MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 eae72481b82348783a682cf62b64d242c1e3b1756ccbff5bf030c5a0ba0b152d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



XorDDoS


Vendor detections: 8


Intelligence 8 IOCs YARA 11 File information Comments

SHA256 hash: eae72481b82348783a682cf62b64d242c1e3b1756ccbff5bf030c5a0ba0b152d
SHA3-384 hash: 5d64ec685105d9280f9a20d1808cf5c52016dc4093669fe6e1f711cee817468bec3538ea00811e8d0121667f1126a800
SHA1 hash: 91526fe606edcee0cb4e16e67d64020c44e479d9
MD5 hash: e19c17973b107cd9439fb5c6807a5ee2
humanhash: alaska-grey-uncle-connecticut
File name:p.txt
Download: download sample
Signature XorDDoS
File size:555'272 bytes
First seen:2026-02-23 02:37:56 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 12288:VBPbw1CH/FwznbIU9sE8c8lqd49N94wT4JohLLp6yWrk3:VBPWCH/eMU9Uc8gd49N94BJohLL4ru
TLSH T16FC45C06E283A2F7D42705B0124BF7BF8620F63594129D9BB7D89D5AB9338F12A4D353
telfhash t129c16ab23eb059d9b3f0880282667220ce19e42765d4397a1df3b194fbf2d522b35d79
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter abuse_ch
Tags:elf XorDDoS

Intelligence


File Origin
# of uploads :
1
# of downloads :
36
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Unknown
Threat level:
  0/10
Confidence:
100%
Tags:
gcc masquerade
Result
Gathering data
Status:
terminated
Behavior Graph:
%3 guuid=9daaddc2-1800-0000-fe98-20e1010a0000 pid=2561 /usr/bin/sudo guuid=da889dc5-1800-0000-fe98-20e10a0a0000 pid=2570 /tmp/sample.bin guuid=9daaddc2-1800-0000-fe98-20e1010a0000 pid=2561->guuid=da889dc5-1800-0000-fe98-20e10a0a0000 pid=2570 execve guuid=8be2d6c5-1800-0000-fe98-20e10c0a0000 pid=2572 /tmp/sample.bin delete-file write-config write-file zombie guuid=da889dc5-1800-0000-fe98-20e10a0a0000 pid=2570->guuid=8be2d6c5-1800-0000-fe98-20e10c0a0000 pid=2572 clone guuid=08341ac6-1800-0000-fe98-20e10d0a0000 pid=2573 /tmp/sample.bin guuid=8be2d6c5-1800-0000-fe98-20e10c0a0000 pid=2572->guuid=08341ac6-1800-0000-fe98-20e10d0a0000 pid=2573 clone guuid=848129c6-1800-0000-fe98-20e10f0a0000 pid=2575 /tmp/sample.bin guuid=8be2d6c5-1800-0000-fe98-20e10c0a0000 pid=2572->guuid=848129c6-1800-0000-fe98-20e10f0a0000 pid=2575 clone guuid=11e6c4c6-1800-0000-fe98-20e1130a0000 pid=2579 /usr/bin/dash guuid=8be2d6c5-1800-0000-fe98-20e10c0a0000 pid=2572->guuid=11e6c4c6-1800-0000-fe98-20e1130a0000 pid=2579 execve guuid=8be2d6c5-1800-0000-fe98-20e10c0a0000 pid=2583 /tmp/sample.bin write-file zombie guuid=8be2d6c5-1800-0000-fe98-20e10c0a0000 pid=2572->guuid=8be2d6c5-1800-0000-fe98-20e10c0a0000 pid=2583 clone guuid=8be2d6c5-1800-0000-fe98-20e10c0a0000 pid=2584 /tmp/sample.bin dns net send-data write-file zombie guuid=8be2d6c5-1800-0000-fe98-20e10c0a0000 pid=2572->guuid=8be2d6c5-1800-0000-fe98-20e10c0a0000 pid=2584 clone guuid=8be2d6c5-1800-0000-fe98-20e10c0a0000 pid=2585 /tmp/sample.bin net zombie guuid=8be2d6c5-1800-0000-fe98-20e10c0a0000 pid=2572->guuid=8be2d6c5-1800-0000-fe98-20e10c0a0000 pid=2585 clone guuid=fc009cf4-1900-0000-fe98-20e1a00c0000 pid=3232 /tmp/sample.bin guuid=8be2d6c5-1800-0000-fe98-20e10c0a0000 pid=2572->guuid=fc009cf4-1900-0000-fe98-20e1a00c0000 pid=3232 clone guuid=c30decf4-1900-0000-fe98-20e1a20c0000 pid=3234 /tmp/sample.bin guuid=8be2d6c5-1800-0000-fe98-20e10c0a0000 pid=2572->guuid=c30decf4-1900-0000-fe98-20e1a20c0000 pid=3234 clone guuid=fd3c23f5-1900-0000-fe98-20e1a40c0000 pid=3236 /tmp/sample.bin guuid=8be2d6c5-1800-0000-fe98-20e10c0a0000 pid=2572->guuid=fd3c23f5-1900-0000-fe98-20e1a40c0000 pid=3236 clone guuid=f1db62f5-1900-0000-fe98-20e1a60c0000 pid=3238 /tmp/sample.bin guuid=8be2d6c5-1800-0000-fe98-20e10c0a0000 pid=2572->guuid=f1db62f5-1900-0000-fe98-20e1a60c0000 pid=3238 clone guuid=d4037cf6-1900-0000-fe98-20e1aa0c0000 pid=3242 /tmp/sample.bin guuid=8be2d6c5-1800-0000-fe98-20e10c0a0000 pid=2572->guuid=d4037cf6-1900-0000-fe98-20e1aa0c0000 pid=3242 clone guuid=2f8cf624-1b00-0000-fe98-20e1840e0000 pid=3716 /tmp/sample.bin guuid=8be2d6c5-1800-0000-fe98-20e10c0a0000 pid=2572->guuid=2f8cf624-1b00-0000-fe98-20e1840e0000 pid=3716 clone guuid=76601525-1b00-0000-fe98-20e1860e0000 pid=3718 /tmp/sample.bin guuid=8be2d6c5-1800-0000-fe98-20e10c0a0000 pid=2572->guuid=76601525-1b00-0000-fe98-20e1860e0000 pid=3718 clone guuid=8aea2b25-1b00-0000-fe98-20e1880e0000 pid=3720 /tmp/sample.bin guuid=8be2d6c5-1800-0000-fe98-20e10c0a0000 pid=2572->guuid=8aea2b25-1b00-0000-fe98-20e1880e0000 pid=3720 clone guuid=58a14525-1b00-0000-fe98-20e18a0e0000 pid=3722 /tmp/sample.bin guuid=8be2d6c5-1800-0000-fe98-20e10c0a0000 pid=2572->guuid=58a14525-1b00-0000-fe98-20e18a0e0000 pid=3722 clone guuid=bfc15925-1b00-0000-fe98-20e18c0e0000 