MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ee3b6aaa1edecd0ed27bcd9ab835ca41735c85263fc8219cc2a9c62f66cad920. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RondoDox


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: ee3b6aaa1edecd0ed27bcd9ab835ca41735c85263fc8219cc2a9c62f66cad920
SHA3-384 hash: a3f613c137811915a41a56d39af6826403b505619c0746e5abbacf7738ba2658dbcfc7995448c90b1a0c99d7b9aff0a0
SHA1 hash: bf4b1587491f9bc00a5cfc5dfaa627c490e87155
MD5 hash: 36894f7a190f3e2eb0f6061671e7299b
humanhash: black-wisconsin-single-sweet
File name:rondo.aqu.sh
Download: download sample
Signature RondoDox
File size:9'731 bytes
First seen:2025-12-20 00:45:55 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 192:mPEcac/goLngQoiOoOoFoMoroSoRoiozoZokojovobCmoCop3oroA:mPhj/xoiOoOoFoMoroSoRoiozoZokojv
TLSH T1D812F1A931C512F6BCA945225193BABCCB07E1E564638EBEFC5848FF6972C08F05C745
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://41.231.37.153/rondo.loln/an/aua-wget
http://41.231.37.153/rondo.x86_64dd23d80709df7b574e859681a96355d14042b9c364b0b9f3992745bc02fba181 RondoDoxRondoDox ua-wget
http://41.231.37.153/rondo.i686e52f0ce6a973cd09345ab3dee9b39418606eb496d4c62b851e1656b68e1888dc Miraimirai ua-wget
http://41.231.37.153/rondo.i586n/an/aua-wget
http://41.231.37.153/rondo.i486a16ca63d5027bd0c74dccf7982d323f167ad3595cac26cd6b24d3bd49f6fcf63 Miraimirai ua-wget
http://41.231.37.153/rondo.armv6l245dcccbf3747bdedaa69b67395a9978a25c1c3bee21324c64c08990c753a202 Miraimirai ua-wget
http://41.231.37.153/rondo.armv5ln/an/aua-wget
http://41.231.37.153/rondo.armv4ln/an/aua-wget
http://41.231.37.153/rondo.armv7l338c51852bc493d583695b47c694248848f2f212613463b0eebe8fbd660855d0 Miraimirai ua-wget
http://41.231.37.153/rondo.powerpc12b8e57f6e57b9b57fb108fb2a905104bace4cf21e27419e7b475fe2596ebf44 Miraimirai ua-wget
http://41.231.37.153/rondo.powerpc-440fpe3ceaaf44d5270d22001fa80dcb2305b02b06dabb63150804c757c563873c8fc Miraimirai RondoDox ua-wget
http://41.231.37.153/rondo.mipsbb7942fd18469c67cb9744ff70e69383229116f05fde4d198ccd2164fec8c6f6 Gafgytgafgyt ua-wget
http://41.231.37.153/rondo.mipsel3e0d08d6710ca0296e0bec1385dc76dba9de819e65e17dde7ebeb8eb15fd08da Gafgytgafgyt ua-wget
http://41.231.37.153/rondo.arc700eba7f55fd909e5a43c09765848af3e7516844a3921641a96be6caa32f74bd2b4 Miraimirai ua-wget
http://41.231.37.153/rondo.sh44f278033b6eb279ac8644b54bd41e2618f096938224cda1430de2655c5a7087d Miraimirai ua-wget
http://41.231.37.153/rondo.sparc296b377852120be33fdaad750dbf4085311c3851c88f132e48f9d7e58d1c6a6c Miraimirai ua-wget
http://41.231.37.153/rondo.m68k6a606126df8031b2c2d16cea3e459a7beed6580eb746f368eaf75cfcaffd3f97 Miraimirai ua-wget
http://41.231.37.153/rondo.armebn/an/aRondoDox ua-wget
http://41.231.37.153/rondo.armebhfn/an/aua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
37
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox masquerade
Verdict:
Adware
File Type:
unix shell
First seen:
2025-12-19T22:01:00Z UTC
Last seen:
2025-12-21T02:00:00Z UTC
Hits:
~10
Detections:
not-a-virus:HEUR:Downloader.Shell.Miner.a
Status:
terminated
Behavior Graph:
%3 guuid=314aca4c-1900-0000-0e4d-559a24100000 pid=4132 /usr/bin/sudo guuid=e018ee4e-1900-0000-0e4d-559a2d100000 pid=4141 /tmp/sample.bin write-file guuid=314aca4c-1900-0000-0e4d-559a24100000 pid=4132->guuid=e018ee4e-1900-0000-0e4d-559a2d100000 pid=4141 execve guuid=90f6364f-1900-0000-0e4d-559a2e100000 pid=4142 /usr/bin/rm guuid=e018ee4e-1900-0000-0e4d-559a2d100000 pid=4141->guuid=90f6364f-1900-0000-0e4d-559a2e100000 pid=4142 execve guuid=75c4cd4f-1900-0000-0e4d-559a30100000 pid=4144 /usr/bin/sudo net guuid=e018ee4e-1900-0000-0e4d-559a2d100000 pid=4141->guuid=75c4cd4f-1900-0000-0e4d-559a30100000 pid=4144 execve guuid=91c16054-1900-0000-0e4d-559a40100000 pid=4160 /usr/bin/sudo net guuid=e018ee4e-1900-0000-0e4d-559a2d100000 pid=4141->guuid=91c16054-1900-0000-0e4d-559a40100000 pid=4160 execve guuid=07c1e05a-1900-0000-0e4d-559a5b100000 pid=4187 /usr/bin/sudo net guuid=e018ee4e-1900-0000-0e4d-559a2d100000 pid=4141->guuid=07c1e05a-1900-0000-0e4d-559a5b100000 pid=4187 execve guuid=528aba5e-1900-0000-0e4d-559a6e100000 pid=4206 /usr/bin/sudo net guuid=e018ee4e-1900-0000-0e4d-559a2d100000 pid=4141->guuid=528aba5e-1900-0000-0e4d-559a6e100000 