MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c3714fc0446a1adaedbc86e3dd0b2121e65b34cc3d40494f709c6873fa0d56bc. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



XorDDoS


Vendor detections: 11


Intelligence 11 IOCs YARA 9 File information Comments

SHA256 hash: c3714fc0446a1adaedbc86e3dd0b2121e65b34cc3d40494f709c6873fa0d56bc
SHA3-384 hash: 00f7abaf4ebe6b49e515fcbe85fc5aa4e8ff272b1127f9b8647e68fc7eb3abbcd847344ea9d6d79cb6f421ccb6810bfa
SHA1 hash: 3cb0c6456d6e6f79ec68444ef3419f6269b1f873
MD5 hash: 71c70f7896d347b9a9d3873f6594bed4
humanhash: stairway-twelve-emma-vegan
File name:p.txt
Download: download sample
Signature XorDDoS
File size:548'616 bytes
First seen:2025-08-26 20:50:23 UTC
Last seen:2025-10-05 13:41:39 UTC
File type: elf
MIME type:application/x-executable
ssdeep 12288:4Ufrcn+vwK5ripVU4tdZ1pNL/pVbz+66ySjQn36Eoj:/fUywKQ7Fb1pNL/p5+fjQn36Eu
TLSH T120C45C56E383E2F7C82705B0134BF7BF4620B6359461CD86B7989D5AB9338F22A4D352
telfhash t12ab138722e7558f8b7f08402425a7620ce39e027259439b71ef2b454f7f2c429b6ad7a
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter abuse_ch
Tags:elf XorDDoS

Intelligence


File Origin
# of uploads :
4
# of downloads :
42
Origin country :
DE DE
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a process from a recently created file
Connection attempt
Launching a process
DNS request
Manages services
Collects information on the network activity
Runs as daemon
Creating a file
Changes owner for a written file
Creates or modifies files in /cron to set up autorun
Writes files to system directory
Deletes a system binary file
Creates or modifies files in /init.d to set up autorun
Creates or modifies symbolic links in /init.d to set up autorun
Deleting of the original file
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
gcc masquerade threat
Verdict:
Malicious
Uses P2P?:
false
Uses anti-vm?:
false
Architecture:
x86
Packer:
not packed
Botnet:
unknown
Number of open files:
13
Number of processes launched:
11
Processes remaning?
false
Remote TCP ports scanned:
not identified
Behaviour
Persistence
Botnet C2s
TCP botnet C2(s):
not identified
UDP botnet C2(s):
not identified
Status:
terminated
Behavior Graph:
%3 guuid=69765420-1700-0000-6338-b146700d0000 pid=3440 /usr/bin/sudo guuid=02144e22-1700-0000-6338-b146780d0000 pid=3448 /tmp/sample.bin guuid=69765420-1700-0000-6338-b146700d0000 pid=3440->guuid=02144e22-1700-0000-6338-b146780d0000 pid=3448 execve guuid=657f7d22-1700-0000-6338-b1467a0d0000 pid=3450 /tmp/sample.bin delete-file write-config write-file zombie guuid=02144e22-1700-0000-6338-b146780d0000 pid=3448->guuid=657f7d22-1700-0000-6338-b1467a0d0000 pid=3450 clone guuid=a814bd22-1700-0000-6338-b1467b0d0000 pid=3451 /tmp/sample.bin guuid=657f7d22-1700-0000-6338-b1467a0d0000 pid=3450->guuid=a814bd22-1700-0000-6338-b1467b0d0000 pid=3451 clone guuid=5554cf22-1700-0000-6338-b1467d0d0000 pid=3453 /tmp/sample.bin guuid=657f7d22-1700-0000-6338-b1467a0d0000 pid=3450->guuid=5554cf22-1700-0000-6338-b1467d0d0000 pid=3453 clone guuid=9056e022-1700-0000-6338-b1467f0d0000 pid=3455 /usr/bin/dash guuid=657f7d22-1700-0000-6338-b1467a0d0000 pid=3450->guuid=9056e022-1700-0000-6338-b1467f0d0000 pid=3455 execve guuid=657f7d22-1700-0000-6338-b1467a0d0000 pid=3457 /tmp/sample.bin write-file zombie guuid=657f7d22-1700-0000-6338-b1467a0d0000 pid=3450->guuid=657f7d22-1700-0000-6338-b1467a0d0000 pid=3457 clone guuid=657f7d22-1700-0000-6338-b1467a0d0000 pid=3458 /tmp/sample.bin dns net send-data write-file zombie guuid=657f7d22-1700-0000-6338-b1467a0d0000 pid=3450->guuid=657f7d22-1700-0000-6338-b1467a0d0000 pid=3458 clone guuid=657f7d22-1700-0000-6338-b1467a0d0000 pid=3459 /tmp/sample.bin net zombie guuid=657f7d22-1700-0000-6338-b1467a0d0000 pid=3450->guuid=657f7d22-1700-0000-6338-b1467a0d0000 pid=3459 clone guuid=ee9cb74f-1800-0000-6338-b14668100000 pid=4200 /tmp/sample.bin guuid=657f7d22-1700-0000-6338-b1467a0d0000 pid=3450->guuid=ee9cb74f-1800-0000-6338-b14668100000 pid=4200 clone guuid=f465d64f-1800-0000-6338-b1466a100000 pid=4202 /tmp/sample.bin guuid=657f7d22-1700-0000-6338-b1467a0d0000 pid=3450->guuid=f465d64f-1800-0000-6338-b1466a100000 pid=4202 clone guuid=2149ea4f-1800-0000-6338-b1466c100000 pid=4204 /tmp/sample.bin guuid=657f7d22-1700-0000-6338-b1467a0d0000 pid=3450->guuid=2149ea4f-1800-0000-6338-b1466c100000 pid=4204 clone guuid=e0120950-1800-0000-6338-b1466e100000 pid=4206 /tmp/sample.bin guuid=657f7d22-1700-0000-6338-b1467a0d0000 pid=3450->guuid=e0120950-1800-0000-6338-b1466e100000 pid=4206 clone guuid=5c659550-1800-0000-6338-b14671100000 pid=4209 /tmp/sample.bin guuid=657f7d22-1700-0000-6338-b1467a0d0000 pid=3450->guuid=5c659550-1800-0000-6338-b14671100000 pid=4209 clone guuid=830f697c-1900-0000-6338-b146f3120000 pid=4851 /tmp/sample.bin guuid=657f7d22-1700-0000-6338-b1467a0d0000 pid=3450->guuid=830f697c-1900-0000-6338-b146f3120000 pid=4851 clone guuid=c535817c-1900-0000-6338-b146f5120000 pid=4853 /tmp/sample.bin guuid=657f7d22-1700-0000-6338-b1467a0d0000 pid=3450->guuid=c535817c-1900-0000-6338-b146f5120000 pid=4853 clone guuid=d19e017d-1900-0000-6338-b146f9120000 pid=4857 /tmp/sample.bin