MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 adec2bf3cdf2ad11ab9174611cfced67ba28a63a8c61ffb7fb88c4670e9e7377. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RondoDox


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: adec2bf3cdf2ad11ab9174611cfced67ba28a63a8c61ffb7fb88c4670e9e7377
SHA3-384 hash: 5aff775a3295e5fba0b9513fbb7971b824f22c8aac8f8ee2ec71409fbda185f511542a37847f5dd9d74bac798615e0db
SHA1 hash: 53035b5d18372e33589eb86c98b851413a0d6d80
MD5 hash: 4304cbd286b1f040424b2d623249f311
humanhash: bravo-finch-papa-fillet
File name:rondo.aqu.sh
Download: download sample
Signature RondoDox
File size:9'432 bytes
First seen:2025-12-27 09:10:40 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 96:Ax0iRoLngDa35y5YLOJsfZqIn2UeC6/ZZ8o++z:g0goLngc2CQH
TLSH T1D512F8BA71C002F666A74C46D1D38A7C8C169FE06273CDB7D9844EB799F04086F5D792
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:RondoDox sh
URLMalware sample (SHA256 hash)SignatureTags
http://41.231.37.153/rondo.loln/an/aua-wget
http://41.231.37.153/rondo.x86_64a5f035343b91205375751e0fb4d828aef261532508ef80129ffe7a9ba8a30ed0 Gafgytgafgyt RondoDox ua-wget
http://41.231.37.153/rondo.i686293a3a492aef65a88cf5434ee66ad55875deb66885871c9199296e707fb17926 Miraimirai ua-wget
http://41.231.37.153/rondo.i58638b3192b7e792073bde272b917f53336ad35d17482d5140b362f697861bd2c55 Miraimirai ua-wget
http://41.231.37.153/rondo.i486f1beda333a121d1fc43ca60075f62a6e9848b5d9e41ef177d934ebc7138a696f Miraimirai ua-wget
http://41.231.37.153/rondo.armv6l29ed805642950a7709d058067ec1882d877beb02e67b56b673b5e2d2b17272d2 Miraimirai RondoDox ua-wget
http://41.231.37.153/rondo.armv5l635916119ab6903aa6f8672e8c59d9c658c279b6fee9b7490abfff1b58395402 Miraimirai RondoDox ua-wget
http://41.231.37.153/rondo.armv4l92a92f68af94dfc82046ebe54a51a639d972608d2516255250cd222ad2b8fddd Miraimirai RondoDox ua-wget
http://41.231.37.153/rondo.armv7lec6125b2e7dba1419d5cb0d0ffbcd40de93826062968999d29a933f1485249dc Miraimirai RondoDox ua-wget
http://41.231.37.153/rondo.powerpc852713af646fc9ebe10d87b98556f42763cd8490bcb855847a46e6db0fced634 Miraimirai ua-wget
http://41.231.37.153/rondo.powerpc-440fp2311ce1f03fd7a7c7b2130ebcd7cf84c346e22cec9e00749835746cfd2f2efa5 Miraimirai RondoDox ua-wget
http://41.231.37.153/rondo.mips5075648683ceb6822b87509f97f7d15436d510feb0a019053084cb63eb44520d Gafgytgafgyt ua-wget
http://41.231.37.153/rondo.mipseld4d72de0e0335c9a3f3eec7cdfd93f7fcc5ee85fc1b8692b8fdab77355db7190 Gafgytgafgyt ua-wget
http://41.231.37.153/rondo.arc700a448a233d175276ab77aa4cf9fd63dd02f9e6fd5f4ee160ce99f177df7d27d11 Miraimirai ua-wget
http://41.231.37.153/rondo.sh487b5360fc1a9b326ab7cdece074614eb30e23bd0ff7b179cb121e29aac0edb31 Miraimirai ua-wget
http://41.231.37.153/rondo.sparc8ccaa9a601ec1a1750338b8074d60609b53cde76135f1761fd705428dd195bb7 Miraimirai RondoDox ua-wget
http://41.231.37.153/rondo.m68k9aedf0f1ae99ae01eed2d8edec1dd9f2a2257435a91c6a57d4b368946b0f1d18 Miraimirai ua-wget
http://41.231.37.153/rondo.armebb335b5eeaf8ea4f275a66c22322e2f35a36707979aa430ea3dadc29564f3ba09 MiraiRondoDox ua-wget
http://41.231.37.153/rondo.armebhf4e7384185cdff726ae05bad052983c0b3854bd5a3a69897d980cacef2f9a06fc RondoDoxua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
39
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox masquerade
Status:
terminated
Behavior Graph:
