MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b26780bcc66dc4f9be647233a80c900fa76f0a706bb9bea437431b5b5c1dd574. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



XorDDoS


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: b26780bcc66dc4f9be647233a80c900fa76f0a706bb9bea437431b5b5c1dd574
SHA3-384 hash: 88855bb4601dbaa3102a5530ae557eeaf28fb42cfc4188cd35b68b8e40f75a908db4e3fb5d5625f3ff82cff5f23c870d
SHA1 hash: 2ed36c9986c0fc5c2436e36f5aa9491b94d2878f
MD5 hash: f6b6079e3660d0ba76a64f06f5e2148f
humanhash: magazine-nuts-lion-steak
File name:p.sh
Download: download sample
Signature XorDDoS
File size:1'255 bytes
First seen:2025-11-25 19:47:17 UTC
Last seen:2025-11-26 16:48:59 UTC
File type: sh
MIME type:text/plain
ssdeep 24:fN7PvyA3RqAAZ5UAFTe4typU4o39LOYvkRexV5O:V7Jh2ZBFTLtyfs9L7vkReVM
TLSH T19321A29950FA689031CD893F94AE5E9C8BCB79928428560D63DFEFE8D06816875C8734
Magika shell
Reporter abuse_ch
Tags:sh XorDDoS
URLMalware sample (SHA256 hash)SignatureTags
http://195.20.19.216/p.txt8f5ebb5b1c09744b4bb0087dca66360530533a1913151eaa04f17b691aae5a6b XorDDoSelf geofenced ua-wget USA x86 Xorddos
http://195.20.19.216/r.txtn/an/an/a

Intelligence


File Origin
# of uploads :
2
# of downloads :
45
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
xorddos
Verdict:
Unknown
File Type:
ps1
First seen:
2025-11-25T17:07:00Z UTC
Last seen:
2025-11-25T17:50:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=e3e049f3-1800-0000-7977-e323ea110000 pid=4586 /usr/bin/sudo guuid=b9aa08f5-1800-0000-7977-e323f1110000 pid=4593 /tmp/sample.bin guuid=e3e049f3-1800-0000-7977-e323ea110000 pid=4586->guuid=b9aa08f5-1800-0000-7977-e323f1110000 pid=4593 execve guuid=cf4851f5-1800-0000-7977-e323f2110000 pid=4594 /usr/bin/curl net send-data write-file guuid=b9aa08f5-1800-0000-7977-e323f1110000 pid=4593->guuid=cf4851f5-1800-0000-7977-e323f2110000 pid=4594 execve guuid=68fb461c-1900-0000-7977-e32373120000 pid=4723 /usr/bin/chmod guuid=b9aa08f5-1800-0000-7977-e323f1110000 pid=4593->guuid=68fb461c-1900-0000-7977-e32373120000 pid=4723 execve guuid=4b61801c-1900-0000-7977-e32374120000 pid=4724 /usr/bin/ygljglkjgfg0 guuid=b9aa08f5-1800-0000-7977-e323f1110000 pid=4593->guuid=4b61801c-1900-0000-7977-e32374120000 pid=4724 execve guuid=a520d21c-1900-0000-7977-e32377120000 pid=4727 /usr/bin/wget net send-data write-file guuid=b9aa08f5-1800-0000-7977-e323f1110000 pid=4593->guuid=a520d21c-1900-0000-7977-e32377120000 pid=4727 execve guuid=5d044032-1900-0000-7977-e323d0120000 pid=4816 /usr/bin/chmod guuid=b9aa08f5-1800-0000-7977-e323f1110000 pid=4593->guuid=5d044032-1900-0000-7977-e323d0120000 pid=4816 execve guuid=25962633-1900-0000-7977-e323d5120000 pid=4821 /usr/bin/ygljglkjgfg1 guuid=b9aa08f5-1800-0000-7977-e323f1110000 pid=4593->guuid=25962633-1900-0000-7977-e323d5120000 pid=4821 execve guuid=97de4c33-1900-0000-7977-e323d7120000 pid=4823 /usr/bin/chmod guuid=b9aa08f5-1800-0000-7977-e323f1110000 pid=4593->guuid=97de4c33-1900-0000-7977-e323d7120000 pid=4823 execve guuid=fb9dde35-1900-0000-7977-e323df120000 pid=4831 /usr/bin/dash guuid=b9aa08f5-1800-0000-7977-e323f1110000 pid=4593->guuid=fb9dde35-1900-0000-7977-e323df120000 pid=4831 clone guuid=d76e4136-1900-0000-7977-e323e1120000 pid=4833 /usr/bin/sleep guuid=b9aa08f5-1800-0000-7977-e323f1110000 pid=4593->guuid=d76e4136-1900-0000-7977-e323e1120000 pid=4833 execve guuid=80595ac5-1900-0000-7977-e32353140000 pid=5203 /usr/bin/wget net send-data guuid=b9aa08f5-1800-0000-7977-e323f1110000 pid=4593->guuid=80595ac5-1900-0000-7977-e32353140000 pid=5203 execve guuid=ea9a6ccc-1900-0000-7977-e3237a140000 pid=5242 /usr/bin/chmod guuid=b9aa08f5-1800-0000-7977-e323f1110000 pid=4593->guuid=ea9a6ccc-1900-0000-7977-e3237a140000 pid=5242 execve guuid=95c6d5cc-1900-0000-7977-e3237c140000 pid=5244 /usr/bin/sdf3fslsdf13 guuid=b9aa08f5-1800-0000-7977-e323f1110000 pid=4593->guuid=95c6d5cc-1900-0000-7977-e3237c140000 pid=5244 execve guuid=f2a1e1cd-1900-0000-7977-e3237e140000 pid=5246 /usr/bin/chmod guuid=b9aa08f5-1800-0000-7977-e323f1110000 pid=4593->guuid=f2a1e1cd-1900-0000-7977-e3237e140000 pid=5246 execve guuid=1b3d40ce-1900-0000-7977-e3237f140000 pid=5247 /usr/bin/dash guuid=b9aa08f5-1800-0000-7977-e323f1110000 pid=4593->guuid=1b3d40ce-1900-0000-7977-e3237f140000 pid=5247 clone guuid=28344dce-1900-0000-7977-e32380140000 pid=5248 /usr/bin/curl net send-data write-file guuid=b9aa08f5-1800-0000-7977-e323f1110000 pid=4593->guuid=28344dce-1900-0000-7977-e32380140000 pid=5248 execve guuid=5a8cfed6-1900-0000-7977-e32381140000 pid=5249 /usr/bin/chmod guuid=b9aa08f5-1800-0000-7977-e323f1110000 pid=4593->guuid=5a8cfed6-1900-0000-7977-e32381140000 pid=5249 execve guuid=0653cad7-1900-0000-7977-e32382140000 pid=5250 /usr/bin/sdf3fslsdf15 guuid=b9aa08f5-1800-0000-7977-e323f1110000 pid=4593->guuid=0653cad7-1900-0000-7977-e32382140000 pid=5250 execve guuid=5a065ad8-1900-0000-7977-e32383140000 pid=5251 /usr/bin/sleep guuid=b9aa08f5-1800-0000-7977-e323f1110000 pid=4593->guuid=5a065ad8-1900-0000-7977-e32383140000 pid=5251 execve guuid=b6b1d64f-1a00-0000-7977-e32399140000 pid=5273 /usr/bin/mv guuid=b9aa08f5-1800-0000-7977-e323f1110000 pid=4593->guuid=b6b1d64f-1a00-0000-7977-e32399140000 pid=5273 execve guuid=93a23551-1a00-0000-7977-e3239a140000 pid=5274 /usr/bin/mv guuid=b9aa08f5-1800-0000-7977-e323f1110000 pid=4593->guuid=93a23551-1a00-0000-7977-e3239a140000 pid=5274 execve guuid=cdc9dc52-1a00-0000-7977-e3239d140000 pid=5277 /usr/bin/cat guuid=b9aa08f5-1800-0000-7977-e323f1110000 