MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5fefeaf30b8cd96607ee013a771c619d2bcba75e294f57e98ba86e8b40e51090. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



XorDDoS


Vendor detections: 10


Intelligence 10 IOCs YARA 9 File information Comments

SHA256 hash: 5fefeaf30b8cd96607ee013a771c619d2bcba75e294f57e98ba86e8b40e51090
SHA3-384 hash: 22c829dddb1908a1fb03871eeb0dbbe40c220f63f3234aba1e84590758ab498a6f7d5e441707b1fedc0094b960ea6410
SHA1 hash: 96cec17277f33bcb1463d2df5c1ff24f9ad5add7
MD5 hash: 05a539916f43952bdb4f249f46dde6a9
humanhash: monkey-finch-september-twenty
File name:p.txt
Download: download sample
Signature XorDDoS
File size:548'616 bytes
First seen:2025-08-23 14:00:58 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 12288:4Ufrcn+vwK5ripVU4tdZ1pNL/pVbza66ySjQn36Eoj:/fUywKQ7Fb1pNL/p5afjQn36Eu
TLSH T1F9C45C56E383E2F7C82705B0134BF7BF4620B6359461CD86B7989D5AB9338F22A4D352
telfhash t12ab138722e7558f8b7f08402425a7620ce39e027259439b71ef2b454f7f2c429b6ad7a
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter abuse_ch
Tags:elf XorDDoS

Intelligence


File Origin
# of uploads :
1
# of downloads :
29
Origin country :
DE DE
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Changes owner for a written file
Collects information on the network activity
Collects information on the RAM
Sends data to a server
Receives data from a server
Connection attempt
DNS request
Creating a file
Launching a process
Runs as daemon
Manages services
Collects information on the CPU
Creating a process from a recently created file
Writes files to system directory
Creates or modifies files in /cron to set up autorun
Deletes a system binary file
Creates or modifies files in /init.d to set up autorun
Creates or modifies symbolic links in /init.d to set up autorun
Deleting of the original file
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
gcc masquerade threat
Status:
terminated
Behavior Graph:
%3 guuid=dfc8541d-1a00-0000-bb6a-df3e9c0d0000 pid=3484 /usr/bin/sudo guuid=c5c7711f-1a00-0000-bb6a-df3e9d0d0000 pid=3485 /tmp/sample.bin guuid=dfc8541d-1a00-0000-bb6a-df3e9c0d0000 pid=3484->guuid=c5c7711f-1a00-0000-bb6a-df3e9d0d0000 pid=3485 execve guuid=084aab1f-1a00-0000-bb6a-df3e9e0d0000 pid=3486 /tmp/sample.bin delete-file write-config write-file zombie guuid=c5c7711f-1a00-0000-bb6a-df3e9d0d0000 pid=3485->guuid=084aab1f-1a00-0000-bb6a-df3e9e0d0000 pid=3486 clone guuid=1130dd1f-1a00-0000-bb6a-df3ea00d0000 pid=3488 /tmp/sample.bin guuid=084aab1f-1a00-0000-bb6a-df3e9e0d0000 pid=3486->guuid=1130dd1f-1a00-0000-bb6a-df3ea00d0000 pid=3488 clone guuid=6c0a0520-1a00-0000-bb6a-df3ea40d0000 pid=3492 /tmp/sample.bin guuid=084aab1f-1a00-0000-bb6a-df3e9e0d0000 pid=3486->guuid=6c0a0520-1a00-0000-bb6a-df3ea40d0000 pid=3492 clone guuid=1ceb1520-1a00-0000-bb6a-df3ea60d0000 pid=3494 /usr/bin/dash guuid=084aab1f-1a00-0000-bb6a-df3e9e0d0000 pid=3486->guuid=1ceb1520-1a00-0000-bb6a-df3ea60d0000 pid=3494 execve guuid=084aab1f-1a00-0000-bb6a-df3e9e0d0000 pid=3501 /tmp/sample.bin write-file zombie guuid=084aab1f-1a00-0000-bb6a-df3e9e0d0000 pid=3486->guuid=084aab1f-1a00-0000-bb6a-df3e9e0d0000 pid=3501 clone guuid=084aab1f-1a00-0000-bb6a-df3e9e0d0000 pid=3502 /tmp/sample.bin dns net send-data write-file zombie guuid=084aab1f-1a00-0000-bb6a-df3e9e0d0000 pid=3486->guuid=084aab1f-1a00-0000-bb6a-df3e9e0d0000 pid=3502 clone guuid=084aab1f-1a00-0000-bb6a-df3e9e0d0000 pid=3503 /tmp/sample.bin net zombie guuid=084aab1f-1a00-0000-bb6a-df3e9e0d0000 pid=3486->guuid=084aab1f-1a00-0000-bb6a-df3e9e0d0000 pid=3503 clone guuid=ecf10b4f-1b00-0000-bb6a-df3e5e100000 pid=4190 /tmp/sample.bin guuid=084aab1f-1a00-0000-bb6a-df3e9e0d0000 pid=3486->guuid=ecf10b4f-1b00-0000-bb6a-df3e5e100000 pid=4190 clone guuid=2fa02a4f-1b00-0000-bb6a-df3e61100000 pid=4193 /tmp/sample.bin guuid=084aab1f-1a00-0000-bb6a-df3e9e0d0000 pid=3486->guuid=2fa02a4f-1b00-0000-bb6a-df3e61100000 pid=4193 clone guuid=367c514f-1b00-0000-bb6a-df3e63100000 pid=4195 /tmp/sample.bin guuid=084aab1f-1a00-0000-bb6a-df3e9e0d0000 pid=3486->guuid=367c514f-1b00-0000-bb6a-df3e63100000 pid=4195 clone guuid=d203914f-1b00-0000-bb6a-df3e65100000 pid=4197 /tmp/sample.bin guuid=084aab1f-1a00-0000-bb6a-df3e9e0d0000 pid=3486->guuid=d203914f-1b00-0000-bb6a-df3e65100000 pid=4197 clone guuid=11ca9150-1b00-0000-bb6a-df3e6d100000 pid=4205 /tmp/sample.bin guuid=084aab1f-1a00-0000-bb6a-df3e9e0d0000 pid=3486->guuid=11ca9150-1b00-0000-bb6a-df3e6d100000 pid=4205 clone guuid=bad0a47c-1c00-0000-bb6a-df3e82130000 pid=4994 /tmp/sample.bin guuid=084aab1f-1a00-0000-bb6a-df3e9e0d0000 pid=3486->guuid=bad0a47c-1c00-0000-bb6a-df3e82130000 pid=4994 clone guuid=5e2ac97c-1c00-0000-bb6a-df3e84130000 pid=4996 /tmp/sample.bin guuid=084aab1f-1a00-0000-bb6a-df3e9e0d0000 pid=3486->guuid=5e2ac97c-1c00-0000-bb6a-df3e84130000 pid=4996 clone guuid=72eded7c-1c00-0000-bb6a-df3e87130000 pid=4999 /tmp/sample.bin guuid=084aab1f-1a00-0000-bb6a-df3e9e0d0000 pid=3486->guuid=72eded7c-1c00-0000-bb6a-df3e87130000 pid=4999 clone guuid=a4f90f7d-1c00-0000-bb6a-df3e89130000 pid=5001 /tmp/sample.bin