MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5b15e7a49f953e28a06ee8aa2d50811edd8566005117af2b0599d07bbd41d8d9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



XorDDoS


Vendor detections: 12


Intelligence 12 IOCs YARA 11 File information Comments

SHA256 hash: 5b15e7a49f953e28a06ee8aa2d50811edd8566005117af2b0599d07bbd41d8d9
SHA3-384 hash: ec3124f0e2901284c8d604bcc18ee16e7482866b8ed026b84afdda62611f22e91a70375f4acbed0f8d55ad59d8f8bf51
SHA1 hash: 0651b6070b704df55893580a9e6871b69e353604
MD5 hash: 87b48cad3e05edc3a20bc65539c0cfc7
humanhash: bakerloo-jupiter-yankee-skylark
File name:p.txt
Download: download sample
Signature XorDDoS
File size:555'272 bytes
First seen:2026-02-19 13:07:31 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 12288:VBPbw1CH/FwznbIU9sE8c8lqd49N94wT4JoqLLp6yWrk3:VBPWCH/eMU9Uc8gd49N94BJoqLL4ru
TLSH T166C45C06F283A2F7D42705B0124BF7BF8620F63594129D9BB7989D5AB9338F12A4D353
telfhash t129c16ab23eb059d9b3f0880282667220ce19e42765d4397a1df3b194fbf2d522b35d79
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter abuse_ch
Tags:elf XorDDoS

Intelligence


File Origin
# of uploads :
1
# of downloads :
48
Origin country :
DE DE
Vendor Threat Intelligence
Malware configuration found for:
XORDDoS
Details
XORDDoS
a string XOR key, C2 socket addresses, a C2 url, a version number, and filepaths
Result
Verdict:
Malware
Maliciousness:

Behaviour
Manages services
Receives data from a server
Sends data to a server
Collects information on the RAM
Launching a process
Connection attempt
DNS request
Changes owner for a written file
Creating a file
Collects information on the CPU
Collects information on the network activity
Runs as daemon
Creating a process from a recently created file
Writes files to system directory
Creates or modifies files in /cron to set up autorun
Deletes a system binary file
Creates or modifies files in /init.d to set up autorun
Creates or modifies symbolic links in /init.d to set up autorun
Deleting of the original file
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
gcc masquerade xorddos
Verdict:
Malicious
File Type:
elf.32.le
Detections:
HEUR:Trojan-DDoS.Linux.Agent.g HEUR:Trojan-DDoS.Linux.Agent.a HEUR:Trojan-DDoS.Linux.Xorddos.gen HEUR:Trojan-DDoS.Linux.Xarcen.d HEUR:Trojan-DDoS.Linux.Xarcen.a
Status:
terminated
Behavior Graph:
%3 guuid=57f02bbe-1600-0000-8e20-229dcc0f0000 pid=4044 /usr/bin/sudo guuid=fe25afbf-1600-0000-8e20-229dd60f0000 pid=4054 /tmp/sample.bin guuid=57f02bbe-1600-0000-8e20-229dcc0f0000 pid=4044->guuid=fe25afbf-1600-0000-8e20-229dd60f0000 pid=4054 execve guuid=64ceddbf-1600-0000-8e20-229dd70f0000 pid=4055 /tmp/sample.bin delete-file write-config write-file zombie guuid=fe25afbf-1600-0000-8e20-229dd60f0000 pid=4054->guuid=64ceddbf-1600-0000-8e20-229dd70f0000 pid=4055 clone guuid=e1ae3cc0-1600-0000-8e20-229dda0f0000 pid=4058 /tmp/sample.bin guuid=64ceddbf-1600-0000-8e20-229dd70f0000 pid=4055->guuid=e1ae3cc0-1600-0000-8e20-229dda0f0000 pid=4058 clone guuid=746947c0-1600-0000-8e20-229ddc0f0000 pid=4060 /tmp/sample.bin guuid=64ceddbf-1600-0000-8e20-229dd70f0000 pid=4055->guuid=746947c0-1600-0000-8e20-229ddc0f0000 pid=4060 clone guuid=0b91dfc0-1600-0000-8e20-229de10f0000 pid=4065 /usr/bin/dash guuid=64ceddbf-1600-0000-8e20-229dd70f0000 pid=4055->guuid=0b91dfc0-1600-0000-8e20-229de10f0000 pid=4065 execve guuid=64ceddbf-1600-0000-8e20-229dd70f0000 pid=4070 /tmp/sample.bin write-file zombie guuid=64ceddbf-1600-0000-8e20-229dd70f0000 pid=4055->guuid=64ceddbf-1600-0000-8e20-229dd70f0000 pid=4070 clone guuid=64ceddbf-1600-0000-8e20-229dd70f0000 pid=4071 /tmp/sample.bin dns net send-data write-file zombie guuid=64ceddbf-1600-0000-8e20-229dd70f0000 pid=4055->guuid=64ceddbf-1600-0000-8e20-229dd70f0000 pid=4071 clone guuid=64ceddbf-1600-0000-8e20-229dd70f0000 pid=4072 /tmp/sample.bin net zombie guuid=64ceddbf-1600-0000-8e20-229dd70f0000 pid=4055->guuid=64ceddbf-1600-0000-8e20-229dd70f0000 pid=4072 clone guuid=e26d1df8-1700-0000-8e20-229d7d140000 pid=5245 /tmp/sample.bin guuid=64ceddbf-1600-0000-8e20-229dd70f0000 pid=4055->guuid=e26d1df8-1700-0000-8e20-229d7d140000 pid=5245 clone guuid=05963af8-1700-0000-8e20-229d7f140000 pid=5247 /tmp/sample.bin guuid=64ceddbf-1600-0000-8e20-229dd70f0000 pid=4055->guuid=05963af8-1700-0000-8e20-229d7f140000 pid=5247 clone guuid=101352f8-1700-0000-8e20-229d81140000 pid=5249 /tmp/sample.bin guuid=64ceddbf-1600-0000-8e20-229dd70f0000 pid=4055->guuid=101352f8-1700-0000-8e20-229d81140000 pid=5249 clone guuid=c9e964f8-1700-0000-8e20-229d83140000 pid=5251 /tmp/sample.bin guuid=64ceddbf-1600-0000-8e20-229dd70f0000 pid=4055->guuid=c9e964f8-1700-0000-8e20-229d83140000 pid=5251 clone guuid=cb0377f8-1700-0000-8e20-229d85140000 pid=5253 /tmp/sample.bin guuid=64ceddbf-1600-0000-8e20-229dd70f0000 pid=4055->guuid=cb0377f8-1700-0000-8e20-229d85140000 pid=5253 clone guuid=3746722d-1900-0000-8e20-229d9b140000 pid=5275 /tmp/sample.bin guuid=64ceddbf-1600-0000-8e20-229dd70f0000 pid=4055->guuid=3746722d-1900-0000-8e20-229d9b140000 pid=5275 clone guuid=02f8b32d-1900-0000-8e20-229d9d140000 