pid=4206 execve guuid=9b2a6c62-1900-0000-0e4d-559a82100000 pid=4226 /usr/bin/sudo net guuid=e018ee4e-1900-0000-0e4d-559a2d100000 pid=4141->guuid=9b2a6c62-1900-0000-0e4d-559a82100000 pid=4226 execve guuid=e1489466-1900-0000-0e4d-559a9b100000 pid=4251 /usr/bin/sudo net guuid=e018ee4e-1900-0000-0e4d-559a2d100000 pid=4141->guuid=e1489466-1900-0000-0e4d-559a9b100000 pid=4251 execve guuid=b2f99f6a-1900-0000-0e4d-559ab2100000 pid=4274 /usr/bin/killall guuid=e018ee4e-1900-0000-0e4d-559a2d100000 pid=4141->guuid=b2f99f6a-1900-0000-0e4d-559ab2100000 pid=4274 execve guuid=4cab486b-1900-0000-0e4d-559ab7100000 pid=4279 /usr/bin/pgrep guuid=e018ee4e-1900-0000-0e4d-559a2d100000 pid=4141->guuid=4cab486b-1900-0000-0e4d-559ab7100000 pid=4279 execve guuid=af1ab46d-1900-0000-0e4d-559ac0100000 pid=4288 /usr/bin/pgrep guuid=e018ee4e-1900-0000-0e4d-559a2d100000 pid=4141->guuid=af1ab46d-1900-0000-0e4d-559ac0100000 pid=4288 execve guuid=52e5c871-1900-0000-0e4d-559ad3100000 pid=4307 /usr/bin/pgrep guuid=e018ee4e-1900-0000-0e4d-559a2d100000 pid=4141->guuid=52e5c871-1900-0000-0e4d-559ad3100000 pid=4307 execve guuid=f6621278-1900-0000-0e4d-559ae7100000 pid=4327 /usr/bin/pgrep guuid=e018ee4e-1900-0000-0e4d-559a2d100000 pid=4141->guuid=f6621278-1900-0000-0e4d-559ae7100000 pid=4327 execve guuid=d3bcc37b-1900-0000-0e4d-559af0100000 pid=4336 /usr/bin/pgrep guuid=e018ee4e-1900-0000-0e4d-559a2d100000 pid=4141->guuid=d3bcc37b-1900-0000-0e4d-559af0100000 pid=4336 execve guuid=02b5877f-1900-0000-0e4d-559afe100000 pid=4350 /usr/bin/systemctl guuid=e018ee4e-1900-0000-0e4d-559a2d100000 pid=4141->guuid=02b5877f-1900-0000-0e4d-559afe100000 pid=4350 execve guuid=232d0782-1900-0000-0e4d-559a03110000 pid=4355 /usr/bin/systemctl guuid=e018ee4e-1900-0000-0e4d-559a2d100000 pid=4141->guuid=232d0782-1900-0000-0e4d-559a03110000 pid=4355 execve guuid=14f9ad83-1900-0000-0e4d-559a08110000 pid=4360 /usr/bin/ls guuid=e018ee4e-1900-0000-0e4d-559a2d100000 pid=4141->guuid=14f9ad83-1900-0000-0e4d-559a08110000 pid=4360 execve guuid=56bc8484-1900-0000-0e4d-559a0b110000 pid=4363 /usr/bin/ls guuid=e018ee4e-1900-0000-0e4d-559a2d100000 pid=4141->guuid=56bc8484-1900-0000-0e4d-559a0b110000 pid=4363 execve guuid=a7461885-1900-0000-0e4d-559a0d110000 pid=4365 /usr/bin/ls guuid=e018ee4e-1900-0000-0e4d-559a2d100000 pid=4141->guuid=a7461885-1900-0000-0e4d-559a0d110000 pid=4365 execve guuid=fbb64886-1900-0000-0e4d-559a0f110000 pid=4367 /usr/bin/ls guuid=e018ee4e-1900-0000-0e4d-559a2d100000 pid=4141->guuid=fbb64886-1900-0000-0e4d-559a0f110000 pid=4367 execve guuid=f8afe386-1900-0000-0e4d-559a11110000 pid=4369 /usr/bin/ls guuid=e018ee4e-1900-0000-0e4d-559a2d100000 pid=4141->guuid=f8afe386-1900-0000-0e4d-559a11110000 pid=4369 execve guuid=d20aaa87-1900-0000-0e4d-559a13110000 pid=4371 /usr/bin/ls guuid=e018ee4e-1900-0000-0e4d-559a2d100000 pid=4141->guuid=d20aaa87-1900-0000-0e4d-559a13110000 pid=4371 execve guuid=e56ba488-1900-0000-0e4d-559a17110000 pid=4375 /usr/bin/ls guuid=e018ee4e-1900-0000-0e4d-559a2d100000 pid=4141->guuid=e56ba488-1900-0000-0e4d-559a17110000 pid=4375 execve guuid=0f5e608a-1900-0000-0e4d-559a1d110000 pid=4381 /usr/bin/ls guuid=e018ee4e-1900-0000-0e4d-559a2d100000 pid=4141->guuid=0f5e608a-1900-0000-0e4d-559a1d110000 pid=4381 execve guuid=b09be98a-1900-0000-0e4d-559a1f110000 pid=4383 /usr/bin/ls guuid=e018ee4e-1900-0000-0e4d-559a2d100000 pid=4141->guuid=b09be98a-1900-0000-0e4d-559a1f110000 pid=4383 execve guuid=a1108a8b-1900-0000-0e4d-559a21110000 pid=4385 /usr/bin/ls guuid=e018ee4e-1900-0000-0e4d-559a2d100000 pid=4141->guuid=a1108a8b-1900-0000-0e4d-559a21110000 pid=4385 execve guuid=c6e7578c-1900-0000-0e4d-559a24110000 pid=4388 /usr/bin/ls guuid=e018ee4e-1900-0000-0e4d-559a2d100000 pid=4141->guuid=c6e7578c-1900-0000-0e4d-559a24110000 pid=4388 execve guuid=c1ca158d-1900-0000-0e4d-559a25110000 pid=4389 /usr/bin/ls guuid=e018ee4e-1900-0000-0e4d-559a2d100000 pid=4141->guuid=c1ca158d-1900-0000-0e4d-559a25110000 pid=4389 execve guuid=1d0ad78d-1900-0000-0e4d-559a29110000 pid=4393 /usr/bin/ls guuid=e018ee4e-1900-0000-0e4d-559a2d100000 pid=4141->guuid=1d0ad78d-1900-0000-0e4d-559a29110000 pid=4393 execve guuid=3c4a7e8e-1900-0000-0e4d-559a2a110000 pid=4394 /usr/bin/ls guuid=e018ee4e-1900-0000-0e4d-559a2d100000 