guuid=084aab1f-1a00-0000-bb6a-df3e9e0d0000 pid=3486->guuid=a4f90f7d-1c00-0000-bb6a-df3e89130000 pid=5001 clone guuid=ad88287d-1c00-0000-bb6a-df3e8b130000 pid=5003 /tmp/sample.bin guuid=084aab1f-1a00-0000-bb6a-df3e9e0d0000 pid=3486->guuid=ad88287d-1c00-0000-bb6a-df3e8b130000 pid=5003 clone guuid=5338a8a9-1d00-0000-bb6a-df3ea3140000 pid=5283 /tmp/sample.bin guuid=084aab1f-1a00-0000-bb6a-df3e9e0d0000 pid=3486->guuid=5338a8a9-1d00-0000-bb6a-df3ea3140000 pid=5283 clone guuid=e437c7a9-1d00-0000-bb6a-df3ea5140000 pid=5285 /tmp/sample.bin guuid=084aab1f-1a00-0000-bb6a-df3e9e0d0000 pid=3486->guuid=e437c7a9-1d00-0000-bb6a-df3ea5140000 pid=5285 clone guuid=72b1e2a9-1d00-0000-bb6a-df3ea7140000 pid=5287 /tmp/sample.bin guuid=084aab1f-1a00-0000-bb6a-df3e9e0d0000 pid=3486->guuid=72b1e2a9-1d00-0000-bb6a-df3ea7140000 pid=5287 clone guuid=10121aaa-1d00-0000-bb6a-df3ea9140000 pid=5289 /tmp/sample.bin guuid=084aab1f-1a00-0000-bb6a-df3e9e0d0000 pid=3486->guuid=10121aaa-1d00-0000-bb6a-df3ea9140000 pid=5289 clone guuid=77d102ab-1d00-0000-bb6a-df3eab140000 pid=5291 /tmp/sample.bin guuid=084aab1f-1a00-0000-bb6a-df3e9e0d0000 pid=3486->guuid=77d102ab-1d00-0000-bb6a-df3eab140000 pid=5291 clone guuid=5cb2bce9-1e00-0000-bb6a-df3ec6140000 pid=5318 /tmp/sample.bin guuid=084aab1f-1a00-0000-bb6a-df3e9e0d0000 pid=3486->guuid=5cb2bce9-1e00-0000-bb6a-df3ec6140000 pid=5318 clone guuid=54d8fae9-1e00-0000-bb6a-df3ec8140000 pid=5320 /tmp/sample.bin guuid=084aab1f-1a00-0000-bb6a-df3e9e0d0000 pid=3486->guuid=54d8fae9-1e00-0000-bb6a-df3ec8140000 pid=5320 clone guuid=f20c36ea-1e00-0000-bb6a-df3eca140000 pid=5322 /tmp/sample.bin guuid=084aab1f-1a00-0000-bb6a-df3e9e0d0000 pid=3486->guuid=f20c36ea-1e00-0000-bb6a-df3eca140000 pid=5322 clone guuid=240c62ea-1e00-0000-bb6a-df3ecc140000 pid=5324 /tmp/sample.bin guuid=084aab1f-1a00-0000-bb6a-df3e9e0d0000 pid=3486->guuid=240c62ea-1e00-0000-bb6a-df3ecc140000 pid=5324 clone guuid=ea3e9cea-1e00-0000-bb6a-df3ece140000 pid=5326 /tmp/sample.bin guuid=084aab1f-1a00-0000-bb6a-df3e9e0d0000 pid=3486->guuid=ea3e9cea-1e00-0000-bb6a-df3ece140000 pid=5326 clone guuid=a23c4825-2000-0000-bb6a-df3e1b150000 pid=5403 /tmp/sample.bin guuid=084aab1f-1a00-0000-bb6a-df3e9e0d0000 pid=3486->guuid=a23c4825-2000-0000-bb6a-df3e1b150000 pid=5403 clone guuid=7e897e25-2000-0000-bb6a-df3e1d150000 pid=5405 /tmp/sample.bin guuid=084aab1f-1a00-0000-bb6a-df3e9e0d0000 pid=3486->guuid=7e897e25-2000-0000-bb6a-df3e1d150000 pid=5405 clone guuid=d835b225-2000-0000-bb6a-df3e1f150000 pid=5407 /tmp/sample.bin guuid=084aab1f-1a00-0000-bb6a-df3e9e0d0000 pid=3486->guuid=d835b225-2000-0000-bb6a-df3e1f150000 pid=5407 clone guuid=1f3dea25-2000-0000-bb6a-df3e21150000 pid=5409 /tmp/sample.bin guuid=084aab1f-1a00-0000-bb6a-df3e9e0d0000 pid=3486->guuid=1f3dea25-2000-0000-bb6a-df3e21150000 pid=5409 clone guuid=45391326-2000-0000-bb6a-df3e23150000 pid=5411 /tmp/sample.bin guuid=084aab1f-1a00-0000-bb6a-df3e9e0d0000 pid=3486->guuid=45391326-2000-0000-bb6a-df3e23150000 pid=5411 clone guuid=54219655-2100-0000-bb6a-df3e99150000 pid=5529 /tmp/sample.bin guuid=084aab1f-1a00-0000-bb6a-df3e9e0d0000 pid=3486->guuid=54219655-2100-0000-bb6a-df3e99150000 pid=5529 clone guuid=fd76c755-2100-0000-bb6a-df3e9b150000 pid=5531 /tmp/sample.bin guuid=084aab1f-1a00-0000-bb6a-df3e9e0d0000 pid=3486->guuid=fd76c755-2100-0000-bb6a-df3e9b150000 pid=5531 clone guuid=7693f255-2100-0000-bb6a-df3e9d150000 pid=5533 /tmp/sample.bin guuid=084aab1f-1a00-0000-bb6a-df3e9e0d0000 pid=3486->guuid=7693f255-2100-0000-bb6a-df3e9d150000 pid=5533 clone guuid=a8101a56-2100-0000-bb6a-df3e9f150000 pid=5535 /tmp/sample.bin guuid=084aab1f-1a00-0000-bb6a-df3e9e0d0000 pid=3486->guuid=a8101a56-2100-0000-bb6a-df3e9f150000 pid=5535 clone guuid=1a201957-2100-0000-bb6a-df3ea1150000 pid=5537 /tmp/sample.bin guuid=084aab1f-1a00-0000-bb6a-df3e9e0d0000 pid=3486->guuid=1a201957-2100-0000-bb6a-df3ea1150000 pid=5537 clone guuid=25bffe82-2200-0000-bb6a-df3e0b160000 pid=5643 /tmp/sample.bin guuid=084aab1f-1a00-0000-bb6a-df3e9e0d0000 pid=3486->guuid=25bffe82-2200-0000-bb6a-df3e0b160000 pid=5643 clone guuid=8a2d1983-2200-0000-bb6a-df3e0d160000 pid=5645 /tmp/sample.bin guuid=084aab1f-1a00-0000-bb6a-df3e9e0d0000 pid=3486->guuid=8a2d1983-2200-0000-bb6a-df3e0d160000 pid=5645 clone guuid=9ec13783-2200-0000-bb6a-df3e0f160000 pid=5647 /tmp/sample.bin guuid=084aab1f-1a00-0000-bb6a-df3e9e0d0000 pid=3486->guuid=9ec13783-2200-0000-bb6a-df3e0f160000 pid=5647 clone guuid=39cd5f83-2200-0000-bb6a-df3e11160000 pid=5649 /tmp/sample.bin guuid=084aab1f-1a00-0000-bb6a-df3e9e0d0000 pid=3486->guuid=39cd5f83-2200-0000-bb6a-df3e11160000 pid=5649 clone guuid=89e02e84-2200-0000-bb6a-df3e13160000 pid=5651 /tmp/sample.bin guuid=084aab1f-1a00-0000-bb6a-df3e9e0d0000 pid=3486->guuid=89e02e84-2200-0000-bb6a-df3e13160000 pid=5651 clone guuid=9525d5b4-2300-0000-bb6a-df3e21160000 pid=5665 /tmp/sample.bin guuid=084aab1f-1a00-0000-bb6a-df3e9e0d0000 pid=3486->guuid=9525d5b4-2300-0000-bb6a-df3e21160000 pid=5665 clone guuid=9e2bffb4-2300-0000-bb6a-df3e23160000 pid=5667 /tmp/sample.bin guuid=084aab1f-1a00-0000-bb6a-df3e9e0d0000 