pid=5277 /tmp/sample.bin guuid=64ceddbf-1600-0000-8e20-229dd70f0000 pid=4055->guuid=02f8b32d-1900-0000-8e20-229d9d140000 pid=5277 clone guuid=ee05162e-1900-0000-8e20-229d9f140000 pid=5279 /tmp/sample.bin guuid=64ceddbf-1600-0000-8e20-229dd70f0000 pid=4055->guuid=ee05162e-1900-0000-8e20-229d9f140000 pid=5279 clone guuid=56b4a82e-1900-0000-8e20-229da1140000 pid=5281 /tmp/sample.bin guuid=64ceddbf-1600-0000-8e20-229dd70f0000 pid=4055->guuid=56b4a82e-1900-0000-8e20-229da1140000 pid=5281 clone guuid=7f73a22f-1900-0000-8e20-229da3140000 pid=5283 /tmp/sample.bin guuid=64ceddbf-1600-0000-8e20-229dd70f0000 pid=4055->guuid=7f73a22f-1900-0000-8e20-229da3140000 pid=5283 clone guuid=fe33405c-1a00-0000-8e20-229dfd140000 pid=5373 /tmp/sample.bin guuid=64ceddbf-1600-0000-8e20-229dd70f0000 pid=4055->guuid=fe33405c-1a00-0000-8e20-229dfd140000 pid=5373 clone guuid=2de5545c-1a00-0000-8e20-229dff140000 pid=5375 /tmp/sample.bin guuid=64ceddbf-1600-0000-8e20-229dd70f0000 pid=4055->guuid=2de5545c-1a00-0000-8e20-229dff140000 pid=5375 clone guuid=669a655c-1a00-0000-8e20-229d01150000 pid=5377 /tmp/sample.bin guuid=64ceddbf-1600-0000-8e20-229dd70f0000 pid=4055->guuid=669a655c-1a00-0000-8e20-229d01150000 pid=5377 clone guuid=d657825c-1a00-0000-8e20-229d03150000 pid=5379 /tmp/sample.bin guuid=64ceddbf-1600-0000-8e20-229dd70f0000 pid=4055->guuid=d657825c-1a00-0000-8e20-229d03150000 pid=5379 clone guuid=85ceff5c-1a00-0000-8e20-229d05150000 pid=5381 /tmp/sample.bin guuid=64ceddbf-1600-0000-8e20-229dd70f0000 pid=4055->guuid=85ceff5c-1a00-0000-8e20-229d05150000 pid=5381 clone guuid=9a930089-1b00-0000-8e20-229d78150000 pid=5496 /tmp/sample.bin guuid=64ceddbf-1600-0000-8e20-229dd70f0000 pid=4055->guuid=9a930089-1b00-0000-8e20-229d78150000 pid=5496 clone guuid=a5c22389-1b00-0000-8e20-229d7a150000 pid=5498 /tmp/sample.bin guuid=64ceddbf-1600-0000-8e20-229dd70f0000 pid=4055->guuid=a5c22389-1b00-0000-8e20-229d7a150000 pid=5498 clone guuid=ff363589-1b00-0000-8e20-229d7c150000 pid=5500 /tmp/sample.bin guuid=64ceddbf-1600-0000-8e20-229dd70f0000 pid=4055->guuid=ff363589-1b00-0000-8e20-229d7c150000 pid=5500 clone guuid=9ccf4589-1b00-0000-8e20-229d7e150000 pid=5502 /tmp/sample.bin guuid=64ceddbf-1600-0000-8e20-229dd70f0000 pid=4055->guuid=9ccf4589-1b00-0000-8e20-229d7e150000 pid=5502 clone guuid=4d251d8a-1b00-0000-8e20-229d80150000 pid=5504 /tmp/sample.bin guuid=64ceddbf-1600-0000-8e20-229dd70f0000 pid=4055->guuid=4d251d8a-1b00-0000-8e20-229d80150000 pid=5504 clone guuid=cbc7f8b6-1c00-0000-8e20-229deb150000 pid=5611 /tmp/sample.bin guuid=64ceddbf-1600-0000-8e20-229dd70f0000 pid=4055->guuid=cbc7f8b6-1c00-0000-8e20-229deb150000 pid=5611 clone guuid=c0c71fb7-1c00-0000-8e20-229ded150000 pid=5613 /tmp/sample.bin guuid=64ceddbf-1600-0000-8e20-229dd70f0000 pid=4055->guuid=c0c71fb7-1c00-0000-8e20-229ded150000 pid=5613 clone guuid=06e234b7-1c00-0000-8e20-229def150000 pid=5615 /tmp/sample.bin guuid=64ceddbf-1600-0000-8e20-229dd70f0000 pid=4055->guuid=06e234b7-1c00-0000-8e20-229def150000 pid=5615 clone guuid=fb2147b7-1c00-0000-8e20-229df1150000 pid=5617 /tmp/sample.bin guuid=64ceddbf-1600-0000-8e20-229dd70f0000 pid=4055->guuid=fb2147b7-1c00-0000-8e20-229df1150000 pid=5617 clone guuid=012c35b8-1c00-0000-8e20-229df3150000 pid=5619 /tmp/sample.bin guuid=64ceddbf-1600-0000-8e20-229dd70f0000 pid=4055->guuid=012c35b8-1c00-0000-8e20-229df3150000 pid=5619 clone guuid=299133e5-1d00-0000-8e20-229dfa150000 pid=5626 /tmp/sample.bin guuid=64ceddbf-1600-0000-8e20-229dd70f0000 pid=4055->guuid=299133e5-1d00-0000-8e20-229dfa150000 pid=5626 clone guuid=a7046fe5-1d00-0000-8e20-229dfc150000 pid=5628 /tmp/sample.bin guuid=64ceddbf-1600-0000-8e20-229dd70f0000 pid=4055->guuid=a7046fe5-1d00-0000-8e20-229dfc150000 pid=5628 clone guuid=a211cae5-1d00-0000-8e20-229dfe150000 pid=5630 /tmp/sample.bin guuid=64ceddbf-1600-0000-8e20-229dd70f0000 pid=4055->guuid=a211cae5-1d00-0000-8e20-229dfe150000 pid=5630 clone guuid=6a5af8e5-1d00-0000-8e20-229d00160000 pid=5632 /tmp/sample.bin guuid=64ceddbf-1600-0000-8e20-229dd70f0000 pid=4055->guuid=6a5af8e5-1d00-0000-8e20-229d00160000 pid=5632 clone guuid=9250c9e6-1d00-0000-8e20-229d02160000 pid=5634 /tmp/sample.bin guuid=64ceddbf-1600-0000-8e20-229dd70f0000 pid=4055->guuid=9250c9e6-1d00-0000-8e20-229d02160000 pid=5634 clone guuid=f692a612-1f00-0000-8e20-229d09160000 pid=5641 /tmp/sample.bin guuid=64ceddbf-1600-0000-8e20-229dd70f0000 pid=4055->guuid=f692a612-1f00-0000-8e20-229d09160000 pid=5641 clone guuid=722bc212-1f00-0000-8e20-229d0b160000 pid=5643 /tmp/sample.bin guuid=64ceddbf-1600-0000-8e20-229dd70f0000 pid=4055->guuid=722bc212-1f00-0000-8e20-229d0b160000 pid=5643 clone guuid=ce53d412-1f00-0000-8e20-229d0d160000 pid=5645 /tmp/sample.bin guuid=64ceddbf-1600-0000-8e20-229dd70f0000 pid=4055->guuid=ce53d412-1f00-0000-8e20-229d0d160000 pid=5645 clone guuid=dbc4e812-1f00-0000-8e20-229d0f160000 pid=5647 /tmp/sample.bin guuid=64ceddbf-1600-0000-8e20-229dd70f0000 pid=4055->guuid=dbc4e812-1f00-0000-8e20-229d0f160000 pid=5647 clone guuid=16dda013-1f00-0000-8e20-229d11160000 