pid=3724 /tmp/sample.bin guuid=8be2d6c5-1800-0000-fe98-20e10c0a0000 pid=2572->guuid=bfc15925-1b00-0000-fe98-20e18c0e0000 pid=3724 clone guuid=b3a10d53-1c00-0000-fe98-20e100120000 pid=4608 /tmp/sample.bin guuid=8be2d6c5-1800-0000-fe98-20e10c0a0000 pid=2572->guuid=b3a10d53-1c00-0000-fe98-20e100120000 pid=4608 clone guuid=01a12d53-1c00-0000-fe98-20e102120000 pid=4610 /tmp/sample.bin guuid=8be2d6c5-1800-0000-fe98-20e10c0a0000 pid=2572->guuid=01a12d53-1c00-0000-fe98-20e102120000 pid=4610 clone guuid=bfd44b53-1c00-0000-fe98-20e104120000 pid=4612 /tmp/sample.bin guuid=8be2d6c5-1800-0000-fe98-20e10c0a0000 pid=2572->guuid=bfd44b53-1c00-0000-fe98-20e104120000 pid=4612 clone guuid=51a46453-1c00-0000-fe98-20e106120000 pid=4614 /tmp/sample.bin guuid=8be2d6c5-1800-0000-fe98-20e10c0a0000 pid=2572->guuid=51a46453-1c00-0000-fe98-20e106120000 pid=4614 clone guuid=34118053-1c00-0000-fe98-20e108120000 pid=4616 /tmp/sample.bin guuid=8be2d6c5-1800-0000-fe98-20e10c0a0000 pid=2572->guuid=34118053-1c00-0000-fe98-20e108120000 pid=4616 clone guuid=9e545780-1d00-0000-fe98-20e1b3140000 pid=5299 /tmp/sample.bin guuid=8be2d6c5-1800-0000-fe98-20e10c0a0000 pid=2572->guuid=9e545780-1d00-0000-fe98-20e1b3140000 pid=5299 clone guuid=53159480-1d00-0000-fe98-20e1b5140000 pid=5301 /tmp/sample.bin guuid=8be2d6c5-1800-0000-fe98-20e10c0a0000 pid=2572->guuid=53159480-1d00-0000-fe98-20e1b5140000 pid=5301 clone guuid=ace7d380-1d00-0000-fe98-20e1b7140000 pid=5303 /tmp/sample.bin guuid=8be2d6c5-1800-0000-fe98-20e10c0a0000 pid=2572->guuid=ace7d380-1d00-0000-fe98-20e1b7140000 pid=5303 clone guuid=82512d81-1d00-0000-fe98-20e1b9140000 pid=5305 /tmp/sample.bin guuid=8be2d6c5-1800-0000-fe98-20e10c0a0000 pid=2572->guuid=82512d81-1d00-0000-fe98-20e1b9140000 pid=5305 clone guuid=e51b7082-1d00-0000-fe98-20e1bb140000 pid=5307 /tmp/sample.bin guuid=8be2d6c5-1800-0000-fe98-20e10c0a0000 pid=2572->guuid=e51b7082-1d00-0000-fe98-20e1bb140000 pid=5307 clone guuid=639f51af-1e00-0000-fe98-20e1c5140000 pid=5317 /tmp/sample.bin guuid=8be2d6c5-1800-0000-fe98-20e10c0a0000 pid=2572->guuid=639f51af-1e00-0000-fe98-20e1c5140000 pid=5317 clone guuid=e18b7daf-1e00-0000-fe98-20e1c7140000 pid=5319 /tmp/sample.bin guuid=8be2d6c5-1800-0000-fe98-20e10c0a0000 pid=2572->guuid=e18b7daf-1e00-0000-fe98-20e1c7140000 pid=5319 clone guuid=44579eaf-1e00-0000-fe98-20e1c9140000 pid=5321 /tmp/sample.bin guuid=8be2d6c5-1800-0000-fe98-20e10c0a0000 pid=2572->guuid=44579eaf-1e00-0000-fe98-20e1c9140000 pid=5321 clone guuid=9337c5af-1e00-0000-fe98-20e1cb140000 pid=5323 /tmp/sample.bin guuid=8be2d6c5-1800-0000-fe98-20e10c0a0000 pid=2572->guuid=9337c5af-1e00-0000-fe98-20e1cb140000 pid=5323 clone guuid=c08e87b0-1e00-0000-fe98-20e1cd140000 pid=5325 /tmp/sample.bin guuid=8be2d6c5-1800-0000-fe98-20e10c0a0000 pid=2572->guuid=c08e87b0-1e00-0000-fe98-20e1cd140000 pid=5325 clone guuid=c2d7d2db-1f00-0000-fe98-20e1e8140000 pid=5352 /tmp/sample.bin guuid=8be2d6c5-1800-0000-fe98-20e10c0a0000 pid=2572->guuid=c2d7d2db-1f00-0000-fe98-20e1e8140000 pid=5352 clone guuid=9c4c00dc-1f00-0000-fe98-20e1ea140000 pid=5354 /tmp/sample.bin guuid=8be2d6c5-1800-0000-fe98-20e10c0a0000 pid=2572->guuid=9c4c00dc-1f00-0000-fe98-20e1ea140000 pid=5354 clone guuid=93fd16dc-1f00-0000-fe98-20e1ec140000 pid=5356 /tmp/sample.bin guuid=8be2d6c5-1800-0000-fe98-20e10c0a0000 pid=2572->guuid=93fd16dc-1f00-0000-fe98-20e1ec140000 pid=5356 clone guuid=49be26dc-1f00-0000-fe98-20e1ee140000 pid=5358 /tmp/sample.bin guuid=8be2d6c5-1800-0000-fe98-20e10c0a0000 pid=2572->guuid=49be26dc-1f00-0000-fe98-20e1ee140000 pid=5358 clone guuid=bfc5ebdc-1f00-0000-fe98-20e1f0140000 pid=5360 /tmp/sample.bin guuid=8be2d6c5-1800-0000-fe98-20e10c0a0000 pid=2572->guuid=bfc5ebdc-1f00-0000-fe98-20e1f0140000 pid=5360 clone guuid=a4314f0e-2100-0000-fe98-20e107150000 pid=5383 /tmp/sample.bin guuid=8be2d6c5-1800-0000-fe98-20e10c0a0000 pid=2572->guuid=a4314f0e-2100-0000-fe98-20e107150000 pid=5383 clone guuid=4931900e-2100-0000-fe98-20e109150000 pid=5385 /tmp/sample.bin guuid=8be2d6c5-1800-0000-fe98-20e10c0a0000 pid=2572->guuid=4931900e-2100-0000-fe98-20e109150000 pid=5385 clone guuid=8595d50e-2100-0000-fe98-20e10b150000 pid=5387 /tmp/sample.bin guuid=8be2d6c5-1800-0000-fe98-20e10c0a0000 pid=2572->guuid=8595d50e-2100-0000-fe98-20e10b150000 pid=5387 clone guuid=e102170f-2100-0000-fe98-20e10d150000 pid=5389 /tmp/sample.bin guuid=8be2d6c5-1800-0000-fe98-20e10c0a0000 pid=2572->guuid=e102170f-2100-0000-fe98-20e10d150000 pid=5389 clone guuid=65a9570f-2100-0000-fe98-20e10f150000 pid=5391 /tmp/sample.bin guuid=8be2d6c5-1800-0000-fe98-20e10c0a0000 