pid=4141->guuid=3c4a7e8e-1900-0000-0e4d-559a2a110000 pid=4394 execve guuid=fde0108f-1900-0000-0e4d-559a2c110000 pid=4396 /usr/bin/ls guuid=e018ee4e-1900-0000-0e4d-559a2d100000 pid=4141->guuid=fde0108f-1900-0000-0e4d-559a2c110000 pid=4396 execve guuid=80b2868f-1900-0000-0e4d-559a2e110000 pid=4398 /usr/bin/ls guuid=e018ee4e-1900-0000-0e4d-559a2d100000 pid=4141->guuid=80b2868f-1900-0000-0e4d-559a2e110000 pid=4398 execve guuid=b4d6e48f-1900-0000-0e4d-559a2f110000 pid=4399 /usr/bin/ls guuid=e018ee4e-1900-0000-0e4d-559a2d100000 pid=4141->guuid=b4d6e48f-1900-0000-0e4d-559a2f110000 pid=4399 execve guuid=dbfa4490-1900-0000-0e4d-559a33110000 pid=4403 /usr/bin/ls guuid=e018ee4e-1900-0000-0e4d-559a2d100000 pid=4141->guuid=dbfa4490-1900-0000-0e4d-559a33110000 pid=4403 execve guuid=7b1ad790-1900-0000-0e4d-559a36110000 pid=4406 /usr/bin/ls guuid=e018ee4e-1900-0000-0e4d-559a2d100000 pid=4141->guuid=7b1ad790-1900-0000-0e4d-559a36110000 pid=4406 execve guuid=c5144491-1900-0000-0e4d-559a38110000 pid=4408 /usr/bin/ls guuid=e018ee4e-1900-0000-0e4d-559a2d100000 pid=4141->guuid=c5144491-1900-0000-0e4d-559a38110000 pid=4408 execve guuid=cd0cb091-1900-0000-0e4d-559a39110000 pid=4409 /usr/bin/ls guuid=e018ee4e-1900-0000-0e4d-559a2d100000 pid=4141->guuid=cd0cb091-1900-0000-0e4d-559a39110000 pid=4409 execve guuid=91042092-1900-0000-0e4d-559a3c110000 pid=4412 /usr/bin/ls guuid=e018ee4e-1900-0000-0e4d-559a2d100000 pid=4141->guuid=91042092-1900-0000-0e4d-559a3c110000 pid=4412 execve guuid=ec49a292-1900-0000-0e4d-559a40110000 pid=4416 /usr/bin/ls guuid=e018ee4e-1900-0000-0e4d-559a2d100000 pid=4141->guuid=ec49a292-1900-0000-0e4d-559a40110000 pid=4416 execve guuid=93620593-1900-0000-0e4d-559a44110000 pid=4420 /usr/bin/ls guuid=e018ee4e-1900-0000-0e4d-559a2d100000 pid=4141->guuid=93620593-1900-0000-0e4d-559a44110000 pid=4420 execve guuid=cca56d93-1900-0000-0e4d-559a47110000 pid=4423 /usr/bin/ls guuid=e018ee4e-1900-0000-0e4d-559a2d100000 pid=4141->guuid=cca56d93-1900-0000-0e4d-559a47110000 pid=4423 execve guuid=68ded093-1900-0000-0e4d-559a49110000 pid=4425 /usr/bin/ls guuid=e018ee4e-1900-0000-0e4d-559a2d100000 pid=4141->guuid=68ded093-1900-0000-0e4d-559a49110000 pid=4425 execve guuid=43de3494-1900-0000-0e4d-559a4b110000 pid=4427 /usr/bin/ls guuid=e018ee4e-1900-0000-0e4d-559a2d100000 pid=4141->guuid=43de3494-1900-0000-0e4d-559a4b110000 pid=4427 execve guuid=8d219394-1900-0000-0e4d-559a4d110000 pid=4429 /usr/bin/ls guuid=e018ee4e-1900-0000-0e4d-559a2d100000 pid=4141->guuid=8d219394-1900-0000-0e4d-559a4d110000 pid=4429 execve guuid=da70fa94-1900-0000-0e4d-559a50110000 pid=4432 /usr/bin/ls guuid=e018ee4e-1900-0000-0e4d-559a2d100000 pid=4141->guuid=da70fa94-1900-0000-0e4d-559a50110000 pid=4432 execve guuid=7ee65d95-1900-0000-0e4d-559a54110000 pid=4436 /usr/bin/ls guuid=e018ee4e-1900-0000-0e4d-559a2d100000 pid=4141->guuid=7ee65d95-1900-0000-0e4d-559a54110000 pid=4436 execve guuid=0030bf95-1900-0000-0e4d-559a55110000 pid=4437 /usr/bin/ls guuid=e018ee4e-1900-0000-0e4d-559a2d100000 pid=4141->guuid=0030bf95-1900-0000-0e4d-559a55110000 pid=4437 execve guuid=796f2896-1900-0000-0e4d-559a59110000 pid=4441 /usr/bin/ls guuid=e018ee4e-1900-0000-0e4d-559a2d100000 pid=4141->guuid=796f2896-1900-0000-0e4d-559a59110000 pid=4441 execve guuid=72348396-1900-0000-0e4d-559a5d110000 pid=4445 /usr/bin/ls guuid=e018ee4e-1900-0000-0e4d-559a2d100000 pid=4141->guuid=72348396-1900-0000-0e4d-559a5d110000 pid=4445 execve guuid=102fe096-1900-0000-0e4d-559a61110000 pid=4449 /usr/bin/systemctl guuid=e018ee4e-1900-0000-0e4d-559a2d100000 pid=4141->guuid=102fe096-1900-0000-0e4d-559a61110000 pid=4449 execve guuid=2ac2b53c-1a00-0000-0e4d-559a9e130000 pid=5022 /usr/bin/mount write-file guuid=e018ee4e-1900-0000-0e4d-559a2d100000 pid=4141->guuid=2ac2b53c-1a00-0000-0e4d-559a9e130000 pid=5022 execve guuid=f30a703e-1a00-0000-0e4d-559aa6130000 pid=5030 /usr/bin/rm delete-file guuid=e018ee4e-1900-0000-0e4d-559a2d100000 pid=4141->guuid=f30a703e-1a00-0000-0e4d-559aa6130000 pid=5030 execve guuid=86191541-1a00-0000-0e4d-559ab2130000 pid=5042 /usr/bin/rm delete-file guuid=e018ee4e-1900-0000-0e4d-559a2d100000 pid=4141->guuid=86191541-1a00-0000-0e4d-559ab2130000 pid=5042 execve guuid=633b5441-1a00-0000-0e4d-559ab4130000 pid=5044 /usr/bin/rm delete-file guuid=e018ee4e-1900-0000-0e4d-559a2d100000 