pid=5649 /tmp/sample.bin guuid=64ceddbf-1600-0000-8e20-229dd70f0000 pid=4055->guuid=16dda013-1f00-0000-8e20-229d11160000 pid=5649 clone guuid=44075442-2000-0000-8e20-229d18160000 pid=5656 /tmp/sample.bin guuid=64ceddbf-1600-0000-8e20-229dd70f0000 pid=4055->guuid=44075442-2000-0000-8e20-229d18160000 pid=5656 clone guuid=9cb68342-2000-0000-8e20-229d1a160000 pid=5658 /tmp/sample.bin guuid=64ceddbf-1600-0000-8e20-229dd70f0000 pid=4055->guuid=9cb68342-2000-0000-8e20-229d1a160000 pid=5658 clone guuid=90a1a242-2000-0000-8e20-229d1c160000 pid=5660 /tmp/sample.bin guuid=64ceddbf-1600-0000-8e20-229dd70f0000 pid=4055->guuid=90a1a242-2000-0000-8e20-229d1c160000 pid=5660 clone guuid=6409bd42-2000-0000-8e20-229d1e160000 pid=5662 /tmp/sample.bin guuid=64ceddbf-1600-0000-8e20-229dd70f0000 pid=4055->guuid=6409bd42-2000-0000-8e20-229d1e160000 pid=5662 clone guuid=e61c6b43-2000-0000-8e20-229d20160000 pid=5664 /tmp/sample.bin guuid=64ceddbf-1600-0000-8e20-229dd70f0000 pid=4055->guuid=e61c6b43-2000-0000-8e20-229d20160000 pid=5664 clone guuid=5c774573-2100-0000-8e20-229d27160000 pid=5671 /tmp/sample.bin guuid=64ceddbf-1600-0000-8e20-229dd70f0000 pid=4055->guuid=5c774573-2100-0000-8e20-229d27160000 pid=5671 clone guuid=ff1e5b73-2100-0000-8e20-229d29160000 pid=5673 /tmp/sample.bin guuid=64ceddbf-1600-0000-8e20-229dd70f0000 pid=4055->guuid=ff1e5b73-2100-0000-8e20-229d29160000 pid=5673 clone guuid=7efc6c73-2100-0000-8e20-229d2b160000 pid=5675 /tmp/sample.bin guuid=64ceddbf-1600-0000-8e20-229dd70f0000 pid=4055->guuid=7efc6c73-2100-0000-8e20-229d2b160000 pid=5675 clone guuid=53417e73-2100-0000-8e20-229d2d160000 pid=5677 /tmp/sample.bin guuid=64ceddbf-1600-0000-8e20-229dd70f0000 pid=4055->guuid=53417e73-2100-0000-8e20-229d2d160000 pid=5677 clone guuid=c2708774-2100-0000-8e20-229d2f160000 pid=5679 /tmp/sample.bin guuid=64ceddbf-1600-0000-8e20-229dd70f0000 pid=4055->guuid=c2708774-2100-0000-8e20-229d2f160000 pid=5679 clone guuid=ae33c3a0-2200-0000-8e20-229d3d160000 pid=5693 /tmp/sample.bin guuid=64ceddbf-1600-0000-8e20-229dd70f0000 pid=4055->guuid=ae33c3a0-2200-0000-8e20-229d3d160000 pid=5693 clone guuid=bf35eba0-2200-0000-8e20-229d3f160000 pid=5695 /tmp/sample.bin guuid=64ceddbf-1600-0000-8e20-229dd70f0000 pid=4055->guuid=bf35eba0-2200-0000-8e20-229d3f160000 pid=5695 clone guuid=439609a1-2200-0000-8e20-229d41160000 pid=5697 /tmp/sample.bin guuid=64ceddbf-1600-0000-8e20-229dd70f0000 pid=4055->guuid=439609a1-2200-0000-8e20-229d41160000 pid=5697 clone guuid=162524a1-2200-0000-8e20-229d43160000 pid=5699 /tmp/sample.bin guuid=64ceddbf-1600-0000-8e20-229dd70f0000 pid=4055->guuid=162524a1-2200-0000-8e20-229d43160000 pid=5699 clone guuid=add0d1a1-2200-0000-8e20-229d45160000 pid=5701 /tmp/sample.bin guuid=64ceddbf-1600-0000-8e20-229dd70f0000 pid=4055->guuid=add0d1a1-2200-0000-8e20-229d45160000 pid=5701 clone guuid=c2f6c2d5-2300-0000-8e20-229d4d160000 pid=5709 /tmp/sample.bin guuid=64ceddbf-1600-0000-8e20-229dd70f0000 pid=4055->guuid=c2f6c2d5-2300-0000-8e20-229d4d160000 pid=5709 clone guuid=8f43e2d5-2300-0000-8e20-229d4f160000 pid=5711 /tmp/sample.bin guuid=64ceddbf-1600-0000-8e20-229dd70f0000 pid=4055->guuid=8f43e2d5-2300-0000-8e20-229d4f160000 pid=5711 clone guuid=191ff9d5-2300-0000-8e20-229d51160000 pid=5713 /tmp/sample.bin guuid=64ceddbf-1600-0000-8e20-229dd70f0000 pid=4055->guuid=191ff9d5-2300-0000-8e20-229d51160000 pid=5713 clone guuid=ad0b0cd6-2300-0000-8e20-229d53160000 pid=5715 /tmp/sample.bin guuid=64ceddbf-1600-0000-8e20-229dd70f0000 pid=4055->guuid=ad0b0cd6-2300-0000-8e20-229d53160000 pid=5715 clone guuid=7e171fd6-2300-0000-8e20-229d55160000 pid=5717 /tmp/sample.bin guuid=64ceddbf-1600-0000-8e20-229dd70f0000 pid=4055->guuid=7e171fd6-2300-0000-8e20-229d55160000 pid=5717 clone guuid=19bd41c0-1600-0000-8e20-229ddb0f0000 pid=4059 /tmp/sample.bin guuid=e1ae3cc0-1600-0000-8e20-229dda0f0000 pid=4058->guuid=19bd41c0-1600-0000-8e20-229ddb0f0000 pid=4059 clone guuid=b526d6c0-1600-0000-8e20-229de00f0000 pid=4064 /usr/sbin/update-rc.d zombie guuid=746947c0-1600-0000-8e20-229ddc0f0000 pid=4060->guuid=b526d6c0-1600-0000-8e20-229de00f0000 pid=4064 execve guuid=a042d4c7-1600-0000-8e20-229dfe0f0000 pid=4094 /usr/bin/systemctl guuid=b526d6c0-1600-0000-8e20-229de00f0000 pid=4064->guuid=a042d4c7-1600-0000-8e20-229dfe0f0000 pid=4094 execve guuid=934d60c1-1600-0000-8e20-229de20f0000 pid=4066 /usr/bin/sed guuid=0b91dfc0-1600-0000-8e20-229de10f0000 pid=4065->guuid=934d60c1-1600-0000-8e20-229de20f0000 pid=4066 execve 92d42247-2273-58b8-bf40-3796f4db0e8d sys-kernel-update.to:1530 guuid=64ceddbf-1600-0000-8e20-229dd70f0000 pid=4071->92d42247-2273-58b8-bf40-3796f4db0e8d send: 4548B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=64ceddbf-1600-0000-8e20-229dd70f0000 pid=4071->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 38B 87f248b3-21f7-50eb-a2c7-cb35eca5cc17 0.0.0.0:80 guuid=64ceddbf-1600-0000-8e20-229dd70f0000 pid=4072->87f248b3-21f7-50eb-a2c7-cb35eca5cc17 con guuid=6e4228f8-1700-0000-8e20-229d7e140000 pid=5246 /usr/bin/clrfwoekkq zombie guuid=e26d1df8-1700-0000-8e20-229d7d140000 