guuid=657f7d22-1700-0000-6338-b1467a0d0000 pid=3450->guuid=d19e017d-1900-0000-6338-b146f9120000 pid=4857 clone guuid=db2e1e7d-1900-0000-6338-b146fb120000 pid=4859 /tmp/sample.bin guuid=657f7d22-1700-0000-6338-b1467a0d0000 pid=3450->guuid=db2e1e7d-1900-0000-6338-b146fb120000 pid=4859 clone guuid=f4c1be7d-1900-0000-6338-b146ff120000 pid=4863 /tmp/sample.bin guuid=657f7d22-1700-0000-6338-b1467a0d0000 pid=3450->guuid=f4c1be7d-1900-0000-6338-b146ff120000 pid=4863 clone guuid=7b191baa-1a00-0000-6338-b146a3140000 pid=5283 /tmp/sample.bin guuid=657f7d22-1700-0000-6338-b1467a0d0000 pid=3450->guuid=7b191baa-1a00-0000-6338-b146a3140000 pid=5283 clone guuid=47cd3aaa-1a00-0000-6338-b146a5140000 pid=5285 /tmp/sample.bin guuid=657f7d22-1700-0000-6338-b1467a0d0000 pid=3450->guuid=47cd3aaa-1a00-0000-6338-b146a5140000 pid=5285 clone guuid=443762aa-1a00-0000-6338-b146a7140000 pid=5287 /tmp/sample.bin guuid=657f7d22-1700-0000-6338-b1467a0d0000 pid=3450->guuid=443762aa-1a00-0000-6338-b146a7140000 pid=5287 clone guuid=ee1397aa-1a00-0000-6338-b146a9140000 pid=5289 /tmp/sample.bin guuid=657f7d22-1700-0000-6338-b1467a0d0000 pid=3450->guuid=ee1397aa-1a00-0000-6338-b146a9140000 pid=5289 clone guuid=f318a9ab-1a00-0000-6338-b146ab140000 pid=5291 /tmp/sample.bin guuid=657f7d22-1700-0000-6338-b1467a0d0000 pid=3450->guuid=f318a9ab-1a00-0000-6338-b146ab140000 pid=5291 clone guuid=888b1ed9-1b00-0000-6338-b146ba140000 pid=5306 /tmp/sample.bin guuid=657f7d22-1700-0000-6338-b1467a0d0000 pid=3450->guuid=888b1ed9-1b00-0000-6338-b146ba140000 pid=5306 clone guuid=978f4dd9-1b00-0000-6338-b146bc140000 pid=5308 /tmp/sample.bin guuid=657f7d22-1700-0000-6338-b1467a0d0000 pid=3450->guuid=978f4dd9-1b00-0000-6338-b146bc140000 pid=5308 clone guuid=dbbd7ad9-1b00-0000-6338-b146be140000 pid=5310 /tmp/sample.bin guuid=657f7d22-1700-0000-6338-b1467a0d0000 pid=3450->guuid=dbbd7ad9-1b00-0000-6338-b146be140000 pid=5310 clone guuid=4a6b9cd9-1b00-0000-6338-b146c0140000 pid=5312 /tmp/sample.bin guuid=657f7d22-1700-0000-6338-b1467a0d0000 pid=3450->guuid=4a6b9cd9-1b00-0000-6338-b146c0140000 pid=5312 clone guuid=9feac0d9-1b00-0000-6338-b146c2140000 pid=5314 /tmp/sample.bin guuid=657f7d22-1700-0000-6338-b1467a0d0000 pid=3450->guuid=9feac0d9-1b00-0000-6338-b146c2140000 pid=5314 clone guuid=06fc8b07-1d00-0000-6338-b146e8140000 pid=5352 /tmp/sample.bin guuid=657f7d22-1700-0000-6338-b1467a0d0000 pid=3450->guuid=06fc8b07-1d00-0000-6338-b146e8140000 pid=5352 clone guuid=bbf6c907-1d00-0000-6338-b146ea140000 pid=5354 /tmp/sample.bin guuid=657f7d22-1700-0000-6338-b1467a0d0000 pid=3450->guuid=bbf6c907-1d00-0000-6338-b146ea140000 pid=5354 clone guuid=ff470108-1d00-0000-6338-b146ec140000 pid=5356 /tmp/sample.bin guuid=657f7d22-1700-0000-6338-b1467a0d0000 pid=3450->guuid=ff470108-1d00-0000-6338-b146ec140000 pid=5356 clone guuid=168b2c08-1d00-0000-6338-b146ee140000 pid=5358 /tmp/sample.bin guuid=657f7d22-1700-0000-6338-b1467a0d0000 pid=3450->guuid=168b2c08-1d00-0000-6338-b146ee140000 pid=5358 clone guuid=71045608-1d00-0000-6338-b146f0140000 pid=5360 /tmp/sample.bin guuid=657f7d22-1700-0000-6338-b1467a0d0000 pid=3450->guuid=71045608-1d00-0000-6338-b146f0140000 pid=5360 clone guuid=d511a335-1e00-0000-6338-b146f7140000 pid=5367 /tmp/sample.bin guuid=657f7d22-1700-0000-6338-b1467a0d0000 pid=3450->guuid=d511a335-1e00-0000-6338-b146f7140000 pid=5367 clone guuid=b07ae035-1e00-0000-6338-b146f9140000 pid=5369 /tmp/sample.bin guuid=657f7d22-1700-0000-6338-b1467a0d0000 pid=3450->guuid=b07ae035-1e00-0000-6338-b146f9140000 pid=5369 clone guuid=270c0f36-1e00-0000-6338-b146fb140000 pid=5371 /tmp/sample.bin guuid=657f7d22-1700-0000-6338-b1467a0d0000 pid=3450->guuid=270c0f36-1e00-0000-6338-b146fb140000 pid=5371 clone guuid=edb03b36-1e00-0000-6338-b146fd140000 pid=5373 /tmp/sample.bin guuid=657f7d22-1700-0000-6338-b1467a0d0000 pid=3450->guuid=edb03b36-1e00-0000-6338-b146fd140000 pid=5373 clone guuid=e5c17036-1e00-0000-6338-b146ff140000 pid=5375 /tmp/sample.bin guuid=657f7d22-1700-0000-6338-b1467a0d0000 pid=3450->guuid=e5c17036-1e00-0000-6338-b146ff140000 pid=5375 clone guuid=6aa80263-1f00-0000-6338-b14606150000 pid=5382 /tmp/sample.bin guuid=657f7d22-1700-0000-6338-b1467a0d0000 pid=3450->guuid=6aa80263-1f00-0000-6338-b14606150000 pid=5382 clone guuid=efc23963-1f00-0000-6338-b14608150000 pid=5384 /tmp/sample.bin guuid=657f7d22-1700-0000-6338-b1467a0d0000 pid=3450->guuid=efc23963-1f00-0000-6338-b14608150000 pid=5384 clone guuid=47e76b63-1f00-0000-6338-b1460a150000 pid=5386 /tmp/sample.bin guuid=657f7d22-1700-0000-6338-b1467a0d0000 pid=3450->guuid=47e76b63-1f00-0000-6338-b1460a150000 pid=5386 clone guuid=81ea8963-1f00-0000-6338-b1460c150000 pid=5388 /tmp/sample.bin guuid=657f7d22-1700-0000-6338-b1467a0d0000 pid=3450->guuid=81ea8963-1f00-0000-6338-b1460c150000 pid=5388 clone guuid=c404a563-1f00-0000-6338-b1460e150000 pid=5390 /tmp/sample.bin guuid=657f7d22-1700-0000-6338-b1467a0d0000 pid=3450->guuid=c404a563-1f00-0000-6338-b1460e150000 pid=5390 clone guuid=9ee6d890-2000-0000-6338-b14615150000 pid=5397 /tmp/sample.bin guuid=657f7d22-1700-0000-6338-b1467a0d0000 pid=3450->guuid=9ee6d890-2000-0000-6338-b14615150000 pid=5397 clone