pid=3486->guuid=9e2bffb4-2300-0000-bb6a-df3e23160000 pid=5667 clone guuid=b79523b5-2300-0000-bb6a-df3e25160000 pid=5669 /tmp/sample.bin guuid=084aab1f-1a00-0000-bb6a-df3e9e0d0000 pid=3486->guuid=b79523b5-2300-0000-bb6a-df3e25160000 pid=5669 clone guuid=c4f34bb5-2300-0000-bb6a-df3e27160000 pid=5671 /tmp/sample.bin guuid=084aab1f-1a00-0000-bb6a-df3e9e0d0000 pid=3486->guuid=c4f34bb5-2300-0000-bb6a-df3e27160000 pid=5671 clone guuid=2e4d4db6-2300-0000-bb6a-df3e29160000 pid=5673 /tmp/sample.bin guuid=084aab1f-1a00-0000-bb6a-df3e9e0d0000 pid=3486->guuid=2e4d4db6-2300-0000-bb6a-df3e29160000 pid=5673 clone guuid=443cdee5-2400-0000-bb6a-df3e31160000 pid=5681 /tmp/sample.bin guuid=084aab1f-1a00-0000-bb6a-df3e9e0d0000 pid=3486->guuid=443cdee5-2400-0000-bb6a-df3e31160000 pid=5681 clone guuid=68a61ce6-2400-0000-bb6a-df3e33160000 pid=5683 /tmp/sample.bin guuid=084aab1f-1a00-0000-bb6a-df3e9e0d0000 pid=3486->guuid=68a61ce6-2400-0000-bb6a-df3e33160000 pid=5683 clone guuid=29d44de6-2400-0000-bb6a-df3e35160000 pid=5685 /tmp/sample.bin guuid=084aab1f-1a00-0000-bb6a-df3e9e0d0000 pid=3486->guuid=29d44de6-2400-0000-bb6a-df3e35160000 pid=5685 clone guuid=a43175e6-2400-0000-bb6a-df3e37160000 pid=5687 /tmp/sample.bin guuid=084aab1f-1a00-0000-bb6a-df3e9e0d0000 pid=3486->guuid=a43175e6-2400-0000-bb6a-df3e37160000 pid=5687 clone guuid=3f9c9be6-2400-0000-bb6a-df3e39160000 pid=5689 /tmp/sample.bin guuid=084aab1f-1a00-0000-bb6a-df3e9e0d0000 pid=3486->guuid=3f9c9be6-2400-0000-bb6a-df3e39160000 pid=5689 clone guuid=e4a1ec16-2600-0000-bb6a-df3e40160000 pid=5696 /tmp/sample.bin guuid=084aab1f-1a00-0000-bb6a-df3e9e0d0000 pid=3486->guuid=e4a1ec16-2600-0000-bb6a-df3e40160000 pid=5696 clone guuid=4d581f17-2600-0000-bb6a-df3e42160000 pid=5698 /tmp/sample.bin guuid=084aab1f-1a00-0000-bb6a-df3e9e0d0000 pid=3486->guuid=4d581f17-2600-0000-bb6a-df3e42160000 pid=5698 clone guuid=67ec5a17-2600-0000-bb6a-df3e44160000 pid=5700 /tmp/sample.bin guuid=084aab1f-1a00-0000-bb6a-df3e9e0d0000 pid=3486->guuid=67ec5a17-2600-0000-bb6a-df3e44160000 pid=5700 clone guuid=37398717-2600-0000-bb6a-df3e46160000 pid=5702 /tmp/sample.bin guuid=084aab1f-1a00-0000-bb6a-df3e9e0d0000 pid=3486->guuid=37398717-2600-0000-bb6a-df3e46160000 pid=5702 clone guuid=68f8b317-2600-0000-bb6a-df3e48160000 pid=5704 /tmp/sample.bin guuid=084aab1f-1a00-0000-bb6a-df3e9e0d0000 pid=3486->guuid=68f8b317-2600-0000-bb6a-df3e48160000 pid=5704 clone guuid=dc7f3360-2700-0000-bb6a-df3e4f160000 pid=5711 /tmp/sample.bin guuid=084aab1f-1a00-0000-bb6a-df3e9e0d0000 pid=3486->guuid=dc7f3360-2700-0000-bb6a-df3e4f160000 pid=5711 clone guuid=4f9a6660-2700-0000-bb6a-df3e51160000 pid=5713 /tmp/sample.bin guuid=084aab1f-1a00-0000-bb6a-df3e9e0d0000 pid=3486->guuid=4f9a6660-2700-0000-bb6a-df3e51160000 pid=5713 clone guuid=f0678b60-2700-0000-bb6a-df3e53160000 pid=5715 /tmp/sample.bin guuid=084aab1f-1a00-0000-bb6a-df3e9e0d0000 pid=3486->guuid=f0678b60-2700-0000-bb6a-df3e53160000 pid=5715 clone guuid=c034ad60-2700-0000-bb6a-df3e55160000 pid=5717 /tmp/sample.bin guuid=084aab1f-1a00-0000-bb6a-df3e9e0d0000 pid=3486->guuid=c034ad60-2700-0000-bb6a-df3e55160000 pid=5717 clone guuid=97c0d860-2700-0000-bb6a-df3e57160000 pid=5719 /tmp/sample.bin guuid=084aab1f-1a00-0000-bb6a-df3e9e0d0000 pid=3486->guuid=97c0d860-2700-0000-bb6a-df3e57160000 pid=5719 clone guuid=a585fb1f-1a00-0000-bb6a-df3ea30d0000 pid=3491 /tmp/sample.bin guuid=1130dd1f-1a00-0000-bb6a-df3ea00d0000 pid=3488->guuid=a585fb1f-1a00-0000-bb6a-df3ea30d0000 pid=3491 clone guuid=b2270b20-1a00-0000-bb6a-df3ea50d0000 pid=3493 /usr/sbin/update-rc.d zombie guuid=6c0a0520-1a00-0000-bb6a-df3ea40d0000 pid=3492->guuid=b2270b20-1a00-0000-bb6a-df3ea50d0000 pid=3493 execve guuid=a11ce326-1a00-0000-bb6a-df3eb70d0000 pid=3511 /usr/bin/systemctl guuid=b2270b20-1a00-0000-bb6a-df3ea50d0000 pid=3493->guuid=a11ce326-1a00-0000-bb6a-df3eb70d0000 pid=3511 execve guuid=3a799020-1a00-0000-bb6a-df3ea80d0000 pid=3496 /usr/bin/sed guuid=1ceb1520-1a00-0000-bb6a-df3ea60d0000 pid=3494->guuid=3a799020-1a00-0000-bb6a-df3ea80d0000 pid=3496 execve 9f7b7b23-9573-5099-ad1c-158ed3c2166f 0.0.0.0:1527 guuid=084aab1f-1a00-0000-bb6a-df3e9e0d0000 pid=3502->9f7b7b23-9573-5099-ad1c-158ed3c2166f con 6df1ee0d-cc81-5df3-9134-d887fbfdbd90 kk.vvbb321.com:1527 guuid=084aab1f-1a00-0000-bb6a-df3e9e0d0000 pid=3502->6df1ee0d-cc81-5df3-9134-d887fbfdbd90 send: 4548B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=084aab1f-1a00-0000-bb6a-df3e9e0d0000 pid=3502->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 96B b4bf20d4-f7c8-5c24-8830-c23364537aa4 8.8.4.4:53 guuid=084aab1f-1a00-0000-bb6a-df3e9e0d0000 pid=3502->b4bf20d4-f7c8-5c24-8830-c23364537aa4 send: 64B 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=084aab1f-1a00-0000-bb6a-df3e9e0d0000 pid=3502->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 64B 87f248b3-21f7-50eb-a2c7-cb35eca5cc17 0.0.0.0:80 guuid=084aab1f-1a00-0000-bb6a-df3e9e0d0000 pid=3503->87f248b3-21f7-50eb-a2c7-cb35eca5cc17 con guuid=2bb2184f-1b00-0000-bb6a-df3e60100000 pid=4192 /usr/bin/wqikizacsc zombie guuid=ecf10b4f-1b00-0000-bb6a-df3e5e100000 