pid=2572->guuid=65a9570f-2100-0000-fe98-20e10f150000 pid=5391 clone guuid=a6e24a40-2200-0000-fe98-20e116150000 pid=5398 /tmp/sample.bin guuid=8be2d6c5-1800-0000-fe98-20e10c0a0000 pid=2572->guuid=a6e24a40-2200-0000-fe98-20e116150000 pid=5398 clone guuid=c40c7c40-2200-0000-fe98-20e118150000 pid=5400 /tmp/sample.bin guuid=8be2d6c5-1800-0000-fe98-20e10c0a0000 pid=2572->guuid=c40c7c40-2200-0000-fe98-20e118150000 pid=5400 clone guuid=4abaaf40-2200-0000-fe98-20e11a150000 pid=5402 /tmp/sample.bin guuid=8be2d6c5-1800-0000-fe98-20e10c0a0000 pid=2572->guuid=4abaaf40-2200-0000-fe98-20e11a150000 pid=5402 clone guuid=b83cde40-2200-0000-fe98-20e11c150000 pid=5404 /tmp/sample.bin guuid=8be2d6c5-1800-0000-fe98-20e10c0a0000 pid=2572->guuid=b83cde40-2200-0000-fe98-20e11c150000 pid=5404 clone guuid=2f4c0441-2200-0000-fe98-20e11e150000 pid=5406 /tmp/sample.bin guuid=8be2d6c5-1800-0000-fe98-20e10c0a0000 pid=2572->guuid=2f4c0441-2200-0000-fe98-20e11e150000 pid=5406 clone guuid=7421956d-2300-0000-fe98-20e125150000 pid=5413 /tmp/sample.bin guuid=8be2d6c5-1800-0000-fe98-20e10c0a0000 pid=2572->guuid=7421956d-2300-0000-fe98-20e125150000 pid=5413 clone guuid=069ec76d-2300-0000-fe98-20e127150000 pid=5415 /tmp/sample.bin guuid=8be2d6c5-1800-0000-fe98-20e10c0a0000 pid=2572->guuid=069ec76d-2300-0000-fe98-20e127150000 pid=5415 clone guuid=4a50f26d-2300-0000-fe98-20e129150000 pid=5417 /tmp/sample.bin guuid=8be2d6c5-1800-0000-fe98-20e10c0a0000 pid=2572->guuid=4a50f26d-2300-0000-fe98-20e129150000 pid=5417 clone guuid=f336126e-2300-0000-fe98-20e12b150000 pid=5419 /tmp/sample.bin guuid=8be2d6c5-1800-0000-fe98-20e10c0a0000 pid=2572->guuid=f336126e-2300-0000-fe98-20e12b150000 pid=5419 clone guuid=33c1346e-2300-0000-fe98-20e12d150000 pid=5421 /tmp/sample.bin guuid=8be2d6c5-1800-0000-fe98-20e10c0a0000 pid=2572->guuid=33c1346e-2300-0000-fe98-20e12d150000 pid=5421 clone guuid=fa1b449d-2400-0000-fe98-20e134150000 pid=5428 /tmp/sample.bin guuid=8be2d6c5-1800-0000-fe98-20e10c0a0000 pid=2572->guuid=fa1b449d-2400-0000-fe98-20e134150000 pid=5428 clone guuid=6cf17e9d-2400-0000-fe98-20e136150000 pid=5430 /tmp/sample.bin guuid=8be2d6c5-1800-0000-fe98-20e10c0a0000 pid=2572->guuid=6cf17e9d-2400-0000-fe98-20e136150000 pid=5430 clone guuid=04ceb09d-2400-0000-fe98-20e138150000 pid=5432 /tmp/sample.bin guuid=8be2d6c5-1800-0000-fe98-20e10c0a0000 pid=2572->guuid=04ceb09d-2400-0000-fe98-20e138150000 pid=5432 clone guuid=b4a1d79d-2400-0000-fe98-20e13a150000 pid=5434 /tmp/sample.bin guuid=8be2d6c5-1800-0000-fe98-20e10c0a0000 pid=2572->guuid=b4a1d79d-2400-0000-fe98-20e13a150000 pid=5434 clone guuid=c0db009e-2400-0000-fe98-20e13c150000 pid=5436 /tmp/sample.bin guuid=8be2d6c5-1800-0000-fe98-20e10c0a0000 pid=2572->guuid=c0db009e-2400-0000-fe98-20e13c150000 pid=5436 clone guuid=31acbecc-2500-0000-fe98-20e143150000 pid=5443 /tmp/sample.bin guuid=8be2d6c5-1800-0000-fe98-20e10c0a0000 pid=2572->guuid=31acbecc-2500-0000-fe98-20e143150000 pid=5443 clone guuid=8e1de2cc-2500-0000-fe98-20e145150000 pid=5445 /tmp/sample.bin guuid=8be2d6c5-1800-0000-fe98-20e10c0a0000 pid=2572->guuid=8e1de2cc-2500-0000-fe98-20e145150000 pid=5445 clone guuid=f30007cd-2500-0000-fe98-20e147150000 pid=5447 /tmp/sample.bin guuid=8be2d6c5-1800-0000-fe98-20e10c0a0000 pid=2572->guuid=f30007cd-2500-0000-fe98-20e147150000 pid=5447 clone guuid=c39622cd-2500-0000-fe98-20e149150000 pid=5449 /tmp/sample.bin guuid=8be2d6c5-1800-0000-fe98-20e10c0a0000 pid=2572->guuid=c39622cd-2500-0000-fe98-20e149150000 pid=5449 clone guuid=2fca42cd-2500-0000-fe98-20e14b150000 pid=5451 /tmp/sample.bin guuid=8be2d6c5-1800-0000-fe98-20e10c0a0000 pid=2572->guuid=2fca42cd-2500-0000-fe98-20e14b150000 pid=5451 clone guuid=48551fc6-1800-0000-fe98-20e10e0a0000 pid=2574 /tmp/sample.bin guuid=08341ac6-1800-0000-fe98-20e10d0a0000 pid=2573->guuid=48551fc6-1800-0000-fe98-20e10e0a0000 pid=2574 clone guuid=8565bbc6-1800-0000-fe98-20e1120a0000 pid=2578 /usr/sbin/update-rc.d zombie guuid=848129c6-1800-0000-fe98-20e10f0a0000 pid=2575->guuid=8565bbc6-1800-0000-fe98-20e1120a0000 pid=2578 execve guuid=00f2b0cf-1800-0000-fe98-20e1320a0000 pid=2610 /usr/bin/systemctl guuid=8565bbc6-1800-0000-fe98-20e1120a0000 pid=2578->guuid=00f2b0cf-1800-0000-fe98-20e1320a0000 pid=2610 execve guuid=8aa60bc7-1800-0000-fe98-20e1140a0000 pid=2580 /usr/bin/sed guuid=11e6c4c6-1800-0000-fe98-20e1130a0000 pid=2579->guuid=8aa60bc7-1800-0000-fe98-20e1140a0000 pid=2580 execve 667ae274-c69a-5201-a957-35a466c6f6bb sys-kernel-update.to:1528 guuid=8be2d6c5-1800-0000-fe98-20e10c0a0000 pid=2584->667ae274-c69a-5201-a957-35a466c6f6bb send: 