guuid=49f90291-2000-0000-6338-b14617150000 pid=5399 /tmp/sample.bin guuid=657f7d22-1700-0000-6338-b1467a0d0000 pid=3450->guuid=49f90291-2000-0000-6338-b14617150000 pid=5399 clone guuid=71803091-2000-0000-6338-b14619150000 pid=5401 /tmp/sample.bin guuid=657f7d22-1700-0000-6338-b1467a0d0000 pid=3450->guuid=71803091-2000-0000-6338-b14619150000 pid=5401 clone guuid=84135d91-2000-0000-6338-b1461b150000 pid=5403 /tmp/sample.bin guuid=657f7d22-1700-0000-6338-b1467a0d0000 pid=3450->guuid=84135d91-2000-0000-6338-b1461b150000 pid=5403 clone guuid=e6727f91-2000-0000-6338-b1461d150000 pid=5405 /tmp/sample.bin guuid=657f7d22-1700-0000-6338-b1467a0d0000 pid=3450->guuid=e6727f91-2000-0000-6338-b1461d150000 pid=5405 clone guuid=cc21d7be-2100-0000-6338-b14624150000 pid=5412 /tmp/sample.bin guuid=657f7d22-1700-0000-6338-b1467a0d0000 pid=3450->guuid=cc21d7be-2100-0000-6338-b14624150000 pid=5412 clone guuid=b68515bf-2100-0000-6338-b14626150000 pid=5414 /tmp/sample.bin guuid=657f7d22-1700-0000-6338-b1467a0d0000 pid=3450->guuid=b68515bf-2100-0000-6338-b14626150000 pid=5414 clone guuid=df7f45bf-2100-0000-6338-b14628150000 pid=5416 /tmp/sample.bin guuid=657f7d22-1700-0000-6338-b1467a0d0000 pid=3450->guuid=df7f45bf-2100-0000-6338-b14628150000 pid=5416 clone guuid=c0fb7abf-2100-0000-6338-b1462a150000 pid=5418 /tmp/sample.bin guuid=657f7d22-1700-0000-6338-b1467a0d0000 pid=3450->guuid=c0fb7abf-2100-0000-6338-b1462a150000 pid=5418 clone guuid=8939d7bf-2100-0000-6338-b1462c150000 pid=5420 /tmp/sample.bin guuid=657f7d22-1700-0000-6338-b1467a0d0000 pid=3450->guuid=8939d7bf-2100-0000-6338-b1462c150000 pid=5420 clone guuid=be5b9fec-2200-0000-6338-b14633150000 pid=5427 /tmp/sample.bin guuid=657f7d22-1700-0000-6338-b1467a0d0000 pid=3450->guuid=be5b9fec-2200-0000-6338-b14633150000 pid=5427 clone guuid=0e15e0ec-2200-0000-6338-b14635150000 pid=5429 /tmp/sample.bin guuid=657f7d22-1700-0000-6338-b1467a0d0000 pid=3450->guuid=0e15e0ec-2200-0000-6338-b14635150000 pid=5429 clone guuid=1fc714ed-2200-0000-6338-b14637150000 pid=5431 /tmp/sample.bin guuid=657f7d22-1700-0000-6338-b1467a0d0000 pid=3450->guuid=1fc714ed-2200-0000-6338-b14637150000 pid=5431 clone guuid=e22743ed-2200-0000-6338-b14639150000 pid=5433 /tmp/sample.bin guuid=657f7d22-1700-0000-6338-b1467a0d0000 pid=3450->guuid=e22743ed-2200-0000-6338-b14639150000 pid=5433 clone guuid=1b6e64ed-2200-0000-6338-b1463b150000 pid=5435 /tmp/sample.bin guuid=657f7d22-1700-0000-6338-b1467a0d0000 pid=3450->guuid=1b6e64ed-2200-0000-6338-b1463b150000 pid=5435 clone guuid=7803b11a-2400-0000-6338-b14642150000 pid=5442 /tmp/sample.bin guuid=657f7d22-1700-0000-6338-b1467a0d0000 pid=3450->guuid=7803b11a-2400-0000-6338-b14642150000 pid=5442 clone guuid=c845ee1a-2400-0000-6338-b14644150000 pid=5444 /tmp/sample.bin guuid=657f7d22-1700-0000-6338-b1467a0d0000 pid=3450->guuid=c845ee1a-2400-0000-6338-b14644150000 pid=5444 clone guuid=bb69231b-2400-0000-6338-b14646150000 pid=5446 /tmp/sample.bin guuid=657f7d22-1700-0000-6338-b1467a0d0000 pid=3450->guuid=bb69231b-2400-0000-6338-b14646150000 pid=5446 clone guuid=76294f1b-2400-0000-6338-b14648150000 pid=5448 /tmp/sample.bin guuid=657f7d22-1700-0000-6338-b1467a0d0000 pid=3450->guuid=76294f1b-2400-0000-6338-b14648150000 pid=5448 clone guuid=7dad891b-2400-0000-6338-b1464a150000 pid=5450 /tmp/sample.bin guuid=657f7d22-1700-0000-6338-b1467a0d0000 pid=3450->guuid=7dad891b-2400-0000-6338-b1464a150000 pid=5450 clone guuid=f79bc422-1700-0000-6338-b1467c0d0000 pid=3452 /tmp/sample.bin guuid=a814bd22-1700-0000-6338-b1467b0d0000 pid=3451->guuid=f79bc422-1700-0000-6338-b1467c0d0000 pid=3452 clone guuid=de0fd722-1700-0000-6338-b1467e0d0000 pid=3454 /usr/sbin/update-rc.d zombie guuid=5554cf22-1700-0000-6338-b1467d0d0000 pid=3453->guuid=de0fd722-1700-0000-6338-b1467e0d0000 pid=3454 execve guuid=e1fcc727-1700-0000-6338-b146940d0000 pid=3476 /usr/bin/systemctl guuid=de0fd722-1700-0000-6338-b1467e0d0000 pid=3454->guuid=e1fcc727-1700-0000-6338-b146940d0000 pid=3476 execve guuid=81761223-1700-0000-6338-b146800d0000 pid=3456 /usr/bin/sed guuid=9056e022-1700-0000-6338-b1467f0d0000 pid=3455->guuid=81761223-1700-0000-6338-b146800d0000 pid=3456 execve f8f8f150-6705-5c6d-b135-03a0b4165a8e 0.0.0.0:1529 guuid=657f7d22-1700-0000-6338-b1467a0d0000 pid=3458->f8f8f150-6705-5c6d-b135-03a0b4165a8e con ec143f60-91e6-5225-ae7f-e225cad41951 zz.vvbb321.com:1529 guuid=657f7d22-1700-0000-6338-b1467a0d0000 pid=3458->ec143f60-91e6-5225-ae7f-e225cad41951 con dcf3440a-494a-5141-be4a-70b3b6a714a2 zz.xxcc789.com:1529 guuid=657f7d22-1700-0000-6338-b1467a0d0000 pid=3458->dcf3440a-494a-5141-be4a-70b3b6a714a2 con 5322e86f-9911-5480-abdf-9e3dc8ed5dcb zz.aass654.com:1529 guuid=657f7d22-1700-0000-6338-b1467a0d0000 pid=3458->5322e86f-9911-5480-abdf-9e3dc8ed5dcb con 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=657f7d22-1700-0000-6338-b1467a0d0000 pid=3458->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 640B b4bf20d4-f7c8-5c24-8830-c23364537aa4 8.8.4.4:53 guuid=657f7d22-1700-0000-6338-b1467a0d0000 pid=3458->b4bf20d4-f7c8-5c24-8830-c23364537aa4 send: 256B 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=657f7d22-1700-0000-6338-b1467a0d0000 