MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 adec2bf3cdf2ad11ab9174611cfced67ba28a63a8c61ffb7fb88c4670e9e7377. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RondoDox


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: adec2bf3cdf2ad11ab9174611cfced67ba28a63a8c61ffb7fb88c4670e9e7377
SHA3-384 hash: 5aff775a3295e5fba0b9513fbb7971b824f22c8aac8f8ee2ec71409fbda185f511542a37847f5dd9d74bac798615e0db
SHA1 hash: 53035b5d18372e33589eb86c98b851413a0d6d80
MD5 hash: 4304cbd286b1f040424b2d623249f311
humanhash: bravo-finch-papa-fillet
File name:rondo.aqu.sh
Download: download sample
Signature RondoDox
File size:9'432 bytes
First seen:2025-12-27 09:10:40 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 96:Ax0iRoLngDa35y5YLOJsfZqIn2UeC6/ZZ8o++z:g0goLngc2CQH
TLSH T1D512F8BA71C002F666A74C46D1D38A7C8C169FE06273CDB7D9844EB799F04086F5D792
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:RondoDox sh
URLMalware sample (SHA256 hash)SignatureTags
http://41.231.37.153/rondo.loln/an/aua-wget
http://41.231.37.153/rondo.x86_647aeb450c57b466d9a280a02f5bbdb2166d6b092a5a6aa7a440b854cc2af333b5 RondoDoxgafgyt mirai RondoDox ua-wget
http://41.231.37.153/rondo.i6868d87fd06b2d964c414affc277c1a34762a24ac10136fa5be9c2cf393f2095a17 Miraimirai ua-wget
http://41.231.37.153/rondo.i586eb40a3a7f8ba5edd91bfa225d9f9f31358bc5233fc50561d382b518f7774980a Miraimirai ua-wget
http://41.231.37.153/rondo.i4867732e3ac296300ee478d9e11dbc87080658130c9d9274c7d39fa891ac0a08b1d Miraimirai ua-wget
http://41.231.37.153/rondo.armv6lf6dd15cb2803eb1a8866104e0bbfa469f8fbe0255106a8cf472d69c81f724b9f Miraimirai RondoDox ua-wget
http://41.231.37.153/rondo.armv5l9affdd7320dda529271f43090f8b8c3e82963d382e21a73d00cde6068090252f Miraimirai RondoDox ua-wget
http://41.231.37.153/rondo.armv4le2c0b7f64c6a8f8cbe51452349c56d8a340c98bb8a6b55d44cf33fabf8766d7f Miraimirai RondoDox ua-wget
http://41.231.37.153/rondo.armv7l2d6cb85fb16a5fa70f9fe9478f6ed924280b74846f12686912105891fac17959 RondoDoxmirai RondoDox ua-wget
http://41.231.37.153/rondo.powerpcc7faf8d356dec3f94a6ea63d22e5ea588083941bd3ff760b5c8d01c112008dc0 Miraimirai ua-wget
http://41.231.37.153/rondo.powerpc-440fp57f9ba41f0cb4f774a98099fb2dda6a9cd6d9c780ecfca87e8618167c79006d2 Miraimirai RondoDox ua-wget
http://41.231.37.153/rondo.mips31e825d0017b4eb68b7afd69a80f84c0a5a079ef31d3fa420088c39a3ebc4547 Gafgytgafgyt ua-wget
http://41.231.37.153/rondo.mipseld2fe03bc659bb4c6ebd78984ac7c6ee6b0cd02d1bf99387679d4ce38a1f1aafe Miraigafgyt mirai ua-wget
http://41.231.37.153/rondo.arc70078d383029563304ded927d7d82613328f6763724fa7192fcaf4f23e882a65bd3 Miraimirai ua-wget
http://41.231.37.153/rondo.sh435d9009800989ef6dfa78d8305e1486ea4cf9d1d89f6483082874493f364fca1 Miraimirai ua-wget
http://41.231.37.153/rondo.sparca501ee00340a2cc0b1a8441c888b6df1d5e52d6ca360e6996973ae85cea51966 Miraimirai RondoDox ua-wget
http://41.231.37.153/rondo.m68ka78f8c90eea0183dbf8d64bd03f34696159980cf3a24937138d50be267865c95 Miraimirai ua-wget
http://41.231.37.153/rondo.armeb67219e9776b9a374c618e948f220f1871647189364487254d5cea968023b6fc9 Miraimirai RondoDox ua-wget
http://41.231.37.153/rondo.armebhf848464e44045c74124c228af6b76665adc8c8ea3994e2b70045a95db862bba21 Miraimirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
47
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox masquerade
Status:
terminated
Behavior Graph:
%3 guuid=be65a44c-1900-0000-9ed6-3b7972110000 pid=4466 /usr/bin/sudo guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473 /tmp/sample.bin write-file guuid=be65a44c-1900-0000-9ed6-3b7972110000 pid=4466->guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473 execve guuid=fde8894e-1900-0000-9ed6-3b797a110000 pid=4474 /usr/bin/rm guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=fde8894e-1900-0000-9ed6-3b797a110000 pid=4474 execve guuid=f087c44e-1900-0000-9ed6-3b797c110000 pid=4476 /usr/bin/sudo net guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=f087c44e-1900-0000-9ed6-3b797c110000 pid=4476 execve guuid=936b3152-1900-0000-9ed6-3b798b110000 pid=4491 /usr/bin/sudo net guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=936b3152-1900-0000-9ed6-3b798b110000 pid=4491 execve guuid=eda56256-1900-0000-9ed6-3b7998110000 pid=4504 /usr/bin/sudo net guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=eda56256-1900-0000-9ed6-3b7998110000 pid=4504 execve guuid=2b090d5a-1900-0000-9ed6-3b79a9110000 pid=4521 /usr/bin/killall guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=2b090d5a-1900-0000-9ed6-3b79a9110000 pid=4521 execve guuid=d37ebc5a-1900-0000-9ed6-3b79ae110000 pid=4526 /usr/bin/pgrep guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=d37ebc5a-1900-0000-9ed6-3b79ae110000 pid=4526 execve guuid=c753495d-1900-0000-9ed6-3b79be110000 pid=4542 /usr/bin/pgrep guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=c753495d-1900-0000-9ed6-3b79be110000 pid=4542 execve guuid=79e98f5f-1900-0000-9ed6-3b79cc110000 pid=4556 /usr/bin/ls guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=79e98f5f-1900-0000-9ed6-3b79cc110000 pid=4556 execve guuid=3c640a60-1900-0000-9ed6-3b79d0110000 pid=4560 /usr/bin/ls guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=3c640a60-1900-0000-9ed6-3b79d0110000 pid=4560 execve guuid=436b7b60-1900-0000-9ed6-3b79d4110000 pid=4564 /usr/bin/ls guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=436b7b60-1900-0000-9ed6-3b79d4110000 pid=4564 execve guuid=7143f660-1900-0000-9ed6-3b79d6110000 pid=4566 /usr/bin/ls guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=7143f660-1900-0000-9ed6-3b79d6110000 pid=4566 execve guuid=803f5961-1900-0000-9ed6-3b79d8110000 pid=4568 /usr/bin/ls guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=803f5961-1900-0000-9ed6-3b79d8110000 pid=4568 execve guuid=8180d661-1900-0000-9ed6-3b79dc110000 pid=4572 /usr/bin/ls guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=8180d661-1900-0000-9ed6-3b79dc110000 pid=4572 execve guuid=8fa86e62-1900-0000-9ed6-3b79e0110000 pid=4576 /usr/bin/ls guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=8fa86e62-1900-0000-9ed6-3b79e0110000 pid=4576 execve guuid=9ab5da62-1900-0000-9ed6-3b79e3110000 pid=4579 /usr/bin/ls guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=9ab5da62-1900-0000-9ed6-3b79e3110000 pid=4579 execve guuid=e54a4d63-1900-0000-9ed6-3b79e7110000 pid=4583 /usr/bin/ls guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=e54a4d63-1900-0000-9ed6-3b79e7110000 pid=4583 execve guuid=7610bd63-1900-0000-9ed6-3b79eb110000 pid=4587 /usr/bin/ls guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=7610bd63-1900-0000-9ed6-3b79eb110000 pid=4587 execve guuid=db1d1c64-1900-0000-9ed6-3b79ed110000 pid=4589 /usr/bin/ls guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=db1d1c64-1900-0000-9ed6-3b79ed110000 pid=4589 execve guuid=a7668764-1900-0000-9ed6-3b79f2110000 pid=4594 /usr/bin/ls guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=a7668764-1900-0000-9ed6-3b79f2110000 pid=4594 execve guuid=a2c8ee64-1900-0000-9ed6-3b79f6110000 pid=4598 /usr/bin/ls guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=a2c8ee64-1900-0000-9ed6-3b79f6110000 pid=4598 execve guuid=cf315065-1900-0000-9ed6-3b79f8110000 pid=4600 /usr/bin/ls guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=cf315065-1900-0000-9ed6-3b79f8110000 pid=4600 execve guuid=6478b865-1900-0000-9ed6-3b79fb110000 pid=4603 /usr/bin/ls guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=6478b865-1900-0000-9ed6-3b79fb110000 pid=4603 execve guuid=24351666-1900-0000-9ed6-3b79fe110000 pid=4606 /usr/bin/ls guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=24351666-1900-0000-9ed6-3b79fe110000 pid=4606 execve guuid=09856a66-1900-0000-9ed6-3b7902120000 pid=4610 /usr/bin/ls guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=09856a66-1900-0000-9ed6-3b7902120000 pid=4610 execve guuid=be29c366-1900-0000-9ed6-3b7905120000 pid=4613 /usr/bin/ls guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=be29c366-1900-0000-9ed6-3b7905120000 pid=4613 execve guuid=747f1a67-1900-0000-9ed6-3b7909120000 pid=4617 /usr/bin/ls guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=747f1a67-1900-0000-9ed6-3b7909120000 pid=4617 execve guuid=9a3a6b67-1900-0000-9ed6-3b790d120000 pid=4621 /usr/bin/ls guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=9a3a6b67-1900-0000-9ed6-3b790d120000 pid=4621 execve guuid=b0cec267-1900-0000-9ed6-3b790e120000 pid=4622 /usr/bin/ls guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=b0cec267-1900-0000-9ed6-3b790e120000 pid=4622 execve guuid=05961d68-1900-0000-9ed6-3b7911120000 pid=4625 /usr/bin/ls guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=05961d68-1900-0000-9ed6-3b7911120000 pid=4625 execve guuid=68e47468-1900-0000-9ed6-3b7915120000 pid=4629 /usr/bin/ls guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=68e47468-1900-0000-9ed6-3b7915120000 pid=4629 execve guuid=fa98d468-1900-0000-9ed6-3b7919120000 pid=4633 /usr/bin/ls guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=fa98d468-1900-0000-9ed6-3b7919120000 pid=4633 execve guuid=3c6e3969-1900-0000-9ed6-3b791b120000 pid=4635 /usr/bin/ls guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=3c6e3969-1900-0000-9ed6-3b791b120000 pid=4635 execve guuid=ba259769-1900-0000-9ed6-3b791e120000 pid=4638 /usr/bin/ls guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=ba259769-1900-0000-9ed6-3b791e120000 pid=4638 execve guuid=70b3fe69-1900-0000-9ed6-3b7921120000 pid=4641 /usr/bin/ls guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=70b3fe69-1900-0000-9ed6-3b7921120000 pid=4641 execve guuid=e4ae5b6a-1900-0000-9ed6-3b7923120000 pid=4643 /usr/bin/ls guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=e4ae5b6a-1900-0000-9ed6-3b7923120000 pid=4643 execve guuid=3651c56a-1900-0000-9ed6-3b7925120000 pid=4645 /usr/bin/ls guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=3651c56a-1900-0000-9ed6-3b7925120000 pid=4645 execve guuid=11ed266b-1900-0000-9ed6-3b7928120000 pid=4648 /usr/bin/ls guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=11ed266b-1900-0000-9ed6-3b7928120000 pid=4648 execve guuid=d8668b6b-1900-0000-9ed6-3b7929120000 pid=4649 /usr/bin/ls guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=d8668b6b-1900-0000-9ed6-3b7929120000 pid=4649 execve guuid=f916036c-1900-0000-9ed6-3b792c120000 pid=4652 /usr/bin/ls guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=f916036c-1900-0000-9ed6-3b792c120000 pid=4652 execve guuid=8a71626c-1900-0000-9ed6-3b792e120000 pid=4654 /usr/bin/ls guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=8a71626c-1900-0000-9ed6-3b792e120000 pid=4654 execve guuid=d029bb6c-1900-0000-9ed6-3b7930120000 pid=4656 /usr/bin/systemctl guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=d029bb6c-1900-0000-9ed6-3b7930120000 pid=4656 execve guuid=6a95c5da-1900-0000-9ed6-3b79bd130000 pid=5053 /usr/bin/mount write-file guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=6a95c5da-1900-0000-9ed6-3b79bd130000 pid=5053 execve guuid=15d52ddc-1900-0000-9ed6-3b79c2130000 pid=5058 /usr/bin/rm delete-file guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=15d52ddc-1900-0000-9ed6-3b79c2130000 pid=5058 execve guuid=9f83c4de-1900-0000-9ed6-3b79d1130000 pid=5073 /usr/bin/rm delete-file guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=9f83c4de-1900-0000-9ed6-3b79d1130000 pid=5073 execve