MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8f5ebb5b1c09744b4bb0087dca66360530533a1913151eaa04f17b691aae5a6b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



XorDDoS


Vendor detections: 10


Intelligence 10 IOCs YARA 8 File information Comments

SHA256 hash: 8f5ebb5b1c09744b4bb0087dca66360530533a1913151eaa04f17b691aae5a6b
SHA3-384 hash: 27374ea36fec8f07c0be6cf0a9bf1e42e997a9093fbe7b3db8a9f4d686177f620b384010a8cddcadaa9f56692a0f0b4c
SHA1 hash: aa06904033abd2e1a080e7be3552f4bd91413c7c
MD5 hash: 720c75bfcecad5ac0f57893b74676583
humanhash: bulldog-bakerloo-west-illinois
File name:p.txt
Download: download sample
Signature XorDDoS
File size:548'616 bytes
First seen:2025-10-23 06:15:09 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 12288:4Ufrcn+vwK5ripVU4tdZ1pNL/pVbz666ySjQn36Eoj:/fUywKQ7Fb1pNL/p56fjQn36Eu
TLSH T11AC45C56E383E2F7C82705B0134BF7BF4620B6359461CD86B7989D5AB9338F22A4D352
telfhash t12ab138722e7558f8b7f08402425a7620ce39e027259439b71ef2b454f7f2c429b6ad7a
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter abuse_ch
Tags:elf XorDDoS

Intelligence


File Origin
# of uploads :
1
# of downloads :
51
Origin country :
DE DE
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Collects information on the RAM
Manages services
Sends data to a server
DNS request
Collects information on the CPU
Runs as daemon
Connection attempt
Creating a process from a recently created file
Receives data from a server
Creating a file
Collects information on the network activity
Launching a process
Changes owner for a written file
Deletes a system binary file
Creates or modifies files in /cron to set up autorun
Writes files to system directory
Deleting of the original file
Creates or modifies symbolic links in /init.d to set up autorun
Creates or modifies files in /init.d to set up autorun
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
gcc lolbin masquerade remote threat xorddos
Verdict:
Malicious
File Type:
elf.32.le
First seen:
2024-05-11T08:24:00Z UTC
Last seen:
2024-09-03T07:49:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=b9aa3b6b-1900-0000-2fd0-5bb4f4100000 pid=4340 /usr/bin/sudo guuid=b42d716e-1900-0000-2fd0-5bb401110000 pid=4353 /tmp/sample.bin guuid=b9aa3b6b-1900-0000-2fd0-5bb4f4100000 pid=4340->guuid=b42d716e-1900-0000-2fd0-5bb401110000 pid=4353 execve guuid=8d9fa86e-1900-0000-2fd0-5bb403110000 pid=4355 /tmp/sample.bin delete-file write-config write-file zombie guuid=b42d716e-1900-0000-2fd0-5bb401110000 pid=4353->guuid=8d9fa86e-1900-0000-2fd0-5bb403110000 pid=4355 clone guuid=531aed6e-1900-0000-2fd0-5bb405110000 pid=4357 /tmp/sample.bin guuid=8d9fa86e-1900-0000-2fd0-5bb403110000 pid=4355->guuid=531aed6e-1900-0000-2fd0-5bb405110000 pid=4357 clone guuid=7e79076f-1900-0000-2fd0-5bb407110000 pid=4359 /tmp/sample.bin guuid=8d9fa86e-1900-0000-2fd0-5bb403110000 pid=4355->guuid=7e79076f-1900-0000-2fd0-5bb407110000 pid=4359 clone guuid=7029356f-1900-0000-2fd0-5bb409110000 pid=4361 /usr/bin/dash guuid=8d9fa86e-1900-0000-2fd0-5bb403110000 pid=4355->guuid=7029356f-1900-0000-2fd0-5bb409110000 pid=4361 execve guuid=8d9fa86e-1900-0000-2fd0-5bb403110000 pid=4367 /tmp/sample.bin write-file zombie guuid=8d9fa86e-1900-0000-2fd0-5bb403110000 pid=4355->guuid=8d9fa86e-1900-0000-2fd0-5bb403110000 pid=4367 clone guuid=8d9fa86e-1900-0000-2fd0-5bb403110000 pid=4368 /tmp/sample.bin dns net send-data write-file zombie guuid=8d9fa86e-1900-0000-2fd0-5bb403110000 pid=4355->guuid=8d9fa86e-1900-0000-2fd0-5bb403110000 pid=4368 clone guuid=8d9fa86e-1900-0000-2fd0-5bb403110000 pid=4369 /tmp/sample.bin net zombie guuid=8d9fa86e-1900-0000-2fd0-5bb403110000 pid=4355->guuid=8d9fa86e-1900-0000-2fd0-5bb403110000 pid=4369 clone guuid=7e2b349e-1a00-0000-2fd0-5bb45e140000 pid=5214 /tmp/sample.bin guuid=8d9fa86e-1900-0000-2fd0-5bb403110000 pid=4355->guuid=7e2b349e-1a00-0000-2fd0-5bb45e140000 pid=5214 clone guuid=aa51619e-1a00-0000-2fd0-5bb461140000 pid=5217 /tmp/sample.bin guuid=8d9fa86e-1900-0000-2fd0-5bb403110000 pid=4355->guuid=aa51619e-1a00-0000-2fd0-5bb461140000 pid=5217 clone guuid=39b38a9e-1a00-0000-2fd0-5bb464140000 pid=5220 /tmp/sample.bin guuid=8d9fa86e-1900-0000-2fd0-5bb403110000 pid=4355->guuid=39b38a9e-1a00-0000-2fd0-5bb464140000 pid=5220 clone guuid=9238a79e-1a00-0000-2fd0-5bb466140000 pid=5222 /tmp/sample.bin guuid=8d9fa86e-1900-0000-2fd0-5bb403110000 pid=4355->guuid=9238a79e-1a00-0000-2fd0-5bb466140000 pid=5222 clone guuid=3740d89e-1a00-0000-2fd0-5bb468140000 pid=5224 /tmp/sample.bin guuid=8d9fa86e-1900-0000-2fd0-5bb403110000 pid=4355->guuid=3740d89e-1a00-0000-2fd0-5bb468140000 pid=5224 clone guuid=ecbb0acd-1b00-0000-2fd0-5bb49e140000 pid=5278 /tmp/sample.bin guuid=8d9fa86e-1900-0000-2fd0-5bb403110000 pid=4355->guuid=ecbb0acd-1b00-0000-2fd0-5bb49e140000 pid=5278 clone guuid=1e6154cd-1b00-0000-2fd0-5bb4a0140000 pid=5280 /tmp/sample.bin guuid=8d9fa86e-1900-0000-2fd0-5bb403110000 pid=4355->guuid=1e6154cd-1b00-0000-2fd0-5bb4a0140000 pid=5280 clone guuid=9a5907d2-1b00-0000-2fd0-5bb4a3140000 pid=5283 /tmp/sample.bin guuid=8d9fa86e-1900-0000-2fd0-5bb403110000 