pid=4190->guuid=2bb2184f-1b00-0000-bb6a-df3e60100000 pid=4192 execve guuid=9db95e54-1b00-0000-bb6a-df3e83100000 pid=4227 /usr/bin/wqikizacsc zombie guuid=2bb2184f-1b00-0000-bb6a-df3e60100000 pid=4192->guuid=9db95e54-1b00-0000-bb6a-df3e83100000 pid=4227 clone guuid=afae3d4f-1b00-0000-bb6a-df3e62100000 pid=4194 /usr/bin/wqikizacsc zombie guuid=2fa02a4f-1b00-0000-bb6a-df3e61100000 pid=4193->guuid=afae3d4f-1b00-0000-bb6a-df3e62100000 pid=4194 execve guuid=9ebb3c53-1b00-0000-bb6a-df3e7d100000 pid=4221 /usr/bin/wqikizacsc zombie guuid=afae3d4f-1b00-0000-bb6a-df3e62100000 pid=4194->guuid=9ebb3c53-1b00-0000-bb6a-df3e7d100000 pid=4221 clone guuid=33e9784f-1b00-0000-bb6a-df3e64100000 pid=4196 /usr/bin/wqikizacsc zombie guuid=367c514f-1b00-0000-bb6a-df3e63100000 pid=4195->guuid=33e9784f-1b00-0000-bb6a-df3e64100000 pid=4196 execve guuid=48687155-1b00-0000-bb6a-df3e86100000 pid=4230 /usr/bin/wqikizacsc zombie guuid=33e9784f-1b00-0000-bb6a-df3e64100000 pid=4196->guuid=48687155-1b00-0000-bb6a-df3e86100000 pid=4230 clone guuid=e0b06f50-1b00-0000-bb6a-df3e6c100000 pid=4204 /usr/bin/wqikizacsc zombie guuid=d203914f-1b00-0000-bb6a-df3e65100000 pid=4197->guuid=e0b06f50-1b00-0000-bb6a-df3e6c100000 pid=4204 execve guuid=1b78c156-1b00-0000-bb6a-df3e8a100000 pid=4234 /usr/bin/wqikizacsc zombie guuid=e0b06f50-1b00-0000-bb6a-df3e6c100000 pid=4204->guuid=1b78c156-1b00-0000-bb6a-df3e8a100000 pid=4234 clone guuid=627a9b50-1b00-0000-bb6a-df3e6f100000 pid=4207 /usr/bin/wqikizacsc zombie guuid=11ca9150-1b00-0000-bb6a-df3e6d100000 pid=4205->guuid=627a9b50-1b00-0000-bb6a-df3e6f100000 pid=4207 execve guuid=9b450056-1b00-0000-bb6a-df3e87100000 pid=4231 /usr/bin/wqikizacsc zombie guuid=627a9b50-1b00-0000-bb6a-df3e6f100000 pid=4207->guuid=9b450056-1b00-0000-bb6a-df3e87100000 pid=4231 clone guuid=2e1bae7c-1c00-0000-bb6a-df3e83130000 pid=4995 /usr/bin/ymryaagxyy zombie guuid=bad0a47c-1c00-0000-bb6a-df3e82130000 pid=4994->guuid=2e1bae7c-1c00-0000-bb6a-df3e83130000 pid=4995 execve guuid=cb571481-1c00-0000-bb6a-df3e9b130000 pid=5019 /usr/bin/ymryaagxyy zombie guuid=2e1bae7c-1c00-0000-bb6a-df3e83130000 pid=4995->guuid=cb571481-1c00-0000-bb6a-df3e9b130000 pid=5019 clone guuid=4d07d97c-1c00-0000-bb6a-df3e85130000 pid=4997 /usr/bin/ymryaagxyy zombie guuid=5e2ac97c-1c00-0000-bb6a-df3e84130000 pid=4996->guuid=4d07d97c-1c00-0000-bb6a-df3e85130000 pid=4997 execve guuid=37ac6782-1c00-0000-bb6a-df3ea2130000 pid=5026 /usr/bin/ymryaagxyy zombie guuid=4d07d97c-1c00-0000-bb6a-df3e85130000 pid=4997->guuid=37ac6782-1c00-0000-bb6a-df3ea2130000 pid=5026 clone guuid=dcd1f57c-1c00-0000-bb6a-df3e88130000 pid=5000 /usr/bin/ymryaagxyy zombie guuid=72eded7c-1c00-0000-bb6a-df3e87130000 pid=4999->guuid=dcd1f57c-1c00-0000-bb6a-df3e88130000 pid=5000 execve guuid=75f1f880-1c00-0000-bb6a-df3e9a130000 pid=5018 /usr/bin/ymryaagxyy guuid=dcd1f57c-1c00-0000-bb6a-df3e88130000 pid=5000->guuid=75f1f880-1c00-0000-bb6a-df3e9a130000 pid=5018 clone guuid=a4bd187d-1c00-0000-bb6a-df3e8a130000 pid=5002 /usr/bin/ymryaagxyy zombie guuid=a4f90f7d-1c00-0000-bb6a-df3e89130000 pid=5001->guuid=a4bd187d-1c00-0000-bb6a-df3e8a130000 pid=5002 execve guuid=c311f681-1c00-0000-bb6a-df3ea0130000 pid=5024 /usr/bin/ymryaagxyy zombie guuid=a4bd187d-1c00-0000-bb6a-df3e8a130000 pid=5002->guuid=c311f681-1c00-0000-bb6a-df3ea0130000 pid=5024 clone guuid=fb9c327d-1c00-0000-bb6a-df3e8d130000 pid=5005 /usr/bin/ymryaagxyy zombie guuid=ad88287d-1c00-0000-bb6a-df3e8b130000 pid=5003->guuid=fb9c327d-1c00-0000-bb6a-df3e8d130000 pid=5005 execve guuid=4ce07081-1c00-0000-bb6a-df3e9d130000 pid=5021 /usr/bin/ymryaagxyy zombie guuid=fb9c327d-1c00-0000-bb6a-df3e8d130000 pid=5005->guuid=4ce07081-1c00-0000-bb6a-df3e9d130000 pid=5021 clone guuid=e949b3a9-1d00-0000-bb6a-df3ea4140000 pid=5284 /usr/bin/oyqtzgmvqe zombie guuid=5338a8a9-1d00-0000-bb6a-df3ea3140000 pid=5283->guuid=e949b3a9-1d00-0000-bb6a-df3ea4140000 pid=5284 execve guuid=b8e898ae-1d00-0000-bb6a-df3eaf140000 pid=5295 /usr/bin/oyqtzgmvqe zombie guuid=e949b3a9-1d00-0000-bb6a-df3ea4140000 pid=5284->guuid=b8e898ae-1d00-0000-bb6a-df3eaf140000 pid=5295 clone guuid=3ea4d1a9-1d00-0000-bb6a-df3ea6140000 pid=5286 /usr/bin/oyqtzgmvqe zombie guuid=e437c7a9-1d00-0000-bb6a-df3ea5140000 pid=5285->guuid=3ea4d1a9-1d00-0000-bb6a-df3ea6140000 pid=5286 execve guuid=56db33ad-1d00-0000-bb6a-df3ead140000 pid=5293 /usr/bin/oyqtzgmvqe zombie guuid=3ea4d1a9-1d00-0000-bb6a-df3ea6140000 pid=5286->guuid=56db33ad-1d00-0000-bb6a-df3ead140000 pid=5293 clone guuid=b8f400aa-1d00-0000-bb6a-df3ea8140000 pid=5288 /usr/bin/oyqtzgmvqe zombie guuid=72b1e2a9-1d00-0000-bb6a-df3ea7140000 pid=5287->guuid=b8f400aa-1d00-0000-bb6a-df3ea8140000 pid=5288 execve guuid=ba2ae0ae-1d00-0000-bb6a-df3eb0140000 pid=5296 /usr/bin/oyqtzgmvqe zombie guuid=b8f400aa-1d00-0000-bb6a-df3ea8140000 pid=5288->guuid=ba2ae0ae-1d00-0000-bb6a-df3eb0140000 pid=5296 clone guuid=cdece6aa-1d00-0000-bb6a-df3eaa140000 pid=5290 /usr/bin/oyqtzgmvqe zombie guuid=10121aaa-1d00-0000-bb6a-df3ea9140000 pid=5289->guuid=cdece6aa-1d00-0000-bb6a-df3eaa140000 pid=5290 execve guuid=8193d0af-1d00-0000-bb6a-df3eb2140000 pid=5298 /usr/bin/oyqtzgmvqe