pid=4593->guuid=cdc9dc52-1a00-0000-7977-e3239d140000 pid=5277 execve guuid=2d4fde53-1a00-0000-7977-e3239f140000 pid=5279 /usr/bin/cat guuid=b9aa08f5-1800-0000-7977-e323f1110000 pid=4593->guuid=2d4fde53-1a00-0000-7977-e3239f140000 pid=5279 execve guuid=673cdc54-1a00-0000-7977-e323a1140000 pid=5281 /usr/bin/cat guuid=b9aa08f5-1800-0000-7977-e323f1110000 pid=4593->guuid=673cdc54-1a00-0000-7977-e323a1140000 pid=5281 execve guuid=b954a755-1a00-0000-7977-e323a2140000 pid=5282 /usr/bin/cat guuid=b9aa08f5-1800-0000-7977-e323f1110000 pid=4593->guuid=b954a755-1a00-0000-7977-e323a2140000 pid=5282 execve guuid=9fe6f655-1a00-0000-7977-e323a3140000 pid=5283 /usr/bin/cat guuid=b9aa08f5-1800-0000-7977-e323f1110000 pid=4593->guuid=9fe6f655-1a00-0000-7977-e323a3140000 pid=5283 execve guuid=935e4456-1a00-0000-7977-e323a4140000 pid=5284 /usr/bin/cat guuid=b9aa08f5-1800-0000-7977-e323f1110000 pid=4593->guuid=935e4456-1a00-0000-7977-e323a4140000 pid=5284 execve guuid=c0449b56-1a00-0000-7977-e323a6140000 pid=5286 /usr/bin/cat guuid=b9aa08f5-1800-0000-7977-e323f1110000 pid=4593->guuid=c0449b56-1a00-0000-7977-e323a6140000 pid=5286 execve guuid=95f82857-1a00-0000-7977-e323a7140000 pid=5287 /usr/bin/cat guuid=b9aa08f5-1800-0000-7977-e323f1110000 pid=4593->guuid=95f82857-1a00-0000-7977-e323a7140000 pid=5287 execve guuid=1f9c7757-1a00-0000-7977-e323a8140000 pid=5288 /usr/bin/cat guuid=b9aa08f5-1800-0000-7977-e323f1110000 pid=4593->guuid=1f9c7757-1a00-0000-7977-e323a8140000 pid=5288 execve guuid=e296bf57-1a00-0000-7977-e323a9140000 pid=5289 /usr/bin/cat guuid=b9aa08f5-1800-0000-7977-e323f1110000 pid=4593->guuid=e296bf57-1a00-0000-7977-e323a9140000 pid=5289 execve guuid=3e1f0a58-1a00-0000-7977-e323aa140000 pid=5290 /usr/bin/cat guuid=b9aa08f5-1800-0000-7977-e323f1110000 pid=4593->guuid=3e1f0a58-1a00-0000-7977-e323aa140000 pid=5290 execve guuid=fdf75258-1a00-0000-7977-e323ab140000 pid=5291 /usr/bin/cat guuid=b9aa08f5-1800-0000-7977-e323f1110000 pid=4593->guuid=fdf75258-1a00-0000-7977-e323ab140000 pid=5291 execve guuid=5eb6aa58-1a00-0000-7977-e323ac140000 pid=5292 /usr/bin/cat guuid=b9aa08f5-1800-0000-7977-e323f1110000 pid=4593->guuid=5eb6aa58-1a00-0000-7977-e323ac140000 pid=5292 execve guuid=3f757159-1a00-0000-7977-e323ad140000 pid=5293 /usr/bin/cat guuid=b9aa08f5-1800-0000-7977-e323f1110000 pid=4593->guuid=3f757159-1a00-0000-7977-e323ad140000 pid=5293 execve guuid=758eb459-1a00-0000-7977-e323ae140000 pid=5294 /usr/bin/cat guuid=b9aa08f5-1800-0000-7977-e323f1110000 pid=4593->guuid=758eb459-1a00-0000-7977-e323ae140000 pid=5294 execve guuid=0b68f559-1a00-0000-7977-e323af140000 pid=5295 /usr/bin/cat guuid=b9aa08f5-1800-0000-7977-e323f1110000 pid=4593->guuid=0b68f559-1a00-0000-7977-e323af140000 pid=5295 execve guuid=7327385a-1a00-0000-7977-e323b0140000 pid=5296 /usr/bin/ls guuid=b9aa08f5-1800-0000-7977-e323f1110000 pid=4593->guuid=7327385a-1a00-0000-7977-e323b0140000 pid=5296 execve 6cc21579-7f39-5b32-b0e0-c17a41692643 195.20.19.216:80 guuid=cf4851f5-1800-0000-7977-e323f2110000 pid=4594->6cc21579-7f39-5b32-b0e0-c17a41692643 send: 82B guuid=a149c71c-1900-0000-7977-e32376120000 pid=4726 /usr/bin/ygljglkjgfg0 delete-file write-config write-file zombie guuid=4b61801c-1900-0000-7977-e32374120000 pid=4724->guuid=a149c71c-1900-0000-7977-e32376120000 pid=4726 clone guuid=7888311d-1900-0000-7977-e32378120000 pid=4728 /usr/bin/ygljglkjgfg0 guuid=a149c71c-1900-0000-7977-e32376120000 pid=4726->guuid=7888311d-1900-0000-7977-e32378120000 pid=4728 clone guuid=f4bf4e1d-1900-0000-7977-e3237a120000 pid=4730 /usr/bin/ygljglkjgfg0 guuid=a149c71c-1900-0000-7977-e32376120000 pid=4726->guuid=f4bf4e1d-1900-0000-7977-e3237a120000 pid=4730 clone guuid=9db4cf1d-1900-0000-7977-e3237c120000 pid=4732 /usr/bin/dash guuid=a149c71c-1900-0000-7977-e32376120000 pid=4726->guuid=9db4cf1d-1900-0000-7977-e3237c120000 pid=4732 execve guuid=a149c71c-1900-0000-7977-e32376120000 pid=4745 /usr/bin/ygljglkjgfg0 write-file zombie guuid=a149c71c-1900-0000-7977-e32376120000 pid=4726->guuid=a149c71c-1900-0000-7977-e32376120000 pid=4745 clone guuid=a149c71c-1900-0000-7977-e32376120000 pid=4746 /usr/bin/ygljglkjgfg0 dns net send-data write-file zombie guuid=a149c71c-1900-0000-7977-e32376120000 pid=4726->guuid=a149c71c-1900-0000-7977-e32376120000 pid=4746 clone guuid=a149c71c-1900-0000-7977-e32376120000 pid=4747 /usr/bin/ygljglkjgfg0 net zombie guuid=a149c71c-1900-0000-7977-e32376120000 pid=4726->guuid=a149c71c-1900-0000-7977-e32376120000 pid=4747 clone guuid=cfa2704d-1a00-0000-7977-e3238f140000 pid=5263 /usr/bin/ygljglkjgfg0 guuid=a149c71c-1900-0000-7977-e32376120000 pid=4726->guuid=cfa2704d-1a00-0000-7977-e3238f140000 pid=5263 clone guuid=24459c4d-1a00-0000-7977-e32391140000 pid=5265 /usr/bin/ygljglkjgfg0 guuid=a149c71c-1900-0000-7977-e32376120000 pid=4726->guuid=24459c4d-1a00-0000-7977-e32391140000 pid=5265 clone guuid=ab44c34d-1a00-0000-7977-e32393140000 pid=5267 /usr/bin/ygljglkjgfg0 guuid=a149c71c-1900-0000-7977-e32376120000 pid=4726->guuid=ab44c34d-1a00-0000-7977-e32393140000 pid=5267 clone guuid=2f6f294e-1a00-0000-7977-e32395140000 pid=5269 /usr/bin/ygljglkjgfg0 guuid=a149c71c-1900-0000-7977-e32376120000 pid=4726->guuid=2f6f294e-1a00-0000-7977-e32395140000 pid=5269 clone guuid=6ba9954e-1a00-0000-7977-e32397140000 pid=5271 /usr/bin/ygljglkjgfg0 guuid=a149c71c-1900-0000-7977-e32376120000 pid=4726->guuid=6ba9954e-1a00-0000-7977-e32397140000 pid=5271 clone guuid=2e9d057c-1b00-0000-7977-e323b8140000 pid=5304 /usr/bin/ygljglkjgfg0 guuid=a149c71c-1900-0000-7977-e32376120000 pid=4726->guuid=2e9d057c-1b00-0000-7977-e323b8140000 pid=5304 clone guuid=22b47f7c-1b00-0000-7977-e323ba140000 pid=5306 /usr/bin/ygljglkjgfg0 guuid=a149c71c-1900-0000-7977-e32376120000 pid=4726->guuid=22b47f7c-1b00-0000-7977-e323ba140000 pid=5306 clone guuid=89ebf77c-1b00-0000-7977-e323bc140000 pid=5308 /usr/bin/ygljglkjgfg0 guuid=a149c71c-1900-0000-7977-e32376120000 pid=4726->guuid=89ebf77c-1b00-0000-7977-e323bc140000 pid=5308 clone guuid=0025157d-1b00-0000-7977-e323be140000 pid=5310 /usr/bin/ygljglkjgfg0 guuid=a149c71c-1900-0000-7977-e32376120000 pid=4726->guuid=0025157d-1b00-0000-7977-e323be140000 pid=5310 clone guuid=a821777e-1b00-0000-7977-e323c0140000 pid=5312 /usr/bin/ygljglkjgfg0 guuid=a149c71c-1900-0000-7977-e32376120000 pid=4726->guuid=a821777e-1b00-0000-7977-e323c0140000 pid=5312 clone guuid=81801cab-1c00-0000-7977-e323e7140000 pid=5351 /usr/bin/ygljglkjgfg0 guuid=a149c71c-1900-0000-7977-e32376120000 pid=4726->guuid=81801cab-1c00-0000-7977-e323e7140000 pid=5351 clone guuid=3bcf53ab-1c00-0000-7977-e323e9140000 pid=5353 /usr/bin/ygljglkjgfg0 guuid=a149c71c-1900-0000-7977-e32376120000 pid=4726->guuid=3bcf53ab-1c00-0000-7977-e323e9140000 pid=5353 clone guuid=534782ab-1c00-0000-7977-e323eb140000 pid=5355 /usr/bin/ygljglkjgfg0 guuid=a149c71c-1900-0000-7977-e32376120000 pid=4726->guuid=534782ab-1c00-0000-7977-e323eb140000 pid=5355 clone guuid=9e37a7ab-1c00-0000-7977-e323ed140000 pid=5357 /usr/bin/ygljglkjgfg0 guuid=a149c71c-1900-0000-7977-e32376120000 pid=4726->guuid=9e37a7ab-1c00-0000-7977-e323ed140000 pid=5357 clone guuid=bb54caab-1c00-0000-7977-e323ef140000 pid=5359 /usr/bin/ygljglkjgfg0 guuid=a149c71c-1900-0000-7977-e32376120000 pid=4726->guuid=bb54caab-1c00-0000-7977-e323ef140000 pid=5359 clone guuid=1726fdd8-1d00-0000-7977-e323f6140000 pid=5366 /usr/bin/ygljglkjgfg0 guuid=a149c71c-1900-0000-7977-e32376120000 pid=4726->guuid=1726fdd8-1d00-0000-7977-e323f6140000 pid=5366 clone guuid=b35a34d9-1d00-0000-7977-e323f8140000 pid=5368 /usr/bin/ygljglkjgfg0 guuid=a149c71c-1900-0000-7977-e32376120000 pid=4726->guuid=b35a34d9-1d00-0000-7977-e323f8140000 pid=5368 clone guuid=3bac66d9-1d00-0000-7977-e323fa140000 pid=5370 /usr/bin/ygljglkjgfg0 guuid=a149c71c-1900-0000-7977-e32376120000 pid=4726->guuid=3bac66d9-1d00-0000-7977-e323fa140000 pid=5370 clone guuid=1c4593d9-1d00-0000-7977-e323fc140000 pid=5372 /usr/bin/ygljglkjgfg0 guuid=a149c71c-1900-0000-7977-e32376120000 pid=4726->guuid=1c4593d9-1d00-0000-7977-e323fc140000 pid=5372 clone guuid=f658b5d9-1d00-0000-7977-e323fe140000 pid=5374 /usr/bin/ygljglkjgfg0 guuid=a149c71c-1900-0000-7977-e32376120000 pid=4726->guuid=f658b5d9-1d00-0000-7977-e323fe140000 pid=5374 clone guuid=ed066308-1f00-0000-7977-e32305150000 pid=5381 /usr/bin/ygljglkjgfg0 guuid=a149c71c-1900-0000-7977-e32376120000 pid=4726->guuid=ed066308-1f00-0000-7977-e32305150000 pid=5381 clone guuid=7c3e9a08-1f00-0000-7977-e32307150000 pid=5383 /usr/bin/ygljglkjgfg0 guuid=a149c71c-1900-0000-7977-e32376120000 pid=4726->guuid=7c3e9a08-1f00-0000-7977-e32307150000 pid=5383 clone guuid=0bd5c808-1f00-0000-7977-e32309150000 pid=5385 /usr/bin/ygljglkjgfg0 guuid=a149c71c-1900-0000-7977-e32376120000 pid=4726->guuid=0bd5c808-1f00-0000-7977-e32309150000 pid=5385 clone guuid=5357f308-1f00-0000-7977-e3230b150000 pid=5387 /usr/bin/ygljglkjgfg0 guuid=a149c71c-1900-0000-7977-e32376120000 pid=4726->guuid=5357f308-1f00-0000-7977-e3230b150000 pid=5387 clone guuid=37fe1809-1f00-0000-7977-e3230d150000 pid=5389 /usr/bin/ygljglkjgfg0 guuid=a149c71c-1900-0000-7977-e32376120000 pid=4726->guuid=37fe1809-1f00-0000-7977-e3230d150000 pid=5389 clone guuid=c4d16836-2000-0000-7977-e32314150000 pid=5396 /usr/bin/ygljglkjgfg0 guuid=a149c71c-1900-0000-7977-e32376120000 pid=4726->guuid=c4d16836-2000-0000-7977-e32314150000 pid=5396 clone guuid=4b0fa136-2000-0000-7977-e32316150000 pid=5398 /usr/bin/ygljglkjgfg0 guuid=a149c71c-1900-0000-7977-e32376120000 pid=4726->guuid=4b0fa136-2000-0000-7977-e32316150000 pid=5398 clone guuid=d880d936-2000-0000-7977-e32318150000 pid=5400 /usr/bin/ygljglkjgfg0 guuid=a149c71c-1900-0000-7977-e32376120000 pid=4726->guuid=d880d936-2000-0000-7977-e32318150000 pid=5400 clone guuid=fbf50337-2000-0000-7977-e3231a150000 pid=5402 /usr/bin/ygljglkjgfg0 guuid=a149c71c-1900-0000-7977-e32376120000 pid=4726->guuid=fbf50337-2000-0000-7977-e3231a150000 pid=5402 clone guuid=d7f12d37-2000-0000-7977-e3231c150000 pid=5404 /usr/bin/ygljglkjgfg0 guuid=a149c71c-1900-0000-7977-e32376120000 pid=4726->guuid=d7f12d37-2000-0000-7977-e3231c150000 pid=5404 clone guuid=46445a65-2100-0000-7977-e32323150000 pid=5411 /usr/bin/ygljglkjgfg0 guuid=a149c71c-1900-0000-7977-e32376120000 pid=4726->guuid=46445a65-2100-0000-7977-e32323150000 pid=5411 clone guuid=2a6a8f65-2100-0000-7977-e32325150000 pid=5413 /usr/bin/ygljglkjgfg0 guuid=a149c71c-1900-0000-7977-e32376120000 pid=4726->guuid=2a6a8f65-2100-0000-7977-e32325150000 pid=5413 clone guuid=326dbe65-2100-0000-7977-e32327150000 pid=5415 /usr/bin/ygljglkjgfg0 guuid=a149c71c-1900-0000-7977-e32376120000 pid=4726->guuid=326dbe65-2100-0000-7977-e32327150000 pid=5415 clone guuid=a074dc65-2100-0000-7977-e32329150000 pid=5417 /usr/bin/ygljglkjgfg0 guuid=a149c71c-1900-0000-7977-e32376120000 pid=4726->guuid=a074dc65-2100-0000-7977-e32329150000 pid=5417 clone guuid=8197f765-2100-0000-7977-e3232b150000 pid=5419 /usr/bin/ygljglkjgfg0 guuid=a149c71c-1900-0000-7977-e32376120000 