pid=4355->guuid=9a5907d2-1b00-0000-2fd0-5bb4a3140000 pid=5283 clone guuid=415736d2-1b00-0000-2fd0-5bb4a5140000 pid=5285 /tmp/sample.bin guuid=8d9fa86e-1900-0000-2fd0-5bb403110000 pid=4355->guuid=415736d2-1b00-0000-2fd0-5bb4a5140000 pid=5285 clone guuid=fa6f1ad3-1b00-0000-2fd0-5bb4a7140000 pid=5287 /tmp/sample.bin guuid=8d9fa86e-1900-0000-2fd0-5bb403110000 pid=4355->guuid=fa6f1ad3-1b00-0000-2fd0-5bb4a7140000 pid=5287 clone guuid=ab70df0a-1d00-0000-2fd0-5bb4cd140000 pid=5325 /tmp/sample.bin guuid=8d9fa86e-1900-0000-2fd0-5bb403110000 pid=4355->guuid=ab70df0a-1d00-0000-2fd0-5bb4cd140000 pid=5325 clone guuid=f597110b-1d00-0000-2fd0-5bb4cf140000 pid=5327 /tmp/sample.bin guuid=8d9fa86e-1900-0000-2fd0-5bb403110000 pid=4355->guuid=f597110b-1d00-0000-2fd0-5bb4cf140000 pid=5327 clone guuid=905d400b-1d00-0000-2fd0-5bb4d1140000 pid=5329 /tmp/sample.bin guuid=8d9fa86e-1900-0000-2fd0-5bb403110000 pid=4355->guuid=905d400b-1d00-0000-2fd0-5bb4d1140000 pid=5329 clone guuid=e7c4710b-1d00-0000-2fd0-5bb4d3140000 pid=5331 /tmp/sample.bin guuid=8d9fa86e-1900-0000-2fd0-5bb403110000 pid=4355->guuid=e7c4710b-1d00-0000-2fd0-5bb4d3140000 pid=5331 clone guuid=3c2f8b0b-1d00-0000-2fd0-5bb4d5140000 pid=5333 /tmp/sample.bin guuid=8d9fa86e-1900-0000-2fd0-5bb403110000 pid=4355->guuid=3c2f8b0b-1d00-0000-2fd0-5bb4d5140000 pid=5333 clone guuid=44467b37-1e00-0000-2fd0-5bb4dc140000 pid=5340 /tmp/sample.bin guuid=8d9fa86e-1900-0000-2fd0-5bb403110000 pid=4355->guuid=44467b37-1e00-0000-2fd0-5bb4dc140000 pid=5340 clone guuid=f8f8a837-1e00-0000-2fd0-5bb4de140000 pid=5342 /tmp/sample.bin guuid=8d9fa86e-1900-0000-2fd0-5bb403110000 pid=4355->guuid=f8f8a837-1e00-0000-2fd0-5bb4de140000 pid=5342 clone guuid=47e5dd37-1e00-0000-2fd0-5bb4e0140000 pid=5344 /tmp/sample.bin guuid=8d9fa86e-1900-0000-2fd0-5bb403110000 pid=4355->guuid=47e5dd37-1e00-0000-2fd0-5bb4e0140000 pid=5344 clone guuid=25530938-1e00-0000-2fd0-5bb4e2140000 pid=5346 /tmp/sample.bin guuid=8d9fa86e-1900-0000-2fd0-5bb403110000 pid=4355->guuid=25530938-1e00-0000-2fd0-5bb4e2140000 pid=5346 clone guuid=14ef3038-1e00-0000-2fd0-5bb4e4140000 pid=5348 /tmp/sample.bin guuid=8d9fa86e-1900-0000-2fd0-5bb403110000 pid=4355->guuid=14ef3038-1e00-0000-2fd0-5bb4e4140000 pid=5348 clone guuid=e4351b6d-1f00-0000-2fd0-5bb4eb140000 pid=5355 /tmp/sample.bin guuid=8d9fa86e-1900-0000-2fd0-5bb403110000 pid=4355->guuid=e4351b6d-1f00-0000-2fd0-5bb4eb140000 pid=5355 clone guuid=b96b5c6d-1f00-0000-2fd0-5bb4ed140000 pid=5357 /tmp/sample.bin guuid=8d9fa86e-1900-0000-2fd0-5bb403110000 pid=4355->guuid=b96b5c6d-1f00-0000-2fd0-5bb4ed140000 pid=5357 clone guuid=2277936d-1f00-0000-2fd0-5bb4ef140000 pid=5359 /tmp/sample.bin guuid=8d9fa86e-1900-0000-2fd0-5bb403110000 pid=4355->guuid=2277936d-1f00-0000-2fd0-5bb4ef140000 pid=5359 clone guuid=5fe9bd6d-1f00-0000-2fd0-5bb4f1140000 pid=5361 /tmp/sample.bin guuid=8d9fa86e-1900-0000-2fd0-5bb403110000 pid=4355->guuid=5fe9bd6d-1f00-0000-2fd0-5bb4f1140000 pid=5361 clone guuid=1bffee6d-1f00-0000-2fd0-5bb4f3140000 pid=5363 /tmp/sample.bin guuid=8d9fa86e-1900-0000-2fd0-5bb403110000 pid=4355->guuid=1bffee6d-1f00-0000-2fd0-5bb4f3140000 pid=5363 clone guuid=39b3fb9a-2000-0000-2fd0-5bb4fa140000 pid=5370 /tmp/sample.bin guuid=8d9fa86e-1900-0000-2fd0-5bb403110000 pid=4355->guuid=39b3fb9a-2000-0000-2fd0-5bb4fa140000 pid=5370 clone guuid=0971369b-2000-0000-2fd0-5bb4fc140000 pid=5372 /tmp/sample.bin guuid=8d9fa86e-1900-0000-2fd0-5bb403110000 pid=4355->guuid=0971369b-2000-0000-2fd0-5bb4fc140000 pid=5372 clone guuid=84df6b9b-2000-0000-2fd0-5bb4fe140000 pid=5374 /tmp/sample.bin guuid=8d9fa86e-1900-0000-2fd0-5bb403110000 pid=4355->guuid=84df6b9b-2000-0000-2fd0-5bb4fe140000 pid=5374 clone guuid=52f49d9b-2000-0000-2fd0-5bb400150000 pid=5376 /tmp/sample.bin guuid=8d9fa86e-1900-0000-2fd0-5bb403110000 pid=4355->guuid=52f49d9b-2000-0000-2fd0-5bb400150000 pid=5376 clone guuid=ffaae29b-2000-0000-2fd0-5bb402150000 pid=5378 /tmp/sample.bin guuid=8d9fa86e-1900-0000-2fd0-5bb403110000 pid=4355->guuid=ffaae29b-2000-0000-2fd0-5bb402150000 pid=5378 clone guuid=d86926ca-2100-0000-2fd0-5bb409150000 pid=5385 /tmp/sample.bin guuid=8d9fa86e-1900-0000-2fd0-5bb403110000 pid=4355->guuid=d86926ca-2100-0000-2fd0-5bb409150000 pid=5385 clone guuid=60565fca-2100-0000-2fd0-5bb40b150000 pid=5387 /tmp/sample.bin guuid=8d9fa86e-1900-0000-2fd0-5bb403110000 pid=4355->guuid=60565fca-2100-0000-2fd0-5bb40b150000 pid=5387 clone guuid=f2a086ca-2100-0000-2fd0-5bb40d150000 pid=5389 /tmp/sample.bin guuid=8d9fa86e-1900-0000-2fd0-5bb403110000 pid=4355->guuid=f2a086ca-2100-0000-2fd0-5bb40d150000 pid=5389 clone guuid=3b54bbca-2100-0000-2fd0-5bb40f150000 pid=5391 /tmp/sample.bin guuid=8d9fa86e-1900-0000-2fd0-5bb403110000 pid=4355->guuid=3b54bbca-2100-0000-2fd0-5bb40f150000 pid=5391 clone guuid=f450e4ca-2100-0000-2fd0-5bb411150000 pid=5393 /tmp/sample.bin guuid=8d9fa86e-1900-0000-2fd0-5bb403110000 pid=4355->guuid=f450e4ca-2100-0000-2fd0-5bb411150000 pid=5393 clone guuid=a59551f8-2200-0000-2fd0-5bb418150000 pid=5400 /tmp/sample.bin guuid=8d9fa86e-1900-0000-2fd0-5bb403110000 pid=4355->guuid=a59551f8-2200-0000-2fd0-5bb418150000 