pid=4141->guuid=633b5441-1a00-0000-0e4d-559ab4130000 pid=5044 execve guuid=3d3c9241-1a00-0000-0e4d-559ab6130000 pid=5046 /usr/bin/rm delete-file guuid=e018ee4e-1900-0000-0e4d-559a2d100000 pid=4141->guuid=3d3c9241-1a00-0000-0e4d-559ab6130000 pid=5046 execve guuid=bff3e041-1a00-0000-0e4d-559ab9130000 pid=5049 /usr/bin/rm delete-file guuid=e018ee4e-1900-0000-0e4d-559a2d100000 pid=4141->guuid=bff3e041-1a00-0000-0e4d-559ab9130000 pid=5049 execve guuid=71021e42-1a00-0000-0e4d-559abb130000 pid=5051 /usr/bin/rm delete-file guuid=e018ee4e-1900-0000-0e4d-559a2d100000 pid=4141->guuid=71021e42-1a00-0000-0e4d-559abb130000 pid=5051 execve guuid=b3785e42-1a00-0000-0e4d-559abd130000 pid=5053 /usr/bin/rm delete-file guuid=e018ee4e-1900-0000-0e4d-559a2d100000 pid=4141->guuid=b3785e42-1a00-0000-0e4d-559abd130000 pid=5053 execve guuid=b24c9b42-1a00-0000-0e4d-559abf130000 pid=5055 /usr/bin/rm delete-file guuid=e018ee4e-1900-0000-0e4d-559a2d100000 pid=4141->guuid=b24c9b42-1a00-0000-0e4d-559abf130000 pid=5055 execve guuid=a9b6db42-1a00-0000-0e4d-559ac1130000 pid=5057 /usr/bin/rm delete-file guuid=e018ee4e-1900-0000-0e4d-559a2d100000 pid=4141->guuid=a9b6db42-1a00-0000-0e4d-559ac1130000 pid=5057 execve guuid=559f1843-1a00-0000-0e4d-559ac3130000 pid=5059 /usr/bin/rm delete-file guuid=e018ee4e-1900-0000-0e4d-559a2d100000 pid=4141->guuid=559f1843-1a00-0000-0e4d-559ac3130000 pid=5059 execve guuid=5de56643-1a00-0000-0e4d-559ac6130000 pid=5062 /usr/bin/rm delete-file guuid=e018ee4e-1900-0000-0e4d-559a2d100000 pid=4141->guuid=5de56643-1a00-0000-0e4d-559ac6130000 pid=5062 execve guuid=5bddb343-1a00-0000-0e4d-559ac8130000 pid=5064 /usr/bin/rm delete-file guuid=e018ee4e-1900-0000-0e4d-559a2d100000 pid=4141->guuid=5bddb343-1a00-0000-0e4d-559ac8130000 pid=5064 execve guuid=a5e1f043-1a00-0000-0e4d-559aca130000 pid=5066 /usr/bin/rm delete-file guuid=e018ee4e-1900-0000-0e4d-559a2d100000 pid=4141->guuid=a5e1f043-1a00-0000-0e4d-559aca130000 pid=5066 execve guuid=29d82c44-1a00-0000-0e4d-559acc130000 pid=5068 /usr/bin/mkdir guuid=e018ee4e-1900-0000-0e4d-559a2d100000 pid=4141->guuid=29d82c44-1a00-0000-0e4d-559acc130000 pid=5068 execve guuid=da767444-1a00-0000-0e4d-559ace130000 pid=5070 /usr/bin/dash guuid=e018ee4e-1900-0000-0e4d-559a2d100000 pid=4141->guuid=da767444-1a00-0000-0e4d-559ace130000 pid=5070 clone guuid=852aca44-1a00-0000-0e4d-559ad2130000 pid=5074 /usr/bin/rm guuid=e018ee4e-1900-0000-0e4d-559a2d100000 pid=4141->guuid=852aca44-1a00-0000-0e4d-559ad2130000 pid=5074 execve guuid=f0750245-1a00-0000-0e4d-559ad4130000 pid=5076 /usr/bin/wget net send-data write-file guuid=e018ee4e-1900-0000-0e4d-559a2d100000 pid=4141->guuid=f0750245-1a00-0000-0e4d-559ad4130000 pid=5076 execve guuid=de22ed62-1a00-0000-0e4d-559a4a140000 pid=5194 /usr/bin/cat guuid=e018ee4e-1900-0000-0e4d-559a2d100000 pid=4141->guuid=de22ed62-1a00-0000-0e4d-559a4a140000 pid=5194 execve guuid=9f024363-1a00-0000-0e4d-559a4c140000 pid=5196 /usr/bin/rm delete-file guuid=e018ee4e-1900-0000-0e4d-559a2d100000 pid=4141->guuid=9f024363-1a00-0000-0e4d-559a4c140000 pid=5196 execve guuid=b3258b63-1a00-0000-0e4d-559a4e140000 pid=5198 /usr/bin/chmod guuid=e018ee4e-1900-0000-0e4d-559a2d100000 pid=4141->guuid=b3258b63-1a00-0000-0e4d-559a4e140000 pid=5198 execve guuid=96bad663-1a00-0000-0e4d-559a50140000 pid=5200 /usr/bin/sudo net guuid=e018ee4e-1900-0000-0e4d-559a2d100000 pid=4141->guuid=96bad663-1a00-0000-0e4d-559a50140000 pid=5200 execve guuid=3a0f6966-1a00-0000-0e4d-559a5a140000 pid=5210 /usr/bin/sudo net guuid=e018ee4e-1900-0000-0e4d-559a2d100000 pid=4141->guuid=3a0f6966-1a00-0000-0e4d-559a5a140000 pid=5210 execve guuid=e9e85b6a-1a00-0000-0e4d-559a65140000 pid=5221 /usr/bin/killall guuid=e018ee4e-1900-0000-0e4d-559a2d100000 pid=4141->guuid=e9e85b6a-1a00-0000-0e4d-559a65140000 pid=5221 execve guuid=cb0a316b-1a00-0000-0e4d-559a69140000 pid=5225 /usr/bin/pgrep guuid=e018ee4e-1900-0000-0e4d-559a2d100000 pid=4141->guuid=cb0a316b-1a00-0000-0e4d-559a69140000 pid=5225 execve guuid=c35a036e-1a00-0000-0e4d-559a74140000 pid=5236 /usr/bin/sudo net guuid=e018ee4e-1900-0000-0e4d-559a2d100000 pid=4141->guuid=c35a036e-1a00-0000-0e4d-559a74140000 pid=5236 execve 0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 10.0.2.15:0 guuid=75c4cd4f-1900-0000-0e4d-559a30100000 