zombie guuid=cdece6aa-1d00-0000-bb6a-df3eaa140000 pid=5290->guuid=8193d0af-1d00-0000-bb6a-df3eb2140000 pid=5298 clone guuid=b64478ab-1d00-0000-bb6a-df3eac140000 pid=5292 /usr/bin/oyqtzgmvqe zombie guuid=77d102ab-1d00-0000-bb6a-df3eab140000 pid=5291->guuid=b64478ab-1d00-0000-bb6a-df3eac140000 pid=5292 execve guuid=1fa57bb3-1d00-0000-bb6a-df3eb6140000 pid=5302 /usr/bin/oyqtzgmvqe zombie guuid=b64478ab-1d00-0000-bb6a-df3eac140000 pid=5292->guuid=1fa57bb3-1d00-0000-bb6a-df3eb6140000 pid=5302 clone guuid=4f02d0e9-1e00-0000-bb6a-df3ec7140000 pid=5319 /usr/bin/hdjqmkggcz zombie guuid=5cb2bce9-1e00-0000-bb6a-df3ec6140000 pid=5318->guuid=4f02d0e9-1e00-0000-bb6a-df3ec7140000 pid=5319 execve guuid=c1fe9eed-1e00-0000-bb6a-df3ed0140000 pid=5328 /usr/bin/hdjqmkggcz zombie guuid=4f02d0e9-1e00-0000-bb6a-df3ec7140000 pid=5319->guuid=c1fe9eed-1e00-0000-bb6a-df3ed0140000 pid=5328 clone guuid=5c1718ea-1e00-0000-bb6a-df3ec9140000 pid=5321 /usr/bin/hdjqmkggcz zombie guuid=54d8fae9-1e00-0000-bb6a-df3ec8140000 pid=5320->guuid=5c1718ea-1e00-0000-bb6a-df3ec9140000 pid=5321 execve guuid=27ed13f0-1e00-0000-bb6a-df3ed4140000 pid=5332 /usr/bin/hdjqmkggcz zombie guuid=5c1718ea-1e00-0000-bb6a-df3ec9140000 pid=5321->guuid=27ed13f0-1e00-0000-bb6a-df3ed4140000 pid=5332 clone guuid=d53945ea-1e00-0000-bb6a-df3ecb140000 pid=5323 /usr/bin/hdjqmkggcz zombie guuid=f20c36ea-1e00-0000-bb6a-df3eca140000 pid=5322->guuid=d53945ea-1e00-0000-bb6a-df3ecb140000 pid=5323 execve guuid=9ceb31ee-1e00-0000-bb6a-df3ed1140000 pid=5329 /usr/bin/hdjqmkggcz zombie guuid=d53945ea-1e00-0000-bb6a-df3ecb140000 pid=5323->guuid=9ceb31ee-1e00-0000-bb6a-df3ed1140000 pid=5329 clone guuid=f1ee6fea-1e00-0000-bb6a-df3ecd140000 pid=5325 /usr/bin/hdjqmkggcz zombie guuid=240c62ea-1e00-0000-bb6a-df3ecc140000 pid=5324->guuid=f1ee6fea-1e00-0000-bb6a-df3ecd140000 pid=5325 execve guuid=feea96ef-1e00-0000-bb6a-df3ed3140000 pid=5331 /usr/bin/hdjqmkggcz zombie guuid=f1ee6fea-1e00-0000-bb6a-df3ecd140000 pid=5325->guuid=feea96ef-1e00-0000-bb6a-df3ed3140000 pid=5331 clone guuid=46e1afea-1e00-0000-bb6a-df3ecf140000 pid=5327 /usr/bin/hdjqmkggcz zombie guuid=ea3e9cea-1e00-0000-bb6a-df3ece140000 pid=5326->guuid=46e1afea-1e00-0000-bb6a-df3ecf140000 pid=5327 execve guuid=a59307ef-1e00-0000-bb6a-df3ed2140000 pid=5330 /usr/bin/hdjqmkggcz zombie guuid=46e1afea-1e00-0000-bb6a-df3ecf140000 pid=5327->guuid=a59307ef-1e00-0000-bb6a-df3ed2140000 pid=5330 clone guuid=301a5b25-2000-0000-bb6a-df3e1c150000 pid=5404 /usr/bin/roamzcsaei zombie guuid=a23c4825-2000-0000-bb6a-df3e1b150000 pid=5403->guuid=301a5b25-2000-0000-bb6a-df3e1c150000 pid=5404 execve guuid=e26f5b29-2000-0000-bb6a-df3e26150000 pid=5414 /usr/bin/roamzcsaei zombie guuid=301a5b25-2000-0000-bb6a-df3e1c150000 pid=5404->guuid=e26f5b29-2000-0000-bb6a-df3e26150000 pid=5414 clone guuid=a4c99225-2000-0000-bb6a-df3e1e150000 pid=5406 /usr/bin/roamzcsaei zombie guuid=7e897e25-2000-0000-bb6a-df3e1d150000 pid=5405->guuid=a4c99225-2000-0000-bb6a-df3e1e150000 pid=5406 execve guuid=12d23f29-2000-0000-bb6a-df3e25150000 pid=5413 /usr/bin/roamzcsaei zombie guuid=a4c99225-2000-0000-bb6a-df3e1e150000 pid=5406->guuid=12d23f29-2000-0000-bb6a-df3e25150000 pid=5413 clone guuid=4b9fce25-2000-0000-bb6a-df3e20150000 pid=5408 /usr/bin/roamzcsaei zombie guuid=d835b225-2000-0000-bb6a-df3e1f150000 pid=5407->guuid=4b9fce25-2000-0000-bb6a-df3e20150000 pid=5408 execve guuid=e1c9742a-2000-0000-bb6a-df3e27150000 pid=5415 /usr/bin/roamzcsaei zombie guuid=4b9fce25-2000-0000-bb6a-df3e20150000 pid=5408->guuid=e1c9742a-2000-0000-bb6a-df3e27150000 pid=5415 clone guuid=496ef825-2000-0000-bb6a-df3e22150000 pid=5410 /usr/bin/roamzcsaei zombie guuid=1f3dea25-2000-0000-bb6a-df3e21150000 pid=5409->guuid=496ef825-2000-0000-bb6a-df3e22150000 pid=5410 execve guuid=85fbdf2a-2000-0000-bb6a-df3e29150000 pid=5417 /usr/bin/roamzcsaei zombie guuid=496ef825-2000-0000-bb6a-df3e22150000 pid=5410->guuid=85fbdf2a-2000-0000-bb6a-df3e29150000 pid=5417 clone guuid=e05cbf26-2000-0000-bb6a-df3e24150000 pid=5412 /usr/bin/roamzcsaei zombie guuid=45391326-2000-0000-bb6a-df3e23150000 pid=5411->guuid=e05cbf26-2000-0000-bb6a-df3e24150000 pid=5412 execve guuid=4f77cf2a-2000-0000-bb6a-df3e28150000 pid=5416 /usr/bin/roamzcsaei zombie guuid=e05cbf26-2000-0000-bb6a-df3e24150000 pid=5412->guuid=4f77cf2a-2000-0000-bb6a-df3e28150000 pid=5416 clone guuid=510da255-2100-0000-bb6a-df3e9a150000 pid=5530 /usr/bin/azmnkwvxkx zombie guuid=54219655-2100-0000-bb6a-df3e99150000 pid=5529->guuid=510da255-2100-0000-bb6a-df3e9a150000 pid=5530 execve guuid=2ed94459-2100-0000-bb6a-df3ea3150000 pid=5539 /usr/bin/azmnkwvxkx zombie guuid=510da255-2100-0000-bb6a-df3e9a150000 pid=5530->guuid=2ed94459-2100-0000-bb6a-df3ea3150000 pid=5539 clone guuid=75c2d555-2100-0000-bb6a-df3e9c150000 pid=5532 /usr/bin/azmnkwvxkx zombie guuid=fd76c755-2100-0000-bb6a-df3e9b150000 pid=5531->guuid=75c2d555-2100-0000-bb6a-df3e9c150000 pid=5532 execve guuid=23b2465a-2100-0000-bb6a-df3ea5150000 pid=5541 /usr/bin/azmnkwvxkx zombie guuid=75c2d555-2100-0000-bb6a-df3e9c150000 pid=5532->guuid=23b2465a-2100-0000-bb6a-df3ea5150000 