4548B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=8be2d6c5-1800-0000-fe98-20e10c0a0000 pid=2584->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 38B 87f248b3-21f7-50eb-a2c7-cb35eca5cc17 0.0.0.0:80 guuid=8be2d6c5-1800-0000-fe98-20e10c0a0000 pid=2585->87f248b3-21f7-50eb-a2c7-cb35eca5cc17 con guuid=c2fbb4f4-1900-0000-fe98-20e1a10c0000 pid=3233 /usr/bin/iiuczesoqu zombie guuid=fc009cf4-1900-0000-fe98-20e1a00c0000 pid=3232->guuid=c2fbb4f4-1900-0000-fe98-20e1a10c0000 pid=3233 execve guuid=f3e6ddf9-1900-0000-fe98-20e1b50c0000 pid=3253 /usr/bin/iiuczesoqu zombie guuid=c2fbb4f4-1900-0000-fe98-20e1a10c0000 pid=3233->guuid=f3e6ddf9-1900-0000-fe98-20e1b50c0000 pid=3253 clone guuid=0b9b05f5-1900-0000-fe98-20e1a30c0000 pid=3235 /usr/bin/iiuczesoqu zombie guuid=c30decf4-1900-0000-fe98-20e1a20c0000 pid=3234->guuid=0b9b05f5-1900-0000-fe98-20e1a30c0000 pid=3235 execve guuid=cf959efa-1900-0000-fe98-20e1b70c0000 pid=3255 /usr/bin/iiuczesoqu zombie guuid=0b9b05f5-1900-0000-fe98-20e1a30c0000 pid=3235->guuid=cf959efa-1900-0000-fe98-20e1b70c0000 pid=3255 clone guuid=8fe945f5-1900-0000-fe98-20e1a50c0000 pid=3237 /usr/bin/iiuczesoqu zombie guuid=fd3c23f5-1900-0000-fe98-20e1a40c0000 pid=3236->guuid=8fe945f5-1900-0000-fe98-20e1a50c0000 pid=3237 execve guuid=7e6b0afa-1900-0000-fe98-20e1b60c0000 pid=3254 /usr/bin/iiuczesoqu zombie guuid=8fe945f5-1900-0000-fe98-20e1a50c0000 pid=3237->guuid=7e6b0afa-1900-0000-fe98-20e1b60c0000 pid=3254 clone guuid=f68c6cf6-1900-0000-fe98-20e1a90c0000 pid=3241 /usr/bin/iiuczesoqu zombie guuid=f1db62f5-1900-0000-fe98-20e1a60c0000 pid=3238->guuid=f68c6cf6-1900-0000-fe98-20e1a90c0000 pid=3241 execve guuid=a91899fb-1900-0000-fe98-20e1b80c0000 pid=3256 /usr/bin/iiuczesoqu zombie guuid=f68c6cf6-1900-0000-fe98-20e1a90c0000 pid=3241->guuid=a91899fb-1900-0000-fe98-20e1b80c0000 pid=3256 clone guuid=dafa9ef6-1900-0000-fe98-20e1ac0c0000 pid=3244 /usr/bin/iiuczesoqu zombie guuid=d4037cf6-1900-0000-fe98-20e1aa0c0000 pid=3242->guuid=dafa9ef6-1900-0000-fe98-20e1ac0c0000 pid=3244 execve guuid=d479d4f9-1900-0000-fe98-20e1b40c0000 pid=3252 /usr/bin/iiuczesoqu zombie guuid=dafa9ef6-1900-0000-fe98-20e1ac0c0000 pid=3244->guuid=d479d4f9-1900-0000-fe98-20e1b40c0000 pid=3252 clone guuid=64dd0125-1b00-0000-fe98-20e1850e0000 pid=3717 /usr/bin/futjbpawcz zombie guuid=2f8cf624-1b00-0000-fe98-20e1840e0000 pid=3716->guuid=64dd0125-1b00-0000-fe98-20e1850e0000 pid=3717 execve guuid=ff3ba62a-1b00-0000-fe98-20e1960e0000 pid=3734 /usr/bin/futjbpawcz zombie guuid=64dd0125-1b00-0000-fe98-20e1850e0000 pid=3717->guuid=ff3ba62a-1b00-0000-fe98-20e1960e0000 pid=3734 clone guuid=54271e25-1b00-0000-fe98-20e1870e0000 pid=3719 /usr/bin/futjbpawcz zombie guuid=76601525-1b00-0000-fe98-20e1860e0000 pid=3718->guuid=54271e25-1b00-0000-fe98-20e1870e0000 pid=3719 execve guuid=5399112a-1b00-0000-fe98-20e1930e0000 pid=3731 /usr/bin/futjbpawcz zombie guuid=54271e25-1b00-0000-fe98-20e1870e0000 pid=3719->guuid=5399112a-1b00-0000-fe98-20e1930e0000 pid=3731 clone guuid=f8363625-1b00-0000-fe98-20e1890e0000 pid=3721 /usr/bin/futjbpawcz zombie guuid=8aea2b25-1b00-0000-fe98-20e1880e0000 pid=3720->guuid=f8363625-1b00-0000-fe98-20e1890e0000 pid=3721 execve guuid=70b4392b-1b00-0000-fe98-20e1980e0000 pid=3736 /usr/bin/futjbpawcz zombie guuid=f8363625-1b00-0000-fe98-20e1890e0000 pid=3721->guuid=70b4392b-1b00-0000-fe98-20e1980e0000 pid=3736 clone guuid=1c9a4c25-1b00-0000-fe98-20e18b0e0000 pid=3723 /usr/bin/futjbpawcz zombie guuid=58a14525-1b00-0000-fe98-20e18a0e0000 pid=3722->guuid=1c9a4c25-1b00-0000-fe98-20e18b0e0000 pid=3723 execve guuid=7a4b6b28-1b00-0000-fe98-20e18e0e0000 pid=3726 /usr/bin/futjbpawcz zombie guuid=1c9a4c25-1b00-0000-fe98-20e18b0e0000 pid=3723->guuid=7a4b6b28-1b00-0000-fe98-20e18e0e0000 pid=3726 clone guuid=a71fb426-1b00-0000-fe98-20e18d0e0000 pid=3725 /usr/bin/futjbpawcz zombie guuid=bfc15925-1b00-0000-fe98-20e18c0e0000 pid=3724->guuid=a71fb426-1b00-0000-fe98-20e18d0e0000 pid=3725 execve guuid=fe58dd2c-1b00-0000-fe98-20e19c0e0000 pid=3740 /usr/bin/futjbpawcz zombie guuid=a71fb426-1b00-0000-fe98-20e18d0e0000 pid=3725->guuid=fe58dd2c-1b00-0000-fe98-20e19c0e0000 pid=3740 clone guuid=83911953-1c00-0000-fe98-20e101120000 pid=4609 /usr/bin/lcuyujjwvz zombie guuid=b3a10d53-1c00-0000-fe98-20e100120000 pid=4608->guuid=83911953-1c00-0000-fe98-20e101120000 pid=4609 execve guuid=023a7258-1c00-0000-fe98-20e123120000 pid=4643 /usr/bin/lcuyujjwvz zombie guuid=83911953-1c00-0000-fe98-20e101120000 pid=4609->guuid=023a7258-1c00-0000-fe98-20e123120000 pid=4643 clone guuid=0cf43853-1c00-0000-fe98-20e103120000 pid=4611 /usr/bin/lcuyujjwvz zombie guuid=01a12d53-1c00-0000-fe98-20e102120000 