pid=3458->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 256B 87f248b3-21f7-50eb-a2c7-cb35eca5cc17 0.0.0.0:80 guuid=657f7d22-1700-0000-6338-b1467a0d0000 pid=3459->87f248b3-21f7-50eb-a2c7-cb35eca5cc17 con guuid=d360c24f-1800-0000-6338-b14669100000 pid=4201 /usr/bin/uiztnlmgdd zombie guuid=ee9cb74f-1800-0000-6338-b14668100000 pid=4200->guuid=d360c24f-1800-0000-6338-b14669100000 pid=4201 execve guuid=6bc17353-1800-0000-6338-b1467a100000 pid=4218 /usr/bin/uiztnlmgdd zombie guuid=d360c24f-1800-0000-6338-b14669100000 pid=4201->guuid=6bc17353-1800-0000-6338-b1467a100000 pid=4218 clone guuid=cb6fde4f-1800-0000-6338-b1466b100000 pid=4203 /usr/bin/uiztnlmgdd zombie guuid=f465d64f-1800-0000-6338-b1466a100000 pid=4202->guuid=cb6fde4f-1800-0000-6338-b1466b100000 pid=4203 execve guuid=037a7154-1800-0000-6338-b1467e100000 pid=4222 /usr/bin/uiztnlmgdd zombie guuid=cb6fde4f-1800-0000-6338-b1466b100000 pid=4203->guuid=037a7154-1800-0000-6338-b1467e100000 pid=4222 clone guuid=1d14fe4f-1800-0000-6338-b1466d100000 pid=4205 /usr/bin/uiztnlmgdd zombie guuid=2149ea4f-1800-0000-6338-b1466c100000 pid=4204->guuid=1d14fe4f-1800-0000-6338-b1466d100000 pid=4205 execve guuid=9791a955-1800-0000-6338-b14682100000 pid=4226 /usr/bin/uiztnlmgdd zombie guuid=1d14fe4f-1800-0000-6338-b1466d100000 pid=4205->guuid=9791a955-1800-0000-6338-b14682100000 pid=4226 clone guuid=624d7450-1800-0000-6338-b14670100000 pid=4208 /usr/bin/uiztnlmgdd zombie guuid=e0120950-1800-0000-6338-b1466e100000 pid=4206->guuid=624d7450-1800-0000-6338-b14670100000 pid=4208 execve guuid=5502cd56-1800-0000-6338-b14686100000 pid=4230 /usr/bin/uiztnlmgdd zombie guuid=624d7450-1800-0000-6338-b14670100000 pid=4208->guuid=5502cd56-1800-0000-6338-b14686100000 pid=4230 clone guuid=229bc950-1800-0000-6338-b14673100000 pid=4211 /usr/bin/uiztnlmgdd zombie guuid=5c659550-1800-0000-6338-b14671100000 pid=4209->guuid=229bc950-1800-0000-6338-b14673100000 pid=4211 execve guuid=0d9ffe55-1800-0000-6338-b14683100000 pid=4227 /usr/bin/uiztnlmgdd zombie guuid=229bc950-1800-0000-6338-b14673100000 pid=4211->guuid=0d9ffe55-1800-0000-6338-b14683100000 pid=4227 clone guuid=f254727c-1900-0000-6338-b146f4120000 pid=4852 /usr/bin/tekidssqmi zombie guuid=830f697c-1900-0000-6338-b146f3120000 pid=4851->guuid=f254727c-1900-0000-6338-b146f4120000 pid=4852 execve guuid=bb7c9a81-1900-0000-6338-b14610130000 pid=4880 /usr/bin/tekidssqmi zombie guuid=f254727c-1900-0000-6338-b146f4120000 pid=4852->guuid=bb7c9a81-1900-0000-6338-b14610130000 pid=4880 clone guuid=9287897c-1900-0000-6338-b146f6120000 pid=4854 /usr/bin/tekidssqmi zombie guuid=c535817c-1900-0000-6338-b146f5120000 pid=4853->guuid=9287897c-1900-0000-6338-b146f6120000 pid=4854 execve guuid=353c9180-1900-0000-6338-b1460a130000 pid=4874 /usr/bin/tekidssqmi zombie guuid=9287897c-1900-0000-6338-b146f6120000 pid=4854->guuid=353c9180-1900-0000-6338-b1460a130000 pid=4874 clone guuid=db9b0e7d-1900-0000-6338-b146fa120000 pid=4858 /usr/bin/tekidssqmi zombie guuid=d19e017d-1900-0000-6338-b146f9120000 pid=4857->guuid=db9b0e7d-1900-0000-6338-b146fa120000 pid=4858 execve guuid=fb432683-1900-0000-6338-b14618130000 pid=4888 /usr/bin/tekidssqmi zombie guuid=db9b0e7d-1900-0000-6338-b146fa120000 pid=4858->guuid=fb432683-1900-0000-6338-b14618130000 pid=4888 clone guuid=4b25a87d-1900-0000-6338-b146fd120000 pid=4861 /usr/bin/tekidssqmi zombie guuid=db2e1e7d-1900-0000-6338-b146fb120000 pid=4859->guuid=4b25a87d-1900-0000-6338-b146fd120000 pid=4861 execve guuid=a60cd684-1900-0000-6338-b1461e130000 pid=4894 /usr/bin/tekidssqmi zombie guuid=4b25a87d-1900-0000-6338-b146fd120000 pid=4861->guuid=a60cd684-1900-0000-6338-b1461e130000 pid=4894 clone guuid=71c87f7e-1900-0000-6338-b14602130000 pid=4866 /usr/bin/tekidssqmi zombie guuid=f4c1be7d-1900-0000-6338-b146ff120000 pid=4863->guuid=71c87f7e-1900-0000-6338-b14602130000 pid=4866 execve guuid=c9054183-1900-0000-6338-b14619130000 pid=4889 /usr/bin/tekidssqmi zombie guuid=71c87f7e-1900-0000-6338-b14602130000 pid=4866->guuid=c9054183-1900-0000-6338-b14619130000 pid=4889 clone guuid=36fb26aa-1a00-0000-6338-b146a4140000 pid=5284 /usr/bin/zqcpybgxln zombie guuid=7b191baa-1a00-0000-6338-b146a3140000 pid=5283->guuid=36fb26aa-1a00-0000-6338-b146a4140000 pid=5284 execve guuid=d63b12ae-1a00-0000-6338-b146ae140000 pid=5294 /usr/bin/zqcpybgxln zombie guuid=36fb26aa-1a00-0000-6338-b146a4140000 pid=5284->guuid=d63b12ae-1a00-0000-6338-b146ae140000 pid=5294 clone guuid=bc7443aa-1a00-0000-6338-b146a6140000 pid=5286 /usr/bin/zqcpybgxln zombie guuid=47cd3aaa-1a00-0000-6338-b146a5140000 pid=5285->guuid=bc7443aa-1a00-0000-6338-b146a6140000 pid=5286 execve guuid=dbfa11ae-1a00-0000-6338-b146ad140000 pid=5293 /usr/bin/zqcpybgxln zombie guuid=bc7443aa-1a00-0000-6338-b146a6140000 pid=5286->guuid=dbfa11ae-1a00-0000-6338-b146ad140000 pid=5293 clone guuid=ebc577aa-1a00-0000-6338-b146a8140000 pid=5288 /usr/bin/zqcpybgxln zombie guuid=443762aa-1a00-0000-6338-b146a7140000 pid=5287->guuid=ebc577aa-1a00-0000-6338-b146a8140000 pid=5288 execve guuid=e2e8c2b0-1a00-0000-6338-b146b0140000 pid=5296 /usr/bin/zqcpybgxln zombie guuid=ebc577aa-1a00-0000-6338-b146a8140000 pid=5288->guuid=e2e8c2b0-1a00-0000-6338-b146b0140000 