pid=4144->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con 558177e1-1f18-5f39-990b-d68b1c194e8a fec0::5054:ff:fe12:3456:0 guuid=75c4cd4f-1900-0000-0e4d-559a30100000 pid=4144->558177e1-1f18-5f39-990b-d68b1c194e8a con cbc59886-1795-52e1-b014-449ae22fd09b fe80::5054:ff:fe12:3456:0 guuid=75c4cd4f-1900-0000-0e4d-559a30100000 pid=4144->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=62961c52-1900-0000-0e4d-559a39100000 pid=4153 /usr/bin/killall guuid=75c4cd4f-1900-0000-0e4d-559a30100000 pid=4144->guuid=62961c52-1900-0000-0e4d-559a39100000 pid=4153 execve guuid=91c16054-1900-0000-0e4d-559a40100000 pid=4160->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con guuid=91c16054-1900-0000-0e4d-559a40100000 pid=4160->558177e1-1f18-5f39-990b-d68b1c194e8a con guuid=91c16054-1900-0000-0e4d-559a40100000 pid=4160->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=ad12b756-1900-0000-0e4d-559a4a100000 pid=4170 /usr/bin/pgrep guuid=91c16054-1900-0000-0e4d-559a40100000 pid=4160->guuid=ad12b756-1900-0000-0e4d-559a4a100000 pid=4170 execve guuid=07c1e05a-1900-0000-0e4d-559a5b100000 pid=4187->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con guuid=07c1e05a-1900-0000-0e4d-559a5b100000 pid=4187->558177e1-1f18-5f39-990b-d68b1c194e8a con guuid=07c1e05a-1900-0000-0e4d-559a5b100000 pid=4187->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=4d1f355c-1900-0000-0e4d-559a61100000 pid=4193 /usr/bin/pgrep guuid=07c1e05a-1900-0000-0e4d-559a5b100000 pid=4187->guuid=4d1f355c-1900-0000-0e4d-559a61100000 pid=4193 execve guuid=528aba5e-1900-0000-0e4d-559a6e100000 pid=4206->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con guuid=528aba5e-1900-0000-0e4d-559a6e100000 pid=4206->558177e1-1f18-5f39-990b-d68b1c194e8a con guuid=528aba5e-1900-0000-0e4d-559a6e100000 pid=4206->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=c8220060-1900-0000-0e4d-559a75100000 pid=4213 /usr/bin/pgrep guuid=528aba5e-1900-0000-0e4d-559a6e100000 pid=4206->guuid=c8220060-1900-0000-0e4d-559a75100000 pid=4213 execve guuid=9b2a6c62-1900-0000-0e4d-559a82100000 pid=4226->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con guuid=9b2a6c62-1900-0000-0e4d-559a82100000 pid=4226->558177e1-1f18-5f39-990b-d68b1c194e8a con guuid=9b2a6c62-1900-0000-0e4d-559a82100000 pid=4226->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=94a1c863-1900-0000-0e4d-559a8a100000 pid=4234 /usr/bin/pgrep guuid=9b2a6c62-1900-0000-0e4d-559a82100000 pid=4226->guuid=94a1c863-1900-0000-0e4d-559a8a100000 pid=4234 execve guuid=e1489466-1900-0000-0e4d-559a9b100000 pid=4251->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con guuid=e1489466-1900-0000-0e4d-559a9b100000 pid=4251->558177e1-1f18-5f39-990b-d68b1c194e8a con guuid=e1489466-1900-0000-0e4d-559a9b100000 pid=4251->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=9a15f967-1900-0000-0e4d-559aa4100000 pid=4260 /usr/bin/pgrep guuid=e1489466-1900-0000-0e4d-559a9b100000 pid=4251->guuid=9a15f967-1900-0000-0e4d-559aa4100000 pid=4260 execve guuid=b7a91f97-1900-0000-0e4d-559a62110000 pid=4450 /usr/bin/basename guuid=102fe096-1900-0000-0e4d-559a61110000 pid=4449->guuid=b7a91f97-1900-0000-0e4d-559a62110000 pid=4450 execve guuid=a48b5e97-1900-0000-0e4d-559a66110000 pid=4454 /usr/bin/basename guuid=102fe096-1900-0000-0e4d-559a61110000 pid=4449->guuid=a48b5e97-1900-0000-0e4d-559a66110000 pid=4454 execve guuid=caee9e97-1900-0000-0e4d-559a68110000 pid=4456 /usr/bin/dash guuid=102fe096-1900-0000-0e4d-559a61110000 pid=4449->guuid=caee9e97-1900-0000-0e4d-559a68110000 pid=4456 clone guuid=4fd7a497-1900-0000-0e4d-559a69110000 pid=4457 /usr/bin/systemctl guuid=caee9e97-1900-0000-0e4d-559a68110000 pid=4456->guuid=4fd7a497-1900-0000-0e4d-559a69110000 pid=4457 execve guuid=f6aba997-1900-0000-0e4d-559a6a110000 pid=4458 /usr/bin/sed guuid=caee9e97-1900-0000-0e4d-559a68110000 pid=4456->guuid=f6aba997-1900-0000-0e4d-559a6a110000 pid=4458 execve guuid=98187b44-1a00-0000-0e4d-559ad0130000 pid=5072 /usr/bin/chmod guuid=da767444-1a00-0000-0e4d-559ace130000 pid=5070->guuid=98187b44-1a00-0000-0e4d-559ad0130000 pid=5072 execve 723b36fb-85d9-5b1d-80ec-f5ebefab4936 41.231.37.153:80 guuid=f0750245-1a00-0000-0e4d-559ad4130000 pid=5076->723b36fb-85d9-5b1d-80ec-f5ebefab4936 send: 140B