MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 69f17c943d7b5f987095d3c288e2e6e5e3f940ae2ce4c35cec24cde07695e977. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



XorDDoS


Vendor detections: 12


Intelligence 12 IOCs YARA 9 File information Comments

SHA256 hash: 69f17c943d7b5f987095d3c288e2e6e5e3f940ae2ce4c35cec24cde07695e977
SHA3-384 hash: 8ef65c167a04e0f132751edb255dc81534ddf0285dd6ba51fd743eefa83d67691da7b290e5af3828901c906221f0190e
SHA1 hash: f0549bf24a24fb4a62190970ffa0f08b3fb88d1e
MD5 hash: c6e68651a8b8c66bcc4ec419aa4b7316
humanhash: washington-nitrogen-oklahoma-neptune
File name:p.txt
Download: download sample
Signature XorDDoS
File size:548'616 bytes
First seen:2025-09-09 15:03:43 UTC
Last seen:2025-11-13 16:11:19 UTC
File type: elf
MIME type:application/x-executable
ssdeep 12288:4Ufrcn+vwK5ripVU4tdZ1pNL/pVbz666ySjQn36Eoj:/fUywKQ7Fb1pNL/p56fjQn36Eu
TLSH T164C45C56E383E2F7C82705B0134BF7BF4620B6359461CD86B7989D5AB9338F22A4D352
telfhash t12ab138722e7558f8b7f08402425a7620ce39e027259439b71ef2b454f7f2c429b6ad7a
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter abuse_ch
Tags:elf XorDDoS

Intelligence


File Origin
# of uploads :
3
# of downloads :
40
Origin country :
DE DE
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Changes owner for a written file
Collects information on the network activity
Collects information on the RAM
Sends data to a server
Receives data from a server
Connection attempt
DNS request
Creating a file
Launching a process
Runs as daemon
Manages services
Collects information on the CPU
Creating a process from a recently created file
Writes files to system directory
Creates or modifies files in /cron to set up autorun
Deletes a system binary file
Creates or modifies files in /init.d to set up autorun
Creates or modifies symbolic links in /init.d to set up autorun
Deleting of the original file
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
gcc lolbin masquerade remote threat xorddos
Verdict:
Malicious
File Type:
elf.32.le
First seen:
2025-08-29T12:02:00Z UTC
Last seen:
2025-08-29T12:02:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-DDoS.Linux.Xarcen.a HEUR:Trojan-DDoS.Linux.Agent.g HEUR:Trojan-DDoS.Linux.Agent.a HEUR:Trojan-DDoS.Linux.Xorddos.gen HEUR:Trojan-DDoS.Linux.Xarcen.d
Status:
terminated
Behavior Graph:
%3 guuid=31f62331-1b00-0000-dd88-13cac10c0000 pid=3265 /usr/bin/sudo guuid=9b740133-1b00-0000-dd88-13cac70c0000 pid=3271 /tmp/sample.bin guuid=31f62331-1b00-0000-dd88-13cac10c0000 pid=3265->guuid=9b740133-1b00-0000-dd88-13cac70c0000 pid=3271 execve guuid=ff612f33-1b00-0000-dd88-13cac90c0000 pid=3273 /tmp/sample.bin delete-file write-config write-file zombie guuid=9b740133-1b00-0000-dd88-13cac70c0000 pid=3271->guuid=ff612f33-1b00-0000-dd88-13cac90c0000 pid=3273 clone guuid=df7f8033-1b00-0000-dd88-13cacb0c0000 pid=3275 /tmp/sample.bin guuid=ff612f33-1b00-0000-dd88-13cac90c0000 pid=3273->guuid=df7f8033-1b00-0000-dd88-13cacb0c0000 pid=3275 clone guuid=62a2a933-1b00-0000-dd88-13cacd0c0000 pid=3277 /tmp/sample.bin guuid=ff612f33-1b00-0000-dd88-13cac90c0000 pid=3273->guuid=62a2a933-1b00-0000-dd88-13cacd0c0000 pid=3277 clone guuid=5b5b1c34-1b00-0000-dd88-13cad10c0000 pid=3281 /usr/bin/dash guuid=ff612f33-1b00-0000-dd88-13cac90c0000 pid=3273->guuid=5b5b1c34-1b00-0000-dd88-13cad10c0000 pid=3281 execve guuid=ff612f33-1b00-0000-dd88-13cac90c0000 pid=3288 /tmp/sample.bin write-file zombie guuid=ff612f33-1b00-0000-dd88-13cac90c0000 pid=3273->guuid=ff612f33-1b00-0000-dd88-13cac90c0000 pid=3288 clone guuid=ff612f33-1b00-0000-dd88-13cac90c0000 pid=3289 /tmp/sample.bin dns net send-data write-file zombie guuid=ff612f33-1b00-0000-dd88-13cac90c0000 pid=3273->guuid=ff612f33-1b00-0000-dd88-13cac90c0000 pid=3289 clone guuid=ff612f33-1b00-0000-dd88-13cac90c0000 pid=3290 /tmp/sample.bin net zombie guuid=ff612f33-1b00-0000-dd88-13cac90c0000 pid=3273->guuid=ff612f33-1b00-0000-dd88-13cac90c0000 pid=3290 clone guuid=5c4dec61-1c00-0000-dd88-13ca7e0f0000 pid=3966 /tmp/sample.bin guuid=ff612f33-1b00-0000-dd88-13cac90c0000 pid=3273->guuid=5c4dec61-1c00-0000-dd88-13ca7e0f0000 pid=3966 clone guuid=b1060762-1c00-0000-dd88-13ca800f0000 pid=3968 /tmp/sample.bin guuid=ff612f33-1b00-0000-dd88-13cac90c0000 pid=3273->guuid=b1060762-1c00-0000-dd88-13ca800f0000 pid=3968 clone guuid=d1282262-1c00-0000-dd88-13ca820f0000 pid=3970 /tmp/sample.bin guuid=ff612f33-1b00-0000-dd88-13cac90c0000 pid=3273->guuid=d1282262-1c00-0000-dd88-13ca820f0000 pid=3970 clone guuid=6af83d62-1c00-0000-dd88-13ca840f0000 pid=3972 /tmp/sample.bin guuid=ff612f33-1b00-0000-dd88-13cac90c0000 pid=3273->guuid=6af83d62-1c00-0000-dd88-13ca840f0000 pid=3972 clone guuid=b17c1663-1c00-0000-dd88-13ca890f0000 pid=3977 /tmp/sample.bin guuid=ff612f33-1b00-0000-dd88-13cac90c0000 pid=3273->guuid=b17c1663-1c00-0000-dd88-13ca890f0000 pid=3977 clone guuid=530af18f-1d00-0000-dd88-13cae7120000 pid=4839 /tmp/sample.bin guuid=ff612f33-1b00-0000-dd88-13cac90c0000 pid=3273->guuid=530af18f-1d00-0000-dd88-13cae7120000 pid=4839 clone guuid=73641490-1d00-0000-dd88-13caea120000 pid=4842 /tmp/sample.bin guuid=ff612f33-1b00-0000-dd88-13cac90c0000 