pid=5296 clone guuid=7ae769ab-1a00-0000-6338-b146aa140000 pid=5290 /usr/bin/zqcpybgxln zombie guuid=ee1397aa-1a00-0000-6338-b146a9140000 pid=5289->guuid=7ae769ab-1a00-0000-6338-b146aa140000 pid=5290 execve guuid=9c4fa2af-1a00-0000-6338-b146af140000 pid=5295 /usr/bin/zqcpybgxln zombie guuid=7ae769ab-1a00-0000-6338-b146aa140000 pid=5290->guuid=9c4fa2af-1a00-0000-6338-b146af140000 pid=5295 clone guuid=fe2375ac-1a00-0000-6338-b146ac140000 pid=5292 /usr/bin/zqcpybgxln zombie guuid=f318a9ab-1a00-0000-6338-b146ab140000 pid=5291->guuid=fe2375ac-1a00-0000-6338-b146ac140000 pid=5292 execve guuid=0301feb1-1a00-0000-6338-b146b1140000 pid=5297 /usr/bin/zqcpybgxln zombie guuid=fe2375ac-1a00-0000-6338-b146ac140000 pid=5292->guuid=0301feb1-1a00-0000-6338-b146b1140000 pid=5297 clone guuid=85012fd9-1b00-0000-6338-b146bb140000 pid=5307 /usr/bin/bmnjgshdll zombie guuid=888b1ed9-1b00-0000-6338-b146ba140000 pid=5306->guuid=85012fd9-1b00-0000-6338-b146bb140000 pid=5307 execve guuid=d9f722de-1b00-0000-6338-b146c5140000 pid=5317 /usr/bin/bmnjgshdll zombie guuid=85012fd9-1b00-0000-6338-b146bb140000 pid=5307->guuid=d9f722de-1b00-0000-6338-b146c5140000 pid=5317 clone guuid=315d59d9-1b00-0000-6338-b146bd140000 pid=5309 /usr/bin/bmnjgshdll zombie guuid=978f4dd9-1b00-0000-6338-b146bc140000 pid=5308->guuid=315d59d9-1b00-0000-6338-b146bd140000 pid=5309 execve guuid=8aae7fdf-1b00-0000-6338-b146c7140000 pid=5319 /usr/bin/bmnjgshdll zombie guuid=315d59d9-1b00-0000-6338-b146bd140000 pid=5309->guuid=8aae7fdf-1b00-0000-6338-b146c7140000 pid=5319 clone guuid=327f87d9-1b00-0000-6338-b146bf140000 pid=5311 /usr/bin/bmnjgshdll zombie guuid=dbbd7ad9-1b00-0000-6338-b146be140000 pid=5310->guuid=327f87d9-1b00-0000-6338-b146bf140000 pid=5311 execve guuid=d472fede-1b00-0000-6338-b146c6140000 pid=5318 /usr/bin/bmnjgshdll zombie guuid=327f87d9-1b00-0000-6338-b146bf140000 pid=5311->guuid=d472fede-1b00-0000-6338-b146c6140000 pid=5318 clone guuid=3364a7d9-1b00-0000-6338-b146c1140000 pid=5313 /usr/bin/bmnjgshdll zombie guuid=4a6b9cd9-1b00-0000-6338-b146c0140000 pid=5312->guuid=3364a7d9-1b00-0000-6338-b146c1140000 pid=5313 execve guuid=815de1dc-1b00-0000-6338-b146c4140000 pid=5316 /usr/bin/bmnjgshdll zombie guuid=3364a7d9-1b00-0000-6338-b146c1140000 pid=5313->guuid=815de1dc-1b00-0000-6338-b146c4140000 pid=5316 clone guuid=285621db-1b00-0000-6338-b146c3140000 pid=5315 /usr/bin/bmnjgshdll zombie guuid=9feac0d9-1b00-0000-6338-b146c2140000 pid=5314->guuid=285621db-1b00-0000-6338-b146c3140000 pid=5315 execve guuid=7db08ee1-1b00-0000-6338-b146ca140000 pid=5322 /usr/bin/bmnjgshdll zombie guuid=285621db-1b00-0000-6338-b146c3140000 pid=5315->guuid=7db08ee1-1b00-0000-6338-b146ca140000 pid=5322 clone guuid=5198a507-1d00-0000-6338-b146e9140000 pid=5353 /usr/bin/ctbippdchx zombie guuid=06fc8b07-1d00-0000-6338-b146e8140000 pid=5352->guuid=5198a507-1d00-0000-6338-b146e9140000 pid=5353 execve guuid=4607b80b-1d00-0000-6338-b146f2140000 pid=5362 /usr/bin/ctbippdchx zombie guuid=5198a507-1d00-0000-6338-b146e9140000 pid=5353->guuid=4607b80b-1d00-0000-6338-b146f2140000 pid=5362 clone guuid=2f63d907-1d00-0000-6338-b146eb140000 pid=5355 /usr/bin/ctbippdchx zombie guuid=bbf6c907-1d00-0000-6338-b146ea140000 pid=5354->guuid=2f63d907-1d00-0000-6338-b146eb140000 pid=5355 execve guuid=ca81fb0b-1d00-0000-6338-b146f3140000 pid=5363 /usr/bin/ctbippdchx zombie guuid=2f63d907-1d00-0000-6338-b146eb140000 pid=5355->guuid=ca81fb0b-1d00-0000-6338-b146f3140000 pid=5363 clone guuid=eae50e08-1d00-0000-6338-b146ed140000 pid=5357 /usr/bin/ctbippdchx zombie guuid=ff470108-1d00-0000-6338-b146ec140000 pid=5356->guuid=eae50e08-1d00-0000-6338-b146ed140000 pid=5357 execve guuid=63d2ec0c-1d00-0000-6338-b146f4140000 pid=5364 /usr/bin/ctbippdchx zombie guuid=eae50e08-1d00-0000-6338-b146ed140000 pid=5357->guuid=63d2ec0c-1d00-0000-6338-b146f4140000 pid=5364 clone guuid=d20c3e08-1d00-0000-6338-b146ef140000 pid=5359 /usr/bin/ctbippdchx zombie guuid=168b2c08-1d00-0000-6338-b146ee140000 pid=5358->guuid=d20c3e08-1d00-0000-6338-b146ef140000 pid=5359 execve guuid=b307870d-1d00-0000-6338-b146f5140000 pid=5365 /usr/bin/ctbippdchx zombie guuid=d20c3e08-1d00-0000-6338-b146ef140000 pid=5359->guuid=b307870d-1d00-0000-6338-b146f5140000 pid=5365 clone guuid=f0acff08-1d00-0000-6338-b146f1140000 pid=5361 /usr/bin/ctbippdchx zombie guuid=71045608-1d00-0000-6338-b146f0140000 pid=5360->guuid=f0acff08-1d00-0000-6338-b146f1140000 pid=5361 execve guuid=c2e1e90d-1d00-0000-6338-b146f6140000 pid=5366 /usr/bin/ctbippdchx zombie guuid=f0acff08-1d00-0000-6338-b146f1140000 pid=5361->guuid=c2e1e90d-1d00-0000-6338-b146f6140000 pid=5366 clone guuid=b82db835-1e00-0000-6338-b146f8140000 pid=5368 /usr/bin/ircuelzhcj zombie guuid=d511a335-1e00-0000-6338-b146f7140000 pid=5367->guuid=b82db835-1e00-0000-6338-b146f8140000 pid=5368 execve guuid=f596fa39-1e00-0000-6338-b14601150000 pid=5377 /usr/bin/ircuelzhcj zombie guuid=b82db835-1e00-0000-6338-b146f8140000 pid=5368->guuid=f596fa39-1e00-0000-6338-b14601150000 pid=5377 clone guuid=8e5bf035-1e00-0000-6338-b146fa140000 pid=5370 /usr/bin/ircuelzhcj zombie guuid=b07ae035-1e00-0000-6338-b146f9140000 