pid=4610->guuid=0cf43853-1c00-0000-fe98-20e103120000 pid=4611 execve guuid=41f14957-1c00-0000-fe98-20e11a120000 pid=4634 /usr/bin/lcuyujjwvz zombie guuid=0cf43853-1c00-0000-fe98-20e103120000 pid=4611->guuid=41f14957-1c00-0000-fe98-20e11a120000 pid=4634 clone guuid=847e5553-1c00-0000-fe98-20e105120000 pid=4613 /usr/bin/lcuyujjwvz zombie guuid=bfd44b53-1c00-0000-fe98-20e104120000 pid=4612->guuid=847e5553-1c00-0000-fe98-20e105120000 pid=4613 execve guuid=48dcc659-1c00-0000-fe98-20e12e120000 pid=4654 /usr/bin/lcuyujjwvz zombie guuid=847e5553-1c00-0000-fe98-20e105120000 pid=4613->guuid=48dcc659-1c00-0000-fe98-20e12e120000 pid=4654 clone guuid=94fc6d53-1c00-0000-fe98-20e107120000 pid=4615 /usr/bin/lcuyujjwvz zombie guuid=51a46453-1c00-0000-fe98-20e106120000 pid=4614->guuid=94fc6d53-1c00-0000-fe98-20e107120000 pid=4615 execve guuid=23855759-1c00-0000-fe98-20e129120000 pid=4649 /usr/bin/lcuyujjwvz zombie guuid=94fc6d53-1c00-0000-fe98-20e107120000 pid=4615->guuid=23855759-1c00-0000-fe98-20e129120000 pid=4649 clone guuid=ee4c8c53-1c00-0000-fe98-20e109120000 pid=4617 /usr/bin/lcuyujjwvz zombie guuid=34118053-1c00-0000-fe98-20e108120000 pid=4616->guuid=ee4c8c53-1c00-0000-fe98-20e109120000 pid=4617 execve guuid=83042059-1c00-0000-fe98-20e127120000 pid=4647 /usr/bin/lcuyujjwvz zombie guuid=ee4c8c53-1c00-0000-fe98-20e109120000 pid=4617->guuid=83042059-1c00-0000-fe98-20e127120000 pid=4647 clone guuid=44a66b80-1d00-0000-fe98-20e1b4140000 pid=5300 /usr/bin/hkevotrait zombie guuid=9e545780-1d00-0000-fe98-20e1b3140000 pid=5299->guuid=44a66b80-1d00-0000-fe98-20e1b4140000 pid=5300 execve guuid=c70c7a84-1d00-0000-fe98-20e1bd140000 pid=5309 /usr/bin/hkevotrait zombie guuid=44a66b80-1d00-0000-fe98-20e1b4140000 pid=5300->guuid=c70c7a84-1d00-0000-fe98-20e1bd140000 pid=5309 clone guuid=9997ac80-1d00-0000-fe98-20e1b6140000 pid=5302 /usr/bin/hkevotrait zombie guuid=53159480-1d00-0000-fe98-20e1b5140000 pid=5301->guuid=9997ac80-1d00-0000-fe98-20e1b6140000 pid=5302 execve guuid=73e74086-1d00-0000-fe98-20e1bf140000 pid=5311 /usr/bin/hkevotrait zombie guuid=9997ac80-1d00-0000-fe98-20e1b6140000 pid=5302->guuid=73e74086-1d00-0000-fe98-20e1bf140000 pid=5311 clone guuid=942e0481-1d00-0000-fe98-20e1b8140000 pid=5304 /usr/bin/hkevotrait zombie guuid=ace7d380-1d00-0000-fe98-20e1b7140000 pid=5303->guuid=942e0481-1d00-0000-fe98-20e1b8140000 pid=5304 execve guuid=c7703685-1d00-0000-fe98-20e1be140000 pid=5310 /usr/bin/hkevotrait zombie guuid=942e0481-1d00-0000-fe98-20e1b8140000 pid=5304->guuid=c7703685-1d00-0000-fe98-20e1be140000 pid=5310 clone guuid=0c8b5082-1d00-0000-fe98-20e1ba140000 pid=5306 /usr/bin/hkevotrait zombie guuid=82512d81-1d00-0000-fe98-20e1b9140000 pid=5305->guuid=0c8b5082-1d00-0000-fe98-20e1ba140000 pid=5306 execve guuid=d16ccf86-1d00-0000-fe98-20e1c0140000 pid=5312 /usr/bin/hkevotrait zombie guuid=0c8b5082-1d00-0000-fe98-20e1ba140000 pid=5306->guuid=d16ccf86-1d00-0000-fe98-20e1c0140000 pid=5312 clone guuid=d4e04e83-1d00-0000-fe98-20e1bc140000 pid=5308 /usr/bin/hkevotrait zombie guuid=e51b7082-1d00-0000-fe98-20e1bb140000 pid=5307->guuid=d4e04e83-1d00-0000-fe98-20e1bc140000 pid=5308 execve guuid=23981089-1d00-0000-fe98-20e1c1140000 pid=5313 /usr/bin/hkevotrait zombie guuid=d4e04e83-1d00-0000-fe98-20e1bc140000 pid=5308->guuid=23981089-1d00-0000-fe98-20e1c1140000 pid=5313 clone guuid=39a35faf-1e00-0000-fe98-20e1c6140000 pid=5318 /usr/bin/mypdhumzwq zombie guuid=639f51af-1e00-0000-fe98-20e1c5140000 pid=5317->guuid=39a35faf-1e00-0000-fe98-20e1c6140000 pid=5318 execve guuid=684712b5-1e00-0000-fe98-20e1d4140000 pid=5332 /usr/bin/mypdhumzwq zombie guuid=39a35faf-1e00-0000-fe98-20e1c6140000 pid=5318->guuid=684712b5-1e00-0000-fe98-20e1d4140000 pid=5332 clone guuid=f97d88af-1e00-0000-fe98-20e1c8140000 pid=5320 /usr/bin/mypdhumzwq zombie guuid=e18b7daf-1e00-0000-fe98-20e1c7140000 pid=5319->guuid=f97d88af-1e00-0000-fe98-20e1c8140000 pid=5320 execve guuid=baffb5b6-1e00-0000-fe98-20e1d5140000 pid=5333 /usr/bin/mypdhumzwq zombie guuid=f97d88af-1e00-0000-fe98-20e1c8140000 pid=5320->guuid=baffb5b6-1e00-0000-fe98-20e1d5140000 pid=5333 clone guuid=0657aeaf-1e00-0000-fe98-20e1ca140000 pid=5322 /usr/bin/mypdhumzwq zombie guuid=44579eaf-1e00-0000-fe98-20e1c9140000 pid=5321->guuid=0657aeaf-1e00-0000-fe98-20e1ca140000 pid=5322 execve guuid=87b198b4-1e00-0000-fe98-20e1d3140000 pid=5331 /usr/bin/mypdhumzwq zombie guuid=0657aeaf-1e00-0000-fe98-20e1ca140000 pid=5322->guuid=87b198b4-1e00-0000-fe98-20e1d3140000 pid=5331 clone guuid=c4ad6fb0-1e00-0000-fe98-20e1cc140000 pid=5324 /usr/bin/mypdhumzwq zombie guuid=9337c5af-1e00-0000-fe98-20e1cb140000 