pid=3273->guuid=73641490-1d00-0000-dd88-13caea120000 pid=4842 clone guuid=eb2b7690-1d00-0000-dd88-13caed120000 pid=4845 /tmp/sample.bin guuid=ff612f33-1b00-0000-dd88-13cac90c0000 pid=3273->guuid=eb2b7690-1d00-0000-dd88-13caed120000 pid=4845 clone guuid=67bb4491-1d00-0000-dd88-13caf0120000 pid=4848 /tmp/sample.bin guuid=ff612f33-1b00-0000-dd88-13cac90c0000 pid=3273->guuid=67bb4491-1d00-0000-dd88-13caf0120000 pid=4848 clone guuid=abc5e891-1d00-0000-dd88-13caf5120000 pid=4853 /tmp/sample.bin guuid=ff612f33-1b00-0000-dd88-13cac90c0000 pid=3273->guuid=abc5e891-1d00-0000-dd88-13caf5120000 pid=4853 clone guuid=a42a50be-1e00-0000-dd88-13caae140000 pid=5294 /tmp/sample.bin guuid=ff612f33-1b00-0000-dd88-13cac90c0000 pid=3273->guuid=a42a50be-1e00-0000-dd88-13caae140000 pid=5294 clone guuid=391e7bbe-1e00-0000-dd88-13cab0140000 pid=5296 /tmp/sample.bin guuid=ff612f33-1b00-0000-dd88-13cac90c0000 pid=3273->guuid=391e7bbe-1e00-0000-dd88-13cab0140000 pid=5296 clone guuid=482699be-1e00-0000-dd88-13cab2140000 pid=5298 /tmp/sample.bin guuid=ff612f33-1b00-0000-dd88-13cac90c0000 pid=3273->guuid=482699be-1e00-0000-dd88-13cab2140000 pid=5298 clone guuid=57d8b9be-1e00-0000-dd88-13cab4140000 pid=5300 /tmp/sample.bin guuid=ff612f33-1b00-0000-dd88-13cac90c0000 pid=3273->guuid=57d8b9be-1e00-0000-dd88-13cab4140000 pid=5300 clone guuid=9acab3bf-1e00-0000-dd88-13cab6140000 pid=5302 /tmp/sample.bin guuid=ff612f33-1b00-0000-dd88-13cac90c0000 pid=3273->guuid=9acab3bf-1e00-0000-dd88-13cab6140000 pid=5302 clone guuid=469fd6eb-1f00-0000-dd88-13cac4140000 pid=5316 /tmp/sample.bin guuid=ff612f33-1b00-0000-dd88-13cac90c0000 pid=3273->guuid=469fd6eb-1f00-0000-dd88-13cac4140000 pid=5316 clone guuid=d4fee9eb-1f00-0000-dd88-13cac6140000 pid=5318 /tmp/sample.bin guuid=ff612f33-1b00-0000-dd88-13cac90c0000 pid=3273->guuid=d4fee9eb-1f00-0000-dd88-13cac6140000 pid=5318 clone guuid=89dd40ec-1f00-0000-dd88-13cac8140000 pid=5320 /tmp/sample.bin guuid=ff612f33-1b00-0000-dd88-13cac90c0000 pid=3273->guuid=89dd40ec-1f00-0000-dd88-13cac8140000 pid=5320 clone guuid=fedadbed-1f00-0000-dd88-13caca140000 pid=5322 /tmp/sample.bin guuid=ff612f33-1b00-0000-dd88-13cac90c0000 pid=3273->guuid=fedadbed-1f00-0000-dd88-13caca140000 pid=5322 clone guuid=2ad239ee-1f00-0000-dd88-13cacc140000 pid=5324 /tmp/sample.bin guuid=ff612f33-1b00-0000-dd88-13cac90c0000 pid=3273->guuid=2ad239ee-1f00-0000-dd88-13cacc140000 pid=5324 clone guuid=f57b3c1b-2100-0000-dd88-13caf3140000 pid=5363 /tmp/sample.bin guuid=ff612f33-1b00-0000-dd88-13cac90c0000 pid=3273->guuid=f57b3c1b-2100-0000-dd88-13caf3140000 pid=5363 clone guuid=3d247c1b-2100-0000-dd88-13caf5140000 pid=5365 /tmp/sample.bin guuid=ff612f33-1b00-0000-dd88-13cac90c0000 pid=3273->guuid=3d247c1b-2100-0000-dd88-13caf5140000 pid=5365 clone guuid=d791b71b-2100-0000-dd88-13caf7140000 pid=5367 /tmp/sample.bin guuid=ff612f33-1b00-0000-dd88-13cac90c0000 pid=3273->guuid=d791b71b-2100-0000-dd88-13caf7140000 pid=5367 clone guuid=72edfb1b-2100-0000-dd88-13caf9140000 pid=5369 /tmp/sample.bin guuid=ff612f33-1b00-0000-dd88-13cac90c0000 pid=3273->guuid=72edfb1b-2100-0000-dd88-13caf9140000 pid=5369 clone guuid=a29d261c-2100-0000-dd88-13cafb140000 pid=5371 /tmp/sample.bin guuid=ff612f33-1b00-0000-dd88-13cac90c0000 pid=3273->guuid=a29d261c-2100-0000-dd88-13cafb140000 pid=5371 clone guuid=cf0a3649-2200-0000-dd88-13ca02150000 pid=5378 /tmp/sample.bin guuid=ff612f33-1b00-0000-dd88-13cac90c0000 pid=3273->guuid=cf0a3649-2200-0000-dd88-13ca02150000 pid=5378 clone guuid=d71b7149-2200-0000-dd88-13ca04150000 pid=5380 /tmp/sample.bin guuid=ff612f33-1b00-0000-dd88-13cac90c0000 pid=3273->guuid=d71b7149-2200-0000-dd88-13ca04150000 pid=5380 clone guuid=ebfea249-2200-0000-dd88-13ca06150000 pid=5382 /tmp/sample.bin guuid=ff612f33-1b00-0000-dd88-13cac90c0000 pid=3273->guuid=ebfea249-2200-0000-dd88-13ca06150000 pid=5382 clone guuid=ba44d449-2200-0000-dd88-13ca08150000 pid=5384 /tmp/sample.bin guuid=ff612f33-1b00-0000-dd88-13cac90c0000 pid=3273->guuid=ba44d449-2200-0000-dd88-13ca08150000 pid=5384 clone guuid=6112014a-2200-0000-dd88-13ca0a150000 pid=5386 /tmp/sample.bin guuid=ff612f33-1b00-0000-dd88-13cac90c0000 pid=3273->guuid=6112014a-2200-0000-dd88-13ca0a150000 pid=5386 clone guuid=38f71b78-2300-0000-dd88-13ca11150000 pid=5393 /tmp/sample.bin guuid=ff612f33-1b00-0000-dd88-13cac90c0000 pid=3273->guuid=38f71b78-2300-0000-dd88-13ca11150000 pid=5393 clone guuid=22e25e78-2300-0000-dd88-13ca13150000 pid=5395 /tmp/sample.bin guuid=ff612f33-1b00-0000-dd88-13cac90c0000 pid=3273->guuid=22e25e78-2300-0000-dd88-13ca13150000 pid=5395 clone guuid=6fb99378-2300-0000-dd88-13ca15150000 pid=5397 /tmp/sample.bin guuid=ff612f33-1b00-0000-dd88-13cac90c0000 pid=3273->guuid=6fb99378-2300-0000-dd88-13ca15150000 pid=5397 clone guuid=31bebe78-2300-0000-dd88-13ca17150000 pid=5399 /tmp/sample.bin guuid=ff612f33-1b00-0000-dd88-13cac90c0000 pid=3273->guuid=31bebe78-2300-0000-dd88-13ca17150000 pid=5399 clone guuid=451dff78-2300-0000-dd88-13ca19150000 pid=5401 /tmp/sample.bin guuid=ff612f33-1b00-0000-dd88-13cac90c0000 pid=3273->guuid=451dff78-2300-0000-dd88-13ca19150000 pid=5401 clone guuid=7353cca6-2400-0000-dd88-13ca20150000 