%3 guuid=be65a44c-1900-0000-9ed6-3b7972110000 pid=4466 /usr/bin/sudo guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473 /tmp/sample.bin write-file guuid=be65a44c-1900-0000-9ed6-3b7972110000 pid=4466->guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473 execve guuid=fde8894e-1900-0000-9ed6-3b797a110000 pid=4474 /usr/bin/rm guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=fde8894e-1900-0000-9ed6-3b797a110000 pid=4474 execve guuid=f087c44e-1900-0000-9ed6-3b797c110000 pid=4476 /usr/bin/sudo net guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=f087c44e-1900-0000-9ed6-3b797c110000 pid=4476 execve guuid=936b3152-1900-0000-9ed6-3b798b110000 pid=4491 /usr/bin/sudo net guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=936b3152-1900-0000-9ed6-3b798b110000 pid=4491 execve guuid=eda56256-1900-0000-9ed6-3b7998110000 pid=4504 /usr/bin/sudo net guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=eda56256-1900-0000-9ed6-3b7998110000 pid=4504 execve guuid=2b090d5a-1900-0000-9ed6-3b79a9110000 pid=4521 /usr/bin/killall guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=2b090d5a-1900-0000-9ed6-3b79a9110000 pid=4521 execve guuid=d37ebc5a-1900-0000-9ed6-3b79ae110000 pid=4526 /usr/bin/pgrep guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=d37ebc5a-1900-0000-9ed6-3b79ae110000 pid=4526 execve guuid=c753495d-1900-0000-9ed6-3b79be110000 pid=4542 /usr/bin/pgrep guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=c753495d-1900-0000-9ed6-3b79be110000 pid=4542 execve guuid=79e98f5f-1900-0000-9ed6-3b79cc110000 pid=4556 /usr/bin/ls guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=79e98f5f-1900-0000-9ed6-3b79cc110000 pid=4556 execve guuid=3c640a60-1900-0000-9ed6-3b79d0110000 pid=4560 /usr/bin/ls guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=3c640a60-1900-0000-9ed6-3b79d0110000 pid=4560 execve guuid=436b7b60-1900-0000-9ed6-3b79d4110000 pid=4564 /usr/bin/ls guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=436b7b60-1900-0000-9ed6-3b79d4110000 pid=4564 execve guuid=7143f660-1900-0000-9ed6-3b79d6110000 pid=4566 /usr/bin/ls guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=7143f660-1900-0000-9ed6-3b79d6110000 pid=4566 execve guuid=803f5961-1900-0000-9ed6-3b79d8110000 pid=4568 /usr/bin/ls guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=803f5961-1900-0000-9ed6-3b79d8110000 pid=4568 execve guuid=8180d661-1900-0000-9ed6-3b79dc110000 pid=4572 /usr/bin/ls guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=8180d661-1900-0000-9ed6-3b79dc110000 pid=4572 execve guuid=8fa86e62-1900-0000-9ed6-3b79e0110000 pid=4576 /usr/bin/ls guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=8fa86e62-1900-0000-9ed6-3b79e0110000 pid=4576 execve guuid=9ab5da62-1900-0000-9ed6-3b79e3110000 pid=4579 /usr/bin/ls guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=9ab5da62-1900-0000-9ed6-3b79e3110000 pid=4579 execve guuid=e54a4d63-1900-0000-9ed6-3b79e7110000 pid=4583 /usr/bin/ls guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=e54a4d63-1900-0000-9ed6-3b79e7110000 pid=4583 execve guuid=7610bd63-1900-0000-9ed6-3b79eb110000 pid=4587 /usr/bin/ls guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=7610bd63-1900-0000-9ed6-3b79eb110000 pid=4587 execve guuid=db1d1c64-1900-0000-9ed6-3b79ed110000 pid=4589 /usr/bin/ls guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=db1d1c64-1900-0000-9ed6-3b79ed110000 pid=4589 execve guuid=a7668764-1900-0000-9ed6-3b79f2110000 pid=4594 /usr/bin/ls guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=a7668764-1900-0000-9ed6-3b79f2110000 pid=4594 execve guuid=a2c8ee64-1900-0000-9ed6-3b79f6110000 pid=4598 /usr/bin/ls guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=a2c8ee64-1900-0000-9ed6-3b79f6110000 pid=4598 execve guuid=cf315065-1900-0000-9ed6-3b79f8110000 pid=4600 /usr/bin/ls guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=cf315065-1900-0000-9ed6-3b79f8110000 pid=4600 execve guuid=6478b865-1900-0000-9ed6-3b79fb110000 pid=4603 /usr/bin/ls guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=6478b865-1900-0000-9ed6-3b79fb110000 pid=4603 execve guuid=24351666-1900-0000-9ed6-3b79fe110000 pid=4606 /usr/bin/ls guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=24351666-1900-0000-9ed6-3b79fe110000 pid=4606 execve guuid=09856a66-1900-0000-9ed6-3b7902120000 pid=4610 /usr/bin/ls guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=09856a66-1900-0000-9ed6-3b7902120000 pid=4610 execve guuid=be29c366-1900-0000-9ed6-3b7905120000 pid=4613 /usr/bin/ls guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=be29c366-1900-0000-9ed6-3b7905120000 pid=4613 execve guuid=747f1a67-1900-0000-9ed6-3b7909120000 pid=4617 /usr/bin/ls guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=747f1a67-1900-0000-9ed6-3b7909120000 pid=4617 execve guuid=9a3a6b67-1900-0000-9ed6-3b790d120000 pid=4621 /usr/bin/ls guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=9a3a6b67-1900-0000-9ed6-3b790d120000 pid=4621 execve guuid=b0cec267-1900-0000-9ed6-3b790e120000 pid=4622 /usr/bin/ls guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=b0cec267-1900-0000-9ed6-3b790e120000 pid=4622 execve guuid=05961d68-1900-0000-9ed6-3b7911120000 pid=4625 /usr/bin/ls guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=05961d68-1900-0000-9ed6-3b7911120000 pid=4625 execve guuid=68e47468-1900-0000-9ed6-3b7915120000 pid=4629 /usr/bin/ls guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=68e47468-1900-0000-9ed6-3b7915120000 pid=4629 execve guuid=fa98d468-1900-0000-9ed6-3b7919120000 pid=4633 /usr/bin/ls guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=fa98d468-1900-0000-9ed6-3b7919120000 pid=4633 execve guuid=3c6e3969-1900-0000-9ed6-3b791b120000 pid=4635 /usr/bin/ls guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=3c6e3969-1900-0000-9ed6-3b791b120000 pid=4635 execve guuid=ba259769-1900-0000-9ed6-3b791e120000 pid=4638 /usr/bin/ls guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=ba259769-1900-0000-9ed6-3b791e120000 pid=4638 execve guuid=70b3fe69-1900-0000-9ed6-3b7921120000 pid=4641 /usr/bin/ls guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=70b3fe69-1900-0000-9ed6-3b7921120000 pid=4641 execve guuid=e4ae5b6a-1900-0000-9ed6-3b7923120000 pid=4643 /usr/bin/ls guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=e4ae5b6a-1900-0000-9ed6-3b7923120000 pid=4643 execve guuid=3651c56a-1900-0000-9ed6-3b7925120000 pid=4645 /usr/bin/ls guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=3651c56a-1900-0000-9ed6-3b7925120000 pid=4645 execve guuid=11ed266b-1900-0000-9ed6-3b7928120000 pid=4648 /usr/bin/ls guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=11ed266b-1900-0000-9ed6-3b7928120000 pid=4648 execve guuid=d8668b6b-1900-0000-9ed6-3b7929120000 pid=4649 /usr/bin/ls guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=d8668b6b-1900-0000-9ed6-3b7929120000 pid=4649 execve guuid=f916036c-1900-0000-9ed6-3b792c120000 pid=4652 /usr/bin/ls guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=f916036c-1900-0000-9ed6-3b792c120000 pid=4652 execve guuid=8a71626c-1900-0000-9ed6-3b792e120000 pid=4654 /usr/bin/ls guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=8a71626c-1900-0000-9ed6-3b792e120000 pid=4654 execve guuid=d029bb6c-1900-0000-9ed6-3b7930120000 pid=4656 /usr/bin/systemctl guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=d029bb6c-1900-0000-9ed6-3b7930120000 pid=4656 execve guuid=6a95c5da-1900-0000-9ed6-3b79bd130000 pid=5053 /usr/bin/mount write-file guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=6a95c5da-1900-0000-9ed6-3b79bd130000 pid=5053 execve guuid=15d52ddc-1900-0000-9ed6-3b79c2130000 pid=5058 /usr/bin/rm delete-file guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=15d52ddc-1900-0000-9ed6-3b79c2130000 pid=5058 execve guuid=9f83c4de-1900-0000-9ed6-3b79d1130000 pid=5073 /usr/bin/rm delete-file guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=9f83c4de-1900-0000-9ed6-3b79d1130000 pid=5073 