pid=5369->guuid=8e5bf035-1e00-0000-6338-b146fa140000 pid=5370 execve guuid=4397633b-1e00-0000-6338-b14604150000 pid=5380 /usr/bin/ircuelzhcj zombie guuid=8e5bf035-1e00-0000-6338-b146fa140000 pid=5370->guuid=4397633b-1e00-0000-6338-b14604150000 pid=5380 clone guuid=fb012136-1e00-0000-6338-b146fc140000 pid=5372 /usr/bin/ircuelzhcj zombie guuid=270c0f36-1e00-0000-6338-b146fb140000 pid=5371->guuid=fb012136-1e00-0000-6338-b146fc140000 pid=5372 execve guuid=9c335e3a-1e00-0000-6338-b14603150000 pid=5379 /usr/bin/ircuelzhcj zombie guuid=fb012136-1e00-0000-6338-b146fc140000 pid=5372->guuid=9c335e3a-1e00-0000-6338-b14603150000 pid=5379 clone guuid=8f415936-1e00-0000-6338-b146fe140000 pid=5374 /usr/bin/ircuelzhcj zombie guuid=edb03b36-1e00-0000-6338-b146fd140000 pid=5373->guuid=8f415936-1e00-0000-6338-b146fe140000 pid=5374 execve guuid=5271d93b-1e00-0000-6338-b14605150000 pid=5381 /usr/bin/ircuelzhcj zombie guuid=8f415936-1e00-0000-6338-b146fe140000 pid=5374->guuid=5271d93b-1e00-0000-6338-b14605150000 pid=5381 clone guuid=72787e36-1e00-0000-6338-b14600150000 pid=5376 /usr/bin/ircuelzhcj zombie guuid=e5c17036-1e00-0000-6338-b146ff140000 pid=5375->guuid=72787e36-1e00-0000-6338-b14600150000 pid=5376 execve guuid=508e393a-1e00-0000-6338-b14602150000 pid=5378 /usr/bin/ircuelzhcj zombie guuid=72787e36-1e00-0000-6338-b14600150000 pid=5376->guuid=508e393a-1e00-0000-6338-b14602150000 pid=5378 clone guuid=57291a63-1f00-0000-6338-b14607150000 pid=5383 /usr/bin/pujbtybnod zombie guuid=6aa80263-1f00-0000-6338-b14606150000 pid=5382->guuid=57291a63-1f00-0000-6338-b14607150000 pid=5383 execve guuid=2396b166-1f00-0000-6338-b14612150000 pid=5394 /usr/bin/pujbtybnod zombie guuid=57291a63-1f00-0000-6338-b14607150000 pid=5383->guuid=2396b166-1f00-0000-6338-b14612150000 pid=5394 clone guuid=e6434e63-1f00-0000-6338-b14609150000 pid=5385 /usr/bin/pujbtybnod zombie guuid=efc23963-1f00-0000-6338-b14608150000 pid=5384->guuid=e6434e63-1f00-0000-6338-b14609150000 pid=5385 execve guuid=5f545766-1f00-0000-6338-b14610150000 pid=5392 /usr/bin/pujbtybnod zombie guuid=e6434e63-1f00-0000-6338-b14609150000 pid=5385->guuid=5f545766-1f00-0000-6338-b14610150000 pid=5392 clone guuid=443d7863-1f00-0000-6338-b1460b150000 pid=5387 /usr/bin/pujbtybnod zombie guuid=47e76b63-1f00-0000-6338-b1460a150000 pid=5386->guuid=443d7863-1f00-0000-6338-b1460b150000 pid=5387 execve guuid=f5e84f68-1f00-0000-6338-b14613150000 pid=5395 /usr/bin/pujbtybnod zombie guuid=443d7863-1f00-0000-6338-b1460b150000 pid=5387->guuid=f5e84f68-1f00-0000-6338-b14613150000 pid=5395 clone guuid=887c9463-1f00-0000-6338-b1460d150000 pid=5389 /usr/bin/pujbtybnod zombie guuid=81ea8963-1f00-0000-6338-b1460c150000 pid=5388->guuid=887c9463-1f00-0000-6338-b1460d150000 pid=5389 execve guuid=7fb09c66-1f00-0000-6338-b14611150000 pid=5393 /usr/bin/pujbtybnod zombie guuid=887c9463-1f00-0000-6338-b1460d150000 pid=5389->guuid=7fb09c66-1f00-0000-6338-b14611150000 pid=5393 clone guuid=afc76c64-1f00-0000-6338-b1460f150000 pid=5391 /usr/bin/pujbtybnod zombie guuid=c404a563-1f00-0000-6338-b1460e150000 pid=5390->guuid=afc76c64-1f00-0000-6338-b1460f150000 pid=5391 execve guuid=3334bb68-1f00-0000-6338-b14614150000 pid=5396 /usr/bin/pujbtybnod zombie guuid=afc76c64-1f00-0000-6338-b1460f150000 pid=5391->guuid=3334bb68-1f00-0000-6338-b14614150000 pid=5396 clone guuid=5a23e790-2000-0000-6338-b14616150000 pid=5398 /usr/bin/gvvhdlkyog zombie guuid=9ee6d890-2000-0000-6338-b14615150000 pid=5397->guuid=5a23e790-2000-0000-6338-b14616150000 pid=5398 execve guuid=359e0c94-2000-0000-6338-b1461f150000 pid=5407 /usr/bin/gvvhdlkyog zombie guuid=5a23e790-2000-0000-6338-b14616150000 pid=5398->guuid=359e0c94-2000-0000-6338-b1461f150000 pid=5407 clone guuid=9d6a1191-2000-0000-6338-b14618150000 pid=5400 /usr/bin/gvvhdlkyog zombie guuid=49f90291-2000-0000-6338-b14617150000 pid=5399->guuid=9d6a1191-2000-0000-6338-b14618150000 pid=5400 execve guuid=b142d894-2000-0000-6338-b14620150000 pid=5408 /usr/bin/gvvhdlkyog zombie guuid=9d6a1191-2000-0000-6338-b14618150000 pid=5400->guuid=b142d894-2000-0000-6338-b14620150000 pid=5408 clone guuid=68153e91-2000-0000-6338-b1461a150000 pid=5402 /usr/bin/gvvhdlkyog zombie guuid=71803091-2000-0000-6338-b14619150000 pid=5401->guuid=68153e91-2000-0000-6338-b1461a150000 pid=5402 execve guuid=baea3795-2000-0000-6338-b14622150000 pid=5410 /usr/bin/gvvhdlkyog zombie guuid=68153e91-2000-0000-6338-b1461a150000 pid=5402->guuid=baea3795-2000-0000-6338-b14622150000 pid=5410 clone guuid=30fe6991-2000-0000-6338-b1461c150000 pid=5404 /usr/bin/gvvhdlkyog zombie guuid=84135d91-2000-0000-6338-b1461b150000 pid=5403->guuid=30fe6991-2000-0000-6338-b1461c150000 pid=5404 execve guuid=e8dc2695-2000-0000-6338-b14621150000 pid=5409 /usr/bin/gvvhdlkyog zombie guuid=30fe6991-2000-0000-6338-b1461c150000 pid=5404->guuid=e8dc2695-2000-0000-6338-b14621150000 pid=5409 clone guuid=d7514492-2000-0000-6338-b1461e150000 pid=5406 /usr/bin/gvvhdlkyog zombie guuid=e6727f91-2000-0000-6338-b1461d150000 pid=5405->guuid=d7514492-2000-0000-6338-b1461e150000 pid=5406 execve guuid=d9d36f96-2000-0000-6338-b14623150000 pid=5411 /usr/bin/gvvhdlkyog zombie guuid=d7514492-2000-0000-6338-b1461e150000 