pid=5408 /tmp/sample.bin guuid=ff612f33-1b00-0000-dd88-13cac90c0000 pid=3273->guuid=7353cca6-2400-0000-dd88-13ca20150000 pid=5408 clone guuid=bd8901a7-2400-0000-dd88-13ca22150000 pid=5410 /tmp/sample.bin guuid=ff612f33-1b00-0000-dd88-13cac90c0000 pid=3273->guuid=bd8901a7-2400-0000-dd88-13ca22150000 pid=5410 clone guuid=ef2434a7-2400-0000-dd88-13ca24150000 pid=5412 /tmp/sample.bin guuid=ff612f33-1b00-0000-dd88-13cac90c0000 pid=3273->guuid=ef2434a7-2400-0000-dd88-13ca24150000 pid=5412 clone guuid=e69c6ca7-2400-0000-dd88-13ca26150000 pid=5414 /tmp/sample.bin guuid=ff612f33-1b00-0000-dd88-13cac90c0000 pid=3273->guuid=e69c6ca7-2400-0000-dd88-13ca26150000 pid=5414 clone guuid=55139aa7-2400-0000-dd88-13ca28150000 pid=5416 /tmp/sample.bin guuid=ff612f33-1b00-0000-dd88-13cac90c0000 pid=3273->guuid=55139aa7-2400-0000-dd88-13ca28150000 pid=5416 clone guuid=1deb8fd6-2500-0000-dd88-13ca2f150000 pid=5423 /tmp/sample.bin guuid=ff612f33-1b00-0000-dd88-13cac90c0000 pid=3273->guuid=1deb8fd6-2500-0000-dd88-13ca2f150000 pid=5423 clone guuid=c18acad6-2500-0000-dd88-13ca31150000 pid=5425 /tmp/sample.bin guuid=ff612f33-1b00-0000-dd88-13cac90c0000 pid=3273->guuid=c18acad6-2500-0000-dd88-13ca31150000 pid=5425 clone guuid=5af0f9d6-2500-0000-dd88-13ca33150000 pid=5427 /tmp/sample.bin guuid=ff612f33-1b00-0000-dd88-13cac90c0000 pid=3273->guuid=5af0f9d6-2500-0000-dd88-13ca33150000 pid=5427 clone guuid=66c123d7-2500-0000-dd88-13ca35150000 pid=5429 /tmp/sample.bin guuid=ff612f33-1b00-0000-dd88-13cac90c0000 pid=3273->guuid=66c123d7-2500-0000-dd88-13ca35150000 pid=5429 clone guuid=2f7e55d7-2500-0000-dd88-13ca37150000 pid=5431 /tmp/sample.bin guuid=ff612f33-1b00-0000-dd88-13cac90c0000 pid=3273->guuid=2f7e55d7-2500-0000-dd88-13ca37150000 pid=5431 clone guuid=665c1b04-2700-0000-dd88-13ca3e150000 pid=5438 /tmp/sample.bin guuid=ff612f33-1b00-0000-dd88-13cac90c0000 pid=3273->guuid=665c1b04-2700-0000-dd88-13ca3e150000 pid=5438 clone guuid=95894904-2700-0000-dd88-13ca40150000 pid=5440 /tmp/sample.bin guuid=ff612f33-1b00-0000-dd88-13cac90c0000 pid=3273->guuid=95894904-2700-0000-dd88-13ca40150000 pid=5440 clone guuid=089a7904-2700-0000-dd88-13ca42150000 pid=5442 /tmp/sample.bin guuid=ff612f33-1b00-0000-dd88-13cac90c0000 pid=3273->guuid=089a7904-2700-0000-dd88-13ca42150000 pid=5442 clone guuid=b92fa704-2700-0000-dd88-13ca44150000 pid=5444 /tmp/sample.bin guuid=ff612f33-1b00-0000-dd88-13cac90c0000 pid=3273->guuid=b92fa704-2700-0000-dd88-13ca44150000 pid=5444 clone guuid=ad2fd004-2700-0000-dd88-13ca46150000 pid=5446 /tmp/sample.bin guuid=ff612f33-1b00-0000-dd88-13cac90c0000 pid=3273->guuid=ad2fd004-2700-0000-dd88-13ca46150000 pid=5446 clone guuid=1ac79247-2800-0000-dd88-13ca4d150000 pid=5453 /tmp/sample.bin guuid=ff612f33-1b00-0000-dd88-13cac90c0000 pid=3273->guuid=1ac79247-2800-0000-dd88-13ca4d150000 pid=5453 clone guuid=b13bd047-2800-0000-dd88-13ca4f150000 pid=5455 /tmp/sample.bin guuid=ff612f33-1b00-0000-dd88-13cac90c0000 pid=3273->guuid=b13bd047-2800-0000-dd88-13ca4f150000 pid=5455 clone guuid=19201248-2800-0000-dd88-13ca51150000 pid=5457 /tmp/sample.bin guuid=ff612f33-1b00-0000-dd88-13cac90c0000 pid=3273->guuid=19201248-2800-0000-dd88-13ca51150000 pid=5457 clone guuid=6ceb3c48-2800-0000-dd88-13ca53150000 pid=5459 /tmp/sample.bin guuid=ff612f33-1b00-0000-dd88-13cac90c0000 pid=3273->guuid=6ceb3c48-2800-0000-dd88-13ca53150000 pid=5459 clone guuid=e2546348-2800-0000-dd88-13ca55150000 pid=5461 /tmp/sample.bin guuid=ff612f33-1b00-0000-dd88-13cac90c0000 pid=3273->guuid=e2546348-2800-0000-dd88-13ca55150000 pid=5461 clone guuid=3b149633-1b00-0000-dd88-13cacc0c0000 pid=3276 /tmp/sample.bin guuid=df7f8033-1b00-0000-dd88-13cacb0c0000 pid=3275->guuid=3b149633-1b00-0000-dd88-13cacc0c0000 pid=3276 clone guuid=8a011334-1b00-0000-dd88-13cad00c0000 pid=3280 /usr/sbin/update-rc.d zombie guuid=62a2a933-1b00-0000-dd88-13cacd0c0000 pid=3277->guuid=8a011334-1b00-0000-dd88-13cad00c0000 pid=3280 execve guuid=7a52303a-1b00-0000-dd88-13cae20c0000 pid=3298 /usr/bin/systemctl guuid=8a011334-1b00-0000-dd88-13cad00c0000 pid=3280->guuid=7a52303a-1b00-0000-dd88-13cae20c0000 pid=3298 execve guuid=4daf1235-1b00-0000-dd88-13cad40c0000 pid=3284 /usr/bin/sed guuid=5b5b1c34-1b00-0000-dd88-13cad10c0000 pid=3281->guuid=4daf1235-1b00-0000-dd88-13cad40c0000 pid=3284 execve ac052bf2-5fa4-52b3-8f45-a2d335dfcdae 0.0.0.0:1530 guuid=ff612f33-1b00-0000-dd88-13cac90c0000 pid=3289->ac052bf2-5fa4-52b3-8f45-a2d335dfcdae con 8f6ccc38-4fb5-54db-a77c-57d1347e94ad cc.vvbb321.com:1530 guuid=ff612f33-1b00-0000-dd88-13cac90c0000 pid=3289->8f6ccc38-4fb5-54db-a77c-57d1347e94ad send: 4548B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=ff612f33-1b00-0000-dd88-13cac90c0000 pid=3289->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 96B b4bf20d4-f7c8-5c24-8830-c23364537aa4 8.8.4.4:53 guuid=ff612f33-1b00-0000-dd88-13cac90c0000 pid=3289->b4bf20d4-f7c8-5c24-8830-c23364537aa4 send: 64B 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=ff612f33-1b00-0000-dd88-13cac90c0000 pid=3289->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 64B 87f248b3-21f7-50eb-a2c7-cb35eca5cc17 0.0.0.0:80 