pid=5541 clone guuid=b9cc0656-2100-0000-bb6a-df3e9e150000 pid=5534 /usr/bin/azmnkwvxkx zombie guuid=7693f255-2100-0000-bb6a-df3e9d150000 pid=5533->guuid=b9cc0656-2100-0000-bb6a-df3e9e150000 pid=5534 execve guuid=b598de59-2100-0000-bb6a-df3ea4150000 pid=5540 /usr/bin/azmnkwvxkx zombie guuid=b9cc0656-2100-0000-bb6a-df3e9e150000 pid=5534->guuid=b598de59-2100-0000-bb6a-df3ea4150000 pid=5540 clone guuid=f86c0457-2100-0000-bb6a-df3ea0150000 pid=5536 /usr/bin/azmnkwvxkx zombie guuid=a8101a56-2100-0000-bb6a-df3e9f150000 pid=5535->guuid=f86c0457-2100-0000-bb6a-df3ea0150000 pid=5536 execve guuid=fa44895a-2100-0000-bb6a-df3ea6150000 pid=5542 /usr/bin/azmnkwvxkx zombie guuid=f86c0457-2100-0000-bb6a-df3ea0150000 pid=5536->guuid=fa44895a-2100-0000-bb6a-df3ea6150000 pid=5542 clone guuid=31e7bf57-2100-0000-bb6a-df3ea2150000 pid=5538 /usr/bin/azmnkwvxkx zombie guuid=1a201957-2100-0000-bb6a-df3ea1150000 pid=5537->guuid=31e7bf57-2100-0000-bb6a-df3ea2150000 pid=5538 execve guuid=6948605b-2100-0000-bb6a-df3ea7150000 pid=5543 /usr/bin/azmnkwvxkx zombie guuid=31e7bf57-2100-0000-bb6a-df3ea2150000 pid=5538->guuid=6948605b-2100-0000-bb6a-df3ea7150000 pid=5543 clone guuid=ed840783-2200-0000-bb6a-df3e0c160000 pid=5644 /usr/bin/nrdxsgeebu zombie guuid=25bffe82-2200-0000-bb6a-df3e0b160000 pid=5643->guuid=ed840783-2200-0000-bb6a-df3e0c160000 pid=5644 execve guuid=6afe9286-2200-0000-bb6a-df3e15160000 pid=5653 /usr/bin/nrdxsgeebu zombie guuid=ed840783-2200-0000-bb6a-df3e0c160000 pid=5644->guuid=6afe9286-2200-0000-bb6a-df3e15160000 pid=5653 clone guuid=c97d2083-2200-0000-bb6a-df3e0e160000 pid=5646 /usr/bin/nrdxsgeebu zombie guuid=8a2d1983-2200-0000-bb6a-df3e0d160000 pid=5645->guuid=c97d2083-2200-0000-bb6a-df3e0e160000 pid=5646 execve guuid=c327a686-2200-0000-bb6a-df3e16160000 pid=5654 /usr/bin/nrdxsgeebu zombie guuid=c97d2083-2200-0000-bb6a-df3e0e160000 pid=5646->guuid=c327a686-2200-0000-bb6a-df3e16160000 pid=5654 clone guuid=3b3c4583-2200-0000-bb6a-df3e10160000 pid=5648 /usr/bin/nrdxsgeebu zombie guuid=9ec13783-2200-0000-bb6a-df3e0f160000 pid=5647->guuid=3b3c4583-2200-0000-bb6a-df3e10160000 pid=5648 execve guuid=ee9b3489-2200-0000-bb6a-df3e18160000 pid=5656 /usr/bin/nrdxsgeebu zombie guuid=3b3c4583-2200-0000-bb6a-df3e10160000 pid=5648->guuid=ee9b3489-2200-0000-bb6a-df3e18160000 pid=5656 clone guuid=e49f1784-2200-0000-bb6a-df3e12160000 pid=5650 /usr/bin/nrdxsgeebu zombie guuid=39cd5f83-2200-0000-bb6a-df3e11160000 pid=5649->guuid=e49f1784-2200-0000-bb6a-df3e12160000 pid=5650 execve guuid=7f225b89-2200-0000-bb6a-df3e19160000 pid=5657 /usr/bin/nrdxsgeebu zombie guuid=e49f1784-2200-0000-bb6a-df3e12160000 pid=5650->guuid=7f225b89-2200-0000-bb6a-df3e19160000 pid=5657 clone guuid=fa428884-2200-0000-bb6a-df3e14160000 pid=5652 /usr/bin/nrdxsgeebu zombie guuid=89e02e84-2200-0000-bb6a-df3e13160000 pid=5651->guuid=fa428884-2200-0000-bb6a-df3e14160000 pid=5652 execve guuid=90f83688-2200-0000-bb6a-df3e17160000 pid=5655 /usr/bin/nrdxsgeebu zombie guuid=fa428884-2200-0000-bb6a-df3e14160000 pid=5652->guuid=90f83688-2200-0000-bb6a-df3e17160000 pid=5655 clone guuid=a936e3b4-2300-0000-bb6a-df3e22160000 pid=5666 /usr/bin/yurwjamgjg zombie guuid=9525d5b4-2300-0000-bb6a-df3e21160000 pid=5665->guuid=a936e3b4-2300-0000-bb6a-df3e22160000 pid=5666 execve guuid=55e257ba-2300-0000-bb6a-df3e2e160000 pid=5678 /usr/bin/yurwjamgjg zombie guuid=a936e3b4-2300-0000-bb6a-df3e22160000 pid=5666->guuid=55e257ba-2300-0000-bb6a-df3e2e160000 pid=5678 clone guuid=b97b0bb5-2300-0000-bb6a-df3e24160000 pid=5668 /usr/bin/yurwjamgjg zombie guuid=9e2bffb4-2300-0000-bb6a-df3e23160000 pid=5667->guuid=b97b0bb5-2300-0000-bb6a-df3e24160000 pid=5668 execve guuid=010ed7b9-2300-0000-bb6a-df3e2d160000 pid=5677 /usr/bin/yurwjamgjg zombie guuid=b97b0bb5-2300-0000-bb6a-df3e24160000 pid=5668->guuid=010ed7b9-2300-0000-bb6a-df3e2d160000 pid=5677 clone guuid=b39033b5-2300-0000-bb6a-df3e26160000 pid=5670 /usr/bin/yurwjamgjg zombie guuid=b79523b5-2300-0000-bb6a-df3e25160000 pid=5669->guuid=b39033b5-2300-0000-bb6a-df3e26160000 pid=5670 execve guuid=34673bb9-2300-0000-bb6a-df3e2b160000 pid=5675 /usr/bin/yurwjamgjg zombie guuid=b39033b5-2300-0000-bb6a-df3e26160000 pid=5670->guuid=34673bb9-2300-0000-bb6a-df3e2b160000 pid=5675 clone guuid=775933b6-2300-0000-bb6a-df3e28160000 pid=5672 /usr/bin/yurwjamgjg zombie guuid=c4f34bb5-2300-0000-bb6a-df3e27160000 pid=5671->guuid=775933b6-2300-0000-bb6a-df3e28160000 pid=5672 execve guuid=e9e80bbc-2300-0000-bb6a-df3e2f160000 pid=5679 /usr/bin/yurwjamgjg zombie guuid=775933b6-2300-0000-bb6a-df3e28160000 pid=5672->guuid=e9e80bbc-2300-0000-bb6a-df3e2f160000 pid=5679 clone guuid=2a2965b6-2300-0000-bb6a-df3e2a160000 pid=5674 /usr/bin/yurwjamgjg zombie guuid=2e4d4db6-2300-0000-bb6a-df3e29160000 pid=5673->guuid=2a2965b6-2300-0000-bb6a-df3e2a160000 pid=5674 execve guuid=084563b9-2300-0000-bb6a-df3e2c160000 pid=5676 /usr/bin/yurwjamgjg zombie guuid=2a2965b6-2300-0000-bb6a-df3e2a160000 pid=5674->guuid=084563b9-2300-0000-bb6a-df3e2c160000 pid=5676 clone guuid=b6c2fbe5-2400-0000-bb6a-df3e32160000 pid=5682 /usr/bin/wksvcmlxen zombie