guuid=9366fdde-1900-0000-9ed6-3b79d2130000 pid=5074 /usr/bin/rm delete-file guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=9366fdde-1900-0000-9ed6-3b79d2130000 pid=5074 execve guuid=79a333df-1900-0000-9ed6-3b79d6130000 pid=5078 /usr/bin/rm delete-file guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=79a333df-1900-0000-9ed6-3b79d6130000 pid=5078 execve guuid=145f7fdf-1900-0000-9ed6-3b79d8130000 pid=5080 /usr/bin/rm delete-file guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=145f7fdf-1900-0000-9ed6-3b79d8130000 pid=5080 execve guuid=8455badf-1900-0000-9ed6-3b79da130000 pid=5082 /usr/bin/rm delete-file guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=8455badf-1900-0000-9ed6-3b79da130000 pid=5082 execve guuid=8656f5df-1900-0000-9ed6-3b79dc130000 pid=5084 /usr/bin/rm delete-file guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=8656f5df-1900-0000-9ed6-3b79dc130000 pid=5084 execve guuid=357c31e0-1900-0000-9ed6-3b79de130000 pid=5086 /usr/bin/rm delete-file guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=357c31e0-1900-0000-9ed6-3b79de130000 pid=5086 execve guuid=77446ce0-1900-0000-9ed6-3b79e0130000 pid=5088 /usr/bin/rm delete-file guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=77446ce0-1900-0000-9ed6-3b79e0130000 pid=5088 execve guuid=dae8a6e0-1900-0000-9ed6-3b79e2130000 pid=5090 /usr/bin/rm delete-file guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=dae8a6e0-1900-0000-9ed6-3b79e2130000 pid=5090 execve guuid=5cabe7e0-1900-0000-9ed6-3b79e3130000 pid=5091 /usr/bin/rm delete-file guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=5cabe7e0-1900-0000-9ed6-3b79e3130000 pid=5091 execve guuid=6e8622e1-1900-0000-9ed6-3b79e7130000 pid=5095 /usr/bin/rm delete-file guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=6e8622e1-1900-0000-9ed6-3b79e7130000 pid=5095 execve guuid=b6b25ce1-1900-0000-9ed6-3b79eb130000 pid=5099 /usr/bin/rm delete-file guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=b6b25ce1-1900-0000-9ed6-3b79eb130000 pid=5099 execve guuid=390892e1-1900-0000-9ed6-3b79ec130000 pid=5100 /usr/bin/mkdir guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=390892e1-1900-0000-9ed6-3b79ec130000 pid=5100 execve guuid=9099d3e1-1900-0000-9ed6-3b79ee130000 pid=5102 /usr/bin/dash guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=9099d3e1-1900-0000-9ed6-3b79ee130000 pid=5102 clone guuid=d5f115e2-1900-0000-9ed6-3b79f1130000 pid=5105 /usr/bin/rm guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=d5f115e2-1900-0000-9ed6-3b79f1130000 pid=5105 execve guuid=28cf47e2-1900-0000-9ed6-3b79f5130000 pid=5109 /usr/bin/wget net send-data write-file guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=28cf47e2-1900-0000-9ed6-3b79f5130000 pid=5109 execve guuid=5516c7f2-1900-0000-9ed6-3b7930140000 pid=5168 /usr/bin/cat guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=5516c7f2-1900-0000-9ed6-3b7930140000 pid=5168 execve guuid=6b2846f3-1900-0000-9ed6-3b7932140000 pid=5170 /usr/bin/rm delete-file guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=6b2846f3-1900-0000-9ed6-3b7932140000 pid=5170 execve guuid=d6bda2f3-1900-0000-9ed6-3b7934140000 pid=5172 /usr/bin/chmod guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=d6bda2f3-1900-0000-9ed6-3b7934140000 pid=5172 execve guuid=518118f4-1900-0000-9ed6-3b7936140000 pid=5174 /usr/bin/sudo net guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=518118f4-1900-0000-9ed6-3b7936140000 pid=5174 execve guuid=cfcb53f7-1900-0000-9ed6-3b793f140000 pid=5183 /usr/bin/sudo net guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=cfcb53f7-1900-0000-9ed6-3b793f140000 pid=5183 execve guuid=731f2dfb-1900-0000-9ed6-3b794f140000 pid=5199 /usr/bin/killall guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=731f2dfb-1900-0000-9ed6-3b794f140000 