pid=5400 clone guuid=ee298ef8-2200-0000-2fd0-5bb41a150000 pid=5402 /tmp/sample.bin guuid=8d9fa86e-1900-0000-2fd0-5bb403110000 pid=4355->guuid=ee298ef8-2200-0000-2fd0-5bb41a150000 pid=5402 clone guuid=6343c3f8-2200-0000-2fd0-5bb41c150000 pid=5404 /tmp/sample.bin guuid=8d9fa86e-1900-0000-2fd0-5bb403110000 pid=4355->guuid=6343c3f8-2200-0000-2fd0-5bb41c150000 pid=5404 clone guuid=875aeaf8-2200-0000-2fd0-5bb41e150000 pid=5406 /tmp/sample.bin guuid=8d9fa86e-1900-0000-2fd0-5bb403110000 pid=4355->guuid=875aeaf8-2200-0000-2fd0-5bb41e150000 pid=5406 clone guuid=ca3308f9-2200-0000-2fd0-5bb420150000 pid=5408 /tmp/sample.bin guuid=8d9fa86e-1900-0000-2fd0-5bb403110000 pid=4355->guuid=ca3308f9-2200-0000-2fd0-5bb420150000 pid=5408 clone guuid=3cfeb537-2400-0000-2fd0-5bb427150000 pid=5415 /tmp/sample.bin guuid=8d9fa86e-1900-0000-2fd0-5bb403110000 pid=4355->guuid=3cfeb537-2400-0000-2fd0-5bb427150000 pid=5415 clone guuid=bf93f737-2400-0000-2fd0-5bb429150000 pid=5417 /tmp/sample.bin guuid=8d9fa86e-1900-0000-2fd0-5bb403110000 pid=4355->guuid=bf93f737-2400-0000-2fd0-5bb429150000 pid=5417 clone guuid=10213238-2400-0000-2fd0-5bb42b150000 pid=5419 /tmp/sample.bin guuid=8d9fa86e-1900-0000-2fd0-5bb403110000 pid=4355->guuid=10213238-2400-0000-2fd0-5bb42b150000 pid=5419 clone guuid=b5337538-2400-0000-2fd0-5bb42d150000 pid=5421 /tmp/sample.bin guuid=8d9fa86e-1900-0000-2fd0-5bb403110000 pid=4355->guuid=b5337538-2400-0000-2fd0-5bb42d150000 pid=5421 clone guuid=889ab938-2400-0000-2fd0-5bb42f150000 pid=5423 /tmp/sample.bin guuid=8d9fa86e-1900-0000-2fd0-5bb403110000 pid=4355->guuid=889ab938-2400-0000-2fd0-5bb42f150000 pid=5423 clone guuid=1eb7f665-2500-0000-2fd0-5bb436150000 pid=5430 /tmp/sample.bin guuid=8d9fa86e-1900-0000-2fd0-5bb403110000 pid=4355->guuid=1eb7f665-2500-0000-2fd0-5bb436150000 pid=5430 clone guuid=e39c2b66-2500-0000-2fd0-5bb438150000 pid=5432 /tmp/sample.bin guuid=8d9fa86e-1900-0000-2fd0-5bb403110000 pid=4355->guuid=e39c2b66-2500-0000-2fd0-5bb438150000 pid=5432 clone guuid=4d0b6266-2500-0000-2fd0-5bb43a150000 pid=5434 /tmp/sample.bin guuid=8d9fa86e-1900-0000-2fd0-5bb403110000 pid=4355->guuid=4d0b6266-2500-0000-2fd0-5bb43a150000 pid=5434 clone guuid=51b88b66-2500-0000-2fd0-5bb43c150000 pid=5436 /tmp/sample.bin guuid=8d9fa86e-1900-0000-2fd0-5bb403110000 pid=4355->guuid=51b88b66-2500-0000-2fd0-5bb43c150000 pid=5436 clone guuid=0203b166-2500-0000-2fd0-5bb43e150000 pid=5438 /tmp/sample.bin guuid=8d9fa86e-1900-0000-2fd0-5bb403110000 pid=4355->guuid=0203b166-2500-0000-2fd0-5bb43e150000 pid=5438 clone guuid=b38fc698-2600-0000-2fd0-5bb445150000 pid=5445 /tmp/sample.bin guuid=8d9fa86e-1900-0000-2fd0-5bb403110000 pid=4355->guuid=b38fc698-2600-0000-2fd0-5bb445150000 pid=5445 clone guuid=12ffe798-2600-0000-2fd0-5bb447150000 pid=5447 /tmp/sample.bin guuid=8d9fa86e-1900-0000-2fd0-5bb403110000 pid=4355->guuid=12ffe798-2600-0000-2fd0-5bb447150000 pid=5447 clone guuid=eb7bff98-2600-0000-2fd0-5bb449150000 pid=5449 /tmp/sample.bin guuid=8d9fa86e-1900-0000-2fd0-5bb403110000 pid=4355->guuid=eb7bff98-2600-0000-2fd0-5bb449150000 pid=5449 clone guuid=84171699-2600-0000-2fd0-5bb44b150000 pid=5451 /tmp/sample.bin guuid=8d9fa86e-1900-0000-2fd0-5bb403110000 pid=4355->guuid=84171699-2600-0000-2fd0-5bb44b150000 pid=5451 clone guuid=33c72799-2600-0000-2fd0-5bb44d150000 pid=5453 /tmp/sample.bin guuid=8d9fa86e-1900-0000-2fd0-5bb403110000 pid=4355->guuid=33c72799-2600-0000-2fd0-5bb44d150000 pid=5453 clone guuid=6e56f46e-1900-0000-2fd0-5bb406110000 pid=4358 /tmp/sample.bin guuid=531aed6e-1900-0000-2fd0-5bb405110000 pid=4357->guuid=6e56f46e-1900-0000-2fd0-5bb406110000 pid=4358 clone guuid=348e1b6f-1900-0000-2fd0-5bb408110000 pid=4360 /usr/sbin/update-rc.d zombie guuid=7e79076f-1900-0000-2fd0-5bb407110000 pid=4359->guuid=348e1b6f-1900-0000-2fd0-5bb408110000 pid=4360 execve guuid=b29e9674-1900-0000-2fd0-5bb426110000 pid=4390 /usr/bin/systemctl guuid=348e1b6f-1900-0000-2fd0-5bb408110000 pid=4360->guuid=b29e9674-1900-0000-2fd0-5bb426110000 pid=4390 execve guuid=b28b1570-1900-0000-2fd0-5bb40b110000 pid=4363 /usr/bin/sed guuid=7029356f-1900-0000-2fd0-5bb409110000 pid=4361->guuid=b28b1570-1900-0000-2fd0-5bb40b110000 pid=4363 execve 568dab0d-6749-508b-aec3-4a3de6d1b1b4 0.0.0.0:1525 guuid=8d9fa86e-1900-0000-2fd0-5bb403110000 pid=4368->568dab0d-6749-508b-aec3-4a3de6d1b1b4 con 3d58e738-14b7-52e1-a513-de63bf221d29 hh.vvbb321.com:1525 guuid=8d9fa86e-1900-0000-2fd0-5bb403110000 pid=4368->3d58e738-14b7-52e1-a513-de63bf221d29 send: 4548B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=8d9fa86e-1900-0000-2fd0-5bb403110000 pid=4368->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 96B b4bf20d4-f7c8-5c24-8830-c23364537aa4 8.8.4.4:53 guuid=8d9fa86e-1900-0000-2fd0-5bb403110000 pid=4368->b4bf20d4-f7c8-5c24-8830-c23364537aa4 send: 64B 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=8d9fa86e-1900-0000-2fd0-5bb403110000 pid=4368->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 64B 87f248b3-21f7-50eb-a2c7-cb35eca5cc17 0.0.0.0:80 guuid=8d9fa86e-1900-0000-2fd0-5bb403110000 pid=4369->87f248b3-21f7-50eb-a2c7-cb35eca5cc17 