pid=4726->guuid=8197f765-2100-0000-7977-e3232b150000 pid=5419 clone guuid=5708c394-2200-0000-7977-e32332150000 pid=5426 /usr/bin/ygljglkjgfg0 guuid=a149c71c-1900-0000-7977-e32376120000 pid=4726->guuid=5708c394-2200-0000-7977-e32332150000 pid=5426 clone guuid=4c49ee94-2200-0000-7977-e32334150000 pid=5428 /usr/bin/ygljglkjgfg0 guuid=a149c71c-1900-0000-7977-e32376120000 pid=4726->guuid=4c49ee94-2200-0000-7977-e32334150000 pid=5428 clone guuid=be351c95-2200-0000-7977-e32336150000 pid=5430 /usr/bin/ygljglkjgfg0 guuid=a149c71c-1900-0000-7977-e32376120000 pid=4726->guuid=be351c95-2200-0000-7977-e32336150000 pid=5430 clone guuid=2a424895-2200-0000-7977-e32338150000 pid=5432 /usr/bin/ygljglkjgfg0 guuid=a149c71c-1900-0000-7977-e32376120000 pid=4726->guuid=2a424895-2200-0000-7977-e32338150000 pid=5432 clone guuid=dce36e95-2200-0000-7977-e3233a150000 pid=5434 /usr/bin/ygljglkjgfg0 guuid=a149c71c-1900-0000-7977-e32376120000 pid=4726->guuid=dce36e95-2200-0000-7977-e3233a150000 pid=5434 clone guuid=5735abc4-2300-0000-7977-e32341150000 pid=5441 /usr/bin/ygljglkjgfg0 guuid=a149c71c-1900-0000-7977-e32376120000 pid=4726->guuid=5735abc4-2300-0000-7977-e32341150000 pid=5441 clone guuid=2de7ebc4-2300-0000-7977-e32343150000 pid=5443 /usr/bin/ygljglkjgfg0 guuid=a149c71c-1900-0000-7977-e32376120000 pid=4726->guuid=2de7ebc4-2300-0000-7977-e32343150000 pid=5443 clone guuid=753d20c5-2300-0000-7977-e32345150000 pid=5445 /usr/bin/ygljglkjgfg0 guuid=a149c71c-1900-0000-7977-e32376120000 pid=4726->guuid=753d20c5-2300-0000-7977-e32345150000 pid=5445 clone guuid=978050c5-2300-0000-7977-e32347150000 pid=5447 /usr/bin/ygljglkjgfg0 guuid=a149c71c-1900-0000-7977-e32376120000 pid=4726->guuid=978050c5-2300-0000-7977-e32347150000 pid=5447 clone guuid=e9cc82c5-2300-0000-7977-e32349150000 pid=5449 /usr/bin/ygljglkjgfg0 guuid=a149c71c-1900-0000-7977-e32376120000 pid=4726->guuid=e9cc82c5-2300-0000-7977-e32349150000 pid=5449 clone guuid=382253f5-2400-0000-7977-e32350150000 pid=5456 /usr/bin/ygljglkjgfg0 guuid=a149c71c-1900-0000-7977-e32376120000 pid=4726->guuid=382253f5-2400-0000-7977-e32350150000 pid=5456 clone guuid=15ab89f5-2400-0000-7977-e32352150000 pid=5458 /usr/bin/ygljglkjgfg0 guuid=a149c71c-1900-0000-7977-e32376120000 pid=4726->guuid=15ab89f5-2400-0000-7977-e32352150000 pid=5458 clone guuid=62cab5f5-2400-0000-7977-e32354150000 pid=5460 /usr/bin/ygljglkjgfg0 guuid=a149c71c-1900-0000-7977-e32376120000 pid=4726->guuid=62cab5f5-2400-0000-7977-e32354150000 pid=5460 clone guuid=7f90d2f5-2400-0000-7977-e32356150000 pid=5462 /usr/bin/ygljglkjgfg0 guuid=a149c71c-1900-0000-7977-e32376120000 pid=4726->guuid=7f90d2f5-2400-0000-7977-e32356150000 pid=5462 clone guuid=b3b8f0f5-2400-0000-7977-e32358150000 pid=5464 /usr/bin/ygljglkjgfg0 guuid=a149c71c-1900-0000-7977-e32376120000 pid=4726->guuid=b3b8f0f5-2400-0000-7977-e32358150000 pid=5464 clone guuid=9e1e8323-2600-0000-7977-e3235f150000 pid=5471 /usr/bin/ygljglkjgfg0 guuid=a149c71c-1900-0000-7977-e32376120000 pid=4726->guuid=9e1e8323-2600-0000-7977-e3235f150000 pid=5471 clone guuid=28aeb023-2600-0000-7977-e32361150000 pid=5473 /usr/bin/ygljglkjgfg0 guuid=a149c71c-1900-0000-7977-e32376120000 pid=4726->guuid=28aeb023-2600-0000-7977-e32361150000 pid=5473 clone guuid=71d2e123-2600-0000-7977-e32363150000 pid=5475 /usr/bin/ygljglkjgfg0 guuid=a149c71c-1900-0000-7977-e32376120000 pid=4726->guuid=71d2e123-2600-0000-7977-e32363150000 pid=5475 clone guuid=b1c60124-2600-0000-7977-e32365150000 pid=5477 /usr/bin/ygljglkjgfg0 guuid=a149c71c-1900-0000-7977-e32376120000 pid=4726->guuid=b1c60124-2600-0000-7977-e32365150000 pid=5477 clone guuid=7b611e24-2600-0000-7977-e32367150000 pid=5479 /usr/bin/ygljglkjgfg0 guuid=a149c71c-1900-0000-7977-e32376120000 pid=4726->guuid=7b611e24-2600-0000-7977-e32367150000 pid=5479 clone guuid=a520d21c-1900-0000-7977-e32377120000 pid=4727->6cc21579-7f39-5b32-b0e0-c17a41692643 send: 133B guuid=8f60411d-1900-0000-7977-e32379120000 pid=4729 /usr/bin/ygljglkjgfg0 guuid=7888311d-1900-0000-7977-e32378120000 pid=4728->guuid=8f60411d-1900-0000-7977-e32379120000 pid=4729 clone guuid=ef5ac11d-1900-0000-7977-e3237b120000 pid=4731 /usr/sbin/update-rc.d zombie guuid=f4bf4e1d-1900-0000-7977-e3237a120000 pid=4730->guuid=ef5ac11d-1900-0000-7977-e3237b120000 pid=4731 execve guuid=4e3e4d22-1900-0000-7977-e32393120000 pid=4755 /usr/bin/systemctl guuid=ef5ac11d-1900-0000-7977-e3237b120000 pid=4731->guuid=4e3e4d22-1900-0000-7977-e32393120000 pid=4755 execve guuid=d366cd1e-1900-0000-7977-e32381120000 pid=4737 /usr/bin/sed guuid=9db4cf1d-1900-0000-7977-e3237c120000 pid=4732->guuid=d366cd1e-1900-0000-7977-e32381120000 pid=4737 execve 568dab0d-6749-508b-aec3-4a3de6d1b1b4 0.0.0.0:1525 guuid=a149c71c-1900-0000-7977-e32376120000 pid=4746->568dab0d-6749-508b-aec3-4a3de6d1b1b4 con 3d58e738-14b7-52e1-a513-de63bf221d29 hh.vvbb321.com:1525 guuid=a149c71c-1900-0000-7977-e32376120000 pid=4746->3d58e738-14b7-52e1-a513-de63bf221d29 send: 4548B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=a149c71c-1900-0000-7977-e32376120000 pid=4746->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 96B b4bf20d4-f7c8-5c24-8830-c23364537aa4 8.8.4.4:53 guuid=a149c71c-1900-0000-7977-e32376120000 pid=4746->b4bf20d4-f7c8-5c24-8830-c23364537aa4 send: 64B 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=a149c71c-1900-0000-7977-e32376120000 pid=4746->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 64B 87f248b3-21f7-50eb-a2c7-cb35eca5cc17 0.0.0.0:80 guuid=a149c71c-1900-0000-7977-e32376120000 