execve guuid=9366fdde-1900-0000-9ed6-3b79d2130000 pid=5074 /usr/bin/rm delete-file guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=9366fdde-1900-0000-9ed6-3b79d2130000 pid=5074 execve guuid=79a333df-1900-0000-9ed6-3b79d6130000 pid=5078 /usr/bin/rm delete-file guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=79a333df-1900-0000-9ed6-3b79d6130000 pid=5078 execve guuid=145f7fdf-1900-0000-9ed6-3b79d8130000 pid=5080 /usr/bin/rm delete-file guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=145f7fdf-1900-0000-9ed6-3b79d8130000 pid=5080 execve guuid=8455badf-1900-0000-9ed6-3b79da130000 pid=5082 /usr/bin/rm delete-file guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=8455badf-1900-0000-9ed6-3b79da130000 pid=5082 execve guuid=8656f5df-1900-0000-9ed6-3b79dc130000 pid=5084 /usr/bin/rm delete-file guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=8656f5df-1900-0000-9ed6-3b79dc130000 pid=5084 execve guuid=357c31e0-1900-0000-9ed6-3b79de130000 pid=5086 /usr/bin/rm delete-file guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=357c31e0-1900-0000-9ed6-3b79de130000 pid=5086 execve guuid=77446ce0-1900-0000-9ed6-3b79e0130000 pid=5088 /usr/bin/rm delete-file guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=77446ce0-1900-0000-9ed6-3b79e0130000 pid=5088 execve guuid=dae8a6e0-1900-0000-9ed6-3b79e2130000 pid=5090 /usr/bin/rm delete-file guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=dae8a6e0-1900-0000-9ed6-3b79e2130000 pid=5090 execve guuid=5cabe7e0-1900-0000-9ed6-3b79e3130000 pid=5091 /usr/bin/rm delete-file guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=5cabe7e0-1900-0000-9ed6-3b79e3130000 pid=5091 execve guuid=6e8622e1-1900-0000-9ed6-3b79e7130000 pid=5095 /usr/bin/rm delete-file guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=6e8622e1-1900-0000-9ed6-3b79e7130000 pid=5095 execve guuid=b6b25ce1-1900-0000-9ed6-3b79eb130000 pid=5099 /usr/bin/rm delete-file guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=b6b25ce1-1900-0000-9ed6-3b79eb130000 pid=5099 execve guuid=390892e1-1900-0000-9ed6-3b79ec130000 pid=5100 /usr/bin/mkdir guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=390892e1-1900-0000-9ed6-3b79ec130000 pid=5100 execve guuid=9099d3e1-1900-0000-9ed6-3b79ee130000 pid=5102 /usr/bin/dash guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=9099d3e1-1900-0000-9ed6-3b79ee130000 pid=5102 clone guuid=d5f115e2-1900-0000-9ed6-3b79f1130000 pid=5105 /usr/bin/rm guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=d5f115e2-1900-0000-9ed6-3b79f1130000 pid=5105 execve guuid=28cf47e2-1900-0000-9ed6-3b79f5130000 pid=5109 /usr/bin/wget net send-data write-file guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=28cf47e2-1900-0000-9ed6-3b79f5130000 pid=5109 execve guuid=5516c7f2-1900-0000-9ed6-3b7930140000 pid=5168 /usr/bin/cat guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=5516c7f2-1900-0000-9ed6-3b7930140000 pid=5168 execve guuid=6b2846f3-1900-0000-9ed6-3b7932140000 pid=5170 /usr/bin/rm delete-file guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=6b2846f3-1900-0000-9ed6-3b7932140000 pid=5170 execve guuid=d6bda2f3-1900-0000-9ed6-3b7934140000 pid=5172 /usr/bin/chmod guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=d6bda2f3-1900-0000-9ed6-3b7934140000 pid=5172 execve guuid=518118f4-1900-0000-9ed6-3b7936140000 pid=5174 /usr/bin/sudo net guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=518118f4-1900-0000-9ed6-3b7936140000 pid=5174 execve guuid=cfcb53f7-1900-0000-9ed6-3b793f140000 pid=5183 /usr/bin/sudo net guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=cfcb53f7-1900-0000-9ed6-3b793f140000 pid=5183 execve guuid=731f2dfb-1900-0000-9ed6-3b794f140000 pid=5199 /usr/bin/killall guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=731f2dfb-1900-0000-9ed6-3b794f140000 pid=5199 execve guuid=79fa0efc-1900-0000-9ed6-3b7954140000 pid=5204 /usr/bin/pgrep guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=79fa0efc-1900-0000-9ed6-3b7954140000 pid=5204 execve guuid=a5668bfe-1900-0000-9ed6-3b795d140000 pid=5213 /usr/bin/sudo net guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=a5668bfe-1900-0000-9ed6-3b795d140000 pid=5213 execve 0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 10.0.2.15:0 guuid=f087c44e-1900-0000-9ed6-3b797c110000 pid=4476->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con 558177e1-1f18-5f39-990b-d68b1c194e8a fec0::5054:ff:fe12:3456:0 guuid=f087c44e-1900-0000-9ed6-3b797c110000 pid=4476->558177e1-1f18-5f39-990b-d68b1c194e8a con cbc59886-1795-52e1-b014-449ae22fd09b fe80::5054:ff:fe12:3456:0 guuid=f087c44e-1900-0000-9ed6-3b797c110000 pid=4476->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=d9d15e50-1900-0000-9ed6-3b7985110000 pid=4485 /usr/bin/killall guuid=f087c44e-1900-0000-9ed6-3b797c110000 pid=4476->guuid=d9d15e50-1900-0000-9ed6-3b7985110000 pid=4485 execve guuid=936b3152-1900-0000-9ed6-3b798b110000 pid=4491->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con guuid=936b3152-1900-0000-9ed6-3b798b110000 pid=4491->558177e1-1f18-5f39-990b-d68b1c194e8a con guuid=936b3152-1900-0000-9ed6-3b798b110000 pid=4491->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=78778453-1900-0000-9ed6-3b798f110000 pid=4495 /usr/bin/pgrep guuid=936b3152-1900-0000-9ed6-3b798b110000 pid=4491->guuid=78778453-1900-0000-9ed6-3b798f110000 pid=4495 execve guuid=eda56256-1900-0000-9ed6-3b7998110000 pid=4504->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con guuid=eda56256-1900-0000-9ed6-3b7998110000 pid=4504->558177e1-1f18-5f39-990b-d68b1c194e8a con guuid=eda56256-1900-0000-9ed6-3b7998110000 pid=4504->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=735d7757-1900-0000-9ed6-3b799e110000 pid=4510 /usr/bin/pgrep guuid=eda56256-1900-0000-9ed6-3b7998110000 pid=4504->guuid=735d7757-1900-0000-9ed6-3b799e110000 pid=4510 execve guuid=51cdf56c-1900-0000-9ed6-3b7932120000 pid=4658 /usr/bin/basename guuid=d029bb6c-1900-0000-9ed6-3b7930120000 pid=4656->guuid=51cdf56c-1900-0000-9ed6-3b7932120000 pid=4658 execve guuid=85962d6d-1900-0000-9ed6-3b7933120000 pid=4659 /usr/bin/basename guuid=d029bb6c-1900-0000-9ed6-3b7930120000 pid=4656->guuid=85962d6d-1900-0000-9ed6-3b7933120000 pid=4659 execve guuid=80f7696d-1900-0000-9ed6-3b7935120000 pid=4661 /usr/bin/dash guuid=d029bb6c-1900-0000-9ed6-3b7930120000 pid=4656->guuid=80f7696d-1900-0000-9ed6-3b7935120000 pid=4661 clone guuid=5b69726d-1900-0000-9ed6-3b7936120000 pid=4662 /usr/bin/systemctl guuid=80f7696d-1900-0000-9ed6-3b7935120000 pid=4661->guuid=5b69726d-1900-0000-9ed6-3b7936120000 pid=4662 execve guuid=f3d6766d-1900-0000-9ed6-3b7937120000 pid=4663 /usr/bin/sed guuid=80f7696d-1900-0000-9ed6-3b7935120000 pid=4661->guuid=f3d6766d-1900-0000-9ed6-3b7937120000 pid=4663 execve guuid=f45ddbe1-1900-0000-9ed6-3b79ef130000 pid=5103 /usr/bin/chmod guuid=9099d3e1-1900-0000-9ed6-3b79ee130000 pid=5102->guuid=f45ddbe1-1900-0000-9ed6-3b79ef130000 pid=5103 execve 723b36fb-85d9-5b1d-80ec-f5ebefab4936 41.231.37.153:80 guuid=28cf47e2-1900-0000-9ed6-3b79f5130000 pid=5109->723b36fb-85d9-5b1d-80ec-f5ebefab4936 send: 140B guuid=518118f4-1900-0000-9ed6-3b7936140000 pid=5174->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con guuid=518118f4-1900-0000-9ed6-3b7936140000 pid=5174->558177e1-1f18-5f39-990b-d68b1c194e8a con guuid=518118f4-1900-0000-9ed6-3b7936140000 pid=5174->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=45383ef6-1900-0000-9ed6-3b793b140000 pid=5179 /usr/bin/killall guuid=518118f4-1900-0000-9ed6-3b7936140000 pid=5174->guuid=45383ef6-1900-0000-9ed6-3b793b140000 