guuid=ff612f33-1b00-0000-dd88-13cac90c0000 pid=3290->87f248b3-21f7-50eb-a2c7-cb35eca5cc17 con guuid=82d6f661-1c00-0000-dd88-13ca7f0f0000 pid=3967 /usr/bin/iahxejwbhv zombie guuid=5c4dec61-1c00-0000-dd88-13ca7e0f0000 pid=3966->guuid=82d6f661-1c00-0000-dd88-13ca7f0f0000 pid=3967 execve guuid=08b56867-1c00-0000-dd88-13ca970f0000 pid=3991 /usr/bin/iahxejwbhv zombie guuid=82d6f661-1c00-0000-dd88-13ca7f0f0000 pid=3967->guuid=08b56867-1c00-0000-dd88-13ca970f0000 pid=3991 clone guuid=1fed0f62-1c00-0000-dd88-13ca810f0000 pid=3969 /usr/bin/iahxejwbhv zombie guuid=b1060762-1c00-0000-dd88-13ca800f0000 pid=3968->guuid=1fed0f62-1c00-0000-dd88-13ca810f0000 pid=3969 execve guuid=12b48c65-1c00-0000-dd88-13ca920f0000 pid=3986 /usr/bin/iahxejwbhv zombie guuid=1fed0f62-1c00-0000-dd88-13ca810f0000 pid=3969->guuid=12b48c65-1c00-0000-dd88-13ca920f0000 pid=3986 clone guuid=8ffa2a62-1c00-0000-dd88-13ca830f0000 pid=3971 /usr/bin/iahxejwbhv zombie guuid=d1282262-1c00-0000-dd88-13ca820f0000 pid=3970->guuid=8ffa2a62-1c00-0000-dd88-13ca830f0000 pid=3971 execve guuid=5d4c1169-1c00-0000-dd88-13ca9d0f0000 pid=3997 /usr/bin/iahxejwbhv zombie guuid=8ffa2a62-1c00-0000-dd88-13ca830f0000 pid=3971->guuid=5d4c1169-1c00-0000-dd88-13ca9d0f0000 pid=3997 clone guuid=7dea0663-1c00-0000-dd88-13ca880f0000 pid=3976 /usr/bin/iahxejwbhv zombie guuid=6af83d62-1c00-0000-dd88-13ca840f0000 pid=3972->guuid=7dea0663-1c00-0000-dd88-13ca880f0000 pid=3976 execve guuid=0c527168-1c00-0000-dd88-13ca9b0f0000 pid=3995 /usr/bin/iahxejwbhv zombie guuid=7dea0663-1c00-0000-dd88-13ca880f0000 pid=3976->guuid=0c527168-1c00-0000-dd88-13ca9b0f0000 pid=3995 clone guuid=7f4c8363-1c00-0000-dd88-13ca8d0f0000 pid=3981 /usr/bin/iahxejwbhv zombie guuid=b17c1663-1c00-0000-dd88-13ca890f0000 pid=3977->guuid=7f4c8363-1c00-0000-dd88-13ca8d0f0000 pid=3981 execve guuid=32cd5168-1c00-0000-dd88-13ca9a0f0000 pid=3994 /usr/bin/iahxejwbhv zombie guuid=7f4c8363-1c00-0000-dd88-13ca8d0f0000 pid=3981->guuid=32cd5168-1c00-0000-dd88-13ca9a0f0000 pid=3994 clone guuid=5112f88f-1d00-0000-dd88-13cae9120000 pid=4841 /usr/bin/mezfnenopr zombie guuid=530af18f-1d00-0000-dd88-13cae7120000 pid=4839->guuid=5112f88f-1d00-0000-dd88-13cae9120000 pid=4841 execve guuid=e9f74995-1d00-0000-dd88-13ca03130000 pid=4867 /usr/bin/mezfnenopr zombie guuid=5112f88f-1d00-0000-dd88-13cae9120000 pid=4841->guuid=e9f74995-1d00-0000-dd88-13ca03130000 pid=4867 clone guuid=111f4090-1d00-0000-dd88-13caeb120000 pid=4843 /usr/bin/mezfnenopr zombie guuid=73641490-1d00-0000-dd88-13caea120000 pid=4842->guuid=111f4090-1d00-0000-dd88-13caeb120000 pid=4843 execve guuid=6c09d694-1d00-0000-dd88-13ca00130000 pid=4864 /usr/bin/mezfnenopr zombie guuid=111f4090-1d00-0000-dd88-13caeb120000 pid=4843->guuid=6c09d694-1d00-0000-dd88-13ca00130000 pid=4864 clone guuid=7e881391-1d00-0000-dd88-13caef120000 pid=4847 /usr/bin/mezfnenopr zombie guuid=eb2b7690-1d00-0000-dd88-13caed120000 pid=4845->guuid=7e881391-1d00-0000-dd88-13caef120000 pid=4847 execve guuid=a7232596-1d00-0000-dd88-13ca05130000 pid=4869 /usr/bin/mezfnenopr zombie guuid=7e881391-1d00-0000-dd88-13caef120000 pid=4847->guuid=a7232596-1d00-0000-dd88-13ca05130000 pid=4869 clone guuid=8f0cd391-1d00-0000-dd88-13caf4120000 pid=4852 /usr/bin/mezfnenopr zombie guuid=67bb4491-1d00-0000-dd88-13caf0120000 pid=4848->guuid=8f0cd391-1d00-0000-dd88-13caf4120000 pid=4852 execve guuid=053dfe96-1d00-0000-dd88-13ca07130000 pid=4871 /usr/bin/mezfnenopr zombie guuid=8f0cd391-1d00-0000-dd88-13caf4120000 pid=4852->guuid=053dfe96-1d00-0000-dd88-13ca07130000 pid=4871 clone guuid=4aadf391-1d00-0000-dd88-13caf7120000 pid=4855 /usr/bin/mezfnenopr zombie guuid=abc5e891-1d00-0000-dd88-13caf5120000 pid=4853->guuid=4aadf391-1d00-0000-dd88-13caf7120000 pid=4855 execve guuid=735c0398-1d00-0000-dd88-13ca0a130000 pid=4874 /usr/bin/mezfnenopr zombie guuid=4aadf391-1d00-0000-dd88-13caf7120000 pid=4855->guuid=735c0398-1d00-0000-dd88-13ca0a130000 pid=4874 clone guuid=06165ebe-1e00-0000-dd88-13caaf140000 pid=5295 /usr/bin/bsfltkstpq zombie guuid=a42a50be-1e00-0000-dd88-13caae140000 pid=5294->guuid=06165ebe-1e00-0000-dd88-13caaf140000 pid=5295 execve guuid=bb1afbc1-1e00-0000-dd88-13cab8140000 pid=5304 /usr/bin/bsfltkstpq zombie guuid=06165ebe-1e00-0000-dd88-13caaf140000 pid=5295->guuid=bb1afbc1-1e00-0000-dd88-13cab8140000 pid=5304 clone guuid=e8ae83be-1e00-0000-dd88-13cab1140000 pid=5297 /usr/bin/bsfltkstpq zombie guuid=391e7bbe-1e00-0000-dd88-13cab0140000 pid=5296->guuid=e8ae83be-1e00-0000-dd88-13cab1140000 pid=5297 execve guuid=ad4483c3-1e00-0000-dd88-13caba140000 pid=5306 /usr/bin/bsfltkstpq zombie guuid=e8ae83be-1e00-0000-dd88-13cab1140000 pid=5297->guuid=ad4483c3-1e00-0000-dd88-13caba140000 pid=5306 clone guuid=425da5be-1e00-0000-dd88-13cab3140000 pid=5299 /usr/bin/bsfltkstpq zombie guuid=482699be-1e00-0000-dd88-13cab2140000 pid=5298->guuid=425da5be-1e00-0000-dd88-13cab3140000 pid=5299 execve guuid=118f99c2-1e00-0000-dd88-13cab9140000 pid=5305 /usr/bin/bsfltkstpq zombie guuid=425da5be-1e00-0000-dd88-13cab3140000 pid=5299->guuid=118f99c2-1e00-0000-dd88-13cab9140000 pid=5305 clone guuid=3b2da7bf-1e00-0000-dd88-13cab5140000 pid=5301 /usr/bin/bsfltkstpq zombie guuid=57d8b9be-1e00-0000-dd88-13cab4140000 pid=5300->guuid=3b2da7bf-1e00-0000-dd88-13cab5140000 pid=5301 execve guuid=bc92a2c5-1e00-0000-dd88-13cabc140000 pid=5308 /usr/bin/bsfltkstpq zombie guuid=3b2da7bf-1e00-0000-dd88-13cab5140000 pid=5301->guuid=bc92a2c5-1e00-0000-dd88-13cabc140000 pid=5308 clone guuid=59e72dc0-1e00-0000-dd88-13cab7140000 pid=5303 /usr/bin/bsfltkstpq zombie guuid=9acab3bf-1e00-0000-dd88-13cab6140000 pid=5302->guuid=59e72dc0-1e00-0000-dd88-13cab7140000 pid=5303 execve guuid=c1279cc4-1e00-0000-dd88-13cabb140000 pid=5307 /usr/bin/bsfltkstpq zombie guuid=59e72dc0-1e00-0000-dd88-13cab7140000 pid=5303->guuid=c1279cc4-1e00-0000-dd88-13cabb140000 pid=5307 clone guuid=087eddeb-1f00-0000-dd88-13cac5140000 pid=5317 /usr/bin/ffpecidxui zombie guuid=469fd6eb-1f00-0000-dd88-13cac4140000 pid=5316->guuid=087eddeb-1f00-0000-dd88-13cac5140000 pid=5317 execve guuid=fd9567f3-1f00-0000-dd88-13cace140000 pid=5326 /usr/bin/ffpecidxui zombie guuid=087eddeb-1f00-0000-dd88-13cac5140000 pid=5317->guuid=fd9567f3-1f00-0000-dd88-13cace140000 pid=5326 clone guuid=e50421ec-1f00-0000-dd88-13cac7140000 pid=5319 /usr/bin/ffpecidxui zombie guuid=d4fee9eb-1f00-0000-dd88-13cac6140000 pid=5318->guuid=e50421ec-1f00-0000-dd88-13cac7140000 pid=5319 execve guuid=6286a0f5-1f00-0000-dd88-13cacf140000 pid=5327 /usr/bin/ffpecidxui zombie guuid=e50421ec-1f00-0000-dd88-13cac7140000 pid=5319->guuid=6286a0f5-1f00-0000-dd88-13cacf140000 pid=5327 clone guuid=1810c7ed-1f00-0000-dd88-13cac9140000 pid=5321 /usr/bin/ffpecidxui zombie guuid=89dd40ec-1f00-0000-dd88-13cac8140000 pid=5320->guuid=1810c7ed-1f00-0000-dd88-13cac9140000 pid=5321 execve guuid=5b0b9bf7-1f00-0000-dd88-13cad1140000 pid=5329 /usr/bin/ffpecidxui zombie guuid=1810c7ed-1f00-0000-dd88-13cac9140000 pid=5321->guuid=5b0b9bf7-1f00-0000-dd88-13cad1140000 pid=5329 clone guuid=fabd01ee-1f00-0000-dd88-13cacb140000 pid=5323 /usr/bin/ffpecidxui zombie guuid=fedadbed-1f00-0000-dd88-13caca140000 pid=5322->guuid=fabd01ee-1f00-0000-dd88-13cacb140000 pid=5323 execve guuid=d539c4f7-1f00-0000-dd88-13cad2140000 pid=5330 /usr/bin/ffpecidxui zombie guuid=fabd01ee-1f00-0000-dd88-13cacb140000 pid=5323->guuid=d539c4f7-1f00-0000-dd88-13cad2140000 pid=5330 clone guuid=f4a5b4ee-1f00-0000-dd88-13cacd140000 pid=5325 /usr/bin/ffpecidxui zombie guuid=2ad239ee-1f00-0000-dd88-13cacc140000 pid=5324->guuid=f4a5b4ee-1f00-0000-dd88-13cacd140000 pid=5325 execve guuid=ad719df6-1f00-0000-dd88-13cad0140000 pid=5328 /usr/bin/ffpecidxui zombie guuid=f4a5b4ee-1f00-0000-dd88-13cacd140000 pid=5325->guuid=ad719df6-1f00-0000-dd88-13cad0140000 pid=5328 clone guuid=fcaf561b-2100-0000-dd88-13caf4140000 pid=5364 /usr/bin/dmxgphiyop zombie guuid=f57b3c1b-2100-0000-dd88-13caf3140000 pid=5363->guuid=fcaf561b-2100-0000-dd88-13caf4140000 pid=5364 execve guuid=d8edaa1f-2100-0000-dd88-13caff140000 pid=5375 /usr/bin/dmxgphiyop zombie guuid=fcaf561b-2100-0000-dd88-13caf4140000 pid=5364->guuid=d8edaa1f-2100-0000-dd88-13caff140000 pid=5375 clone guuid=c0c58a1b-2100-0000-dd88-13caf6140000 pid=5366 /usr/bin/dmxgphiyop zombie guuid=3d247c1b-2100-0000-dd88-13caf5140000 pid=5365->guuid=c0c58a1b-2100-0000-dd88-13caf6140000 pid=5366 execve guuid=b100fc1e-2100-0000-dd88-13cafd140000 pid=5373 /usr/bin/dmxgphiyop zombie guuid=c0c58a1b-2100-0000-dd88-13caf6140000 pid=5366->guuid=b100fc1e-2100-0000-dd88-13cafd140000 pid=5373 clone guuid=6d03dc1b-2100-0000-dd88-13caf8140000 pid=5368 /usr/bin/dmxgphiyop zombie guuid=d791b71b-2100-0000-dd88-13caf7140000 pid=5367->guuid=6d03dc1b-2100-0000-dd88-13caf8140000 pid=5368 execve guuid=39622e1f-2100-0000-dd88-13cafe140000 pid=5374 /usr/bin/dmxgphiyop zombie guuid=6d03dc1b-2100-0000-dd88-13caf8140000 pid=5368->guuid=39622e1f-2100-0000-dd88-13cafe140000 pid=5374 clone guuid=94b70d1c-2100-0000-dd88-13cafa140000 pid=5370 /usr/bin/dmxgphiyop zombie guuid=72edfb1b-2100-0000-dd88-13caf9140000 pid=5369->guuid=94b70d1c-2100-0000-dd88-13cafa140000 pid=5370 execve guuid=36618920-2100-0000-dd88-13ca00150000 pid=5376 /usr/bin/dmxgphiyop zombie guuid=94b70d1c-2100-0000-dd88-13cafa140000 pid=5370->guuid=36618920-2100-0000-dd88-13ca00150000 pid=5376 clone guuid=a41dc91c-2100-0000-dd88-13cafc140000 pid=5372 /usr/bin/dmxgphiyop zombie guuid=a29d261c-2100-0000-dd88-13cafb140000 pid=5371->guuid=a41dc91c-2100-0000-dd88-13cafc140000 pid=5372 execve guuid=3d2b0d21-2100-0000-dd88-13ca01150000 pid=5377 /usr/bin/dmxgphiyop zombie guuid=a41dc91c-2100-0000-dd88-13cafc140000 pid=5372->guuid=3d2b0d21-2100-0000-dd88-13ca01150000 pid=5377 clone guuid=c5a64a49-2200-0000-dd88-13ca03150000 pid=5379 /usr/bin/fzikvgeaie zombie guuid=cf0a3649-2200-0000-dd88-13ca02150000 pid=5378->guuid=c5a64a49-2200-0000-dd88-13ca03150000 pid=5379 execve guuid=5dd9c24b-2200-0000-dd88-13ca0c150000 pid=5388 /usr/bin/fzikvgeaie zombie guuid=c5a64a49-2200-0000-dd88-13ca03150000 pid=5379->guuid=5dd9c24b-2200-0000-dd88-13ca0c150000 pid=5388 clone guuid=4bb38149-2200-0000-dd88-13ca05150000 pid=5381 /usr/bin/fzikvgeaie zombie guuid=d71b7149-2200-0000-dd88-13ca04150000 pid=5380->guuid=4bb38149-2200-0000-dd88-13ca05150000 pid=5381 execve guuid=d82bb34d-2200-0000-dd88-13ca0e150000 