pid=4747->87f248b3-21f7-50eb-a2c7-cb35eca5cc17 con guuid=efa84533-1900-0000-7977-e323d6120000 pid=4822 /usr/bin/ygljglkjgfg1 delete-file zombie guuid=25962633-1900-0000-7977-e323d5120000 pid=4821->guuid=efa84533-1900-0000-7977-e323d6120000 pid=4822 clone guuid=80595ac5-1900-0000-7977-e32353140000 pid=5203->6cc21579-7f39-5b32-b0e0-c17a41692643 send: 133B guuid=28344dce-1900-0000-7977-e32380140000 pid=5248->6cc21579-7f39-5b32-b0e0-c17a41692643 send: 82B guuid=1a6e7f4d-1a00-0000-7977-e32390140000 pid=5264 /usr/bin/sbjfwkqmjv zombie guuid=cfa2704d-1a00-0000-7977-e3238f140000 pid=5263->guuid=1a6e7f4d-1a00-0000-7977-e32390140000 pid=5264 execve guuid=f2845553-1a00-0000-7977-e3239e140000 pid=5278 /usr/bin/sbjfwkqmjv zombie guuid=1a6e7f4d-1a00-0000-7977-e32390140000 pid=5264->guuid=f2845553-1a00-0000-7977-e3239e140000 pid=5278 clone guuid=023baa4d-1a00-0000-7977-e32392140000 pid=5266 /usr/bin/sbjfwkqmjv zombie guuid=24459c4d-1a00-0000-7977-e32391140000 pid=5265->guuid=023baa4d-1a00-0000-7977-e32392140000 pid=5266 execve guuid=0f469051-1a00-0000-7977-e3239b140000 pid=5275 /usr/bin/sbjfwkqmjv zombie guuid=023baa4d-1a00-0000-7977-e32392140000 pid=5266->guuid=0f469051-1a00-0000-7977-e3239b140000 pid=5275 clone guuid=31cbe94d-1a00-0000-7977-e32394140000 pid=5268 /usr/bin/sbjfwkqmjv zombie guuid=ab44c34d-1a00-0000-7977-e32393140000 pid=5267->guuid=31cbe94d-1a00-0000-7977-e32394140000 pid=5268 execve guuid=a7712154-1a00-0000-7977-e323a0140000 pid=5280 /usr/bin/sbjfwkqmjv zombie guuid=31cbe94d-1a00-0000-7977-e32394140000 pid=5268->guuid=a7712154-1a00-0000-7977-e323a0140000 pid=5280 clone guuid=5723544e-1a00-0000-7977-e32396140000 pid=5270 /usr/bin/sbjfwkqmjv zombie guuid=2f6f294e-1a00-0000-7977-e32395140000 pid=5269->guuid=5723544e-1a00-0000-7977-e32396140000 pid=5270 execve guuid=5c55c852-1a00-0000-7977-e3239c140000 pid=5276 /usr/bin/sbjfwkqmjv zombie guuid=5723544e-1a00-0000-7977-e32396140000 pid=5270->guuid=5c55c852-1a00-0000-7977-e3239c140000 pid=5276 clone guuid=6878024f-1a00-0000-7977-e32398140000 pid=5272 /usr/bin/sbjfwkqmjv zombie guuid=6ba9954e-1a00-0000-7977-e32397140000 pid=5271->guuid=6878024f-1a00-0000-7977-e32398140000 pid=5272 execve guuid=b5557456-1a00-0000-7977-e323a5140000 pid=5285 /usr/bin/sbjfwkqmjv zombie guuid=6878024f-1a00-0000-7977-e32398140000 pid=5272->guuid=b5557456-1a00-0000-7977-e323a5140000 pid=5285 clone guuid=4f721b7c-1b00-0000-7977-e323b9140000 pid=5305 /usr/bin/lgvrziqfor zombie guuid=2e9d057c-1b00-0000-7977-e323b8140000 pid=5304->guuid=4f721b7c-1b00-0000-7977-e323b9140000 pid=5305 execve guuid=a9dee282-1b00-0000-7977-e323c2140000 pid=5314 /usr/bin/lgvrziqfor zombie guuid=4f721b7c-1b00-0000-7977-e323b9140000 pid=5305->guuid=a9dee282-1b00-0000-7977-e323c2140000 pid=5314 clone guuid=86a6b67c-1b00-0000-7977-e323bb140000 pid=5307 /usr/bin/lgvrziqfor zombie guuid=22b47f7c-1b00-0000-7977-e323ba140000 pid=5306->guuid=86a6b67c-1b00-0000-7977-e323bb140000 pid=5307 execve guuid=fe181989-1b00-0000-7977-e323c6140000 pid=5318 /usr/bin/lgvrziqfor zombie guuid=86a6b67c-1b00-0000-7977-e323bb140000 pid=5307->guuid=fe181989-1b00-0000-7977-e323c6140000 pid=5318 clone guuid=4e42027d-1b00-0000-7977-e323bd140000 pid=5309 /usr/bin/lgvrziqfor zombie guuid=89ebf77c-1b00-0000-7977-e323bc140000 pid=5308->guuid=4e42027d-1b00-0000-7977-e323bd140000 pid=5309 execve guuid=960e3686-1b00-0000-7977-e323c3140000 pid=5315 /usr/bin/lgvrziqfor zombie guuid=4e42027d-1b00-0000-7977-e323bd140000 pid=5309->guuid=960e3686-1b00-0000-7977-e323c3140000 pid=5315 clone guuid=c9e51f7e-1b00-0000-7977-e323bf140000 pid=5311 /usr/bin/lgvrziqfor zombie guuid=0025157d-1b00-0000-7977-e323be140000 pid=5310->guuid=c9e51f7e-1b00-0000-7977-e323bf140000 pid=5311 execve guuid=bbbc4588-1b00-0000-7977-e323c4140000 pid=5316 /usr/bin/lgvrziqfor zombie guuid=c9e51f7e-1b00-0000-7977-e323bf140000 pid=5311->guuid=bbbc4588-1b00-0000-7977-e323c4140000 pid=5316 clone guuid=8899817e-1b00-0000-7977-e323c1140000 pid=5313 /usr/bin/lgvrziqfor zombie guuid=a821777e-1b00-0000-7977-e323c0140000 pid=5312->guuid=8899817e-1b00-0000-7977-e323c1140000 pid=5313 execve guuid=b9c36388-1b00-0000-7977-e323c5140000 pid=5317 /usr/bin/lgvrziqfor zombie guuid=8899817e-1b00-0000-7977-e323c1140000 pid=5313->guuid=b9c36388-1b00-0000-7977-e323c5140000 pid=5317 clone guuid=f24530ab-1c00-0000-7977-e323e8140000 pid=5352 /usr/bin/hgqqdjxhwt zombie guuid=81801cab-1c00-0000-7977-e323e7140000 pid=5351->guuid=f24530ab-1c00-0000-7977-e323e8140000 pid=5352 execve guuid=b2abd5af-1c00-0000-7977-e323f3140000 pid=5363 /usr/bin/hgqqdjxhwt zombie guuid=f24530ab-1c00-0000-7977-e323e8140000 pid=5352->guuid=b2abd5af-1c00-0000-7977-e323f3140000 pid=5363 clone guuid=744c63ab-1c00-0000-7977-e323ea140000 pid=5354 /usr/bin/hgqqdjxhwt zombie guuid=3bcf53ab-1c00-0000-7977-e323e9140000 pid=5353->guuid=744c63ab-1c00-0000-7977-e323ea140000 pid=5354 execve guuid=a7c84daf-1c00-0000-7977-e323f1140000 pid=5361 /usr/bin/hgqqdjxhwt zombie guuid=744c63ab-1c00-0000-7977-e323ea140000 pid=5354->guuid=a7c84daf-1c00-0000-7977-e323f1140000 pid=5361 clone guuid=9d2d8fab-1c00-0000-7977-e323ec140000 pid=5356 /usr/bin/hgqqdjxhwt zombie guuid=534782ab-1c00-0000-7977-e323eb140000 pid=5355->guuid=9d2d8fab-1c00-0000-7977-e323ec140000 pid=5356 execve guuid=15d787b0-1c00-0000-7977-e323f4140000 pid=5364 /usr/bin/hgqqdjxhwt zombie guuid=9d2d8fab-1c00-0000-7977-e323ec140000 pid=5356->guuid=15d787b0-1c00-0000-7977-e323f4140000 pid=5364 clone