con guuid=3961439e-1a00-0000-2fd0-5bb45f140000 pid=5215 /usr/bin/gavesldmuu zombie guuid=7e2b349e-1a00-0000-2fd0-5bb45e140000 pid=5214->guuid=3961439e-1a00-0000-2fd0-5bb45f140000 pid=5215 execve guuid=0f00eaa1-1a00-0000-2fd0-5bb479140000 pid=5241 /usr/bin/gavesldmuu zombie guuid=3961439e-1a00-0000-2fd0-5bb45f140000 pid=5215->guuid=0f00eaa1-1a00-0000-2fd0-5bb479140000 pid=5241 clone guuid=567d719e-1a00-0000-2fd0-5bb462140000 pid=5218 /usr/bin/gavesldmuu zombie guuid=aa51619e-1a00-0000-2fd0-5bb461140000 pid=5217->guuid=567d719e-1a00-0000-2fd0-5bb462140000 pid=5218 execve guuid=cd3e1fa5-1a00-0000-2fd0-5bb487140000 pid=5255 /usr/bin/gavesldmuu zombie guuid=567d719e-1a00-0000-2fd0-5bb462140000 pid=5218->guuid=cd3e1fa5-1a00-0000-2fd0-5bb487140000 pid=5255 clone guuid=6d6e969e-1a00-0000-2fd0-5bb465140000 pid=5221 /usr/bin/gavesldmuu zombie guuid=39b38a9e-1a00-0000-2fd0-5bb464140000 pid=5220->guuid=6d6e969e-1a00-0000-2fd0-5bb465140000 pid=5221 execve guuid=3c31b6a4-1a00-0000-2fd0-5bb484140000 pid=5252 /usr/bin/gavesldmuu zombie guuid=6d6e969e-1a00-0000-2fd0-5bb465140000 pid=5221->guuid=3c31b6a4-1a00-0000-2fd0-5bb484140000 pid=5252 clone guuid=4c25bd9e-1a00-0000-2fd0-5bb467140000 pid=5223 /usr/bin/gavesldmuu zombie guuid=9238a79e-1a00-0000-2fd0-5bb466140000 pid=5222->guuid=4c25bd9e-1a00-0000-2fd0-5bb467140000 pid=5223 execve guuid=3b5faca2-1a00-0000-2fd0-5bb47c140000 pid=5244 /usr/bin/gavesldmuu zombie guuid=4c25bd9e-1a00-0000-2fd0-5bb467140000 pid=5223->guuid=3b5faca2-1a00-0000-2fd0-5bb47c140000 pid=5244 clone guuid=524bd69f-1a00-0000-2fd0-5bb470140000 pid=5232 /usr/bin/gavesldmuu zombie guuid=3740d89e-1a00-0000-2fd0-5bb468140000 pid=5224->guuid=524bd69f-1a00-0000-2fd0-5bb470140000 pid=5232 execve guuid=bd017ba6-1a00-0000-2fd0-5bb48a140000 pid=5258 /usr/bin/gavesldmuu zombie guuid=524bd69f-1a00-0000-2fd0-5bb470140000 pid=5232->guuid=bd017ba6-1a00-0000-2fd0-5bb48a140000 pid=5258 clone guuid=e7e631cd-1b00-0000-2fd0-5bb49f140000 pid=5279 /usr/bin/hyxakqmtih zombie guuid=ecbb0acd-1b00-0000-2fd0-5bb49e140000 pid=5278->guuid=e7e631cd-1b00-0000-2fd0-5bb49f140000 pid=5279 execve guuid=2b84a8d0-1b00-0000-2fd0-5bb4a1140000 pid=5281 /usr/bin/hyxakqmtih zombie guuid=e7e631cd-1b00-0000-2fd0-5bb49f140000 pid=5279->guuid=2b84a8d0-1b00-0000-2fd0-5bb4a1140000 pid=5281 clone guuid=1e56ead1-1b00-0000-2fd0-5bb4a2140000 pid=5282 /usr/bin/hyxakqmtih zombie guuid=1e6154cd-1b00-0000-2fd0-5bb4a0140000 pid=5280->guuid=1e56ead1-1b00-0000-2fd0-5bb4a2140000 pid=5282 execve guuid=26b168d8-1b00-0000-2fd0-5bb4a9140000 pid=5289 /usr/bin/hyxakqmtih zombie guuid=1e56ead1-1b00-0000-2fd0-5bb4a2140000 pid=5282->guuid=26b168d8-1b00-0000-2fd0-5bb4a9140000 pid=5289 clone guuid=ff351dd2-1b00-0000-2fd0-5bb4a4140000 pid=5284 /usr/bin/hyxakqmtih zombie guuid=9a5907d2-1b00-0000-2fd0-5bb4a3140000 pid=5283->guuid=ff351dd2-1b00-0000-2fd0-5bb4a4140000 pid=5284 execve guuid=ee1d97d9-1b00-0000-2fd0-5bb4aa140000 pid=5290 /usr/bin/hyxakqmtih zombie guuid=ff351dd2-1b00-0000-2fd0-5bb4a4140000 pid=5284->guuid=ee1d97d9-1b00-0000-2fd0-5bb4aa140000 pid=5290 clone guuid=a4cc0bd3-1b00-0000-2fd0-5bb4a6140000 pid=5286 /usr/bin/hyxakqmtih zombie guuid=415736d2-1b00-0000-2fd0-5bb4a5140000 pid=5285->guuid=a4cc0bd3-1b00-0000-2fd0-5bb4a6140000 pid=5286 execve guuid=b876cedc-1b00-0000-2fd0-5bb4ab140000 pid=5291 /usr/bin/hyxakqmtih zombie guuid=a4cc0bd3-1b00-0000-2fd0-5bb4a6140000 pid=5286->guuid=b876cedc-1b00-0000-2fd0-5bb4ab140000 pid=5291 clone guuid=2c633dd4-1b00-0000-2fd0-5bb4a8140000 pid=5288 /usr/bin/hyxakqmtih zombie guuid=fa6f1ad3-1b00-0000-2fd0-5bb4a7140000 pid=5287->guuid=2c633dd4-1b00-0000-2fd0-5bb4a8140000 pid=5288 execve guuid=a53ec5dd-1b00-0000-2fd0-5bb4ac140000 pid=5292 /usr/bin/hyxakqmtih zombie guuid=2c633dd4-1b00-0000-2fd0-5bb4a8140000 pid=5288->guuid=a53ec5dd-1b00-0000-2fd0-5bb4ac140000 pid=5292 clone guuid=396ff20a-1d00-0000-2fd0-5bb4ce140000 pid=5326 /usr/bin/nemtrzdwie zombie guuid=ab70df0a-1d00-0000-2fd0-5bb4cd140000 pid=5325->guuid=396ff20a-1d00-0000-2fd0-5bb4ce140000 pid=5326 execve guuid=4c2a630e-1d00-0000-2fd0-5bb4d8140000 pid=5336 /usr/bin/nemtrzdwie zombie guuid=396ff20a-1d00-0000-2fd0-5bb4ce140000 pid=5326->guuid=4c2a630e-1d00-0000-2fd0-5bb4d8140000 pid=5336 clone guuid=9811250b-1d00-0000-2fd0-5bb4d0140000 pid=5328 /usr/bin/nemtrzdwie zombie guuid=f597110b-1d00-0000-2fd0-5bb4cf140000 pid=5327->guuid=9811250b-1d00-0000-2fd0-5bb4d0140000 pid=5328 execve guuid=95fe2d0f-1d00-0000-2fd0-5bb4d9140000 pid=5337 /usr/bin/nemtrzdwie zombie guuid=9811250b-1d00-0000-2fd0-5bb4d0140000 pid=5328->guuid=95fe2d0f-1d00-0000-2fd0-5bb4d9140000 pid=5337 clone guuid=25e04a0b-1d00-0000-2fd0-5bb4d2140000 pid=5330 /usr/bin/nemtrzdwie zombie guuid=905d400b-1d00-0000-2fd0-5bb4d1140000 pid=5329->guuid=25e04a0b-1d00-0000-2fd0-5bb4d2140000 pid=5330 execve guuid=d108ff0f-1d00-0000-2fd0-5bb4da140000 pid=5338 /usr/bin/nemtrzdwie zombie guuid=25e04a0b-1d00-0000-2fd0-5bb4d2140000 pid=5330->guuid=d108ff0f-1d00-0000-2fd0-5bb4da140000 pid=5338 clone guuid=31ad7b0b-1d00-0000-2fd0-5bb4d4140000 pid=5332 /usr/bin/nemtrzdwie zombie