guuid=443cdee5-2400-0000-bb6a-df3e31160000 pid=5681->guuid=b6c2fbe5-2400-0000-bb6a-df3e32160000 pid=5682 execve guuid=cd609ee9-2400-0000-bb6a-df3e3b160000 pid=5691 /usr/bin/wksvcmlxen zombie guuid=b6c2fbe5-2400-0000-bb6a-df3e32160000 pid=5682->guuid=cd609ee9-2400-0000-bb6a-df3e3b160000 pid=5691 clone guuid=01f12fe6-2400-0000-bb6a-df3e34160000 pid=5684 /usr/bin/wksvcmlxen zombie guuid=68a61ce6-2400-0000-bb6a-df3e33160000 pid=5683->guuid=01f12fe6-2400-0000-bb6a-df3e34160000 pid=5684 execve guuid=1d81b5ea-2400-0000-bb6a-df3e3e160000 pid=5694 /usr/bin/wksvcmlxen zombie guuid=01f12fe6-2400-0000-bb6a-df3e34160000 pid=5684->guuid=1d81b5ea-2400-0000-bb6a-df3e3e160000 pid=5694 clone guuid=a89a5be6-2400-0000-bb6a-df3e36160000 pid=5686 /usr/bin/wksvcmlxen zombie guuid=29d44de6-2400-0000-bb6a-df3e35160000 pid=5685->guuid=a89a5be6-2400-0000-bb6a-df3e36160000 pid=5686 execve guuid=c1562aea-2400-0000-bb6a-df3e3c160000 pid=5692 /usr/bin/wksvcmlxen zombie guuid=a89a5be6-2400-0000-bb6a-df3e36160000 pid=5686->guuid=c1562aea-2400-0000-bb6a-df3e3c160000 pid=5692 clone guuid=19be82e6-2400-0000-bb6a-df3e38160000 pid=5688 /usr/bin/wksvcmlxen zombie guuid=a43175e6-2400-0000-bb6a-df3e37160000 pid=5687->guuid=19be82e6-2400-0000-bb6a-df3e38160000 pid=5688 execve guuid=ec433fea-2400-0000-bb6a-df3e3d160000 pid=5693 /usr/bin/wksvcmlxen zombie guuid=19be82e6-2400-0000-bb6a-df3e38160000 pid=5688->guuid=ec433fea-2400-0000-bb6a-df3e3d160000 pid=5693 clone guuid=cdae48e7-2400-0000-bb6a-df3e3a160000 pid=5690 /usr/bin/wksvcmlxen zombie guuid=3f9c9be6-2400-0000-bb6a-df3e39160000 pid=5689->guuid=cdae48e7-2400-0000-bb6a-df3e3a160000 pid=5690 execve guuid=bb8b48eb-2400-0000-bb6a-df3e3f160000 pid=5695 /usr/bin/wksvcmlxen zombie guuid=cdae48e7-2400-0000-bb6a-df3e3a160000 pid=5690->guuid=bb8b48eb-2400-0000-bb6a-df3e3f160000 pid=5695 clone guuid=6acafc16-2600-0000-bb6a-df3e41160000 pid=5697 /usr/bin/axxkmrwoyf zombie guuid=e4a1ec16-2600-0000-bb6a-df3e40160000 pid=5696->guuid=6acafc16-2600-0000-bb6a-df3e41160000 pid=5697 execve guuid=d2edd41b-2600-0000-bb6a-df3e4c160000 pid=5708 /usr/bin/axxkmrwoyf zombie guuid=6acafc16-2600-0000-bb6a-df3e41160000 pid=5697->guuid=d2edd41b-2600-0000-bb6a-df3e4c160000 pid=5708 clone guuid=d1593117-2600-0000-bb6a-df3e43160000 pid=5699 /usr/bin/axxkmrwoyf zombie guuid=4d581f17-2600-0000-bb6a-df3e42160000 pid=5698->guuid=d1593117-2600-0000-bb6a-df3e43160000 pid=5699 execve guuid=28e4d71a-2600-0000-bb6a-df3e4a160000 pid=5706 /usr/bin/axxkmrwoyf zombie guuid=d1593117-2600-0000-bb6a-df3e43160000 pid=5699->guuid=28e4d71a-2600-0000-bb6a-df3e4a160000 pid=5706 clone guuid=ac036917-2600-0000-bb6a-df3e45160000 pid=5701 /usr/bin/axxkmrwoyf zombie guuid=67ec5a17-2600-0000-bb6a-df3e44160000 pid=5700->guuid=ac036917-2600-0000-bb6a-df3e45160000 pid=5701 execve guuid=8b1f2d1c-2600-0000-bb6a-df3e4d160000 pid=5709 /usr/bin/axxkmrwoyf zombie guuid=ac036917-2600-0000-bb6a-df3e45160000 pid=5701->guuid=8b1f2d1c-2600-0000-bb6a-df3e4d160000 pid=5709 clone guuid=7c9d9c17-2600-0000-bb6a-df3e47160000 pid=5703 /usr/bin/axxkmrwoyf zombie guuid=37398717-2600-0000-bb6a-df3e46160000 pid=5702->guuid=7c9d9c17-2600-0000-bb6a-df3e47160000 pid=5703 execve guuid=734b2f1b-2600-0000-bb6a-df3e4b160000 pid=5707 /usr/bin/axxkmrwoyf zombie guuid=7c9d9c17-2600-0000-bb6a-df3e47160000 pid=5703->guuid=734b2f1b-2600-0000-bb6a-df3e4b160000 pid=5707 clone guuid=d2d2b618-2600-0000-bb6a-df3e49160000 pid=5705 /usr/bin/axxkmrwoyf zombie guuid=68f8b317-2600-0000-bb6a-df3e48160000 pid=5704->guuid=d2d2b618-2600-0000-bb6a-df3e49160000 pid=5705 execve guuid=aa9b721c-2600-0000-bb6a-df3e4e160000 pid=5710 /usr/bin/axxkmrwoyf zombie guuid=d2d2b618-2600-0000-bb6a-df3e49160000 pid=5705->guuid=aa9b721c-2600-0000-bb6a-df3e4e160000 pid=5710 clone guuid=03ac4760-2700-0000-bb6a-df3e50160000 pid=5712 /usr/bin/tnzwukwsgt zombie guuid=dc7f3360-2700-0000-bb6a-df3e4f160000 pid=5711->guuid=03ac4760-2700-0000-bb6a-df3e50160000 pid=5712 execve guuid=80bfb863-2700-0000-bb6a-df3e59160000 pid=5721 /usr/bin/tnzwukwsgt zombie guuid=03ac4760-2700-0000-bb6a-df3e50160000 pid=5712->guuid=80bfb863-2700-0000-bb6a-df3e59160000 pid=5721 clone guuid=17b07160-2700-0000-bb6a-df3e52160000 pid=5714 /usr/bin/tnzwukwsgt zombie guuid=4f9a6660-2700-0000-bb6a-df3e51160000 pid=5713->guuid=17b07160-2700-0000-bb6a-df3e52160000 pid=5714 execve guuid=93dee864-2700-0000-bb6a-df3e5c160000 pid=5724 /usr/bin/tnzwukwsgt zombie guuid=17b07160-2700-0000-bb6a-df3e52160000 pid=5714->guuid=93dee864-2700-0000-bb6a-df3e5c160000 pid=5724 clone guuid=fcbb9360-2700-0000-bb6a-df3e54160000 pid=5716 /usr/bin/tnzwukwsgt zombie guuid=f0678b60-2700-0000-bb6a-df3e53160000 pid=5715->guuid=fcbb9360-2700-0000-bb6a-df3e54160000 pid=5716 execve guuid=1940ff63-2700-0000-bb6a-df3e5b160000 pid=5723 /usr/bin/tnzwukwsgt zombie guuid=fcbb9360-2700-0000-bb6a-df3e54160000 pid=5716->guuid=1940ff63-2700-0000-bb6a-df3e5b160000 pid=5723 clone guuid=fd5fba60-2700-0000-bb6a-df3e56160000 pid=5718 /usr/bin/tnzwukwsgt zombie guuid=c034ad60-2700-0000-bb6a-df3e55160000 pid=5717->guuid=fd5fba60-2700-0000-bb6a-df3e56160000 pid=5718 execve guuid=75d74f65-2700-0000-bb6a-df3e5d160000 pid=5725 /usr/bin/tnzwukwsgt zombie guuid=fd5fba60-2700-0000-bb6a-df3e56160000 pid=5718->guuid=75d74f65-2700-0000-bb6a-df3e5d160000 pid=5725 clone guuid=b1d8e460-2700-0000-bb6a-df3e58160000 pid=5720 /usr/bin/tnzwukwsgt zombie guuid=97c0d860-2700-0000-bb6a-df3e57160000 pid=5719->guuid=b1d8e460-2700-0000-bb6a-df3e58160000 pid=5720 execve guuid=9ebcf363-2700-0000-bb6a-df3e5a160000 pid=5722 /usr/bin/tnzwukwsgt zombie guuid=b1d8e460-2700-0000-bb6a-df3e58160000 pid=5720->guuid=9ebcf363-2700-0000-bb6a-df3e5a160000 pid=5722 clone