pid=5406->guuid=d9d36f96-2000-0000-6338-b14623150000 pid=5411 clone guuid=b5d5e8be-2100-0000-6338-b14625150000 pid=5413 /usr/bin/ilcjjigxwz zombie guuid=cc21d7be-2100-0000-6338-b14624150000 pid=5412->guuid=b5d5e8be-2100-0000-6338-b14625150000 pid=5413 execve guuid=1ede72c3-2100-0000-6338-b1462e150000 pid=5422 /usr/bin/ilcjjigxwz zombie guuid=b5d5e8be-2100-0000-6338-b14625150000 pid=5413->guuid=1ede72c3-2100-0000-6338-b1462e150000 pid=5422 clone guuid=94982dbf-2100-0000-6338-b14627150000 pid=5415 /usr/bin/ilcjjigxwz zombie guuid=b68515bf-2100-0000-6338-b14626150000 pid=5414->guuid=94982dbf-2100-0000-6338-b14627150000 pid=5415 execve guuid=2b2eb4c4-2100-0000-6338-b14631150000 pid=5425 /usr/bin/ilcjjigxwz zombie guuid=94982dbf-2100-0000-6338-b14627150000 pid=5415->guuid=2b2eb4c4-2100-0000-6338-b14631150000 pid=5425 clone guuid=e58d5dbf-2100-0000-6338-b14629150000 pid=5417 /usr/bin/ilcjjigxwz zombie guuid=df7f45bf-2100-0000-6338-b14628150000 pid=5416->guuid=e58d5dbf-2100-0000-6338-b14629150000 pid=5417 execve guuid=72e1bac3-2100-0000-6338-b1462f150000 pid=5423 /usr/bin/ilcjjigxwz zombie guuid=e58d5dbf-2100-0000-6338-b14629150000 pid=5417->guuid=72e1bac3-2100-0000-6338-b1462f150000 pid=5423 clone guuid=1e1390bf-2100-0000-6338-b1462b150000 pid=5419 /usr/bin/ilcjjigxwz zombie guuid=c0fb7abf-2100-0000-6338-b1462a150000 pid=5418->guuid=1e1390bf-2100-0000-6338-b1462b150000 pid=5419 execve guuid=f50adfc4-2100-0000-6338-b14632150000 pid=5426 /usr/bin/ilcjjigxwz zombie guuid=1e1390bf-2100-0000-6338-b1462b150000 pid=5419->guuid=f50adfc4-2100-0000-6338-b14632150000 pid=5426 clone guuid=bbadefbf-2100-0000-6338-b1462d150000 pid=5421 /usr/bin/ilcjjigxwz zombie guuid=8939d7bf-2100-0000-6338-b1462c150000 pid=5420->guuid=bbadefbf-2100-0000-6338-b1462d150000 pid=5421 execve guuid=b71ffac3-2100-0000-6338-b14630150000 pid=5424 /usr/bin/ilcjjigxwz zombie guuid=bbadefbf-2100-0000-6338-b1462d150000 pid=5421->guuid=b71ffac3-2100-0000-6338-b14630150000 pid=5424 clone guuid=01ddbaec-2200-0000-6338-b14634150000 pid=5428 /usr/bin/iexekrzhqv zombie guuid=be5b9fec-2200-0000-6338-b14633150000 pid=5427->guuid=01ddbaec-2200-0000-6338-b14634150000 pid=5428 execve guuid=d16336f1-2200-0000-6338-b1463e150000 pid=5438 /usr/bin/iexekrzhqv zombie guuid=01ddbaec-2200-0000-6338-b14634150000 pid=5428->guuid=d16336f1-2200-0000-6338-b1463e150000 pid=5438 clone guuid=c95befec-2200-0000-6338-b14636150000 pid=5430 /usr/bin/iexekrzhqv zombie guuid=0e15e0ec-2200-0000-6338-b14635150000 pid=5429->guuid=c95befec-2200-0000-6338-b14636150000 pid=5430 execve guuid=dcb12af0-2200-0000-6338-b1463d150000 pid=5437 /usr/bin/iexekrzhqv zombie guuid=c95befec-2200-0000-6338-b14636150000 pid=5430->guuid=dcb12af0-2200-0000-6338-b1463d150000 pid=5437 clone guuid=d64f24ed-2200-0000-6338-b14638150000 pid=5432 /usr/bin/iexekrzhqv zombie guuid=1fc714ed-2200-0000-6338-b14637150000 pid=5431->guuid=d64f24ed-2200-0000-6338-b14638150000 pid=5432 execve guuid=3dcd55f2-2200-0000-6338-b1463f150000 pid=5439 /usr/bin/iexekrzhqv zombie guuid=d64f24ed-2200-0000-6338-b14638150000 pid=5432->guuid=3dcd55f2-2200-0000-6338-b1463f150000 pid=5439 clone guuid=477b4eed-2200-0000-6338-b1463a150000 pid=5434 /usr/bin/iexekrzhqv zombie guuid=e22743ed-2200-0000-6338-b14639150000 pid=5433->guuid=477b4eed-2200-0000-6338-b1463a150000 pid=5434 execve guuid=de0dfdf2-2200-0000-6338-b14641150000 pid=5441 /usr/bin/iexekrzhqv zombie guuid=477b4eed-2200-0000-6338-b1463a150000 pid=5434->guuid=de0dfdf2-2200-0000-6338-b14641150000 pid=5441 clone guuid=cc5d28ee-2200-0000-6338-b1463c150000 pid=5436 /usr/bin/iexekrzhqv zombie guuid=1b6e64ed-2200-0000-6338-b1463b150000 pid=5435->guuid=cc5d28ee-2200-0000-6338-b1463c150000 pid=5436 execve guuid=610caef2-2200-0000-6338-b14640150000 pid=5440 /usr/bin/iexekrzhqv zombie guuid=cc5d28ee-2200-0000-6338-b1463c150000 pid=5436->guuid=610caef2-2200-0000-6338-b14640150000 pid=5440 clone guuid=a1a0cf1a-2400-0000-6338-b14643150000 pid=5443 /usr/bin/wxgtvvdgfj zombie guuid=7803b11a-2400-0000-6338-b14642150000 pid=5442->guuid=a1a0cf1a-2400-0000-6338-b14643150000 pid=5443 execve guuid=aeda741f-2400-0000-6338-b1464e150000 pid=5454 /usr/bin/wxgtvvdgfj zombie guuid=a1a0cf1a-2400-0000-6338-b14643150000 pid=5443->guuid=aeda741f-2400-0000-6338-b1464e150000 pid=5454 clone guuid=b583fe1a-2400-0000-6338-b14645150000 pid=5445 /usr/bin/wxgtvvdgfj zombie guuid=c845ee1a-2400-0000-6338-b14644150000 pid=5444->guuid=b583fe1a-2400-0000-6338-b14645150000 pid=5445 execve guuid=8b15fc1e-2400-0000-6338-b1464c150000 pid=5452 /usr/bin/wxgtvvdgfj zombie guuid=b583fe1a-2400-0000-6338-b14645150000 pid=5445->guuid=8b15fc1e-2400-0000-6338-b1464c150000 pid=5452 clone guuid=f41a331b-2400-0000-6338-b14647150000 pid=5447 /usr/bin/wxgtvvdgfj zombie guuid=bb69231b-2400-0000-6338-b14646150000 pid=5446->guuid=f41a331b-2400-0000-6338-b14647150000 pid=5447 execve guuid=ccb68220-2400-0000-6338-b1464f150000 pid=5455 /usr/bin/wxgtvvdgfj zombie guuid=f41a331b-2400-0000-6338-b14647150000 pid=5447->guuid=ccb68220-2400-0000-6338-b1464f150000 pid=5455 clone guuid=7318681b-2400-0000-6338-b14649150000 pid=5449 /usr/bin/wxgtvvdgfj zombie guuid=76294f1b-2400-0000-6338-b14648150000 pid=5448->guuid=7318681b-2400-0000-6338-b14649150000 pid=5449 execve guuid=b1a2511f-2400-0000-6338-b1464d150000 pid=5453 /usr/bin/wxgtvvdgfj zombie guuid=7318681b-2400-0000-6338-b14649150000 pid=5449->guuid=b1a2511f-2400-0000-6338-b1464d150000 pid=5453 clone guuid=6ca0441c-2400-0000-6338-b1464b150000 pid=5451 /usr/bin/wxgtvvdgfj zombie guuid=7dad891b-2400-0000-6338-b1464a150000 pid=5450->guuid=6ca0441c-2400-0000-6338-b1464b150000 pid=5451 execve guuid=bb32f620-2400-0000-6338-b14650150000 pid=5456 /usr/bin/wxgtvvdgfj zombie guuid=6ca0441c-2400-0000-6338-b1464b150000 pid=5451->guuid=bb32f620-2400-0000-6338-b14650150000 pid=5456 clone