pid=5323->guuid=c4ad6fb0-1e00-0000-fe98-20e1cc140000 pid=5324 execve guuid=c29b15b7-1e00-0000-fe98-20e1d7140000 pid=5335 /usr/bin/mypdhumzwq zombie guuid=c4ad6fb0-1e00-0000-fe98-20e1cc140000 pid=5324->guuid=c29b15b7-1e00-0000-fe98-20e1d7140000 pid=5335 clone guuid=b75aa4b0-1e00-0000-fe98-20e1ce140000 pid=5326 /usr/bin/mypdhumzwq zombie guuid=c08e87b0-1e00-0000-fe98-20e1cd140000 pid=5325->guuid=b75aa4b0-1e00-0000-fe98-20e1ce140000 pid=5326 execve guuid=0c5cfcb6-1e00-0000-fe98-20e1d6140000 pid=5334 /usr/bin/mypdhumzwq zombie guuid=b75aa4b0-1e00-0000-fe98-20e1ce140000 pid=5326->guuid=0c5cfcb6-1e00-0000-fe98-20e1d6140000 pid=5334 clone guuid=0ba0e6db-1f00-0000-fe98-20e1e9140000 pid=5353 /usr/bin/caiamikpaa zombie guuid=c2d7d2db-1f00-0000-fe98-20e1e8140000 pid=5352->guuid=0ba0e6db-1f00-0000-fe98-20e1e9140000 pid=5353 execve guuid=69a056de-1f00-0000-fe98-20e1f2140000 pid=5362 /usr/bin/caiamikpaa zombie guuid=0ba0e6db-1f00-0000-fe98-20e1e9140000 pid=5353->guuid=69a056de-1f00-0000-fe98-20e1f2140000 pid=5362 clone guuid=16af09dc-1f00-0000-fe98-20e1eb140000 pid=5355 /usr/bin/caiamikpaa zombie guuid=9c4c00dc-1f00-0000-fe98-20e1ea140000 pid=5354->guuid=16af09dc-1f00-0000-fe98-20e1eb140000 pid=5355 execve guuid=37fc00e1-1f00-0000-fe98-20e1f5140000 pid=5365 /usr/bin/caiamikpaa zombie guuid=16af09dc-1f00-0000-fe98-20e1eb140000 pid=5355->guuid=37fc00e1-1f00-0000-fe98-20e1f5140000 pid=5365 clone guuid=e0561cdc-1f00-0000-fe98-20e1ed140000 pid=5357 /usr/bin/caiamikpaa zombie guuid=93fd16dc-1f00-0000-fe98-20e1ec140000 pid=5356->guuid=e0561cdc-1f00-0000-fe98-20e1ed140000 pid=5357 execve guuid=d5cdbadf-1f00-0000-fe98-20e1f3140000 pid=5363 /usr/bin/caiamikpaa zombie guuid=e0561cdc-1f00-0000-fe98-20e1ed140000 pid=5357->guuid=d5cdbadf-1f00-0000-fe98-20e1f3140000 pid=5363 clone guuid=3047d6dc-1f00-0000-fe98-20e1ef140000 pid=5359 /usr/bin/caiamikpaa zombie guuid=49be26dc-1f00-0000-fe98-20e1ee140000 pid=5358->guuid=3047d6dc-1f00-0000-fe98-20e1ef140000 pid=5359 execve guuid=98074fe2-1f00-0000-fe98-20e1f8140000 pid=5368 /usr/bin/caiamikpaa zombie guuid=3047d6dc-1f00-0000-fe98-20e1ef140000 pid=5359->guuid=98074fe2-1f00-0000-fe98-20e1f8140000 pid=5368 clone guuid=63018edd-1f00-0000-fe98-20e1f1140000 pid=5361 /usr/bin/caiamikpaa zombie guuid=bfc5ebdc-1f00-0000-fe98-20e1f0140000 pid=5360->guuid=63018edd-1f00-0000-fe98-20e1f1140000 pid=5361 execve guuid=31117ee2-1f00-0000-fe98-20e1fa140000 pid=5370 /usr/bin/caiamikpaa zombie guuid=63018edd-1f00-0000-fe98-20e1f1140000 pid=5361->guuid=31117ee2-1f00-0000-fe98-20e1fa140000 pid=5370 clone guuid=4b9c650e-2100-0000-fe98-20e108150000 pid=5384 /usr/bin/vftffsobsx zombie guuid=a4314f0e-2100-0000-fe98-20e107150000 pid=5383->guuid=4b9c650e-2100-0000-fe98-20e108150000 pid=5384 execve guuid=fd3ab012-2100-0000-fe98-20e111150000 pid=5393 /usr/bin/vftffsobsx zombie guuid=4b9c650e-2100-0000-fe98-20e108150000 pid=5384->guuid=fd3ab012-2100-0000-fe98-20e111150000 pid=5393 clone guuid=921ca40e-2100-0000-fe98-20e10a150000 pid=5386 /usr/bin/vftffsobsx zombie guuid=4931900e-2100-0000-fe98-20e109150000 pid=5385->guuid=921ca40e-2100-0000-fe98-20e10a150000 pid=5386 execve guuid=b6e54014-2100-0000-fe98-20e113150000 pid=5395 /usr/bin/vftffsobsx zombie guuid=921ca40e-2100-0000-fe98-20e10a150000 pid=5386->guuid=b6e54014-2100-0000-fe98-20e113150000 pid=5395 clone guuid=0f36e60e-2100-0000-fe98-20e10c150000 pid=5388 /usr/bin/vftffsobsx zombie guuid=8595d50e-2100-0000-fe98-20e10b150000 pid=5387->guuid=0f36e60e-2100-0000-fe98-20e10c150000 pid=5388 execve guuid=947c6814-2100-0000-fe98-20e115150000 pid=5397 /usr/bin/vftffsobsx zombie guuid=0f36e60e-2100-0000-fe98-20e10c150000 pid=5388->guuid=947c6814-2100-0000-fe98-20e115150000 pid=5397 clone guuid=a31a320f-2100-0000-fe98-20e10e150000 pid=5390 /usr/bin/vftffsobsx zombie guuid=e102170f-2100-0000-fe98-20e10d150000 pid=5389->guuid=a31a320f-2100-0000-fe98-20e10e150000 pid=5390 execve guuid=79d6f112-2100-0000-fe98-20e112150000 pid=5394 /usr/bin/vftffsobsx zombie guuid=a31a320f-2100-0000-fe98-20e10e150000 pid=5390->guuid=79d6f112-2100-0000-fe98-20e112150000 pid=5394 clone guuid=8cf7e60f-2100-0000-fe98-20e110150000 pid=5392 /usr/bin/vftffsobsx zombie guuid=65a9570f-2100-0000-fe98-20e10f150000 pid=5391->guuid=8cf7e60f-2100-0000-fe98-20e110150000 pid=5392 execve guuid=35395114-2100-0000-fe98-20e114150000 pid=5396 /usr/bin/vftffsobsx zombie guuid=8cf7e60f-2100-0000-fe98-20e110150000 pid=5392->guuid=35395114-2100-0000-fe98-20e114150000 pid=5396 clone guuid=cd475c40-2200-0000-fe98-20e117150000 pid=5399 /usr/bin/ocexpjhwmn zombie guuid=a6e24a40-2200-0000-fe98-20e116150000 