pid=5199 execve guuid=79fa0efc-1900-0000-9ed6-3b7954140000 pid=5204 /usr/bin/pgrep guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=79fa0efc-1900-0000-9ed6-3b7954140000 pid=5204 execve guuid=a5668bfe-1900-0000-9ed6-3b795d140000 pid=5213 /usr/bin/sudo net guuid=1ac2564e-1900-0000-9ed6-3b7979110000 pid=4473->guuid=a5668bfe-1900-0000-9ed6-3b795d140000 pid=5213 execve 0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 10.0.2.15:0 guuid=f087c44e-1900-0000-9ed6-3b797c110000 pid=4476->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con 558177e1-1f18-5f39-990b-d68b1c194e8a fec0::5054:ff:fe12:3456:0 guuid=f087c44e-1900-0000-9ed6-3b797c110000 pid=4476->558177e1-1f18-5f39-990b-d68b1c194e8a con cbc59886-1795-52e1-b014-449ae22fd09b fe80::5054:ff:fe12:3456:0 guuid=f087c44e-1900-0000-9ed6-3b797c110000 pid=4476->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=d9d15e50-1900-0000-9ed6-3b7985110000 pid=4485 /usr/bin/killall guuid=f087c44e-1900-0000-9ed6-3b797c110000 pid=4476->guuid=d9d15e50-1900-0000-9ed6-3b7985110000 pid=4485 execve guuid=936b3152-1900-0000-9ed6-3b798b110000 pid=4491->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con guuid=936b3152-1900-0000-9ed6-3b798b110000 pid=4491->558177e1-1f18-5f39-990b-d68b1c194e8a con guuid=936b3152-1900-0000-9ed6-3b798b110000 pid=4491->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=78778453-1900-0000-9ed6-3b798f110000 pid=4495 /usr/bin/pgrep guuid=936b3152-1900-0000-9ed6-3b798b110000 pid=4491->guuid=78778453-1900-0000-9ed6-3b798f110000 pid=4495 execve guuid=eda56256-1900-0000-9ed6-3b7998110000 pid=4504->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con guuid=eda56256-1900-0000-9ed6-3b7998110000 pid=4504->558177e1-1f18-5f39-990b-d68b1c194e8a con guuid=eda56256-1900-0000-9ed6-3b7998110000 pid=4504->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=735d7757-1900-0000-9ed6-3b799e110000 pid=4510 /usr/bin/pgrep guuid=eda56256-1900-0000-9ed6-3b7998110000 pid=4504->guuid=735d7757-1900-0000-9ed6-3b799e110000 pid=4510 execve guuid=51cdf56c-1900-0000-9ed6-3b7932120000 pid=4658 /usr/bin/basename guuid=d029bb6c-1900-0000-9ed6-3b7930120000 pid=4656->guuid=51cdf56c-1900-0000-9ed6-3b7932120000 pid=4658 execve guuid=85962d6d-1900-0000-9ed6-3b7933120000 pid=4659 /usr/bin/basename guuid=d029bb6c-1900-0000-9ed6-3b7930120000 pid=4656->guuid=85962d6d-1900-0000-9ed6-3b7933120000 pid=4659 execve guuid=80f7696d-1900-0000-9ed6-3b7935120000 pid=4661 /usr/bin/dash guuid=d029bb6c-1900-0000-9ed6-3b7930120000 pid=4656->guuid=80f7696d-1900-0000-9ed6-3b7935120000 pid=4661 clone guuid=5b69726d-1900-0000-9ed6-3b7936120000 pid=4662 /usr/bin/systemctl guuid=80f7696d-1900-0000-9ed6-3b7935120000 pid=4661->guuid=5b69726d-1900-0000-9ed6-3b7936120000 pid=4662 execve guuid=f3d6766d-1900-0000-9ed6-3b7937120000 pid=4663 /usr/bin/sed guuid=80f7696d-1900-0000-9ed6-3b7935120000 pid=4661->guuid=f3d6766d-1900-0000-9ed6-3b7937120000 pid=4663 execve guuid=f45ddbe1-1900-0000-9ed6-3b79ef130000 pid=5103 /usr/bin/chmod guuid=9099d3e1-1900-0000-9ed6-3b79ee130000 pid=5102->guuid=f45ddbe1-1900-0000-9ed6-3b79ef130000 pid=5103 execve 723b36fb-85d9-5b1d-80ec-f5ebefab4936 41.231.37.153:80 guuid=28cf47e2-1900-0000-9ed6-3b79f5130000 pid=5109->723b36fb-85d9-5b1d-80ec-f5ebefab4936 send: 140B guuid=518118f4-1900-0000-9ed6-3b7936140000 pid=5174->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con guuid=518118f4-1900-0000-9ed6-3b7936140000 pid=5174->558177e1-1f18-5f39-990b-d68b1c194e8a con guuid=518118f4-1900-0000-9ed6-3b7936140000 pid=5174->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=45383ef6-1900-0000-9ed6-3b793b140000 pid=5179 /usr/bin/killall guuid=518118f4-1900-0000-9ed6-3b7936140000 pid=5174->guuid=45383ef6-1900-0000-9ed6-3b793b140000 pid=5179 execve