guuid=b573b1ab-1c00-0000-7977-e323ee140000 pid=5358 /usr/bin/hgqqdjxhwt zombie guuid=9e37a7ab-1c00-0000-7977-e323ed140000 pid=5357->guuid=b573b1ab-1c00-0000-7977-e323ee140000 pid=5358 execve guuid=40157caf-1c00-0000-7977-e323f2140000 pid=5362 /usr/bin/hgqqdjxhwt zombie guuid=b573b1ab-1c00-0000-7977-e323ee140000 pid=5358->guuid=40157caf-1c00-0000-7977-e323f2140000 pid=5362 clone guuid=e85a82ac-1c00-0000-7977-e323f0140000 pid=5360 /usr/bin/hgqqdjxhwt zombie guuid=bb54caab-1c00-0000-7977-e323ef140000 pid=5359->guuid=e85a82ac-1c00-0000-7977-e323f0140000 pid=5360 execve guuid=1dd337b1-1c00-0000-7977-e323f5140000 pid=5365 /usr/bin/hgqqdjxhwt zombie guuid=e85a82ac-1c00-0000-7977-e323f0140000 pid=5360->guuid=1dd337b1-1c00-0000-7977-e323f5140000 pid=5365 clone guuid=24a70dd9-1d00-0000-7977-e323f7140000 pid=5367 /usr/bin/nwxtxuzoqe zombie guuid=1726fdd8-1d00-0000-7977-e323f6140000 pid=5366->guuid=24a70dd9-1d00-0000-7977-e323f7140000 pid=5367 execve guuid=78a232de-1d00-0000-7977-e32302150000 pid=5378 /usr/bin/nwxtxuzoqe zombie guuid=24a70dd9-1d00-0000-7977-e323f7140000 pid=5367->guuid=78a232de-1d00-0000-7977-e32302150000 pid=5378 clone guuid=d71844d9-1d00-0000-7977-e323f9140000 pid=5369 /usr/bin/nwxtxuzoqe zombie guuid=b35a34d9-1d00-0000-7977-e323f8140000 pid=5368->guuid=d71844d9-1d00-0000-7977-e323f9140000 pid=5369 execve guuid=020e27dd-1d00-0000-7977-e32300150000 pid=5376 /usr/bin/nwxtxuzoqe zombie guuid=d71844d9-1d00-0000-7977-e323f9140000 pid=5369->guuid=020e27dd-1d00-0000-7977-e32300150000 pid=5376 clone guuid=d01175d9-1d00-0000-7977-e323fb140000 pid=5371 /usr/bin/nwxtxuzoqe zombie guuid=3bac66d9-1d00-0000-7977-e323fa140000 pid=5370->guuid=d01175d9-1d00-0000-7977-e323fb140000 pid=5371 execve guuid=2357d8de-1d00-0000-7977-e32303150000 pid=5379 /usr/bin/nwxtxuzoqe zombie guuid=d01175d9-1d00-0000-7977-e323fb140000 pid=5371->guuid=2357d8de-1d00-0000-7977-e32303150000 pid=5379 clone guuid=557d9fd9-1d00-0000-7977-e323fd140000 pid=5373 /usr/bin/nwxtxuzoqe zombie guuid=1c4593d9-1d00-0000-7977-e323fc140000 pid=5372->guuid=557d9fd9-1d00-0000-7977-e323fd140000 pid=5373 execve guuid=31c3e4dd-1d00-0000-7977-e32301150000 pid=5377 /usr/bin/nwxtxuzoqe zombie guuid=557d9fd9-1d00-0000-7977-e323fd140000 pid=5373->guuid=31c3e4dd-1d00-0000-7977-e32301150000 pid=5377 clone guuid=484f50da-1d00-0000-7977-e323ff140000 pid=5375 /usr/bin/nwxtxuzoqe zombie guuid=f658b5d9-1d00-0000-7977-e323fe140000 pid=5374->guuid=484f50da-1d00-0000-7977-e323ff140000 pid=5375 execve guuid=8e3e1edf-1d00-0000-7977-e32304150000 pid=5380 /usr/bin/nwxtxuzoqe zombie guuid=484f50da-1d00-0000-7977-e323ff140000 pid=5375->guuid=8e3e1edf-1d00-0000-7977-e32304150000 pid=5380 clone guuid=fc1c7608-1f00-0000-7977-e32306150000 pid=5382 /usr/bin/tentlsfdtp zombie guuid=ed066308-1f00-0000-7977-e32305150000 pid=5381->guuid=fc1c7608-1f00-0000-7977-e32306150000 pid=5382 execve guuid=67624d0c-1f00-0000-7977-e3230f150000 pid=5391 /usr/bin/tentlsfdtp zombie guuid=fc1c7608-1f00-0000-7977-e32306150000 pid=5382->guuid=67624d0c-1f00-0000-7977-e3230f150000 pid=5391 clone guuid=e2f8a808-1f00-0000-7977-e32308150000 pid=5384 /usr/bin/tentlsfdtp zombie guuid=7c3e9a08-1f00-0000-7977-e32307150000 pid=5383->guuid=e2f8a808-1f00-0000-7977-e32308150000 pid=5384 execve guuid=a75a7b0c-1f00-0000-7977-e32310150000 pid=5392 /usr/bin/tentlsfdtp zombie guuid=e2f8a808-1f00-0000-7977-e32308150000 pid=5384->guuid=a75a7b0c-1f00-0000-7977-e32310150000 pid=5392 clone guuid=6bbfd908-1f00-0000-7977-e3230a150000 pid=5386 /usr/bin/tentlsfdtp zombie guuid=0bd5c808-1f00-0000-7977-e32309150000 pid=5385->guuid=6bbfd908-1f00-0000-7977-e3230a150000 pid=5386 execve guuid=3c26970e-1f00-0000-7977-e32312150000 pid=5394 /usr/bin/tentlsfdtp zombie guuid=6bbfd908-1f00-0000-7977-e3230a150000 pid=5386->guuid=3c26970e-1f00-0000-7977-e32312150000 pid=5394 clone guuid=4548ff08-1f00-0000-7977-e3230c150000 pid=5388 /usr/bin/tentlsfdtp zombie guuid=5357f308-1f00-0000-7977-e3230b150000 pid=5387->guuid=4548ff08-1f00-0000-7977-e3230c150000 pid=5388 execve guuid=214d750d-1f00-0000-7977-e32311150000 pid=5393 /usr/bin/tentlsfdtp zombie guuid=4548ff08-1f00-0000-7977-e3230c150000 pid=5388->guuid=214d750d-1f00-0000-7977-e32311150000 pid=5393 clone guuid=aa0fd409-1f00-0000-7977-e3230e150000 pid=5390 /usr/bin/tentlsfdtp zombie guuid=37fe1809-1f00-0000-7977-e3230d150000 pid=5389->guuid=aa0fd409-1f00-0000-7977-e3230e150000 pid=5390 execve guuid=71791a0f-1f00-0000-7977-e32313150000 pid=5395 /usr/bin/tentlsfdtp zombie guuid=aa0fd409-1f00-0000-7977-e3230e150000 pid=5390->guuid=71791a0f-1f00-0000-7977-e32313150000 pid=5395 clone guuid=af598036-2000-0000-7977-e32315150000 pid=5397 /usr/bin/ngeivfckti zombie guuid=c4d16836-2000-0000-7977-e32314150000 pid=5396->guuid=af598036-2000-0000-7977-e32315150000 pid=5397 execve guuid=eb4a553b-2000-0000-7977-e32320150000 pid=5408 /usr/bin/ngeivfckti zombie guuid=af598036-2000-0000-7977-e32315150000 pid=5397->guuid=eb4a553b-2000-0000-7977-e32320150000 pid=5408 clone guuid=ee5eb436-2000-0000-7977-e32317150000 pid=5399 /usr/bin/ngeivfckti zombie guuid=4b0fa136-2000-0000-7977-e32316150000 pid=5398->guuid=ee5eb436-2000-0000-7977-e32317150000 pid=5399 execve guuid=202eaa3a-2000-0000-7977-e3231e150000 pid=5406 /usr/bin/ngeivfckti zombie guuid=ee5eb436-2000-0000-7977-e32317150000 pid=5399->guuid=202eaa3a-2000-0000-7977-e3231e150000 pid=5406 clone guuid=776eec36-2000-0000-7977-e32319150000 pid=5401 /usr/bin/ngeivfckti zombie guuid=d880d936-2000-0000-7977-e32318150000 