Result
Threat name:
XorDDoS
Detection:
malicious
Classification:
troj.evad
Score:
100 / 100
Signature
Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Drops files in suspicious directories
Found malware configuration
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Sample deletes itself
Sample tries to persist itself using cron
Sample tries to persist itself using System V runlevels
Suricata IDS alerts for network traffic
Yara detected XorDDoS Bot
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1763611 Sample: p.txt.elf Startdate: 23/08/2025 Architecture: LINUX Score: 100 76 kk.xxcc789.com 5.196.167.243, 1527, 43900 OVHFR France 2->76 78 kk.nnmm234.com 2->78 80 2 other IPs or domains 2->80 84 Suricata IDS alerts for network traffic 2->84 86 Found malware configuration 2->86 88 Malicious sample detected (through community Yara rule) 2->88 90 4 other signatures 2->90 10 dash rm p.txt.elf 2->10         started        12 dash rm 2->12         started        14 dash cat 2->14         started        16 8 other processes 2->16 signatures3 process4 process5 18 p.txt.elf 10->18         started        file6 66 /usr/lib/libudev.so, ELF 18->66 dropped 68 /usr/bin/wjompasjen, ELF 18->68 dropped 70 /usr/bin/whmkwysiol, ELF 18->70 dropped 72 15 other malicious files 18->72 dropped 92 Drops files in suspicious directories 18->92 94 Sample deletes itself 18->94 96 Sample tries to persist itself using cron 18->96 98 Sample tries to persist itself using System V runlevels 18->98 22 p.txt.elf sh 18->22         started        26 p.txt.elf 18->26         started        28 p.txt.elf 18->28         started        30 115 other processes 18->30 signatures7 process8 file9 74 /etc/crontab, ASCII 22->74 dropped 100 Sample tries to persist itself using cron 22->100 32 sh sed 22->32         started        35 p.txt.elf ivgltsckjc 26->35         started        37 p.txt.elf ivgltsckjc 28->37         started        39 p.txt.elf ivgltsckjc 30->39         started        41 p.txt.elf ivgltsckjc 30->41         started        43 p.txt.elf ivgltsckjc 30->43         started        45 112 other processes 30->45 signatures10 process11 signatures12 82 Sample tries to persist itself using cron 32->82 47 ivgltsckjc 35->47         started        50 ivgltsckjc 37->50         started        52 ivgltsckjc 39->52         started        54 ivgltsckjc 41->54         started        56 ivgltsckjc 43->56         started        58 fgvqugngip 45->58         started        60 fgvqugngip 45->60         started        62 fgvqugngip 45->62         started        64 108 other processes 45->64 process13 signatures14 102 Sample deletes itself 47->102
Threat name:
Linux.Network.Xor
Status:
Malicious
First seen:
2025-08-23 14:01:59 UTC
File Type:
ELF32 Little (Exe)
AV detection:
26 of 38 (68.42%)
Threat level:
  3/5
Result
Malware family:
xorddos
Score:
  10/10
Tags:
family:xorddos botnet discovery downloader execution linux persistence privilege_escalation rootkit
Behaviour
Reads runtime system information
Creates/modifies Cron job
Loads a kernel module
Writes memory of remote process
XorDDoS
XorDDoS payload
Xorddos family
Malware Config
C2 Extraction:
https://ww.aass654.com/config.rar
kk.aass654.com:1527
kk.xxcc789.com:1527
kk.vvbb321.com:1527
kk.jjkk567.com:1527
kk.nnmm234.com:1527
Verdict:
Malicious
Tags:
backdoor trojan xor_ddos Unix.Malware.Xorddos-9856891-0
YARA:
libgcc_backdoor Linux_Trojan_Xorddos_2aef46a6 Linux_Trojan_Xorddos_884cab60 MALWARE_Linux_XORDDoS
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:CP_AllMal_Detector
Author:DiegoAnalytics
Description:CrossPlatform All Malwares Detector: Detect PE, ELF, Mach-O, scripts, archives; overlay, obfuscation, encryption, spoofing, hiding, high entropy, network communication
Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:enterpriseapps2
Author:Tim Brown @timb_machine
Description:Enterprise apps
Rule name:F01_s1ckrule
Author:s1ckb017
Rule name:linux_generic_ipv6_catcher
Author:@_lubiedo
Description:ELF samples using IPv6 addresses
Rule name:Linux_Trojan_Xorddos_2aef46a6
Author:Elastic Security
Rule name:MALWARE_Linux_XORDDoS
Author:ditekSHen
Description:Detects XORDDoS
Rule name:NET
Author:malware-lu
Rule name:unixredflags3
Author:Tim Brown @timb_machine
Description:Hunts for UNIX red flags

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

XorDDoS

elf 5fefeaf30b8cd96607ee013a771c619d2bcba75e294f57e98ba86e8b40e51090

(this sample)

  
Delivery method
Distributed via web download

Comments