guuid=e7c4710b-1d00-0000-2fd0-5bb4d3140000 pid=5331->guuid=31ad7b0b-1d00-0000-2fd0-5bb4d4140000 pid=5332 execve guuid=91b81110-1d00-0000-2fd0-5bb4db140000 pid=5339 /usr/bin/nemtrzdwie zombie guuid=31ad7b0b-1d00-0000-2fd0-5bb4d4140000 pid=5332->guuid=91b81110-1d00-0000-2fd0-5bb4db140000 pid=5339 clone guuid=9888950b-1d00-0000-2fd0-5bb4d6140000 pid=5334 /usr/bin/nemtrzdwie zombie guuid=3c2f8b0b-1d00-0000-2fd0-5bb4d5140000 pid=5333->guuid=9888950b-1d00-0000-2fd0-5bb4d6140000 pid=5334 execve guuid=074a4c0e-1d00-0000-2fd0-5bb4d7140000 pid=5335 /usr/bin/nemtrzdwie zombie guuid=9888950b-1d00-0000-2fd0-5bb4d6140000 pid=5334->guuid=074a4c0e-1d00-0000-2fd0-5bb4d7140000 pid=5335 clone guuid=84658e37-1e00-0000-2fd0-5bb4dd140000 pid=5341 /usr/bin/fvpsrrdrsz zombie guuid=44467b37-1e00-0000-2fd0-5bb4dc140000 pid=5340->guuid=84658e37-1e00-0000-2fd0-5bb4dd140000 pid=5341 execve guuid=155c6c3b-1e00-0000-2fd0-5bb4e7140000 pid=5351 /usr/bin/fvpsrrdrsz zombie guuid=84658e37-1e00-0000-2fd0-5bb4dd140000 pid=5341->guuid=155c6c3b-1e00-0000-2fd0-5bb4e7140000 pid=5351 clone guuid=f2dfb737-1e00-0000-2fd0-5bb4df140000 pid=5343 /usr/bin/fvpsrrdrsz zombie guuid=f8f8a837-1e00-0000-2fd0-5bb4de140000 pid=5342->guuid=f2dfb737-1e00-0000-2fd0-5bb4df140000 pid=5343 execve guuid=c7b20f3b-1e00-0000-2fd0-5bb4e6140000 pid=5350 /usr/bin/fvpsrrdrsz zombie guuid=f2dfb737-1e00-0000-2fd0-5bb4df140000 pid=5343->guuid=c7b20f3b-1e00-0000-2fd0-5bb4e6140000 pid=5350 clone guuid=14f5eb37-1e00-0000-2fd0-5bb4e1140000 pid=5345 /usr/bin/fvpsrrdrsz zombie guuid=47e5dd37-1e00-0000-2fd0-5bb4e0140000 pid=5344->guuid=14f5eb37-1e00-0000-2fd0-5bb4e1140000 pid=5345 execve guuid=ed63e73c-1e00-0000-2fd0-5bb4e9140000 pid=5353 /usr/bin/fvpsrrdrsz zombie guuid=14f5eb37-1e00-0000-2fd0-5bb4e1140000 pid=5345->guuid=ed63e73c-1e00-0000-2fd0-5bb4e9140000 pid=5353 clone guuid=1b841638-1e00-0000-2fd0-5bb4e3140000 pid=5347 /usr/bin/fvpsrrdrsz zombie guuid=25530938-1e00-0000-2fd0-5bb4e2140000 pid=5346->guuid=1b841638-1e00-0000-2fd0-5bb4e3140000 pid=5347 execve guuid=fd28373c-1e00-0000-2fd0-5bb4e8140000 pid=5352 /usr/bin/fvpsrrdrsz zombie guuid=1b841638-1e00-0000-2fd0-5bb4e3140000 pid=5347->guuid=fd28373c-1e00-0000-2fd0-5bb4e8140000 pid=5352 clone guuid=9857bb38-1e00-0000-2fd0-5bb4e5140000 pid=5349 /usr/bin/fvpsrrdrsz zombie guuid=14ef3038-1e00-0000-2fd0-5bb4e4140000 pid=5348->guuid=9857bb38-1e00-0000-2fd0-5bb4e5140000 pid=5349 execve guuid=5552143d-1e00-0000-2fd0-5bb4ea140000 pid=5354 /usr/bin/fvpsrrdrsz zombie guuid=9857bb38-1e00-0000-2fd0-5bb4e5140000 pid=5349->guuid=5552143d-1e00-0000-2fd0-5bb4ea140000 pid=5354 clone guuid=60e0316d-1f00-0000-2fd0-5bb4ec140000 pid=5356 /usr/bin/yslnobhkbt zombie guuid=e4351b6d-1f00-0000-2fd0-5bb4eb140000 pid=5355->guuid=60e0316d-1f00-0000-2fd0-5bb4ec140000 pid=5356 execve guuid=389fc971-1f00-0000-2fd0-5bb4f6140000 pid=5366 /usr/bin/yslnobhkbt zombie guuid=60e0316d-1f00-0000-2fd0-5bb4ec140000 pid=5356->guuid=389fc971-1f00-0000-2fd0-5bb4f6140000 pid=5366 clone guuid=4fd76f6d-1f00-0000-2fd0-5bb4ee140000 pid=5358 /usr/bin/yslnobhkbt zombie guuid=b96b5c6d-1f00-0000-2fd0-5bb4ed140000 pid=5357->guuid=4fd76f6d-1f00-0000-2fd0-5bb4ee140000 pid=5358 execve guuid=63d51471-1f00-0000-2fd0-5bb4f5140000 pid=5365 /usr/bin/yslnobhkbt zombie guuid=4fd76f6d-1f00-0000-2fd0-5bb4ee140000 pid=5358->guuid=63d51471-1f00-0000-2fd0-5bb4f5140000 pid=5365 clone guuid=2e4da26d-1f00-0000-2fd0-5bb4f0140000 pid=5360 /usr/bin/yslnobhkbt zombie guuid=2277936d-1f00-0000-2fd0-5bb4ef140000 pid=5359->guuid=2e4da26d-1f00-0000-2fd0-5bb4f0140000 pid=5360 execve guuid=84dbb572-1f00-0000-2fd0-5bb4f8140000 pid=5368 /usr/bin/yslnobhkbt zombie guuid=2e4da26d-1f00-0000-2fd0-5bb4f0140000 pid=5360->guuid=84dbb572-1f00-0000-2fd0-5bb4f8140000 pid=5368 clone guuid=54a1ca6d-1f00-0000-2fd0-5bb4f2140000 pid=5362 /usr/bin/yslnobhkbt zombie guuid=5fe9bd6d-1f00-0000-2fd0-5bb4f1140000 pid=5361->guuid=54a1ca6d-1f00-0000-2fd0-5bb4f2140000 pid=5362 execve guuid=79c8f471-1f00-0000-2fd0-5bb4f7140000 pid=5367 /usr/bin/yslnobhkbt zombie guuid=54a1ca6d-1f00-0000-2fd0-5bb4f2140000 pid=5362->guuid=79c8f471-1f00-0000-2fd0-5bb4f7140000 pid=5367 clone guuid=00a96e6e-1f00-0000-2fd0-5bb4f4140000 pid=5364 /usr/bin/yslnobhkbt zombie guuid=1bffee6d-1f00-0000-2fd0-5bb4f3140000 pid=5363->guuid=00a96e6e-1f00-0000-2fd0-5bb4f4140000 pid=5364 execve guuid=8ef74a73-1f00-0000-2fd0-5bb4f9140000 pid=5369 /usr/bin/yslnobhkbt zombie guuid=00a96e6e-1f00-0000-2fd0-5bb4f4140000 pid=5364->guuid=8ef74a73-1f00-0000-2fd0-5bb4f9140000 pid=5369 clone guuid=b63b159b-2000-0000-2fd0-5bb4fb140000 pid=5371 /usr/bin/qcuvfuhnjj zombie guuid=39b3fb9a-2000-0000-2fd0-5bb4fa140000 pid=5370->guuid=b63b159b-2000-0000-2fd0-5bb4fb140000 pid=5371 execve guuid=b22e7c9f-2000-0000-2fd0-5bb404150000 pid=5380 /usr/bin/qcuvfuhnjj zombie guuid=b63b159b-2000-0000-2fd0-5bb4fb140000 pid=5371->guuid=b22e7c9f-2000-0000-2fd0-5bb404150000 pid=5380 clone guuid=f2254b9b-2000-0000-2fd0-5bb4fd140000 pid=5373 /usr/bin/qcuvfuhnjj zombie guuid=0971369b-2000-0000-2fd0-5bb4fc140000 pid=5372->guuid=f2254b9b-2000-0000-2fd0-5bb4fd140000 pid=5373 execve