guuid=96bad663-1a00-0000-0e4d-559a50140000 pid=5200->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con guuid=96bad663-1a00-0000-0e4d-559a50140000 pid=5200->558177e1-1f18-5f39-990b-d68b1c194e8a con guuid=96bad663-1a00-0000-0e4d-559a50140000 pid=5200->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=fb978865-1a00-0000-0e4d-559a58140000 pid=5208 /usr/bin/killall guuid=96bad663-1a00-0000-0e4d-559a50140000 pid=5200->guuid=fb978865-1a00-0000-0e4d-559a58140000 pid=5208 execve guuid=3a0f6966-1a00-0000-0e4d-559a5a140000 pid=5210->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con guuid=3a0f6966-1a00-0000-0e4d-559a5a140000 pid=5210->558177e1-1f18-5f39-990b-d68b1c194e8a con guuid=3a0f6966-1a00-0000-0e4d-559a5a140000 pid=5210->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=f998d467-1a00-0000-0e4d-559a5e140000 pid=5214 /usr/bin/pgrep guuid=3a0f6966-1a00-0000-0e4d-559a5a140000 pid=5210->guuid=f998d467-1a00-0000-0e4d-559a5e140000 pid=5214 execve guuid=c35a036e-1a00-0000-0e4d-559a74140000 pid=5236->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con guuid=c35a036e-1a00-0000-0e4d-559a74140000 pid=5236->558177e1-1f18-5f39-990b-d68b1c194e8a con guuid=c35a036e-1a00-0000-0e4d-559a74140000 pid=5236->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=b7af436f-1a00-0000-0e4d-559a7a140000 pid=5242 /usr/bin/lib/rondo guuid=c35a036e-1a00-0000-0e4d-559a74140000 pid=5236->guuid=b7af436f-1a00-0000-0e4d-559a7a140000 pid=5242 execve guuid=327e586f-1a00-0000-0e4d-559a7b140000 pid=5243 /usr/bin/lib/rondo write-file zombie guuid=b7af436f-1a00-0000-0e4d-559a7a140000 pid=5242->guuid=327e586f-1a00-0000-0e4d-559a7b140000 pid=5243 clone guuid=78f16d6f-1a00-0000-0e4d-559a7c140000 pid=5244 /usr/bin/lib/rondo write-file zombie guuid=327e586f-1a00-0000-0e4d-559a7b140000 pid=5243->guuid=78f16d6f-1a00-0000-0e4d-559a7c140000 pid=5244 clone guuid=d1b0dd6f-1a00-0000-0e4d-559a7e140000 pid=5246 /usr/lib/systemd/scjbcqy delete-file net send-data write-config write-file zombie guuid=78f16d6f-1a00-0000-0e4d-559a7c140000 pid=5244->guuid=d1b0dd6f-1a00-0000-0e4d-559a7e140000 pid=5246 clone guuid=d1b0dd6f-1a00-0000-0e4d-559a7e140000 pid=5246->723b36fb-85d9-5b1d-80ec-f5ebefab4936 send: 91B c6d3c8d1-ccce-5272-b764-c5a3ff34618d 45.94.31.89:8443 guuid=d1b0dd6f-1a00-0000-0e4d-559a7e140000 pid=5246->c6d3c8d1-ccce-5272-b764-c5a3ff34618d con guuid=5fd25870-1a00-0000-0e4d-559a81140000 pid=5249 /usr/lib/systemd/scjbcqy write-file guuid=d1b0dd6f-1a00-0000-0e4d-559a7e140000 pid=5246->guuid=5fd25870-1a00-0000-0e4d-559a81140000 pid=5249 clone guuid=41a8a470-1a00-0000-0e4d-559a85140000 pid=5253 /usr/lib/systemd/scjbcqy write-file guuid=d1b0dd6f-1a00-0000-0e4d-559a7e140000 pid=5246->guuid=41a8a470-1a00-0000-0e4d-559a85140000 pid=5253 clone guuid=ba6ea770-1a00-0000-0e4d-559a86140000 pid=5254 /usr/lib/systemd/scjbcqy write-file guuid=d1b0dd6f-1a00-0000-0e4d-559a7e140000 pid=5246->guuid=ba6ea770-1a00-0000-0e4d-559a86140000 pid=5254 clone guuid=7ceef7a5-1a00-0000-0e4d-559acb140000 pid=5323 /usr/lib/systemd/scjbcqy write-file guuid=d1b0dd6f-1a00-0000-0e4d-559a7e140000 pid=5246->guuid=7ceef7a5-1a00-0000-0e4d-559acb140000 pid=5323 clone guuid=872c6f70-1a00-0000-0e4d-559a82140000 pid=5250 /usr/bin/dash guuid=5fd25870-1a00-0000-0e4d-559a81140000 pid=5249->guuid=872c6f70-1a00-0000-0e4d-559a82140000 pid=5250 execve guuid=3b5e9a70-1a00-0000-0e4d-559a84140000 pid=5252 /usr/bin/systemctl guuid=872c6f70-1a00-0000-0e4d-559a82140000 pid=5250->guuid=3b5e9a70-1a00-0000-0e4d-559a84140000 pid=5252 execve guuid=9fcea571-1a00-0000-0e4d-559a8a140000 pid=5258 /usr/bin/systemctl guuid=872c6f70-1a00-0000-0e4d-559a82140000 pid=5250->guuid=9fcea571-1a00-0000-0e4d-559a8a140000 pid=5258 execve guuid=8d8fb172-1a00-0000-0e4d-559a90140000 pid=5264 /usr/sbin/update-rc.d guuid=872c6f70-1a00-0000-0e4d-559a82140000 pid=5250->guuid=8d8fb172-1a00-0000-0e4d-559a90140000 pid=5264 execve guuid=a86706a6-1a00-0000-0e4d-559acc140000 pid=5324 /usr/bin/dash guuid=7ceef7a5-1a00-0000-0e4d-559acb140000 pid=5323->guuid=a86706a6-1a00-0000-0e4d-559acc140000 pid=5324 execve guuid=3bfe33a6-1a00-0000-0e4d-559acd140000 pid=5325 /usr/bin/softirq mprotect-exec guuid=a86706a6-1a00-0000-0e4d-559acc140000 pid=5324->guuid=3bfe33a6-1a00-0000-0e4d-559acd140000 pid=5325 