2->10         started        12 systemd snapd-env-generator 2->12         started        signatures3 process4 process5 14 p.txt.elf 10->14         started        file6 64 /usr/lib/libudev.so, ELF 14->64 dropped 66 /usr/bin/radhhirimg, ELF 14->66 dropped 68 /usr/bin/qemnpgaled, ELF 14->68 dropped 70 16 other malicious files 14->70 dropped 92 Drops files in suspicious directories 14->92 94 Sample deletes itself 14->94 96 Sample tries to persist itself using cron 14->96 98 Sample tries to persist itself using System V runlevels 14->98 18 p.txt.elf sh 14->18         started        22 p.txt.elf 14->22         started        24 p.txt.elf 14->24         started        26 120 other processes 14->26 signatures7 process8 file9 62 /etc/crontab, ASCII 18->62 dropped 86 Sample tries to persist itself using cron 18->86 28 sh sed 18->28         started        31 p.txt.elf qemnpgaled 22->31         started        33 p.txt.elf qemnpgaled 24->33         started        35 p.txt.elf qemnpgaled 26->35         started        37 p.txt.elf qemnpgaled 26->37         started        39 p.txt.elf qemnpgaled 26->39         started        41 117 other processes 26->41 signatures10 process11 signatures12 90 Sample tries to persist itself using cron 28->90 43 qemnpgaled 31->43         started        46 qemnpgaled 33->46         started        48 qemnpgaled 35->48         started        50 qemnpgaled 37->50         started        52 qemnpgaled 39->52         started        54 ebfmgkegvo 41->54         started        56 ebfmgkegvo 41->56         started        58 ebfmgkegvo 41->58         started        60 108 other processes 41->60 process13 signatures14 88 Sample deletes itself 43->88
Threat name:
Linux.Trojan.XorDDoS
Status:
Malicious
First seen:
2025-08-24 18:16:40 UTC
File Type:
ELF32 Little (Exe)
AV detection:
19 of 24 (79.17%)
Threat level:
  5/5
Result
Malware family:
xorddos
Score:
  10/10
Tags:
family:xorddos botnet discovery downloader execution linux persistence privilege_escalation rootkit
Behaviour
Reads runtime system information
Creates/modifies Cron job
Loads a kernel module
Writes memory of remote process
XorDDoS
XorDDoS payload
Xorddos family
Malware Config
C2 Extraction:
https://ww.aass654.com/config.rar
ll.aass654.com:1528
ll.xxcc789.com:1528
ll.vvbb321.com:1528
ll.jjkk567.com:1528
ll.nnmm234.com:1528
Verdict:
Malicious
Tags:
backdoor trojan xor_ddos Unix.Malware.Xorddos-9856891-0
YARA:
libgcc_backdoor Linux_Trojan_Xorddos_2aef46a6 Linux_Trojan_Xorddos_884cab60 MALWARE_Linux_XORDDoS
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:CP_AllMal_Detector
Author:DiegoAnalytics
Description:CrossPlatform All Malwares Detector: Detect PE, ELF, Mach-O, scripts, archives; overlay, obfuscation, encryption, spoofing, hiding, high entropy, network communication
Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:enterpriseapps2
Author:Tim Brown @timb_machine
Description:Enterprise apps
Rule name:F01_s1ckrule
Author:s1ckb017
Rule name:linux_generic_ipv6_catcher
Author:@_lubiedo
Description:ELF samples using IPv6 addresses
Rule name:Linux_Trojan_Xorddos_2aef46a6
Author:Elastic Security
Rule name:MALWARE_Linux_XORDDoS
Author:ditekSHen
Description:Detects XORDDoS
Rule name:NET
Author:malware-lu
Rule name:unixredflags3
Author:Tim Brown @timb_machine
Description:Hunts for UNIX red flags

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

XorDDoS

elf 10e43894490d98a91f3d409a83d984556d619e91782333033ad3d7fb1b9def8b

(this sample)

  
Delivery method
Distributed via web download

Comments