guuid=bb6c9a9f-2000-0000-2fd0-5bb405150000 pid=5381 /usr/bin/qcuvfuhnjj zombie guuid=f2254b9b-2000-0000-2fd0-5bb4fd140000 pid=5373->guuid=bb6c9a9f-2000-0000-2fd0-5bb405150000 pid=5381 clone guuid=7cb8809b-2000-0000-2fd0-5bb4ff140000 pid=5375 /usr/bin/qcuvfuhnjj zombie guuid=84df6b9b-2000-0000-2fd0-5bb4fe140000 pid=5374->guuid=7cb8809b-2000-0000-2fd0-5bb4ff140000 pid=5375 execve guuid=7d51b2a0-2000-0000-2fd0-5bb407150000 pid=5383 /usr/bin/qcuvfuhnjj zombie guuid=7cb8809b-2000-0000-2fd0-5bb4ff140000 pid=5375->guuid=7d51b2a0-2000-0000-2fd0-5bb407150000 pid=5383 clone guuid=7038b19b-2000-0000-2fd0-5bb401150000 pid=5377 /usr/bin/qcuvfuhnjj zombie guuid=52f49d9b-2000-0000-2fd0-5bb400150000 pid=5376->guuid=7038b19b-2000-0000-2fd0-5bb401150000 pid=5377 execve guuid=8170df9f-2000-0000-2fd0-5bb406150000 pid=5382 /usr/bin/qcuvfuhnjj zombie guuid=7038b19b-2000-0000-2fd0-5bb401150000 pid=5377->guuid=8170df9f-2000-0000-2fd0-5bb406150000 pid=5382 clone guuid=71648d9c-2000-0000-2fd0-5bb403150000 pid=5379 /usr/bin/qcuvfuhnjj zombie guuid=ffaae29b-2000-0000-2fd0-5bb402150000 pid=5378->guuid=71648d9c-2000-0000-2fd0-5bb403150000 pid=5379 execve guuid=40021da1-2000-0000-2fd0-5bb408150000 pid=5384 /usr/bin/qcuvfuhnjj zombie guuid=71648d9c-2000-0000-2fd0-5bb403150000 pid=5379->guuid=40021da1-2000-0000-2fd0-5bb408150000 pid=5384 clone guuid=e1183aca-2100-0000-2fd0-5bb40a150000 pid=5386 /usr/bin/vhbeewnnao zombie guuid=d86926ca-2100-0000-2fd0-5bb409150000 pid=5385->guuid=e1183aca-2100-0000-2fd0-5bb40a150000 pid=5386 execve guuid=df7a88ce-2100-0000-2fd0-5bb414150000 pid=5396 /usr/bin/vhbeewnnao zombie guuid=e1183aca-2100-0000-2fd0-5bb40a150000 pid=5386->guuid=df7a88ce-2100-0000-2fd0-5bb414150000 pid=5396 clone guuid=b3bb6bca-2100-0000-2fd0-5bb40c150000 pid=5388 /usr/bin/vhbeewnnao zombie guuid=60565fca-2100-0000-2fd0-5bb40b150000 pid=5387->guuid=b3bb6bca-2100-0000-2fd0-5bb40c150000 pid=5388 execve guuid=b1734ecf-2100-0000-2fd0-5bb416150000 pid=5398 /usr/bin/vhbeewnnao zombie guuid=b3bb6bca-2100-0000-2fd0-5bb40c150000 pid=5388->guuid=b1734ecf-2100-0000-2fd0-5bb416150000 pid=5398 clone guuid=df2d9aca-2100-0000-2fd0-5bb40e150000 pid=5390 /usr/bin/vhbeewnnao zombie guuid=f2a086ca-2100-0000-2fd0-5bb40d150000 pid=5389->guuid=df2d9aca-2100-0000-2fd0-5bb40e150000 pid=5390 execve guuid=0e744bce-2100-0000-2fd0-5bb413150000 pid=5395 /usr/bin/vhbeewnnao zombie guuid=df2d9aca-2100-0000-2fd0-5bb40e150000 pid=5390->guuid=0e744bce-2100-0000-2fd0-5bb413150000 pid=5395 clone guuid=8ee9c6ca-2100-0000-2fd0-5bb410150000 pid=5392 /usr/bin/vhbeewnnao zombie guuid=3b54bbca-2100-0000-2fd0-5bb40f150000 pid=5391->guuid=8ee9c6ca-2100-0000-2fd0-5bb410150000 pid=5392 execve guuid=9007f2ce-2100-0000-2fd0-5bb415150000 pid=5397 /usr/bin/vhbeewnnao zombie guuid=8ee9c6ca-2100-0000-2fd0-5bb410150000 pid=5392->guuid=9007f2ce-2100-0000-2fd0-5bb415150000 pid=5397 clone guuid=0b7492cb-2100-0000-2fd0-5bb412150000 pid=5394 /usr/bin/vhbeewnnao zombie guuid=f450e4ca-2100-0000-2fd0-5bb411150000 pid=5393->guuid=0b7492cb-2100-0000-2fd0-5bb412150000 pid=5394 execve guuid=955266d0-2100-0000-2fd0-5bb417150000 pid=5399 /usr/bin/vhbeewnnao zombie guuid=0b7492cb-2100-0000-2fd0-5bb412150000 pid=5394->guuid=955266d0-2100-0000-2fd0-5bb417150000 pid=5399 clone guuid=3c066df8-2200-0000-2fd0-5bb419150000 pid=5401 /usr/bin/epjmdnabot zombie guuid=a59551f8-2200-0000-2fd0-5bb418150000 pid=5400->guuid=3c066df8-2200-0000-2fd0-5bb419150000 pid=5401 execve guuid=959ab1fb-2200-0000-2fd0-5bb422150000 pid=5410 /usr/bin/epjmdnabot zombie guuid=3c066df8-2200-0000-2fd0-5bb419150000 pid=5401->guuid=959ab1fb-2200-0000-2fd0-5bb422150000 pid=5410 clone guuid=70d79ef8-2200-0000-2fd0-5bb41b150000 pid=5403 /usr/bin/epjmdnabot zombie guuid=ee298ef8-2200-0000-2fd0-5bb41a150000 pid=5402->guuid=70d79ef8-2200-0000-2fd0-5bb41b150000 pid=5403 execve guuid=231a04fc-2200-0000-2fd0-5bb423150000 pid=5411 /usr/bin/epjmdnabot zombie guuid=70d79ef8-2200-0000-2fd0-5bb41b150000 pid=5403->guuid=231a04fc-2200-0000-2fd0-5bb423150000 pid=5411 clone guuid=cb2ecef8-2200-0000-2fd0-5bb41d150000 pid=5405 /usr/bin/epjmdnabot zombie guuid=6343c3f8-2200-0000-2fd0-5bb41c150000 pid=5404->guuid=cb2ecef8-2200-0000-2fd0-5bb41d150000 pid=5405 execve guuid=ff3db5fd-2200-0000-2fd0-5bb425150000 pid=5413 /usr/bin/epjmdnabot zombie guuid=cb2ecef8-2200-0000-2fd0-5bb41d150000 pid=5405->guuid=ff3db5fd-2200-0000-2fd0-5bb425150000 pid=5413 clone guuid=0c56f5f8-2200-0000-2fd0-5bb41f150000 pid=5407 /usr/bin/epjmdnabot zombie guuid=875aeaf8-2200-0000-2fd0-5bb41e150000 pid=5406->guuid=0c56f5f8-2200-0000-2fd0-5bb41f150000 pid=5407 execve guuid=5dd70dfd-2200-0000-2fd0-5bb424150000 pid=5412 /usr/bin/epjmdnabot zombie guuid=0c56f5f8-2200-0000-2fd0-5bb41f150000 pid=5407->guuid=5dd70dfd-2200-0000-2fd0-5bb424150000 pid=5412 clone guuid=a6b09ff9-2200-0000-2fd0-5bb421150000 pid=5409 /usr/bin/epjmdnabot zombie guuid=ca3308f9-2200-0000-2fd0-5bb420150000 pid=5408->guuid=a6b09ff9-2200-0000-2fd0-5bb421150000 pid=5409 execve guuid=5e6b73fe-2200-0000-2fd0-5bb426150000 pid=5414 /usr/bin/epjmdnabot zombie