Result
Threat name:
XorDDoS
Detection:
malicious
Classification:
troj.evad
Score:
100 / 100
Signature
Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Drops files in suspicious directories
Found malware configuration
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Sample deletes itself
Sample tries to persist itself using cron
Sample tries to persist itself using System V runlevels
Yara detected XorDDoS Bot
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1765813 Sample: p.txt.elf Startdate: 26/08/2025 Architecture: LINUX Score: 100 76 zz.nnmm234.com 2->76 78 zz.jjkk567.com 2->78 80 8 other IPs or domains 2->80 84 Found malware configuration 2->84 86 Malicious sample detected (through community Yara rule) 2->86 88 Antivirus detection for dropped file 2->88 90 3 other signatures 2->90 10 dash rm p.txt.elf 2->10         started        12 dash rm 2->12         started        14 dash head 2->14         started        16 8 other processes 2->16 signatures3 process4 process5 18 p.txt.elf 10->18         started        file6 66 /usr/lib/libudev.so, ELF 18->66 dropped 68 /usr/bin/zgxvevgthn, ELF 18->68 dropped 70 /usr/bin/ytelouhbow, ELF 18->70 dropped 72 16 other malicious files 18->72 dropped 92 Drops files in suspicious directories 18->92 94 Sample deletes itself 18->94 96 Sample tries to persist itself using cron 18->96 98 Sample tries to persist itself using System V runlevels 18->98 22 p.txt.elf sh 18->22         started        26 p.txt.elf 18->26         started        28 p.txt.elf 18->28         started        30 120 other processes 18->30 signatures7 process8 file9 74 /etc/crontab, ASCII 22->74 dropped 100 Sample tries to persist itself using cron 22->100 32 sh sed 22->32         started        35 p.txt.elf ezuavkhojx 26->35         started        37 p.txt.elf ezuavkhojx 28->37         started        39 p.txt.elf ezuavkhojx 30->39         started        41 p.txt.elf ezuavkhojx 30->41         started        43 p.txt.elf ezuavkhojx 30->43         started        45 117 other processes 30->45 signatures10 process11 signatures12 82 Sample tries to persist itself using cron 32->82 47 ezuavkhojx 35->47         started        50 ezuavkhojx 37->50         started        52 ezuavkhojx 39->52         started        54 ezuavkhojx 41->54         started        56 ezuavkhojx 43->56         started        58 gutusfwbwv 45->58         started        60 gutusfwbwv 45->60         started        62 gutusfwbwv 45->62         started        64 108 other processes 45->64 process13 signatures14 102 Sample deletes itself 47->102
Threat name:
Linux.Network.Xor
Status:
Malicious
First seen:
2025-08-26 20:51:44 UTC
File Type:
ELF32 Little (Exe)
AV detection:
24 of 36 (66.67%)
Threat level:
  3/5
Result
Malware family:
xorddos
Score:
  10/10
Tags:
family:xorddos botnet discovery downloader execution linux persistence privilege_escalation
Behaviour
Reads runtime system information
System Network Configuration Discovery
Creates/modifies Cron job
Modifies init.d
Write file to user bin folder
Executes dropped EXE
Xorddos family
XorDDoS
XorDDoS payload
Malware Config
C2 Extraction:
https://ww.aass654.com/config.rar
zz.aass654.com:1529
zz.xxcc789.com:1529
zz.vvbb321.com:1529
zz.jjkk567.com:1529
zz.nnmm234.com:1529
Verdict:
Malicious
Tags:
backdoor trojan xor_ddos Unix.Malware.Xorddos-9856891-0
YARA:
libgcc_backdoor Linux_Trojan_Xorddos_2aef46a6 Linux_Trojan_Xorddos_884cab60 MALWARE_Linux_XORDDoS
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:CP_AllMal_Detector
Author:DiegoAnalytics
Description:CrossPlatform All Malwares Detector: Detect PE, ELF, Mach-O, scripts, archives; overlay, obfuscation, encryption, spoofing, hiding, high entropy, network communication
Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:enterpriseapps2
Author:Tim Brown @timb_machine
Description:Enterprise apps
Rule name:F01_s1ckrule
Author:s1ckb017
Rule name:linux_generic_ipv6_catcher
Author:@_lubiedo
Description:ELF samples using IPv6 addresses
Rule name:Linux_Trojan_Xorddos_2aef46a6
Author:Elastic Security
Rule name:MALWARE_Linux_XORDDoS
Author:ditekSHen
Description:Detects XORDDoS
Rule name:NET
Author:malware-lu
Rule name:unixredflags3
Author:Tim Brown @timb_machine
Description:Hunts for UNIX red flags

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

XorDDoS

elf c3714fc0446a1adaedbc86e3dd0b2121e65b34cc3d40494f709c6873fa0d56bc

(this sample)

  
Delivery method
Distributed via web download

Comments