pid=5398->guuid=cd475c40-2200-0000-fe98-20e117150000 pid=5399 execve guuid=c95e6844-2200-0000-fe98-20e120150000 pid=5408 /usr/bin/ocexpjhwmn zombie guuid=cd475c40-2200-0000-fe98-20e117150000 pid=5399->guuid=c95e6844-2200-0000-fe98-20e120150000 pid=5408 clone guuid=91e98a40-2200-0000-fe98-20e119150000 pid=5401 /usr/bin/ocexpjhwmn zombie guuid=c40c7c40-2200-0000-fe98-20e118150000 pid=5400->guuid=91e98a40-2200-0000-fe98-20e119150000 pid=5401 execve guuid=4c49bf44-2200-0000-fe98-20e122150000 pid=5410 /usr/bin/ocexpjhwmn zombie guuid=91e98a40-2200-0000-fe98-20e119150000 pid=5401->guuid=4c49bf44-2200-0000-fe98-20e122150000 pid=5410 clone guuid=9da6bd40-2200-0000-fe98-20e11b150000 pid=5403 /usr/bin/ocexpjhwmn zombie guuid=4abaaf40-2200-0000-fe98-20e11a150000 pid=5402->guuid=9da6bd40-2200-0000-fe98-20e11b150000 pid=5403 execve guuid=0da59645-2200-0000-fe98-20e123150000 pid=5411 /usr/bin/ocexpjhwmn zombie guuid=9da6bd40-2200-0000-fe98-20e11b150000 pid=5403->guuid=0da59645-2200-0000-fe98-20e123150000 pid=5411 clone guuid=4eaaec40-2200-0000-fe98-20e11d150000 pid=5405 /usr/bin/ocexpjhwmn zombie guuid=b83cde40-2200-0000-fe98-20e11c150000 pid=5404->guuid=4eaaec40-2200-0000-fe98-20e11d150000 pid=5405 execve guuid=3738c345-2200-0000-fe98-20e124150000 pid=5412 /usr/bin/ocexpjhwmn zombie guuid=4eaaec40-2200-0000-fe98-20e11d150000 pid=5405->guuid=3738c345-2200-0000-fe98-20e124150000 pid=5412 clone guuid=ce751441-2200-0000-fe98-20e11f150000 pid=5407 /usr/bin/ocexpjhwmn zombie guuid=2f4c0441-2200-0000-fe98-20e11e150000 pid=5406->guuid=ce751441-2200-0000-fe98-20e11f150000 pid=5407 execve guuid=328d9f44-2200-0000-fe98-20e121150000 pid=5409 /usr/bin/ocexpjhwmn zombie guuid=ce751441-2200-0000-fe98-20e11f150000 pid=5407->guuid=328d9f44-2200-0000-fe98-20e121150000 pid=5409 clone guuid=2744a36d-2300-0000-fe98-20e126150000 pid=5414 /usr/bin/kuacsfmvmo zombie guuid=7421956d-2300-0000-fe98-20e125150000 pid=5413->guuid=2744a36d-2300-0000-fe98-20e126150000 pid=5414 execve guuid=dbf2c571-2300-0000-fe98-20e131150000 pid=5425 /usr/bin/kuacsfmvmo zombie guuid=2744a36d-2300-0000-fe98-20e126150000 pid=5414->guuid=dbf2c571-2300-0000-fe98-20e131150000 pid=5425 clone guuid=9705d56d-2300-0000-fe98-20e128150000 pid=5416 /usr/bin/kuacsfmvmo zombie guuid=069ec76d-2300-0000-fe98-20e127150000 pid=5415->guuid=9705d56d-2300-0000-fe98-20e128150000 pid=5416 execve guuid=0ec73e71-2300-0000-fe98-20e130150000 pid=5424 /usr/bin/kuacsfmvmo zombie guuid=9705d56d-2300-0000-fe98-20e128150000 pid=5416->guuid=0ec73e71-2300-0000-fe98-20e130150000 pid=5424 clone guuid=cd6dfe6d-2300-0000-fe98-20e12a150000 pid=5418 /usr/bin/kuacsfmvmo zombie guuid=4a50f26d-2300-0000-fe98-20e129150000 pid=5417->guuid=cd6dfe6d-2300-0000-fe98-20e12a150000 pid=5418 execve guuid=d5333a72-2300-0000-fe98-20e132150000 pid=5426 /usr/bin/kuacsfmvmo zombie guuid=cd6dfe6d-2300-0000-fe98-20e12a150000 pid=5418->guuid=d5333a72-2300-0000-fe98-20e132150000 pid=5426 clone guuid=ce9f1e6e-2300-0000-fe98-20e12c150000 pid=5420 /usr/bin/kuacsfmvmo zombie guuid=f336126e-2300-0000-fe98-20e12b150000 pid=5419->guuid=ce9f1e6e-2300-0000-fe98-20e12c150000 pid=5420 execve guuid=1d221a71-2300-0000-fe98-20e12f150000 pid=5423 /usr/bin/kuacsfmvmo zombie guuid=ce9f1e6e-2300-0000-fe98-20e12c150000 pid=5420->guuid=1d221a71-2300-0000-fe98-20e12f150000 pid=5423 clone guuid=e2eaea6e-2300-0000-fe98-20e12e150000 pid=5422 /usr/bin/kuacsfmvmo zombie guuid=33c1346e-2300-0000-fe98-20e12d150000 pid=5421->guuid=e2eaea6e-2300-0000-fe98-20e12e150000 pid=5422 execve guuid=1568ce72-2300-0000-fe98-20e133150000 pid=5427 /usr/bin/kuacsfmvmo zombie guuid=e2eaea6e-2300-0000-fe98-20e12e150000 pid=5422->guuid=1568ce72-2300-0000-fe98-20e133150000 pid=5427 clone guuid=81e1589d-2400-0000-fe98-20e135150000 pid=5429 /usr/bin/zkdhsvltct zombie guuid=fa1b449d-2400-0000-fe98-20e134150000 pid=5428->guuid=81e1589d-2400-0000-fe98-20e135150000 pid=5429 execve guuid=6ba990a1-2400-0000-fe98-20e13e150000 pid=5438 /usr/bin/zkdhsvltct zombie guuid=81e1589d-2400-0000-fe98-20e135150000 pid=5429->guuid=6ba990a1-2400-0000-fe98-20e13e150000 pid=5438 clone guuid=0a008c9d-2400-0000-fe98-20e137150000 pid=5431 /usr/bin/zkdhsvltct zombie guuid=6cf17e9d-2400-0000-fe98-20e136150000 pid=5430->guuid=0a008c9d-2400-0000-fe98-20e137150000 pid=5431 execve guuid=f07dbba1-2400-0000-fe98-20e13f150000 pid=5439 /usr/bin/zkdhsvltct zombie guuid=0a008c9d-2400-0000-fe98-20e137150000 pid=5431->guuid=f07dbba1-2400-0000-fe98-20e13f150000 pid=5439 clone guuid=342ebe9d-2400-0000-fe98-20e139150000 pid=5433 /usr/bin/zkdhsvltct zombie guuid=04ceb09d-2400-0000-fe98-20e138150000 