pid=5390 /usr/bin/fzikvgeaie zombie guuid=4bb38149-2200-0000-dd88-13ca05150000 pid=5381->guuid=d82bb34d-2200-0000-dd88-13ca0e150000 pid=5390 clone guuid=80d7ba49-2200-0000-dd88-13ca07150000 pid=5383 /usr/bin/fzikvgeaie zombie guuid=ebfea249-2200-0000-dd88-13ca06150000 pid=5382->guuid=80d7ba49-2200-0000-dd88-13ca07150000 pid=5383 execve guuid=631e4f4e-2200-0000-dd88-13ca0f150000 pid=5391 /usr/bin/fzikvgeaie zombie guuid=80d7ba49-2200-0000-dd88-13ca07150000 pid=5383->guuid=631e4f4e-2200-0000-dd88-13ca0f150000 pid=5391 clone guuid=fb22e549-2200-0000-dd88-13ca09150000 pid=5385 /usr/bin/fzikvgeaie zombie guuid=ba44d449-2200-0000-dd88-13ca08150000 pid=5384->guuid=fb22e549-2200-0000-dd88-13ca09150000 pid=5385 execve guuid=2b944a4d-2200-0000-dd88-13ca0d150000 pid=5389 /usr/bin/fzikvgeaie zombie guuid=fb22e549-2200-0000-dd88-13ca09150000 pid=5385->guuid=2b944a4d-2200-0000-dd88-13ca0d150000 pid=5389 clone guuid=c1a5084b-2200-0000-dd88-13ca0b150000 pid=5387 /usr/bin/fzikvgeaie zombie guuid=6112014a-2200-0000-dd88-13ca0a150000 pid=5386->guuid=c1a5084b-2200-0000-dd88-13ca0b150000 pid=5387 execve guuid=90ae884e-2200-0000-dd88-13ca10150000 pid=5392 /usr/bin/fzikvgeaie zombie guuid=c1a5084b-2200-0000-dd88-13ca0b150000 pid=5387->guuid=90ae884e-2200-0000-dd88-13ca10150000 pid=5392 clone guuid=137b3478-2300-0000-dd88-13ca12150000 pid=5394 /usr/bin/dhddtsaidm zombie guuid=38f71b78-2300-0000-dd88-13ca11150000 pid=5393->guuid=137b3478-2300-0000-dd88-13ca12150000 pid=5394 execve guuid=e568577c-2300-0000-dd88-13ca1b150000 pid=5403 /usr/bin/dhddtsaidm zombie guuid=137b3478-2300-0000-dd88-13ca12150000 pid=5394->guuid=e568577c-2300-0000-dd88-13ca1b150000 pid=5403 clone guuid=fb037278-2300-0000-dd88-13ca14150000 pid=5396 /usr/bin/dhddtsaidm zombie guuid=22e25e78-2300-0000-dd88-13ca13150000 pid=5395->guuid=fb037278-2300-0000-dd88-13ca14150000 pid=5396 execve guuid=69ed147e-2300-0000-dd88-13ca1e150000 pid=5406 /usr/bin/dhddtsaidm zombie guuid=fb037278-2300-0000-dd88-13ca14150000 pid=5396->guuid=69ed147e-2300-0000-dd88-13ca1e150000 pid=5406 clone guuid=a829a278-2300-0000-dd88-13ca16150000 pid=5398 /usr/bin/dhddtsaidm zombie guuid=6fb99378-2300-0000-dd88-13ca15150000 pid=5397->guuid=a829a278-2300-0000-dd88-13ca16150000 pid=5398 execve guuid=6cddee7c-2300-0000-dd88-13ca1d150000 pid=5405 /usr/bin/dhddtsaidm zombie guuid=a829a278-2300-0000-dd88-13ca16150000 pid=5398->guuid=6cddee7c-2300-0000-dd88-13ca1d150000 pid=5405 clone guuid=e8dfe078-2300-0000-dd88-13ca18150000 pid=5400 /usr/bin/dhddtsaidm zombie guuid=31bebe78-2300-0000-dd88-13ca17150000 pid=5399->guuid=e8dfe078-2300-0000-dd88-13ca18150000 pid=5400 execve guuid=6913bc7c-2300-0000-dd88-13ca1c150000 pid=5404 /usr/bin/dhddtsaidm zombie guuid=e8dfe078-2300-0000-dd88-13ca18150000 pid=5400->guuid=6913bc7c-2300-0000-dd88-13ca1c150000 pid=5404 clone guuid=fef16f79-2300-0000-dd88-13ca1a150000 pid=5402 /usr/bin/dhddtsaidm zombie guuid=451dff78-2300-0000-dd88-13ca19150000 pid=5401->guuid=fef16f79-2300-0000-dd88-13ca1a150000 pid=5402 execve guuid=d8cc6c7e-2300-0000-dd88-13ca1f150000 pid=5407 /usr/bin/dhddtsaidm zombie guuid=fef16f79-2300-0000-dd88-13ca1a150000 pid=5402->guuid=d8cc6c7e-2300-0000-dd88-13ca1f150000 pid=5407 clone guuid=3928e0a6-2400-0000-dd88-13ca21150000 pid=5409 /usr/bin/fdcfrmmtzv zombie guuid=7353cca6-2400-0000-dd88-13ca20150000 pid=5408->guuid=3928e0a6-2400-0000-dd88-13ca21150000 pid=5409 execve guuid=cef7f2aa-2400-0000-dd88-13ca2a150000 pid=5418 /usr/bin/fdcfrmmtzv zombie guuid=3928e0a6-2400-0000-dd88-13ca21150000 pid=5409->guuid=cef7f2aa-2400-0000-dd88-13ca2a150000 pid=5418 clone guuid=04f50fa7-2400-0000-dd88-13ca23150000 pid=5411 /usr/bin/fdcfrmmtzv zombie guuid=bd8901a7-2400-0000-dd88-13ca22150000 pid=5410->guuid=04f50fa7-2400-0000-dd88-13ca23150000 pid=5411 execve guuid=73f71cab-2400-0000-dd88-13ca2b150000 pid=5419 /usr/bin/fdcfrmmtzv zombie guuid=04f50fa7-2400-0000-dd88-13ca23150000 pid=5411->guuid=73f71cab-2400-0000-dd88-13ca2b150000 pid=5419 clone guuid=4a7753a7-2400-0000-dd88-13ca25150000 pid=5413 /usr/bin/fdcfrmmtzv zombie guuid=ef2434a7-2400-0000-dd88-13ca24150000 pid=5412->guuid=4a7753a7-2400-0000-dd88-13ca25150000 pid=5413 execve guuid=20c31aac-2400-0000-dd88-13ca2d150000 pid=5421 /usr/bin/fdcfrmmtzv zombie guuid=4a7753a7-2400-0000-dd88-13ca25150000 pid=5413->guuid=20c31aac-2400-0000-dd88-13ca2d150000 pid=5421 clone guuid=6bb27ea7-2400-0000-dd88-13ca27150000 pid=5415 /usr/bin/fdcfrmmtzv zombie guuid=e69c6ca7-2400-0000-dd88-13ca26150000 pid=5414->guuid=6bb27ea7-2400-0000-dd88-13ca27150000 pid=5415 execve guuid=e7c43fab-2400-0000-dd88-13ca2c150000 pid=5420 /usr/bin/fdcfrmmtzv zombie guuid=6bb27ea7-2400-0000-dd88-13ca27150000 pid=5415->guuid=e7c43fab-2400-0000-dd88-13ca2c150000 pid=5420 clone guuid=a8e6aba8-2400-0000-dd88-13ca29150000 pid=5417 /usr/bin/fdcfrmmtzv zombie guuid=55139aa7-2400-0000-dd88-13ca28150000 pid=5416->guuid=a8e6aba8-2400-0000-dd88-13ca29150000 pid=5417 execve guuid=c016bbac-2400-0000-dd88-13ca2e150000 pid=5422 /usr/bin/fdcfrmmtzv zombie guuid=a8e6aba8-2400-0000-dd88-13ca29150000 pid=5417->guuid=c016bbac-2400-0000-dd88-13ca2e150000 