pid=5245->guuid=6e4228f8-1700-0000-8e20-229d7e140000 pid=5246 execve guuid=cc6fb3fa-1700-0000-8e20-229d88140000 pid=5256 /usr/bin/clrfwoekkq zombie guuid=6e4228f8-1700-0000-8e20-229d7e140000 pid=5246->guuid=cc6fb3fa-1700-0000-8e20-229d88140000 pid=5256 clone guuid=11e042f8-1700-0000-8e20-229d80140000 pid=5248 /usr/bin/clrfwoekkq zombie guuid=05963af8-1700-0000-8e20-229d7f140000 pid=5247->guuid=11e042f8-1700-0000-8e20-229d80140000 pid=5248 execve guuid=2ad7acfa-1700-0000-8e20-229d87140000 pid=5255 /usr/bin/clrfwoekkq zombie guuid=11e042f8-1700-0000-8e20-229d80140000 pid=5248->guuid=2ad7acfa-1700-0000-8e20-229d87140000 pid=5255 clone guuid=934f59f8-1700-0000-8e20-229d82140000 pid=5250 /usr/bin/clrfwoekkq zombie guuid=101352f8-1700-0000-8e20-229d81140000 pid=5249->guuid=934f59f8-1700-0000-8e20-229d82140000 pid=5250 execve guuid=c48edffb-1700-0000-8e20-229d89140000 pid=5257 /usr/bin/clrfwoekkq zombie guuid=934f59f8-1700-0000-8e20-229d82140000 pid=5250->guuid=c48edffb-1700-0000-8e20-229d89140000 pid=5257 clone guuid=085f6af8-1700-0000-8e20-229d84140000 pid=5252 /usr/bin/clrfwoekkq zombie guuid=c9e964f8-1700-0000-8e20-229d83140000 pid=5251->guuid=085f6af8-1700-0000-8e20-229d84140000 pid=5252 execve guuid=e78df1fb-1700-0000-8e20-229d8a140000 pid=5258 /usr/bin/clrfwoekkq zombie guuid=085f6af8-1700-0000-8e20-229d84140000 pid=5252->guuid=e78df1fb-1700-0000-8e20-229d8a140000 pid=5258 clone guuid=efa72af9-1700-0000-8e20-229d86140000 pid=5254 /usr/bin/clrfwoekkq zombie guuid=cb0377f8-1700-0000-8e20-229d85140000 pid=5253->guuid=efa72af9-1700-0000-8e20-229d86140000 pid=5254 execve guuid=1af9fbfc-1700-0000-8e20-229d8b140000 pid=5259 /usr/bin/clrfwoekkq zombie guuid=efa72af9-1700-0000-8e20-229d86140000 pid=5254->guuid=1af9fbfc-1700-0000-8e20-229d8b140000 pid=5259 clone guuid=f3d5902d-1900-0000-8e20-229d9c140000 pid=5276 /usr/bin/shrlpjantb zombie guuid=3746722d-1900-0000-8e20-229d9b140000 pid=5275->guuid=f3d5902d-1900-0000-8e20-229d9c140000 pid=5276 execve guuid=8684de35-1900-0000-8e20-229da6140000 pid=5286 /usr/bin/shrlpjantb zombie guuid=f3d5902d-1900-0000-8e20-229d9c140000 pid=5276->guuid=8684de35-1900-0000-8e20-229da6140000 pid=5286 clone guuid=1121f92d-1900-0000-8e20-229d9e140000 pid=5278 /usr/bin/shrlpjantb zombie guuid=02f8b32d-1900-0000-8e20-229d9d140000 pid=5277->guuid=1121f92d-1900-0000-8e20-229d9e140000 pid=5278 execve guuid=0cbdd533-1900-0000-8e20-229da5140000 pid=5285 /usr/bin/shrlpjantb zombie guuid=1121f92d-1900-0000-8e20-229d9e140000 pid=5278->guuid=0cbdd533-1900-0000-8e20-229da5140000 pid=5285 clone guuid=1fc26f2e-1900-0000-8e20-229da0140000 pid=5280 /usr/bin/shrlpjantb zombie guuid=ee05162e-1900-0000-8e20-229d9f140000 pid=5279->guuid=1fc26f2e-1900-0000-8e20-229da0140000 pid=5280 execve guuid=eb018938-1900-0000-8e20-229da8140000 pid=5288 /usr/bin/shrlpjantb zombie guuid=1fc26f2e-1900-0000-8e20-229da0140000 pid=5280->guuid=eb018938-1900-0000-8e20-229da8140000 pid=5288 clone guuid=4ceae72e-1900-0000-8e20-229da2140000 pid=5282 /usr/bin/shrlpjantb zombie guuid=56b4a82e-1900-0000-8e20-229da1140000 pid=5281->guuid=4ceae72e-1900-0000-8e20-229da2140000 pid=5282 execve guuid=6a034d38-1900-0000-8e20-229da7140000 pid=5287 /usr/bin/shrlpjantb zombie guuid=4ceae72e-1900-0000-8e20-229da2140000 pid=5282->guuid=6a034d38-1900-0000-8e20-229da7140000 pid=5287 clone guuid=e894f130-1900-0000-8e20-229da4140000 pid=5284 /usr/bin/shrlpjantb zombie guuid=7f73a22f-1900-0000-8e20-229da3140000 pid=5283->guuid=e894f130-1900-0000-8e20-229da4140000 pid=5284 execve guuid=f914f138-1900-0000-8e20-229da9140000 pid=5289 /usr/bin/shrlpjantb zombie guuid=e894f130-1900-0000-8e20-229da4140000 pid=5284->guuid=f914f138-1900-0000-8e20-229da9140000 pid=5289 clone guuid=63c1475c-1a00-0000-8e20-229dfe140000 pid=5374 /usr/bin/ulwygdiqwx zombie guuid=fe33405c-1a00-0000-8e20-229dfd140000 pid=5373->guuid=63c1475c-1a00-0000-8e20-229dfe140000 pid=5374 execve guuid=c5f19d5f-1a00-0000-8e20-229d07150000 pid=5383 /usr/bin/ulwygdiqwx zombie guuid=63c1475c-1a00-0000-8e20-229dfe140000 pid=5374->guuid=c5f19d5f-1a00-0000-8e20-229d07150000 pid=5383 clone guuid=95375b5c-1a00-0000-8e20-229d00150000 pid=5376 /usr/bin/ulwygdiqwx zombie guuid=2de5545c-1a00-0000-8e20-229dff140000 pid=5375->guuid=95375b5c-1a00-0000-8e20-229d00150000 pid=5376 execve guuid=c5c54561-1a00-0000-8e20-229d09150000 pid=5385 /usr/bin/ulwygdiqwx zombie guuid=95375b5c-1a00-0000-8e20-229d00150000 pid=5376->guuid=c5c54561-1a00-0000-8e20-229d09150000 pid=5385 clone guuid=8973765c-1a00-0000-8e20-229d02150000 pid=5378 /usr/bin/ulwygdiqwx zombie guuid=669a655c-1a00-0000-8e20-229d01150000 pid=5377->guuid=8973765c-1a00-0000-8e20-229d02150000 pid=5378 execve guuid=32c15f60-1a00-0000-8e20-229d08150000 pid=5384 /usr/bin/ulwygdiqwx zombie guuid=8973765c-1a00-0000-8e20-229d02150000 pid=5378->guuid=32c15f60-1a00-0000-8e20-229d08150000 pid=5384 clone guuid=94f0f15c-1a00-0000-8e20-229d04150000 pid=5380 /usr/bin/ulwygdiqwx zombie guuid=d657825c-1a00-0000-8e20-229d03150000 pid=5379->guuid=94f0f15c-1a00-0000-8e20-229d04150000 pid=5380 execve