guuid=a6b09ff9-2200-0000-2fd0-5bb421150000 pid=5409->guuid=5e6b73fe-2200-0000-2fd0-5bb426150000 pid=5414 clone guuid=e2b4cb37-2400-0000-2fd0-5bb428150000 pid=5416 /usr/bin/tznnahumyd zombie guuid=3cfeb537-2400-0000-2fd0-5bb427150000 pid=5415->guuid=e2b4cb37-2400-0000-2fd0-5bb428150000 pid=5416 execve guuid=470bb03b-2400-0000-2fd0-5bb431150000 pid=5425 /usr/bin/tznnahumyd zombie guuid=e2b4cb37-2400-0000-2fd0-5bb428150000 pid=5416->guuid=470bb03b-2400-0000-2fd0-5bb431150000 pid=5425 clone guuid=57720938-2400-0000-2fd0-5bb42a150000 pid=5418 /usr/bin/tznnahumyd zombie guuid=bf93f737-2400-0000-2fd0-5bb429150000 pid=5417->guuid=57720938-2400-0000-2fd0-5bb42a150000 pid=5418 execve guuid=2355963c-2400-0000-2fd0-5bb432150000 pid=5426 /usr/bin/tznnahumyd zombie guuid=57720938-2400-0000-2fd0-5bb42a150000 pid=5418->guuid=2355963c-2400-0000-2fd0-5bb432150000 pid=5426 clone guuid=09924438-2400-0000-2fd0-5bb42c150000 pid=5420 /usr/bin/tznnahumyd zombie guuid=10213238-2400-0000-2fd0-5bb42b150000 pid=5419->guuid=09924438-2400-0000-2fd0-5bb42c150000 pid=5420 execve guuid=bc3e973c-2400-0000-2fd0-5bb433150000 pid=5427 /usr/bin/tznnahumyd zombie guuid=09924438-2400-0000-2fd0-5bb42c150000 pid=5420->guuid=bc3e973c-2400-0000-2fd0-5bb433150000 pid=5427 clone guuid=87298b38-2400-0000-2fd0-5bb42e150000 pid=5422 /usr/bin/tznnahumyd zombie guuid=b5337538-2400-0000-2fd0-5bb42d150000 pid=5421->guuid=87298b38-2400-0000-2fd0-5bb42e150000 pid=5422 execve guuid=d180ff3d-2400-0000-2fd0-5bb434150000 pid=5428 /usr/bin/tznnahumyd zombie guuid=87298b38-2400-0000-2fd0-5bb42e150000 pid=5422->guuid=d180ff3d-2400-0000-2fd0-5bb434150000 pid=5428 clone guuid=b2db6139-2400-0000-2fd0-5bb430150000 pid=5424 /usr/bin/tznnahumyd zombie guuid=889ab938-2400-0000-2fd0-5bb42f150000 pid=5423->guuid=b2db6139-2400-0000-2fd0-5bb430150000 pid=5424 execve guuid=7939203e-2400-0000-2fd0-5bb435150000 pid=5429 /usr/bin/tznnahumyd zombie guuid=b2db6139-2400-0000-2fd0-5bb430150000 pid=5424->guuid=7939203e-2400-0000-2fd0-5bb435150000 pid=5429 clone guuid=28470a66-2500-0000-2fd0-5bb437150000 pid=5431 /usr/bin/oakwymsfmz zombie guuid=1eb7f665-2500-0000-2fd0-5bb436150000 pid=5430->guuid=28470a66-2500-0000-2fd0-5bb437150000 pid=5431 execve guuid=06299269-2500-0000-2fd0-5bb440150000 pid=5440 /usr/bin/oakwymsfmz zombie guuid=28470a66-2500-0000-2fd0-5bb437150000 pid=5431->guuid=06299269-2500-0000-2fd0-5bb440150000 pid=5440 clone guuid=1bf64066-2500-0000-2fd0-5bb439150000 pid=5433 /usr/bin/oakwymsfmz zombie guuid=e39c2b66-2500-0000-2fd0-5bb438150000 pid=5432->guuid=1bf64066-2500-0000-2fd0-5bb439150000 pid=5433 execve guuid=31e6b169-2500-0000-2fd0-5bb441150000 pid=5441 /usr/bin/oakwymsfmz zombie guuid=1bf64066-2500-0000-2fd0-5bb439150000 pid=5433->guuid=31e6b169-2500-0000-2fd0-5bb441150000 pid=5441 clone guuid=884d7366-2500-0000-2fd0-5bb43b150000 pid=5435 /usr/bin/oakwymsfmz zombie guuid=4d0b6266-2500-0000-2fd0-5bb43a150000 pid=5434->guuid=884d7366-2500-0000-2fd0-5bb43b150000 pid=5435 execve guuid=c2305d6b-2500-0000-2fd0-5bb443150000 pid=5443 /usr/bin/oakwymsfmz zombie guuid=884d7366-2500-0000-2fd0-5bb43b150000 pid=5435->guuid=c2305d6b-2500-0000-2fd0-5bb443150000 pid=5443 clone guuid=841b9666-2500-0000-2fd0-5bb43d150000 pid=5437 /usr/bin/oakwymsfmz zombie guuid=51b88b66-2500-0000-2fd0-5bb43c150000 pid=5436->guuid=841b9666-2500-0000-2fd0-5bb43d150000 pid=5437 execve guuid=7ecfd769-2500-0000-2fd0-5bb442150000 pid=5442 /usr/bin/oakwymsfmz zombie guuid=841b9666-2500-0000-2fd0-5bb43d150000 pid=5437->guuid=7ecfd769-2500-0000-2fd0-5bb442150000 pid=5442 clone guuid=7a606967-2500-0000-2fd0-5bb43f150000 pid=5439 /usr/bin/oakwymsfmz zombie guuid=0203b166-2500-0000-2fd0-5bb43e150000 pid=5438->guuid=7a606967-2500-0000-2fd0-5bb43f150000 pid=5439 execve guuid=cf65a56b-2500-0000-2fd0-5bb444150000 pid=5444 /usr/bin/oakwymsfmz zombie guuid=7a606967-2500-0000-2fd0-5bb43f150000 pid=5439->guuid=cf65a56b-2500-0000-2fd0-5bb444150000 pid=5444 clone guuid=122cd698-2600-0000-2fd0-5bb446150000 pid=5446 /usr/bin/zstoyuungz zombie guuid=b38fc698-2600-0000-2fd0-5bb445150000 pid=5445->guuid=122cd698-2600-0000-2fd0-5bb446150000 pid=5446 execve guuid=24d66a9b-2600-0000-2fd0-5bb44f150000 pid=5455 /usr/bin/zstoyuungz zombie guuid=122cd698-2600-0000-2fd0-5bb446150000 pid=5446->guuid=24d66a9b-2600-0000-2fd0-5bb44f150000 pid=5455 clone guuid=9065ef98-2600-0000-2fd0-5bb448150000 pid=5448 /usr/bin/zstoyuungz zombie guuid=12ffe798-2600-0000-2fd0-5bb447150000 pid=5447->guuid=9065ef98-2600-0000-2fd0-5bb448150000 pid=5448 execve guuid=a24e369c-2600-0000-2fd0-5bb451150000 pid=5457 /usr/bin/zstoyuungz zombie guuid=9065ef98-2600-0000-2fd0-5bb448150000 pid=5448->guuid=a24e369c-2600-0000-2fd0-5bb451150000 pid=5457 clone guuid=3e720999-2600-0000-2fd0-5bb44a150000 pid=5450 /usr/bin/zstoyuungz zombie guuid=eb7bff98-2600-0000-2fd0-5bb449150000 pid=5449->guuid=3e720999-2600-0000-2fd0-5bb44a150000 pid=5450 execve guuid=f752ae9b-2600-0000-2fd0-5bb450150000 pid=5456 /usr/bin/zstoyuungz zombie guuid=3e720999-2600-0000-2fd0-5bb44a150000 pid=5450->guuid=f752ae9b-2600-0000-2fd0-5bb450150000 pid=5456 clone guuid=d6501c99-2600-0000-2fd0-5bb44c150000 pid=5452 /usr/bin/zstoyuungz zombie guuid=84171699-2600-0000-2fd0-5bb44b150000 pid=5451->guuid=d6501c99-2600-0000-2fd0-5bb44c150000 pid=5452 execve guuid=d1b3119d-2600-0000-2fd0-5bb452150000 pid=5458 /usr/bin/zstoyuungz zombie guuid=d6501c99-2600-0000-2fd0-5bb44c150000 pid=5452->guuid=d1b3119d-2600-0000-2fd0-5bb452150000 pid=5458 clone guuid=a320c499-2600-0000-2fd0-5bb44e150000 pid=5454 /usr/bin/zstoyuungz zombie guuid=33c72799-2600-0000-2fd0-5bb44d150000 pid=5453->guuid=a320c499-2600-0000-2fd0-5bb44e150000 pid=5454 execve guuid=c5d1609d-2600-0000-2fd0-5bb453150000 pid=5459 /usr/bin/zstoyuungz zombie guuid=a320c499-2600-0000-2fd0-5bb44e150000 pid=5454->guuid=c5d1609d-2600-0000-2fd0-5bb453150000 pid=5459 clone