pid=5422 clone guuid=65b1a4d6-2500-0000-dd88-13ca30150000 pid=5424 /usr/bin/kodghqesuj zombie guuid=1deb8fd6-2500-0000-dd88-13ca2f150000 pid=5423->guuid=65b1a4d6-2500-0000-dd88-13ca30150000 pid=5424 execve guuid=b35b92da-2500-0000-dd88-13ca39150000 pid=5433 /usr/bin/kodghqesuj zombie guuid=65b1a4d6-2500-0000-dd88-13ca30150000 pid=5424->guuid=b35b92da-2500-0000-dd88-13ca39150000 pid=5433 clone guuid=01a0d9d6-2500-0000-dd88-13ca32150000 pid=5426 /usr/bin/kodghqesuj zombie guuid=c18acad6-2500-0000-dd88-13ca31150000 pid=5425->guuid=01a0d9d6-2500-0000-dd88-13ca32150000 pid=5426 execve guuid=c2074edc-2500-0000-dd88-13ca3c150000 pid=5436 /usr/bin/kodghqesuj zombie guuid=01a0d9d6-2500-0000-dd88-13ca32150000 pid=5426->guuid=c2074edc-2500-0000-dd88-13ca3c150000 pid=5436 clone guuid=862507d7-2500-0000-dd88-13ca34150000 pid=5428 /usr/bin/kodghqesuj zombie guuid=5af0f9d6-2500-0000-dd88-13ca33150000 pid=5427->guuid=862507d7-2500-0000-dd88-13ca34150000 pid=5428 execve guuid=9f70feda-2500-0000-dd88-13ca3a150000 pid=5434 /usr/bin/kodghqesuj zombie guuid=862507d7-2500-0000-dd88-13ca34150000 pid=5428->guuid=9f70feda-2500-0000-dd88-13ca3a150000 pid=5434 clone guuid=9d0b3dd7-2500-0000-dd88-13ca36150000 pid=5430 /usr/bin/kodghqesuj zombie guuid=66c123d7-2500-0000-dd88-13ca35150000 pid=5429->guuid=9d0b3dd7-2500-0000-dd88-13ca36150000 pid=5430 execve guuid=6ee3a2dc-2500-0000-dd88-13ca3d150000 pid=5437 /usr/bin/kodghqesuj zombie guuid=9d0b3dd7-2500-0000-dd88-13ca36150000 pid=5430->guuid=6ee3a2dc-2500-0000-dd88-13ca3d150000 pid=5437 clone guuid=7ef362d7-2500-0000-dd88-13ca38150000 pid=5432 /usr/bin/kodghqesuj zombie guuid=2f7e55d7-2500-0000-dd88-13ca37150000 pid=5431->guuid=7ef362d7-2500-0000-dd88-13ca38150000 pid=5432 execve guuid=1f4e5adb-2500-0000-dd88-13ca3b150000 pid=5435 /usr/bin/kodghqesuj zombie guuid=7ef362d7-2500-0000-dd88-13ca38150000 pid=5432->guuid=1f4e5adb-2500-0000-dd88-13ca3b150000 pid=5435 clone guuid=65023104-2700-0000-dd88-13ca3f150000 pid=5439 /usr/bin/fxzmkruwwo zombie guuid=665c1b04-2700-0000-dd88-13ca3e150000 pid=5438->guuid=65023104-2700-0000-dd88-13ca3f150000 pid=5439 execve guuid=e4301508-2700-0000-dd88-13ca49150000 pid=5449 /usr/bin/fxzmkruwwo zombie guuid=65023104-2700-0000-dd88-13ca3f150000 pid=5439->guuid=e4301508-2700-0000-dd88-13ca49150000 pid=5449 clone guuid=13cd5b04-2700-0000-dd88-13ca41150000 pid=5441 /usr/bin/fxzmkruwwo zombie guuid=95894904-2700-0000-dd88-13ca40150000 pid=5440->guuid=13cd5b04-2700-0000-dd88-13ca41150000 pid=5441 execve guuid=68e0ea07-2700-0000-dd88-13ca48150000 pid=5448 /usr/bin/fxzmkruwwo zombie guuid=13cd5b04-2700-0000-dd88-13ca41150000 pid=5441->guuid=68e0ea07-2700-0000-dd88-13ca48150000 pid=5448 clone guuid=41ed8b04-2700-0000-dd88-13ca43150000 pid=5443 /usr/bin/fxzmkruwwo zombie guuid=089a7904-2700-0000-dd88-13ca42150000 pid=5442->guuid=41ed8b04-2700-0000-dd88-13ca43150000 pid=5443 execve guuid=7bc81309-2700-0000-dd88-13ca4b150000 pid=5451 /usr/bin/fxzmkruwwo zombie guuid=41ed8b04-2700-0000-dd88-13ca43150000 pid=5443->guuid=7bc81309-2700-0000-dd88-13ca4b150000 pid=5451 clone guuid=f693b304-2700-0000-dd88-13ca45150000 pid=5445 /usr/bin/fxzmkruwwo zombie guuid=b92fa704-2700-0000-dd88-13ca44150000 pid=5444->guuid=f693b304-2700-0000-dd88-13ca45150000 pid=5445 execve guuid=97325608-2700-0000-dd88-13ca4a150000 pid=5450 /usr/bin/fxzmkruwwo zombie guuid=f693b304-2700-0000-dd88-13ca45150000 pid=5445->guuid=97325608-2700-0000-dd88-13ca4a150000 pid=5450 clone guuid=cedb5205-2700-0000-dd88-13ca47150000 pid=5447 /usr/bin/fxzmkruwwo zombie guuid=ad2fd004-2700-0000-dd88-13ca46150000 pid=5446->guuid=cedb5205-2700-0000-dd88-13ca47150000 pid=5447 execve guuid=7fecbe09-2700-0000-dd88-13ca4c150000 pid=5452 /usr/bin/fxzmkruwwo zombie guuid=cedb5205-2700-0000-dd88-13ca47150000 pid=5447->guuid=7fecbe09-2700-0000-dd88-13ca4c150000 pid=5452 clone guuid=314ea747-2800-0000-dd88-13ca4e150000 pid=5454 /usr/bin/oxgxzfurze zombie guuid=1ac79247-2800-0000-dd88-13ca4d150000 pid=5453->guuid=314ea747-2800-0000-dd88-13ca4e150000 pid=5454 execve guuid=e11b424b-2800-0000-dd88-13ca57150000 pid=5463 /usr/bin/oxgxzfurze zombie guuid=314ea747-2800-0000-dd88-13ca4e150000 pid=5454->guuid=e11b424b-2800-0000-dd88-13ca57150000 pid=5463 clone guuid=6669e947-2800-0000-dd88-13ca50150000 pid=5456 /usr/bin/oxgxzfurze zombie guuid=b13bd047-2800-0000-dd88-13ca4f150000 pid=5455->guuid=6669e947-2800-0000-dd88-13ca50150000 pid=5456 execve guuid=e7ee8b4b-2800-0000-dd88-13ca58150000 pid=5464 /usr/bin/oxgxzfurze zombie guuid=6669e947-2800-0000-dd88-13ca50150000 pid=5456->guuid=e7ee8b4b-2800-0000-dd88-13ca58150000 pid=5464 clone guuid=db0b2248-2800-0000-dd88-13ca52150000 pid=5458 /usr/bin/oxgxzfurze zombie guuid=19201248-2800-0000-dd88-13ca51150000 pid=5457->guuid=db0b2248-2800-0000-dd88-13ca52150000 pid=5458 execve guuid=2369f54b-2800-0000-dd88-13ca59150000 pid=5465 /usr/bin/oxgxzfurze zombie guuid=db0b2248-2800-0000-dd88-13ca52150000 pid=5458->guuid=2369f54b-2800-0000-dd88-13ca59150000 pid=5465 clone guuid=534a4948-2800-0000-dd88-13ca54150000 pid=5460 /usr/bin/oxgxzfurze zombie guuid=6ceb3c48-2800-0000-dd88-13ca53150000 pid=5459->guuid=534a4948-2800-0000-dd88-13ca54150000 pid=5460 execve guuid=1c35fa4c-2800-0000-dd88-13ca5a150000 pid=5466 /usr/bin/oxgxzfurze zombie guuid=534a4948-2800-0000-dd88-13ca54150000 pid=5460->guuid=1c35fa4c-2800-0000-dd88-13ca5a150000 pid=5466 clone guuid=99fa1349-2800-0000-dd88-13ca56150000 pid=5462 /usr/bin/oxgxzfurze zombie guuid=e2546348-2800-0000-dd88-13ca55150000 pid=5461->guuid=99fa1349-2800-0000-dd88-13ca56150000 pid=5462 execve guuid=bb729f4d-2800-0000-dd88-13ca5b150000 pid=5467 /usr/bin/oxgxzfurze zombie guuid=99fa1349-2800-0000-dd88-13ca56150000 pid=5462->guuid=bb729f4d-2800-0000-dd88-13ca5b150000 pid=5467 clone