guuid=0fd9a661-1a00-0000-8e20-229d0b150000 pid=5387 /usr/bin/ulwygdiqwx zombie guuid=94f0f15c-1a00-0000-8e20-229d04150000 pid=5380->guuid=0fd9a661-1a00-0000-8e20-229d0b150000 pid=5387 clone guuid=3baca75d-1a00-0000-8e20-229d06150000 pid=5382 /usr/bin/ulwygdiqwx zombie guuid=85ceff5c-1a00-0000-8e20-229d05150000 pid=5381->guuid=3baca75d-1a00-0000-8e20-229d06150000 pid=5382 execve guuid=3c646161-1a00-0000-8e20-229d0a150000 pid=5386 /usr/bin/ulwygdiqwx zombie guuid=3baca75d-1a00-0000-8e20-229d06150000 pid=5382->guuid=3c646161-1a00-0000-8e20-229d0a150000 pid=5386 clone guuid=f01e0b89-1b00-0000-8e20-229d79150000 pid=5497 /usr/bin/qnumsfzgpg zombie guuid=9a930089-1b00-0000-8e20-229d78150000 pid=5496->guuid=f01e0b89-1b00-0000-8e20-229d79150000 pid=5497 execve guuid=e681508c-1b00-0000-8e20-229d82150000 pid=5506 /usr/bin/qnumsfzgpg zombie guuid=f01e0b89-1b00-0000-8e20-229d79150000 pid=5497->guuid=e681508c-1b00-0000-8e20-229d82150000 pid=5506 clone guuid=2dff2989-1b00-0000-8e20-229d7b150000 pid=5499 /usr/bin/qnumsfzgpg zombie guuid=a5c22389-1b00-0000-8e20-229d7a150000 pid=5498->guuid=2dff2989-1b00-0000-8e20-229d7b150000 pid=5499 execve guuid=8af0a28c-1b00-0000-8e20-229d83150000 pid=5507 /usr/bin/qnumsfzgpg zombie guuid=2dff2989-1b00-0000-8e20-229d7b150000 pid=5499->guuid=8af0a28c-1b00-0000-8e20-229d83150000 pid=5507 clone guuid=001d3c89-1b00-0000-8e20-229d7d150000 pid=5501 /usr/bin/qnumsfzgpg zombie guuid=ff363589-1b00-0000-8e20-229d7c150000 pid=5500->guuid=001d3c89-1b00-0000-8e20-229d7d150000 pid=5501 execve guuid=b8028c8d-1b00-0000-8e20-229d84150000 pid=5508 /usr/bin/qnumsfzgpg zombie guuid=001d3c89-1b00-0000-8e20-229d7d150000 pid=5501->guuid=b8028c8d-1b00-0000-8e20-229d84150000 pid=5508 clone guuid=2683118a-1b00-0000-8e20-229d7f150000 pid=5503 /usr/bin/qnumsfzgpg zombie guuid=9ccf4589-1b00-0000-8e20-229d7e150000 pid=5502->guuid=2683118a-1b00-0000-8e20-229d7f150000 pid=5503 execve guuid=b54c438e-1b00-0000-8e20-229d85150000 pid=5509 /usr/bin/qnumsfzgpg zombie guuid=2683118a-1b00-0000-8e20-229d7f150000 pid=5503->guuid=b54c438e-1b00-0000-8e20-229d85150000 pid=5509 clone guuid=66308c8a-1b00-0000-8e20-229d81150000 pid=5505 /usr/bin/qnumsfzgpg zombie guuid=4d251d8a-1b00-0000-8e20-229d80150000 pid=5504->guuid=66308c8a-1b00-0000-8e20-229d81150000 pid=5505 execve guuid=925c4a8e-1b00-0000-8e20-229d86150000 pid=5510 /usr/bin/qnumsfzgpg zombie guuid=66308c8a-1b00-0000-8e20-229d81150000 pid=5505->guuid=925c4a8e-1b00-0000-8e20-229d86150000 pid=5510 clone guuid=2fcb06b7-1c00-0000-8e20-229dec150000 pid=5612 /usr/bin/jnxfmzgmgz zombie guuid=cbc7f8b6-1c00-0000-8e20-229deb150000 pid=5611->guuid=2fcb06b7-1c00-0000-8e20-229dec150000 pid=5612 execve guuid=994acdbb-1c00-0000-8e20-229df7150000 pid=5623 /usr/bin/jnxfmzgmgz zombie guuid=2fcb06b7-1c00-0000-8e20-229dec150000 pid=5612->guuid=994acdbb-1c00-0000-8e20-229df7150000 pid=5623 clone guuid=289626b7-1c00-0000-8e20-229dee150000 pid=5614 /usr/bin/jnxfmzgmgz zombie guuid=c0c71fb7-1c00-0000-8e20-229ded150000 pid=5613->guuid=289626b7-1c00-0000-8e20-229dee150000 pid=5614 execve guuid=e11d6cbb-1c00-0000-8e20-229df6150000 pid=5622 /usr/bin/jnxfmzgmgz zombie guuid=289626b7-1c00-0000-8e20-229dee150000 pid=5614->guuid=e11d6cbb-1c00-0000-8e20-229df6150000 pid=5622 clone guuid=76683cb7-1c00-0000-8e20-229df0150000 pid=5616 /usr/bin/jnxfmzgmgz zombie guuid=06e234b7-1c00-0000-8e20-229def150000 pid=5615->guuid=76683cb7-1c00-0000-8e20-229df0150000 pid=5616 execve guuid=cf99d6ba-1c00-0000-8e20-229df5150000 pid=5621 /usr/bin/jnxfmzgmgz zombie guuid=76683cb7-1c00-0000-8e20-229df0150000 pid=5616->guuid=cf99d6ba-1c00-0000-8e20-229df5150000 pid=5621 clone guuid=75ab25b8-1c00-0000-8e20-229df2150000 pid=5618 /usr/bin/jnxfmzgmgz zombie guuid=fb2147b7-1c00-0000-8e20-229df1150000 pid=5617->guuid=75ab25b8-1c00-0000-8e20-229df2150000 pid=5618 execve guuid=34c6f2bb-1c00-0000-8e20-229df8150000 pid=5624 /usr/bin/jnxfmzgmgz zombie guuid=75ab25b8-1c00-0000-8e20-229df2150000 pid=5618->guuid=34c6f2bb-1c00-0000-8e20-229df8150000 pid=5624 clone guuid=5b0bdab8-1c00-0000-8e20-229df4150000 pid=5620 /usr/bin/jnxfmzgmgz zombie guuid=012c35b8-1c00-0000-8e20-229df3150000 pid=5619->guuid=5b0bdab8-1c00-0000-8e20-229df4150000 pid=5620 execve guuid=f7740abd-1c00-0000-8e20-229df9150000 pid=5625 /usr/bin/jnxfmzgmgz zombie guuid=5b0bdab8-1c00-0000-8e20-229df4150000 pid=5620->guuid=f7740abd-1c00-0000-8e20-229df9150000 pid=5625 clone guuid=fbe247e5-1d00-0000-8e20-229dfb150000 pid=5627 /usr/bin/rtwmghryuw zombie guuid=299133e5-1d00-0000-8e20-229dfa150000 pid=5626->guuid=fbe247e5-1d00-0000-8e20-229dfb150000 pid=5627 execve guuid=27deddea-1d00-0000-8e20-229d05160000 pid=5637 /usr/bin/rtwmghryuw zombie guuid=fbe247e5-1d00-0000-8e20-229dfb150000 pid=5627->guuid=27deddea-1d00-0000-8e20-229d05160000 pid=5637 clone guuid=994b85e5-1d00-0000-8e20-229dfd150000 pid=5629 /usr/bin/rtwmghryuw zombie guuid=a7046fe5-1d00-0000-8e20-229dfc150000 pid=5628->guuid=994b85e5-1d00-0000-8e20-229dfd150000 pid=5629 execve guuid=116e5dec-1d00-0000-8e20-229d07160000 pid=5639 /usr/bin/rtwmghryuw