pid=5432->guuid=342ebe9d-2400-0000-fe98-20e139150000 pid=5433 execve guuid=8136bfa2-2400-0000-fe98-20e141150000 pid=5441 /usr/bin/zkdhsvltct zombie guuid=342ebe9d-2400-0000-fe98-20e139150000 pid=5433->guuid=8136bfa2-2400-0000-fe98-20e141150000 pid=5441 clone guuid=c6c4e39d-2400-0000-fe98-20e13b150000 pid=5435 /usr/bin/zkdhsvltct zombie guuid=b4a1d79d-2400-0000-fe98-20e13a150000 pid=5434->guuid=c6c4e39d-2400-0000-fe98-20e13b150000 pid=5435 execve guuid=c1feeea1-2400-0000-fe98-20e140150000 pid=5440 /usr/bin/zkdhsvltct zombie guuid=c6c4e39d-2400-0000-fe98-20e13b150000 pid=5435->guuid=c1feeea1-2400-0000-fe98-20e140150000 pid=5440 clone guuid=6006ae9e-2400-0000-fe98-20e13d150000 pid=5437 /usr/bin/zkdhsvltct zombie guuid=c0db009e-2400-0000-fe98-20e13c150000 pid=5436->guuid=6006ae9e-2400-0000-fe98-20e13d150000 pid=5437 execve guuid=de6420a3-2400-0000-fe98-20e142150000 pid=5442 /usr/bin/zkdhsvltct zombie guuid=6006ae9e-2400-0000-fe98-20e13d150000 pid=5437->guuid=de6420a3-2400-0000-fe98-20e142150000 pid=5442 clone guuid=d415cdcc-2500-0000-fe98-20e144150000 pid=5444 /usr/bin/miqsttkzcz zombie guuid=31acbecc-2500-0000-fe98-20e143150000 pid=5443->guuid=d415cdcc-2500-0000-fe98-20e144150000 pid=5444 execve guuid=c92503d1-2500-0000-fe98-20e14f150000 pid=5455 /usr/bin/miqsttkzcz zombie guuid=d415cdcc-2500-0000-fe98-20e144150000 pid=5444->guuid=c92503d1-2500-0000-fe98-20e14f150000 pid=5455 clone guuid=1c5ceecc-2500-0000-fe98-20e146150000 pid=5446 /usr/bin/miqsttkzcz zombie guuid=8e1de2cc-2500-0000-fe98-20e145150000 pid=5445->guuid=1c5ceecc-2500-0000-fe98-20e146150000 pid=5446 execve guuid=67d3fad0-2500-0000-fe98-20e14e150000 pid=5454 /usr/bin/miqsttkzcz zombie guuid=1c5ceecc-2500-0000-fe98-20e146150000 pid=5446->guuid=67d3fad0-2500-0000-fe98-20e14e150000 pid=5454 clone guuid=774a10cd-2500-0000-fe98-20e148150000 pid=5448 /usr/bin/miqsttkzcz zombie guuid=f30007cd-2500-0000-fe98-20e147150000 pid=5447->guuid=774a10cd-2500-0000-fe98-20e148150000 pid=5448 execve guuid=d4aee1d0-2500-0000-fe98-20e14d150000 pid=5453 /usr/bin/miqsttkzcz zombie guuid=774a10cd-2500-0000-fe98-20e148150000 pid=5448->guuid=d4aee1d0-2500-0000-fe98-20e14d150000 pid=5453 clone guuid=31f32acd-2500-0000-fe98-20e14a150000 pid=5450 /usr/bin/miqsttkzcz zombie guuid=c39622cd-2500-0000-fe98-20e149150000 pid=5449->guuid=31f32acd-2500-0000-fe98-20e14a150000 pid=5450 execve guuid=236bf9d1-2500-0000-fe98-20e150150000 pid=5456 /usr/bin/miqsttkzcz zombie guuid=31f32acd-2500-0000-fe98-20e14a150000 pid=5450->guuid=236bf9d1-2500-0000-fe98-20e150150000 pid=5456 clone guuid=f61eb0cd-2500-0000-fe98-20e14c150000 pid=5452 /usr/bin/miqsttkzcz zombie guuid=2fca42cd-2500-0000-fe98-20e14b150000 pid=5451->guuid=f61eb0cd-2500-0000-fe98-20e14c150000 pid=5452 execve guuid=ef0e41d2-2500-0000-fe98-20e151150000 pid=5457 /usr/bin/miqsttkzcz zombie guuid=f61eb0cd-2500-0000-fe98-20e14c150000 pid=5452->guuid=ef0e41d2-2500-0000-fe98-20e151150000 pid=5457 clone
Threat name:
Linux.Trojan.XorDDoS
Status:
Malicious
First seen:
2026-02-21 17:46:05 UTC
File Type:
ELF32 Little (Exe)
AV detection:
27 of 36 (75.00%)
Threat level:
  5/5
Result
Malware family:
xorddos
Score:
  10/10
Tags:
family:xorddos antivm botnet discovery downloader execution linux persistence privilege_escalation
Behaviour
Reads runtime system information
System Network Configuration Discovery
Checks CPU configuration
Creates/modifies Cron job
Modifies init.d
Write file to user bin folder
Executes dropped EXE
XorDDoS
XorDDoS payload
Xorddos family
Malware Config
C2 Extraction:
https://api-metadata-v6.is/config.rar
sys-kernel-update.to:1528
telemetry-pipe.sh:1528
api-metadata-v6.is:1528
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:enterpriseapps2
Author:Tim Brown @timb_machine
Description:Enterprise apps
Rule name:F01_s1ckrule
Author:s1ckb017
Rule name:linux_generic_ipv6_catcher
Author:@_lubiedo
Description:ELF samples using IPv6 addresses
Rule name:Linux_Trojan_Xorddos_0eb147ca
Author:Elastic Security
Rule name:Linux_Trojan_Xorddos_2084099a
Author:Elastic Security
Rule name:Linux_Trojan_Xorddos_2aef46a6
Author:Elastic Security
Rule name:Linux_Trojan_Xorddos_ba961ed2
Author:Elastic Security
Rule name:MALWARE_Linux_XORDDoS
Author:ditekSHen
Description:Detects XORDDoS
Rule name:NET
Author:malware-lu
Rule name:unixredflags3
Author:Tim Brown @timb_machine
Description:Hunts for UNIX red flags

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

XorDDoS

elf eae72481b82348783a682cf62b64d242c1e3b1756ccbff5bf030c5a0ba0b152d

(this sample)

  
Delivery method
Distributed via web download

Comments