pid=5179 execve guuid=cfcb53f7-1900-0000-9ed6-3b793f140000 pid=5183->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con guuid=cfcb53f7-1900-0000-9ed6-3b793f140000 pid=5183->558177e1-1f18-5f39-990b-d68b1c194e8a con guuid=cfcb53f7-1900-0000-9ed6-3b793f140000 pid=5183->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=29ef9bf8-1900-0000-9ed6-3b7945140000 pid=5189 /usr/bin/pgrep guuid=cfcb53f7-1900-0000-9ed6-3b793f140000 pid=5183->guuid=29ef9bf8-1900-0000-9ed6-3b7945140000 pid=5189 execve guuid=a5668bfe-1900-0000-9ed6-3b795d140000 pid=5213->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con guuid=a5668bfe-1900-0000-9ed6-3b795d140000 pid=5213->558177e1-1f18-5f39-990b-d68b1c194e8a con guuid=a5668bfe-1900-0000-9ed6-3b795d140000 pid=5213->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=656da9ff-1900-0000-9ed6-3b7962140000 pid=5218 /usr/bin/lib/rondo guuid=a5668bfe-1900-0000-9ed6-3b795d140000 pid=5213->guuid=656da9ff-1900-0000-9ed6-3b7962140000 pid=5218 execve guuid=bae3bbff-1900-0000-9ed6-3b7963140000 pid=5219 /usr/bin/lib/rondo write-file zombie guuid=656da9ff-1900-0000-9ed6-3b7962140000 pid=5218->guuid=bae3bbff-1900-0000-9ed6-3b7963140000 pid=5219 clone guuid=3498d1ff-1900-0000-9ed6-3b7964140000 pid=5220 /usr/bin/lib/rondo write-file zombie guuid=bae3bbff-1900-0000-9ed6-3b7963140000 pid=5219->guuid=3498d1ff-1900-0000-9ed6-3b7964140000 pid=5220 clone guuid=d3fd3400-1a00-0000-9ed6-3b7967140000 pid=5223 /usr/lib/systemd/blfzmdy delete-file net send-data write-config write-file zombie guuid=3498d1ff-1900-0000-9ed6-3b7964140000 pid=5220->guuid=d3fd3400-1a00-0000-9ed6-3b7967140000 pid=5223 clone guuid=d3fd3400-1a00-0000-9ed6-3b7967140000 pid=5223->723b36fb-85d9-5b1d-80ec-f5ebefab4936 send: 91B c6d3c8d1-ccce-5272-b764-c5a3ff34618d 45.94.31.89:8443 guuid=d3fd3400-1a00-0000-9ed6-3b7967140000 pid=5223->c6d3c8d1-ccce-5272-b764-c5a3ff34618d send: 21B guuid=25e4d100-1a00-0000-9ed6-3b796a140000 pid=5226 /usr/lib/systemd/blfzmdy write-file guuid=d3fd3400-1a00-0000-9ed6-3b7967140000 pid=5223->guuid=25e4d100-1a00-0000-9ed6-3b796a140000 pid=5226 clone guuid=31a4d800-1a00-0000-9ed6-3b796b140000 pid=5227 /usr/lib/systemd/blfzmdy net send-data write-file zombie guuid=d3fd3400-1a00-0000-9ed6-3b7967140000 pid=5223->guuid=31a4d800-1a00-0000-9ed6-3b796b140000 pid=5227 clone guuid=eaa5903f-1a00-0000-9ed6-3b79be140000 pid=5310 /usr/lib/systemd/blfzmdy write-file zombie guuid=d3fd3400-1a00-0000-9ed6-3b7967140000 pid=5223->guuid=eaa5903f-1a00-0000-9ed6-3b79be140000 pid=5310 clone guuid=31a4d800-1a00-0000-9ed6-3b796b140000 pid=5227->c6d3c8d1-ccce-5272-b764-c5a3ff34618d send: 21B guuid=29d96f41-1a00-0000-9ed6-3b79c1140000 pid=5313 /usr/lib/systemd/blfzmdy net send-data write-file zombie guuid=31a4d800-1a00-0000-9ed6-3b796b140000 pid=5227->guuid=29d96f41-1a00-0000-9ed6-3b79c1140000 pid=5313 clone guuid=cf159d3f-1a00-0000-9ed6-3b79bf140000 pid=5311 /usr/bin/dash guuid=eaa5903f-1a00-0000-9ed6-3b79be140000 pid=5310->guuid=cf159d3f-1a00-0000-9ed6-3b79bf140000 pid=5311 execve guuid=c265c83f-1a00-0000-9ed6-3b79c0140000 pid=5312 /usr/bin/softirq mprotect-exec guuid=cf159d3f-1a00-0000-9ed6-3b79bf140000 pid=5311->guuid=c265c83f-1a00-0000-9ed6-3b79c0140000 pid=5312 execve guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314 /usr/bin/softirq net send-data zombie guuid=c265c83f-1a00-0000-9ed6-3b79c0140000 pid=5312->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314 clone guuid=29d96f41-1a00-0000-9ed6-3b79c1140000 pid=5313->c6d3c8d1-ccce-5272-b764-c5a3ff34618d send: 21B guuid=e9788343-1a00-0000-9ed6-3b79c8140000 pid=5320 /usr/lib/systemd/blfzmdy net send-data write-file zombie guuid=29d96f41-1a00-0000-9ed6-3b79c1140000 pid=5313->guuid=e9788343-1a00-0000-9ed6-3b79c8140000 pid=5320 clone 