zombie guuid=994b85e5-1d00-0000-8e20-229dfd150000 pid=5629->guuid=116e5dec-1d00-0000-8e20-229d07160000 pid=5639 clone guuid=4fa9dae5-1d00-0000-8e20-229dff150000 pid=5631 /usr/bin/rtwmghryuw zombie guuid=a211cae5-1d00-0000-8e20-229dfe150000 pid=5630->guuid=4fa9dae5-1d00-0000-8e20-229dff150000 pid=5631 execve guuid=eefdc8ea-1d00-0000-8e20-229d04160000 pid=5636 /usr/bin/rtwmghryuw zombie guuid=4fa9dae5-1d00-0000-8e20-229dff150000 pid=5631->guuid=eefdc8ea-1d00-0000-8e20-229d04160000 pid=5636 clone guuid=21dcb3e6-1d00-0000-8e20-229d01160000 pid=5633 /usr/bin/rtwmghryuw zombie guuid=6a5af8e5-1d00-0000-8e20-229d00160000 pid=5632->guuid=21dcb3e6-1d00-0000-8e20-229d01160000 pid=5633 execve guuid=eed8d6ec-1d00-0000-8e20-229d08160000 pid=5640 /usr/bin/rtwmghryuw zombie guuid=21dcb3e6-1d00-0000-8e20-229d01160000 pid=5633->guuid=eed8d6ec-1d00-0000-8e20-229d08160000 pid=5640 clone guuid=a62f69e7-1d00-0000-8e20-229d03160000 pid=5635 /usr/bin/rtwmghryuw zombie guuid=9250c9e6-1d00-0000-8e20-229d02160000 pid=5634->guuid=a62f69e7-1d00-0000-8e20-229d03160000 pid=5635 execve guuid=d42ccaeb-1d00-0000-8e20-229d06160000 pid=5638 /usr/bin/rtwmghryuw zombie guuid=a62f69e7-1d00-0000-8e20-229d03160000 pid=5635->guuid=d42ccaeb-1d00-0000-8e20-229d06160000 pid=5638 clone guuid=cd13b112-1f00-0000-8e20-229d0a160000 pid=5642 /usr/bin/xylvmmajbc zombie guuid=f692a612-1f00-0000-8e20-229d09160000 pid=5641->guuid=cd13b112-1f00-0000-8e20-229d0a160000 pid=5642 execve guuid=3ba83516-1f00-0000-8e20-229d13160000 pid=5651 /usr/bin/xylvmmajbc zombie guuid=cd13b112-1f00-0000-8e20-229d0a160000 pid=5642->guuid=3ba83516-1f00-0000-8e20-229d13160000 pid=5651 clone guuid=b1e6c812-1f00-0000-8e20-229d0c160000 pid=5644 /usr/bin/xylvmmajbc zombie guuid=722bc212-1f00-0000-8e20-229d0b160000 pid=5643->guuid=b1e6c812-1f00-0000-8e20-229d0c160000 pid=5644 execve guuid=e4300f17-1f00-0000-8e20-229d14160000 pid=5652 /usr/bin/xylvmmajbc zombie guuid=b1e6c812-1f00-0000-8e20-229d0c160000 pid=5644->guuid=e4300f17-1f00-0000-8e20-229d14160000 pid=5652 clone guuid=2e3edd12-1f00-0000-8e20-229d0e160000 pid=5646 /usr/bin/xylvmmajbc zombie guuid=ce53d412-1f00-0000-8e20-229d0d160000 pid=5645->guuid=2e3edd12-1f00-0000-8e20-229d0e160000 pid=5646 execve guuid=72443517-1f00-0000-8e20-229d15160000 pid=5653 /usr/bin/xylvmmajbc zombie guuid=2e3edd12-1f00-0000-8e20-229d0e160000 pid=5646->guuid=72443517-1f00-0000-8e20-229d15160000 pid=5653 clone guuid=fbfd9413-1f00-0000-8e20-229d10160000 pid=5648 /usr/bin/xylvmmajbc zombie guuid=dbc4e812-1f00-0000-8e20-229d0f160000 pid=5647->guuid=fbfd9413-1f00-0000-8e20-229d10160000 pid=5648 execve guuid=43da2618-1f00-0000-8e20-229d16160000 pid=5654 /usr/bin/xylvmmajbc zombie guuid=fbfd9413-1f00-0000-8e20-229d10160000 pid=5648->guuid=43da2618-1f00-0000-8e20-229d16160000 pid=5654 clone guuid=fc856d14-1f00-0000-8e20-229d12160000 pid=5650 /usr/bin/xylvmmajbc zombie guuid=16dda013-1f00-0000-8e20-229d11160000 pid=5649->guuid=fc856d14-1f00-0000-8e20-229d12160000 pid=5650 execve guuid=69b92718-1f00-0000-8e20-229d17160000 pid=5655 /usr/bin/xylvmmajbc zombie guuid=fc856d14-1f00-0000-8e20-229d12160000 pid=5650->guuid=69b92718-1f00-0000-8e20-229d17160000 pid=5655 clone guuid=eb3a6b42-2000-0000-8e20-229d19160000 pid=5657 /usr/bin/yqhzoqwbol zombie guuid=44075442-2000-0000-8e20-229d18160000 pid=5656->guuid=eb3a6b42-2000-0000-8e20-229d19160000 pid=5657 execve guuid=489c1a46-2000-0000-8e20-229d22160000 pid=5666 /usr/bin/yqhzoqwbol zombie guuid=eb3a6b42-2000-0000-8e20-229d19160000 pid=5657->guuid=489c1a46-2000-0000-8e20-229d22160000 pid=5666 clone guuid=393c8e42-2000-0000-8e20-229d1b160000 pid=5659 /usr/bin/yqhzoqwbol zombie guuid=9cb68342-2000-0000-8e20-229d1a160000 pid=5658->guuid=393c8e42-2000-0000-8e20-229d1b160000 pid=5659 execve guuid=1e6a3547-2000-0000-8e20-229d24160000 pid=5668 /usr/bin/yqhzoqwbol zombie guuid=393c8e42-2000-0000-8e20-229d1b160000 pid=5659->guuid=1e6a3547-2000-0000-8e20-229d24160000 pid=5668 clone guuid=b669ac42-2000-0000-8e20-229d1d160000 pid=5661 /usr/bin/yqhzoqwbol zombie guuid=90a1a242-2000-0000-8e20-229d1c160000 pid=5660->guuid=b669ac42-2000-0000-8e20-229d1d160000 pid=5661 execve guuid=01629546-2000-0000-8e20-229d23160000 pid=5667 /usr/bin/yqhzoqwbol zombie guuid=b669ac42-2000-0000-8e20-229d1d160000 pid=5661->guuid=01629546-2000-0000-8e20-229d23160000 pid=5667 clone guuid=76925a43-2000-0000-8e20-229d1f160000 pid=5663 /usr/bin/yqhzoqwbol zombie guuid=6409bd42-2000-0000-8e20-229d1e160000 pid=5662->guuid=76925a43-2000-0000-8e20-229d1f160000 pid=5663 execve guuid=e08cc647-2000-0000-8e20-229d25160000 pid=5669 /usr/bin/yqhzoqwbol zombie guuid=76925a43-2000-0000-8e20-229d1f160000 pid=5663->guuid=e08cc647-2000-0000-8e20-229d25160000 pid=5669 clone guuid=65190d44-2000-0000-8e20-229d21160000 pid=5665 /usr/bin/yqhzoqwbol zombie guuid=e61c6b43-2000-0000-8e20-229d20160000 pid=5664->guuid=65190d44-2000-0000-8e20-229d21160000 pid=5665 execve guuid=3dc7f047-2000-0000-8e20-229d26160000 pid=5670 /usr/bin/yqhzoqwbol zombie guuid=65190d44-2000-0000-8e20-229d21160000 