pid=5400->guuid=776eec36-2000-0000-7977-e32319150000 pid=5401 execve guuid=758bce3b-2000-0000-7977-e32321150000 pid=5409 /usr/bin/ngeivfckti zombie guuid=776eec36-2000-0000-7977-e32319150000 pid=5401->guuid=758bce3b-2000-0000-7977-e32321150000 pid=5409 clone guuid=6d611137-2000-0000-7977-e3231b150000 pid=5403 /usr/bin/ngeivfckti zombie guuid=fbf50337-2000-0000-7977-e3231a150000 pid=5402->guuid=6d611137-2000-0000-7977-e3231b150000 pid=5403 execve guuid=1738373c-2000-0000-7977-e32322150000 pid=5410 /usr/bin/ngeivfckti zombie guuid=6d611137-2000-0000-7977-e3231b150000 pid=5403->guuid=1738373c-2000-0000-7977-e32322150000 pid=5410 clone guuid=23cf3937-2000-0000-7977-e3231d150000 pid=5405 /usr/bin/ngeivfckti zombie guuid=d7f12d37-2000-0000-7977-e3231c150000 pid=5404->guuid=23cf3937-2000-0000-7977-e3231d150000 pid=5405 execve guuid=8bd8c83a-2000-0000-7977-e3231f150000 pid=5407 /usr/bin/ngeivfckti zombie guuid=23cf3937-2000-0000-7977-e3231d150000 pid=5405->guuid=8bd8c83a-2000-0000-7977-e3231f150000 pid=5407 clone guuid=7cb16d65-2100-0000-7977-e32324150000 pid=5412 /usr/bin/tpkuzpzvun zombie guuid=46445a65-2100-0000-7977-e32323150000 pid=5411->guuid=7cb16d65-2100-0000-7977-e32324150000 pid=5412 execve guuid=495c7068-2100-0000-7977-e3232d150000 pid=5421 /usr/bin/tpkuzpzvun zombie guuid=7cb16d65-2100-0000-7977-e32324150000 pid=5412->guuid=495c7068-2100-0000-7977-e3232d150000 pid=5421 clone guuid=ed709e65-2100-0000-7977-e32326150000 pid=5414 /usr/bin/tpkuzpzvun zombie guuid=2a6a8f65-2100-0000-7977-e32325150000 pid=5413->guuid=ed709e65-2100-0000-7977-e32326150000 pid=5414 execve guuid=436fad68-2100-0000-7977-e3232e150000 pid=5422 /usr/bin/tpkuzpzvun zombie guuid=ed709e65-2100-0000-7977-e32326150000 pid=5414->guuid=436fad68-2100-0000-7977-e3232e150000 pid=5422 clone guuid=6687c865-2100-0000-7977-e32328150000 pid=5416 /usr/bin/tpkuzpzvun zombie guuid=326dbe65-2100-0000-7977-e32327150000 pid=5415->guuid=6687c865-2100-0000-7977-e32328150000 pid=5416 execve guuid=45e59d6a-2100-0000-7977-e32330150000 pid=5424 /usr/bin/tpkuzpzvun zombie guuid=6687c865-2100-0000-7977-e32328150000 pid=5416->guuid=45e59d6a-2100-0000-7977-e32330150000 pid=5424 clone guuid=5764e565-2100-0000-7977-e3232a150000 pid=5418 /usr/bin/tpkuzpzvun zombie guuid=a074dc65-2100-0000-7977-e32329150000 pid=5417->guuid=5764e565-2100-0000-7977-e3232a150000 pid=5418 execve guuid=032da869-2100-0000-7977-e3232f150000 pid=5423 /usr/bin/tpkuzpzvun zombie guuid=5764e565-2100-0000-7977-e3232a150000 pid=5418->guuid=032da869-2100-0000-7977-e3232f150000 pid=5423 clone guuid=f613ad66-2100-0000-7977-e3232c150000 pid=5420 /usr/bin/tpkuzpzvun zombie guuid=8197f765-2100-0000-7977-e3232b150000 pid=5419->guuid=f613ad66-2100-0000-7977-e3232c150000 pid=5420 execve guuid=ee62666b-2100-0000-7977-e32331150000 pid=5425 /usr/bin/tpkuzpzvun zombie guuid=f613ad66-2100-0000-7977-e3232c150000 pid=5420->guuid=ee62666b-2100-0000-7977-e32331150000 pid=5425 clone guuid=242fd494-2200-0000-7977-e32333150000 pid=5427 /usr/bin/wyezptkvxk zombie guuid=5708c394-2200-0000-7977-e32332150000 pid=5426->guuid=242fd494-2200-0000-7977-e32333150000 pid=5427 execve guuid=814d0998-2200-0000-7977-e3233c150000 pid=5436 /usr/bin/wyezptkvxk zombie guuid=242fd494-2200-0000-7977-e32333150000 pid=5427->guuid=814d0998-2200-0000-7977-e3233c150000 pid=5436 clone guuid=7ab9fd94-2200-0000-7977-e32335150000 pid=5429 /usr/bin/wyezptkvxk zombie guuid=4c49ee94-2200-0000-7977-e32334150000 pid=5428->guuid=7ab9fd94-2200-0000-7977-e32335150000 pid=5429 execve guuid=1e190999-2200-0000-7977-e3233d150000 pid=5437 /usr/bin/wyezptkvxk zombie guuid=7ab9fd94-2200-0000-7977-e32335150000 pid=5429->guuid=1e190999-2200-0000-7977-e3233d150000 pid=5437 clone guuid=cd1a2b95-2200-0000-7977-e32337150000 pid=5431 /usr/bin/wyezptkvxk zombie guuid=be351c95-2200-0000-7977-e32336150000 pid=5430->guuid=cd1a2b95-2200-0000-7977-e32337150000 pid=5431 execve guuid=8e0b5499-2200-0000-7977-e3233e150000 pid=5438 /usr/bin/wyezptkvxk zombie guuid=cd1a2b95-2200-0000-7977-e32337150000 pid=5431->guuid=8e0b5499-2200-0000-7977-e3233e150000 pid=5438 clone guuid=280f5695-2200-0000-7977-e32339150000 pid=5433 /usr/bin/wyezptkvxk zombie guuid=2a424895-2200-0000-7977-e32338150000 pid=5432->guuid=280f5695-2200-0000-7977-e32339150000 pid=5433 execve guuid=10d9b599-2200-0000-7977-e3233f150000 pid=5439 /usr/bin/wyezptkvxk zombie guuid=280f5695-2200-0000-7977-e32339150000 pid=5433->guuid=10d9b599-2200-0000-7977-e3233f150000 pid=5439 clone guuid=f7fae995-2200-0000-7977-e3233b150000 pid=5435 /usr/bin/wyezptkvxk zombie guuid=dce36e95-2200-0000-7977-e3233a150000 pid=5434->guuid=f7fae995-2200-0000-7977-e3233b150000 pid=5435 execve guuid=2d242d9a-2200-0000-7977-e32340150000 pid=5440 /usr/bin/wyezptkvxk zombie guuid=f7fae995-2200-0000-7977-e3233b150000 pid=5435->guuid=2d242d9a-2200-0000-7977-e32340150000 pid=5440 clone guuid=a323c3c4-2300-0000-7977-e32342150000 pid=5442 /usr/bin/sburqpssig zombie guuid=5735abc4-2300-0000-7977-e32341150000 pid=5441->guuid=a323c3c4-2300-0000-7977-e32342150000 pid=5442 execve guuid=3975f7c8-2300-0000-7977-e3234b150000 pid=5451 /usr/bin/sburqpssig zombie guuid=a323c3c4-2300-0000-7977-e32342150000 pid=5442->guuid=3975f7c8-2300-0000-7977-e3234b150000 pid=5451 clone guuid=d1f0fec4-2300-0000-7977-e32344150000 pid=5444 /usr/bin/sburqpssig zombie guuid=2de7ebc4-2300-0000-7977-e32343150000 pid=5443->guuid=d1f0fec4-2300-0000-7977-e32344150000 pid=5444 execve guuid=8bdc25ca-2300-0000-7977-e3234e150000 