5b4f37ef-41f0-5901-b8f0-5c79c4d5f639 45.94.31.89:443 guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->5b4f37ef-41f0-5901-b8f0-5c79c4d5f639 send: 862B guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5315 /usr/bin/softirq write-file zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5315 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5316 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5316 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5317 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5317 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5318 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5318 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5319 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5319 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5321 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5321 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5322 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5322 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5323 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5323 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5324 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5324 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5326 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5326 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5327 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5327 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5328 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5328 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5329 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5329 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5330 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5330 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5331 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5331 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5332 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5332 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5333 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5333 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5334 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5334 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5335 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5335 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5336 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5336 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5337 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5337 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5338 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5338 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5339 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5339 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5340 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5340 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5341 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5341 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5342 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5342 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5343 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5343 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5344 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5344 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5345 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5345 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5346 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5346 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5347 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5347 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5348 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5348 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5349 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5349 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5350 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5350 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5351 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5351 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5352 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5352 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5353 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5353 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5354 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5354 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5355 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5355 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5356 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5356 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5357 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5357 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5358 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5358 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5359 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5359 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5360 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5360 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5361 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5361 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5362 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5362 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5363 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5363 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5364 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5364 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5365 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5365 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5366 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5366 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5367 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5367 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5368 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5368 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5369 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5369 clone guuid=e9788343-1a00-0000-9ed6-3b79c8140000 pid=5320->c6d3c8d1-ccce-5272-b764-c5a3ff34618d send: 21B guuid=49ec4945-1a00-0000-9ed6-3b79cd140000 pid=5325 /usr/lib/systemd/blfzmdy write-file zombie guuid=e9788343-1a00-0000-9ed6-3b79c8140000 pid=5320->guuid=49ec4945-1a00-0000-9ed6-3b79cd140000 pid=5325 clone
Threat name:
Script-Shell.Downloader.Heuristic
Status:
Malicious
First seen:
2025-12-27 09:11:14 UTC
File Type:
Text (Shell)
AV detection:
5 of 24 (20.83%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion discovery linux persistence privilege_escalation
Behaviour
Enumerates kernel/hardware configuration
Reads runtime system information
Writes file to shm directory
Writes file to tmp directory
Reads CPU attributes
Abuse Elevation Control Mechanism: Sudo and Sudo Caching
Deletes log files
Disables AppArmor
Disables SELinux
Enumerates running processes
Write file to user bin folder
Writes file to system bin folder
File and Directory Permissions Modification
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

RondoDox

sh adec2bf3cdf2ad11ab9174611cfced67ba28a63a8c61ffb7fb88c4670e9e7377

(this sample)

  
Delivery method
Distributed via web download

Comments