pid=5665->guuid=3dc7f047-2000-0000-8e20-229d26160000 pid=5670 clone guuid=9bcf4d73-2100-0000-8e20-229d28160000 pid=5672 /usr/bin/hxwgxledal zombie guuid=5c774573-2100-0000-8e20-229d27160000 pid=5671->guuid=9bcf4d73-2100-0000-8e20-229d28160000 pid=5672 execve guuid=049e9c76-2100-0000-8e20-229d31160000 pid=5681 /usr/bin/hxwgxledal zombie guuid=9bcf4d73-2100-0000-8e20-229d28160000 pid=5672->guuid=049e9c76-2100-0000-8e20-229d31160000 pid=5681 clone guuid=d2636273-2100-0000-8e20-229d2a160000 pid=5674 /usr/bin/hxwgxledal zombie guuid=ff1e5b73-2100-0000-8e20-229d29160000 pid=5673->guuid=d2636273-2100-0000-8e20-229d2a160000 pid=5674 execve guuid=9441bc78-2100-0000-8e20-229d34160000 pid=5684 /usr/bin/hxwgxledal zombie guuid=d2636273-2100-0000-8e20-229d2a160000 pid=5674->guuid=9441bc78-2100-0000-8e20-229d34160000 pid=5684 clone guuid=e67d7373-2100-0000-8e20-229d2c160000 pid=5676 /usr/bin/hxwgxledal zombie guuid=7efc6c73-2100-0000-8e20-229d2b160000 pid=5675->guuid=e67d7373-2100-0000-8e20-229d2c160000 pid=5676 execve guuid=9bee2c78-2100-0000-8e20-229d33160000 pid=5683 /usr/bin/hxwgxledal zombie guuid=e67d7373-2100-0000-8e20-229d2c160000 pid=5676->guuid=9bee2c78-2100-0000-8e20-229d33160000 pid=5683 clone guuid=69997b74-2100-0000-8e20-229d2e160000 pid=5678 /usr/bin/hxwgxledal zombie guuid=53417e73-2100-0000-8e20-229d2d160000 pid=5677->guuid=69997b74-2100-0000-8e20-229d2e160000 pid=5678 execve guuid=1043b977-2100-0000-8e20-229d32160000 pid=5682 /usr/bin/hxwgxledal zombie guuid=69997b74-2100-0000-8e20-229d2e160000 pid=5678->guuid=1043b977-2100-0000-8e20-229d32160000 pid=5682 clone guuid=bb6c3b75-2100-0000-8e20-229d30160000 pid=5680 /usr/bin/hxwgxledal zombie guuid=c2708774-2100-0000-8e20-229d2f160000 pid=5679->guuid=bb6c3b75-2100-0000-8e20-229d30160000 pid=5680 execve guuid=1922ab79-2100-0000-8e20-229d35160000 pid=5685 /usr/bin/hxwgxledal zombie guuid=bb6c3b75-2100-0000-8e20-229d30160000 pid=5680->guuid=1922ab79-2100-0000-8e20-229d35160000 pid=5685 clone guuid=8168d1a0-2200-0000-8e20-229d3e160000 pid=5694 /usr/bin/hadunbxlhy zombie guuid=ae33c3a0-2200-0000-8e20-229d3d160000 pid=5693->guuid=8168d1a0-2200-0000-8e20-229d3e160000 pid=5694 execve guuid=90248ca5-2200-0000-8e20-229d47160000 pid=5703 /usr/bin/hadunbxlhy zombie guuid=8168d1a0-2200-0000-8e20-229d3e160000 pid=5694->guuid=90248ca5-2200-0000-8e20-229d47160000 pid=5703 clone guuid=a735f5a0-2200-0000-8e20-229d40160000 pid=5696 /usr/bin/hadunbxlhy zombie guuid=bf35eba0-2200-0000-8e20-229d3f160000 pid=5695->guuid=a735f5a0-2200-0000-8e20-229d40160000 pid=5696 execve guuid=5dfd04a7-2200-0000-8e20-229d49160000 pid=5705 /usr/bin/hadunbxlhy zombie guuid=a735f5a0-2200-0000-8e20-229d40160000 pid=5696->guuid=5dfd04a7-2200-0000-8e20-229d49160000 pid=5705 clone guuid=236d12a1-2200-0000-8e20-229d42160000 pid=5698 /usr/bin/hadunbxlhy zombie guuid=439609a1-2200-0000-8e20-229d41160000 pid=5697->guuid=236d12a1-2200-0000-8e20-229d42160000 pid=5698 execve guuid=0250d5a6-2200-0000-8e20-229d48160000 pid=5704 /usr/bin/hadunbxlhy zombie guuid=236d12a1-2200-0000-8e20-229d42160000 pid=5698->guuid=0250d5a6-2200-0000-8e20-229d48160000 pid=5704 clone guuid=48e7bfa1-2200-0000-8e20-229d44160000 pid=5700 /usr/bin/hadunbxlhy zombie guuid=162524a1-2200-0000-8e20-229d43160000 pid=5699->guuid=48e7bfa1-2200-0000-8e20-229d44160000 pid=5700 execve guuid=c7671da8-2200-0000-8e20-229d4b160000 pid=5707 /usr/bin/hadunbxlhy zombie guuid=48e7bfa1-2200-0000-8e20-229d44160000 pid=5700->guuid=c7671da8-2200-0000-8e20-229d4b160000 pid=5707 clone guuid=33b647a2-2200-0000-8e20-229d46160000 pid=5702 /usr/bin/hadunbxlhy zombie guuid=add0d1a1-2200-0000-8e20-229d45160000 pid=5701->guuid=33b647a2-2200-0000-8e20-229d46160000 pid=5702 execve guuid=a4ececa7-2200-0000-8e20-229d4a160000 pid=5706 /usr/bin/hadunbxlhy zombie guuid=33b647a2-2200-0000-8e20-229d46160000 pid=5702->guuid=a4ececa7-2200-0000-8e20-229d4a160000 pid=5706 clone guuid=8145d0d5-2300-0000-8e20-229d4e160000 pid=5710 /usr/bin/griahzwdcu zombie guuid=c2f6c2d5-2300-0000-8e20-229d4d160000 pid=5709->guuid=8145d0d5-2300-0000-8e20-229d4e160000 pid=5710 execve guuid=d85359d8-2300-0000-8e20-229d57160000 pid=5719 /usr/bin/griahzwdcu zombie guuid=8145d0d5-2300-0000-8e20-229d4e160000 pid=5710->guuid=d85359d8-2300-0000-8e20-229d57160000 pid=5719 clone guuid=049aead5-2300-0000-8e20-229d50160000 pid=5712 /usr/bin/griahzwdcu zombie guuid=8f43e2d5-2300-0000-8e20-229d4f160000 pid=5711->guuid=049aead5-2300-0000-8e20-229d50160000 pid=5712 execve guuid=c18968d9-2300-0000-8e20-229d5a160000 pid=5722 /usr/bin/griahzwdcu zombie guuid=049aead5-2300-0000-8e20-229d50160000 pid=5712->guuid=c18968d9-2300-0000-8e20-229d5a160000 pid=5722 clone guuid=508100d6-2300-0000-8e20-229d52160000 pid=5714 /usr/bin/griahzwdcu zombie guuid=191ff9d5-2300-0000-8e20-229d51160000 pid=5713->guuid=508100d6-2300-0000-8e20-229d52160000 pid=5714 execve guuid=2af31bd9-2300-0000-8e20-229d59160000 pid=5721 /usr/bin/griahzwdcu zombie guuid=508100d6-2300-0000-8e20-229d52160000 pid=5714->guuid=2af31bd9-2300-0000-8e20-229d59160000 pid=5721 clone guuid=c10713d6-2300-0000-8e20-229d54160000 pid=5716 /usr/bin/griahzwdcu zombie guuid=ad0b0cd6-2300-0000-8e20-229d53160000 pid=5715->guuid=c10713d6-2300-0000-8e20-229d54160000 pid=5716 execve guuid=9d458fd8-2300-0000-8e20-229d58160000 pid=5720 /usr/bin/griahzwdcu zombie guuid=c10713d6-2300-0000-8e20-229d54160000 pid=5716->guuid=9d458fd8-2300-0000-8e20-229d58160000 pid=5720 clone guuid=453615d7-2300-0000-8e20-229d56160000 pid=5718 /usr/bin/griahzwdcu zombie guuid=7e171fd6-2300-0000-8e20-229d55160000 pid=5717->guuid=453615d7-2300-0000-8e20-229d56160000 pid=5718 execve guuid=bd6ad6da-2300-0000-8e20-229d5b160000 pid=5723 /usr/bin/griahzwdcu zombie guuid=453615d7-2300-0000-8e20-229d56160000 pid=5718->guuid=bd6ad6da-2300-0000-8e20-229d5b160000 pid=5723 clone