guuid=cfcb53f7-1900-0000-9ed6-3b793f140000 pid=5183->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con guuid=cfcb53f7-1900-0000-9ed6-3b793f140000 pid=5183->558177e1-1f18-5f39-990b-d68b1c194e8a con guuid=cfcb53f7-1900-0000-9ed6-3b793f140000 pid=5183->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=29ef9bf8-1900-0000-9ed6-3b7945140000 pid=5189 /usr/bin/pgrep guuid=cfcb53f7-1900-0000-9ed6-3b793f140000 pid=5183->guuid=29ef9bf8-1900-0000-9ed6-3b7945140000 pid=5189 execve guuid=a5668bfe-1900-0000-9ed6-3b795d140000 pid=5213->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con guuid=a5668bfe-1900-0000-9ed6-3b795d140000 pid=5213->558177e1-1f18-5f39-990b-d68b1c194e8a con guuid=a5668bfe-1900-0000-9ed6-3b795d140000 pid=5213->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=656da9ff-1900-0000-9ed6-3b7962140000 pid=5218 /usr/bin/lib/rondo guuid=a5668bfe-1900-0000-9ed6-3b795d140000 pid=5213->guuid=656da9ff-1900-0000-9ed6-3b7962140000 pid=5218 execve guuid=bae3bbff-1900-0000-9ed6-3b7963140000 pid=5219 /usr/bin/lib/rondo write-file zombie guuid=656da9ff-1900-0000-9ed6-3b7962140000 pid=5218->guuid=bae3bbff-1900-0000-9ed6-3b7963140000 pid=5219 clone guuid=3498d1ff-1900-0000-9ed6-3b7964140000 pid=5220 /usr/bin/lib/rondo write-file zombie guuid=bae3bbff-1900-0000-9ed6-3b7963140000 pid=5219->guuid=3498d1ff-1900-0000-9ed6-3b7964140000 pid=5220 clone guuid=d3fd3400-1a00-0000-9ed6-3b7967140000 pid=5223 /usr/lib/systemd/blfzmdy delete-file net send-data write-config write-file zombie guuid=3498d1ff-1900-0000-9ed6-3b7964140000 pid=5220->guuid=d3fd3400-1a00-0000-9ed6-3b7967140000 pid=5223 clone guuid=d3fd3400-1a00-0000-9ed6-3b7967140000 pid=5223->723b36fb-85d9-5b1d-80ec-f5ebefab4936 send: 91B c6d3c8d1-ccce-5272-b764-c5a3ff34618d 45.94.31.89:8443 guuid=d3fd3400-1a00-0000-9ed6-3b7967140000 pid=5223->c6d3c8d1-ccce-5272-b764-c5a3ff34618d send: 21B guuid=25e4d100-1a00-0000-9ed6-3b796a140000 pid=5226 /usr/lib/systemd/blfzmdy write-file guuid=d3fd3400-1a00-0000-9ed6-3b7967140000 pid=5223->guuid=25e4d100-1a00-0000-9ed6-3b796a140000 pid=5226 clone guuid=31a4d800-1a00-0000-9ed6-3b796b140000 pid=5227 /usr/lib/systemd/blfzmdy net send-data write-file zombie guuid=d3fd3400-1a00-0000-9ed6-3b7967140000 pid=5223->guuid=31a4d800-1a00-0000-9ed6-3b796b140000 pid=5227 clone guuid=eaa5903f-1a00-0000-9ed6-3b79be140000 pid=5310 /usr/lib/systemd/blfzmdy write-file zombie guuid=d3fd3400-1a00-0000-9ed6-3b7967140000 pid=5223->guuid=eaa5903f-1a00-0000-9ed6-3b79be140000 pid=5310 clone guuid=31a4d800-1a00-0000-9ed6-3b796b140000 pid=5227->c6d3c8d1-ccce-5272-b764-c5a3ff34618d send: 21B guuid=29d96f41-1a00-0000-9ed6-3b79c1140000 pid=5313 /usr/lib/systemd/blfzmdy net send-data write-file zombie guuid=31a4d800-1a00-0000-9ed6-3b796b140000 pid=5227->guuid=29d96f41-1a00-0000-9ed6-3b79c1140000 pid=5313 clone guuid=cf159d3f-1a00-0000-9ed6-3b79bf140000 pid=5311 /usr/bin/dash guuid=eaa5903f-1a00-0000-9ed6-3b79be140000 pid=5310->guuid=cf159d3f-1a00-0000-9ed6-3b79bf140000 pid=5311 execve guuid=c265c83f-1a00-0000-9ed6-3b79c0140000 pid=5312 /usr/bin/softirq mprotect-exec guuid=cf159d3f-1a00-0000-9ed6-3b79bf140000 pid=5311->guuid=c265c83f-1a00-0000-9ed6-3b79c0140000 pid=5312 execve guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314 /usr/bin/softirq net send-data zombie guuid=c265c83f-1a00-0000-9ed6-3b79c0140000 pid=5312->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314 clone guuid=29d96f41-1a00-0000-9ed6-3b79c1140000 pid=5313->c6d3c8d1-ccce-5272-b764-c5a3ff34618d send: 21B guuid=e9788343-1a00-0000-9ed6-3b79c8140000 pid=5320 /usr/lib/systemd/blfzmdy net send-data write-file zombie guuid=29d96f41-1a00-0000-9ed6-3b79c1140000 pid=5313->guuid=e9788343-1a00-0000-9ed6-3b79c8140000 pid=5320 clone 5b4f37ef-41f0-5901-b8f0-5c79c4d5f639 45.94.31.89:443 guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->5b4f37ef-41f0-5901-b8f0-5c79c4d5f639 send: 862B guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5315 /usr/bin/softirq write-file zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5315 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5316 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5316 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5317 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5317 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5318 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5318 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5319 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5319 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5321 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5321 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5322 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5322 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5323 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5323 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5324 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5324 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5326 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5326 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5327 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5327 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5328 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5328 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5329 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5329 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5330 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5330 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5331 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5331 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5332 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5332 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5333 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5333 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5334 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5334 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5335 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5335 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5336 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5336 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5337 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5337 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5338 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5338 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5339 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5339 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5340 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5340 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5341 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5341 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5342 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5342 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5343 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5343 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5344 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5344 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5345 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5345 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5346 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5346 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5347 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5347 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5348 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5348 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5349 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5349 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5350 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5350 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5351 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5351 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5352 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5352 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5353 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5353 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5354 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5354 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5355 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5355 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5356 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5356 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5357 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5357 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5358 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5358 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5359 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5359 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5360 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5360 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5361 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5361 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5362 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5362 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5363 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5363 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5364 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5364 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5365 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5365 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5366 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5366 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5367 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5367 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5368 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5368 clone guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5369 /usr/bin/softirq zombie guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5314->guuid=0b2e8941-1a00-0000-9ed6-3b79c2140000 pid=5369 clone guuid=e9788343-1a00-0000-9ed6-3b79c8140000 pid=5320->c6d3c8d1-ccce-5272-b764-c5a3ff34618d send: 21B guuid=49ec4945-1a00-0000-9ed6-3b79cd140000 pid=5325 /usr/lib/systemd/blfzmdy write-file zombie guuid=e9788343-1a00-0000-9ed6-3b79c8140000 pid=5320->guuid=49ec4945-1a00-0000-9ed6-3b79cd140000 pid=5325 clone
Threat name:
Script-Shell.Downloader.Heuristic
Status:
Malicious
First seen:
2025-12-27 09:11:14 UTC
File Type:
Text (Shell)
AV detection:
5 of 24 (20.83%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion discovery linux persistence privilege_escalation
Behaviour
Enumerates kernel/hardware configuration
Reads runtime system information
Writes file to shm directory
Writes file to tmp directory
Reads CPU attributes
Abuse Elevation Control Mechanism: Sudo and Sudo Caching
Deletes log files
Disables AppArmor
Disables SELinux
Enumerates running processes
Write file to user bin folder
Writes file to system bin folder
File and Directory Permissions Modification
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

RondoDox

sh adec2bf3cdf2ad11ab9174611cfced67ba28a63a8c61ffb7fb88c4670e9e7377

(this sample)

  
Delivery method
Distributed via web download

Comments