Result
Threat name:
XorDDoS
Detection:
malicious
Classification:
troj.evad
Score:
100 / 100
Signature
Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Drops files in suspicious directories
Found malware configuration
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Sample deletes itself
Sample tries to persist itself using cron
Sample tries to persist itself using System V runlevels
Suricata IDS alerts for network traffic
Yara detected XorDDoS Bot
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1800342 Sample: p.txt.elf Startdate: 23/10/2025 Architecture: LINUX Score: 100 76 hh.vvbb321.com 123.136.95.227, 1525, 45340 A-STAR-AS-APA-STARSG China 2->76 78 hh.nnmm234.com 2->78 80 5 other IPs or domains 2->80 84 Suricata IDS alerts for network traffic 2->84 86 Found malware configuration 2->86 88 Malicious sample detected (through community Yara rule) 2->88 90 4 other signatures 2->90 10 p.txt.elf 2->10         started        12 systemd snapd-env-generator 2->12         started        14 dash rm 2->14         started        16 dash rm 2->16         started        signatures3 process4 process5 18 p.txt.elf 10->18         started        file6 66 /usr/lib/libudev.so, ELF 18->66 dropped 68 /usr/bin/zgkwivouat, ELF 18->68 dropped 70 /usr/bin/ythacedknq, ELF 18->70 dropped 72 15 other malicious files 18->72 dropped 92 Drops files in suspicious directories 18->92 94 Sample deletes itself 18->94 96 Sample tries to persist itself using cron 18->96 98 Sample tries to persist itself using System V runlevels 18->98 22 p.txt.elf sh 18->22         started        26 p.txt.elf 18->26         started        28 p.txt.elf 18->28         started        30 110 other processes 18->30 signatures7 process8 file9 74 /etc/crontab, ASCII 22->74 dropped 100 Sample tries to persist itself using cron 22->100 32 sh sed 22->32         started        35 p.txt.elf jprtixfwcx 26->35         started        37 p.txt.elf jprtixfwcx 28->37         started        39 p.txt.elf jprtixfwcx 30->39         started        41 p.txt.elf jprtixfwcx 30->41         started        43 p.txt.elf jprtixfwcx 30->43         started        45 107 other processes 30->45 signatures10 process11 signatures12 82 Sample tries to persist itself using cron 32->82 47 jprtixfwcx 35->47         started        50 jprtixfwcx 37->50         started        52 jprtixfwcx 39->52         started        54 jprtixfwcx 41->54         started        56 jprtixfwcx 43->56         started        58 uxmliaynij 45->58         started        60 uxmliaynij 45->60         started        62 uxmliaynij 45->62         started        64 103 other processes 45->64 process13 signatures14 102 Sample deletes itself 56->102
Threat name:
Linux.Network.Xor
Status:
Malicious
First seen:
2024-05-11 13:10:24 UTC
File Type:
ELF32 Little (Exe)
AV detection:
24 of 36 (66.67%)
Threat level:
  3/5
Result
Malware family:
xorddos
Score:
  10/10
Tags:
family:xorddos antivm botnet discovery downloader execution linux persistence privilege_escalation
Behaviour
Reads runtime system information
System Network Configuration Discovery
Checks CPU configuration
Creates/modifies Cron job
Modifies init.d
Write file to user bin folder
Executes dropped EXE
XorDDoS
XorDDoS payload
Xorddos family
Malware Config
C2 Extraction:
https://ww.aass654.com/config.rar
hh.aass654.com:1525
hh.xxcc789.com:1525
hh.vvbb321.com:1525
hh.jjkk567.com:1525
hh.nnmm234.com:1525
Verdict:
Unknown
Tags:
backdoor trojan xor_ddos
YARA:
libgcc_backdoor Linux_Trojan_Xorddos_2aef46a6 Linux_Trojan_Xorddos_884cab60 MALWARE_Linux_XORDDoS
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:enterpriseapps2
Author:Tim Brown @timb_machine
Description:Enterprise apps
Rule name:F01_s1ckrule
Author:s1ckb017
Rule name:linux_generic_ipv6_catcher
Author:@_lubiedo
Description:ELF samples using IPv6 addresses
Rule name:Linux_Trojan_Xorddos_2aef46a6
Author:Elastic Security
Rule name:MALWARE_Linux_XORDDoS
Author:ditekSHen
Description:Detects XORDDoS
Rule name:NET
Author:malware-lu
Rule name:unixredflags3
Author:Tim Brown @timb_machine
Description:Hunts for UNIX red flags

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

XorDDoS

elf 8f5ebb5b1c09744b4bb0087dca66360530533a1913151eaa04f17b691aae5a6b

(this sample)

  
Delivery method
Distributed via web download

Comments