Result
Threat name:
XorDDoS
Detection:
malicious
Classification:
troj.evad
Score:
100 / 100
Signature
Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Drops files in suspicious directories
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Sample deletes itself
Sample tries to persist itself using cron
Sample tries to persist itself using System V runlevels
Suricata IDS alerts for network traffic
Yara detected XorDDoS Bot
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1871886 Sample: p.txt.elf Startdate: 19/02/2026 Architecture: LINUX Score: 100 76 sys-kernel-update.to 123.136.95.227, 1530, 36728 A-STAR-AS-APA-STARSG China 2->76 78 109.202.202.202, 80 INIT7CH Switzerland 2->78 80 3 other IPs or domains 2->80 84 Suricata IDS alerts for network traffic 2->84 86 Malicious sample detected (through community Yara rule) 2->86 88 Antivirus detection for dropped file 2->88 90 3 other signatures 2->90 10 p.txt.elf 2->10         started        12 systemd snapd-env-generator 2->12         started        14 dash rm 2->14         started        16 dash rm 2->16         started        signatures3 process4 process5 18 p.txt.elf 10->18         started        file6 66 /usr/lib/libudev.so, ELF 18->66 dropped 68 /usr/bin/zxjwmfymju, ELF 18->68 dropped 70 /usr/bin/woacspddsh, ELF 18->70 dropped 72 16 other malicious files 18->72 dropped 92 Drops files in suspicious directories 18->92 94 Sample deletes itself 18->94 96 Sample tries to persist itself using cron 18->96 98 Sample tries to persist itself using System V runlevels 18->98 22 p.txt.elf sh 18->22         started        26 p.txt.elf 18->26         started        28 p.txt.elf 18->28         started        30 115 other processes 18->30 signatures7 process8 file9 74 /etc/crontab, ASCII 22->74 dropped 100 Sample tries to persist itself using cron 22->100 32 sh sed 22->32         started        35 p.txt.elf foeskcqikl 26->35         started        37 p.txt.elf foeskcqikl 28->37         started        39 p.txt.elf foeskcqikl 30->39         started        41 p.txt.elf foeskcqikl 30->41         started        43 p.txt.elf foeskcqikl 30->43         started        45 112 other processes 30->45 signatures10 process11 signatures12 82 Sample tries to persist itself using cron 32->82 47 foeskcqikl 35->47         started        50 foeskcqikl 37->50         started        52 foeskcqikl 39->52         started        54 foeskcqikl 41->54         started        56 foeskcqikl 43->56         started        58 tqjwchvaxx 45->58         started        60 tqjwchvaxx 45->60         started        62 tqjwchvaxx 45->62         started        64 103 other processes 45->64 process13 signatures14 102 Sample deletes itself 47->102
Threat name:
Linux.Network.XorDDoS
Status:
Malicious
First seen:
2026-02-19 11:52:35 UTC
AV detection:
20 of 24 (83.33%)
Threat level:
  3/5
Result
Malware family:
xorddos
Score:
  10/10
Tags:
family:xorddos antivm botnet discovery downloader execution linux persistence privilege_escalation
Behaviour
Reads runtime system information
System Network Configuration Discovery
Checks CPU configuration
Creates/modifies Cron job
Modifies init.d
Write file to user bin folder
Executes dropped EXE
XorDDoS
XorDDoS payload
Xorddos family
Malware Config
C2 Extraction:
https://api-metadata-v6.is/config.rar
sys-kernel-update.to:1530
telemetry-pipe.sh:1530
api-metadata-v6.is:1530
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:enterpriseapps2
Author:Tim Brown @timb_machine
Description:Enterprise apps
Rule name:F01_s1ckrule
Author:s1ckb017
Rule name:linux_generic_ipv6_catcher
Author:@_lubiedo
Description:ELF samples using IPv6 addresses
Rule name:Linux_Trojan_Xorddos_0eb147ca
Author:Elastic Security
Rule name:Linux_Trojan_Xorddos_2084099a
Author:Elastic Security
Rule name:Linux_Trojan_Xorddos_2aef46a6
Author:Elastic Security
Rule name:Linux_Trojan_Xorddos_ba961ed2
Author:Elastic Security
Rule name:MALWARE_Linux_XORDDoS
Author:ditekSHen
Description:Detects XORDDoS
Rule name:NET
Author:malware-lu
Rule name:unixredflags3
Author:Tim Brown @timb_machine
Description:Hunts for UNIX red flags

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

XorDDoS

elf 5b15e7a49f953e28a06ee8aa2d50811edd8566005117af2b0599d07bbd41d8d9

(this sample)

  
Delivery method
Distributed via web download

Comments