Result
Threat name:
XorDDoS
Detection:
malicious
Classification:
troj.evad
Score:
100 / 100
Signature
Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Drops files in suspicious directories
Found malware configuration
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Sample deletes itself
Sample tries to persist itself using cron
Sample tries to persist itself using System V runlevels
Suricata IDS alerts for network traffic
Yara detected XorDDoS Bot
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1774067 Sample: p.txt.elf Startdate: 09/09/2025 Architecture: LINUX Score: 100 72 cc.vvbb321.com 123.136.95.226, 1530, 39782 A-STAR-AS-APA-STARSG China 2->72 74 cc.nnmm234.com 2->74 76 cc.jjkk567.com 2->76 78 Suricata IDS alerts for network traffic 2->78 80 Found malware configuration 2->80 82 Malicious sample detected (through community Yara rule) 2->82 84 4 other signatures 2->84 10 p.txt.elf 2->10         started        12 systemd snapd-env-generator 2->12         started        signatures3 process4 process5 14 p.txt.elf 10->14         started        file6 64 /usr/lib/libudev.so, ELF 14->64 dropped 66 /usr/bin/xvynpbajkc, ELF 14->66 dropped 68 /usr/bin/tldhtfqbtp, ELF 14->68 dropped 70 15 other malicious files 14->70 dropped 92 Drops files in suspicious directories 14->92 94 Sample deletes itself 14->94 96 Sample tries to persist itself using cron 14->96 98 Sample tries to persist itself using System V runlevels 14->98 18 p.txt.elf sh 14->18         started        22 p.txt.elf 14->22         started        24 p.txt.elf 14->24         started        26 110 other processes 14->26 signatures7 process8 file9 62 /etc/crontab, ASCII 18->62 dropped 86 Sample tries to persist itself using cron 18->86 28 sh sed 18->28         started        31 p.txt.elf rnpejbtiaz 22->31         started        33 p.txt.elf rnpejbtiaz 24->33         started        35 p.txt.elf rnpejbtiaz 26->35         started        37 p.txt.elf rnpejbtiaz 26->37         started        39 p.txt.elf rnpejbtiaz 26->39         started        41 107 other processes 26->41 signatures10 process11 signatures12 90 Sample tries to persist itself using cron 28->90 43 rnpejbtiaz 31->43         started        46 rnpejbtiaz 33->46         started        48 rnpejbtiaz 35->48         started        50 rnpejbtiaz 37->50         started        52 rnpejbtiaz 39->52         started        54 gwfwggreta 41->54         started        56 gwfwggreta 41->56         started        58 gwfwggreta 41->58         started        60 103 other processes 41->60 process13 signatures14 88 Sample deletes itself 54->88
Threat name:
Linux.Network.Xor
Status:
Malicious
First seen:
2025-08-29 18:01:49 UTC
AV detection:
26 of 38 (68.42%)
Threat level:
  3/5
Result
Malware family:
xorddos
Score:
  10/10
Tags:
family:xorddos antivm botnet discovery downloader execution linux persistence privilege_escalation
Behaviour
Reads runtime system information
System Network Configuration Discovery
Checks CPU configuration
Creates/modifies Cron job
Modifies init.d
Write file to user bin folder
Executes dropped EXE
XorDDoS
XorDDoS payload
Xorddos family
Malware Config
C2 Extraction:
https://ww.aass654.com/config.rar
cc.aass654.com:1530
cc.xxcc789.com:1530
cc.vvbb321.com:1530
cc.jjkk567.com:1530
cc.nnmm234.com:1530
Verdict:
Malicious
Tags:
backdoor trojan xor_ddos Unix.Malware.Xorddos-9856891-0
YARA:
libgcc_backdoor Linux_Trojan_Xorddos_2aef46a6 Linux_Trojan_Xorddos_884cab60 MALWARE_Linux_XORDDoS
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:CP_AllMal_Detector
Author:DiegoAnalytics
Description:CrossPlatform All Malwares Detector: Detect PE, ELF, Mach-O, scripts, archives; overlay, obfuscation, encryption, spoofing, hiding, high entropy, network communication
Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:enterpriseapps2
Author:Tim Brown @timb_machine
Description:Enterprise apps
Rule name:F01_s1ckrule
Author:s1ckb017
Rule name:linux_generic_ipv6_catcher
Author:@_lubiedo
Description:ELF samples using IPv6 addresses
Rule name:Linux_Trojan_Xorddos_2aef46a6
Author:Elastic Security
Rule name:MALWARE_Linux_XORDDoS
Author:ditekSHen
Description:Detects XORDDoS
Rule name:NET
Author:malware-lu
Rule name:unixredflags3
Author:Tim Brown @timb_machine
Description:Hunts for UNIX red flags

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

XorDDoS

elf 69f17c943d7b5f987095d3c288e2e6e5e3f940ae2ce4c35cec24cde07695e977

(this sample)

  
Delivery method
Distributed via web download

Comments