pid=5454 /usr/bin/sburqpssig zombie guuid=d1f0fec4-2300-0000-7977-e32344150000 pid=5444->guuid=8bdc25ca-2300-0000-7977-e3234e150000 pid=5454 clone guuid=94382ec5-2300-0000-7977-e32346150000 pid=5446 /usr/bin/sburqpssig zombie guuid=753d20c5-2300-0000-7977-e32345150000 pid=5445->guuid=94382ec5-2300-0000-7977-e32346150000 pid=5446 execve guuid=e759d3c9-2300-0000-7977-e3234d150000 pid=5453 /usr/bin/sburqpssig zombie guuid=94382ec5-2300-0000-7977-e32346150000 pid=5446->guuid=e759d3c9-2300-0000-7977-e3234d150000 pid=5453 clone guuid=b72865c5-2300-0000-7977-e32348150000 pid=5448 /usr/bin/sburqpssig zombie guuid=978050c5-2300-0000-7977-e32347150000 pid=5447->guuid=b72865c5-2300-0000-7977-e32348150000 pid=5448 execve guuid=4ae481c9-2300-0000-7977-e3234c150000 pid=5452 /usr/bin/sburqpssig zombie guuid=b72865c5-2300-0000-7977-e32348150000 pid=5448->guuid=4ae481c9-2300-0000-7977-e3234c150000 pid=5452 clone guuid=38cdf8c5-2300-0000-7977-e3234a150000 pid=5450 /usr/bin/sburqpssig zombie guuid=e9cc82c5-2300-0000-7977-e32349150000 pid=5449->guuid=38cdf8c5-2300-0000-7977-e3234a150000 pid=5450 execve guuid=505cd1ca-2300-0000-7977-e3234f150000 pid=5455 /usr/bin/sburqpssig zombie guuid=38cdf8c5-2300-0000-7977-e3234a150000 pid=5450->guuid=505cd1ca-2300-0000-7977-e3234f150000 pid=5455 clone guuid=2d7e66f5-2400-0000-7977-e32351150000 pid=5457 /usr/bin/chiguvheyp zombie guuid=382253f5-2400-0000-7977-e32350150000 pid=5456->guuid=2d7e66f5-2400-0000-7977-e32351150000 pid=5457 execve guuid=a92964f8-2400-0000-7977-e3235a150000 pid=5466 /usr/bin/chiguvheyp zombie guuid=2d7e66f5-2400-0000-7977-e32351150000 pid=5457->guuid=a92964f8-2400-0000-7977-e3235a150000 pid=5466 clone guuid=89e297f5-2400-0000-7977-e32353150000 pid=5459 /usr/bin/chiguvheyp zombie guuid=15ab89f5-2400-0000-7977-e32352150000 pid=5458->guuid=89e297f5-2400-0000-7977-e32353150000 pid=5459 execve guuid=89e37cf9-2400-0000-7977-e3235c150000 pid=5468 /usr/bin/chiguvheyp zombie guuid=89e297f5-2400-0000-7977-e32353150000 pid=5459->guuid=89e37cf9-2400-0000-7977-e3235c150000 pid=5468 clone guuid=83d1c0f5-2400-0000-7977-e32355150000 pid=5461 /usr/bin/chiguvheyp zombie guuid=62cab5f5-2400-0000-7977-e32354150000 pid=5460->guuid=83d1c0f5-2400-0000-7977-e32355150000 pid=5461 execve guuid=d3e25dfa-2400-0000-7977-e3235d150000 pid=5469 /usr/bin/chiguvheyp zombie guuid=83d1c0f5-2400-0000-7977-e32355150000 pid=5461->guuid=d3e25dfa-2400-0000-7977-e3235d150000 pid=5469 clone guuid=8227ddf5-2400-0000-7977-e32357150000 pid=5463 /usr/bin/chiguvheyp zombie guuid=7f90d2f5-2400-0000-7977-e32356150000 pid=5462->guuid=8227ddf5-2400-0000-7977-e32357150000 pid=5463 execve guuid=05a2aef8-2400-0000-7977-e3235b150000 pid=5467 /usr/bin/chiguvheyp zombie guuid=8227ddf5-2400-0000-7977-e32357150000 pid=5463->guuid=05a2aef8-2400-0000-7977-e3235b150000 pid=5467 clone guuid=0b02e2f6-2400-0000-7977-e32359150000 pid=5465 /usr/bin/chiguvheyp zombie guuid=b3b8f0f5-2400-0000-7977-e32358150000 pid=5464->guuid=0b02e2f6-2400-0000-7977-e32359150000 pid=5465 execve guuid=3ea32bfb-2400-0000-7977-e3235e150000 pid=5470 /usr/bin/chiguvheyp zombie guuid=0b02e2f6-2400-0000-7977-e32359150000 pid=5465->guuid=3ea32bfb-2400-0000-7977-e3235e150000 pid=5470 clone guuid=09759523-2600-0000-7977-e32360150000 pid=5472 /usr/bin/uunayuhejo zombie guuid=9e1e8323-2600-0000-7977-e3235f150000 pid=5471->guuid=09759523-2600-0000-7977-e32360150000 pid=5472 execve guuid=781c9426-2600-0000-7977-e32369150000 pid=5481 /usr/bin/uunayuhejo zombie guuid=09759523-2600-0000-7977-e32360150000 pid=5472->guuid=781c9426-2600-0000-7977-e32369150000 pid=5481 clone guuid=cbd4c423-2600-0000-7977-e32362150000 pid=5474 /usr/bin/uunayuhejo zombie guuid=28aeb023-2600-0000-7977-e32361150000 pid=5473->guuid=cbd4c423-2600-0000-7977-e32362150000 pid=5474 execve guuid=a4bee427-2600-0000-7977-e3236b150000 pid=5483 /usr/bin/uunayuhejo zombie guuid=cbd4c423-2600-0000-7977-e32362150000 pid=5474->guuid=a4bee427-2600-0000-7977-e3236b150000 pid=5483 clone guuid=bc31ed23-2600-0000-7977-e32364150000 pid=5476 /usr/bin/uunayuhejo zombie guuid=71d2e123-2600-0000-7977-e32363150000 pid=5475->guuid=bc31ed23-2600-0000-7977-e32364150000 pid=5476 execve guuid=d6eb7028-2600-0000-7977-e3236c150000 pid=5484 /usr/bin/uunayuhejo zombie guuid=bc31ed23-2600-0000-7977-e32364150000 pid=5476->guuid=d6eb7028-2600-0000-7977-e3236c150000 pid=5484 clone guuid=1ca50b24-2600-0000-7977-e32366150000 pid=5478 /usr/bin/uunayuhejo zombie guuid=b1c60124-2600-0000-7977-e32365150000 pid=5477->guuid=1ca50b24-2600-0000-7977-e32366150000 pid=5478 execve guuid=6afcde27-2600-0000-7977-e3236a150000 pid=5482 /usr/bin/uunayuhejo zombie guuid=1ca50b24-2600-0000-7977-e32366150000 pid=5478->guuid=6afcde27-2600-0000-7977-e3236a150000 pid=5482 clone guuid=46a1b424-2600-0000-7977-e32368150000 pid=5480 /usr/bin/uunayuhejo zombie guuid=7b611e24-2600-0000-7977-e32367150000 pid=5479->guuid=46a1b424-2600-0000-7977-e32368150000 pid=5480 execve guuid=070cd528-2600-0000-7977-e3236d150000 pid=5485 /usr/bin/uunayuhejo zombie guuid=46a1b424-2600-0000-7977-e32368150000 pid=5480->guuid=070cd528-2600-0000-7977-e3236d150000 pid=5485 clone
Threat name:
Linux.Trojan.XorDDoS
Status:
Malicious
First seen:
2025-11-25 19:48:15 UTC
File Type:
Text (Shell)
AV detection:
9 of 38 (23.68%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

XorDDoS

sh b26780bcc66dc4f9be647233a80c900fa76f0a706bb9bea437431b5b5c1dd574

(this sample)

  
Delivery method
Distributed via web download

Comments