execve guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5326 /usr/bin/softirq net send-data zombie guuid=3bfe33a6-1a00-0000-0e4d-559acd140000 pid=5325->guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5326 clone 5b4f37ef-41f0-5901-b8f0-5c79c4d5f639 45.94.31.89:443 guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5326->5b4f37ef-41f0-5901-b8f0-5c79c4d5f639 send: 862B guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5327 /usr/bin/softirq write-file zombie guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5326->guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5327 clone guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5328 /usr/bin/softirq zombie guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5326->guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5328 clone guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5329 /usr/bin/softirq zombie guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5326->guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5329 clone guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5330 /usr/bin/softirq zombie guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5326->guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5330 clone guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5331 /usr/bin/softirq zombie guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5326->guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5331 clone guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5332 /usr/bin/softirq zombie guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5326->guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5332 clone guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5333 /usr/bin/softirq zombie guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5326->guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5333 clone guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5334 /usr/bin/softirq zombie guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5326->guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5334 clone guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5335 /usr/bin/softirq zombie guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5326->guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5335 clone guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5336 /usr/bin/softirq zombie guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5326->guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5336 clone guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5337 /usr/bin/softirq zombie guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5326->guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5337 clone guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5338 /usr/bin/softirq zombie guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5326->guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5338 clone guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5339 /usr/bin/softirq zombie guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5326->guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5339 clone guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5340 /usr/bin/softirq zombie guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5326->guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5340 clone guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5341 /usr/bin/softirq zombie guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5326->guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5341 clone guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5342 /usr/bin/softirq zombie guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5326->guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5342 clone guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5343 /usr/bin/softirq zombie guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5326->guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5343 clone guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5344 /usr/bin/softirq zombie guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5326->guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5344 clone guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5345 /usr/bin/softirq zombie guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5326->guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5345 clone guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5346 /usr/bin/softirq zombie guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5326->guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5346 clone guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5347 /usr/bin/softirq zombie guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5326->guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5347 clone guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5348 /usr/bin/softirq zombie guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5326->guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5348 clone guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5349 /usr/bin/softirq zombie guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5326->guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5349 clone guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5350 /usr/bin/softirq zombie guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5326->guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5350 clone guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5351 /usr/bin/softirq zombie guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5326->guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5351 clone guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5352 /usr/bin/softirq zombie guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5326->guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5352 clone guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5353 /usr/bin/softirq zombie guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5326->guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5353 clone guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5354 /usr/bin/softirq zombie guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5326->guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5354 clone guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5355 /usr/bin/softirq zombie guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5326->guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5355 clone guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5356 /usr/bin/softirq zombie guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5326->guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5356 clone guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5357 /usr/bin/softirq zombie guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5326->guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5357 clone guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5358 /usr/bin/softirq zombie guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5326->guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5358 clone guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5359 /usr/bin/softirq zombie guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5326->guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5359 clone guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5360 /usr/bin/softirq zombie guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5326->guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5360 clone guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5361 /usr/bin/softirq zombie guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5326->guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5361 clone guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5362 /usr/bin/softirq zombie guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5326->guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5362 clone guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5363 /usr/bin/softirq zombie guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5326->guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5363 clone guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5364 /usr/bin/softirq zombie guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5326->guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5364 clone guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5365 /usr/bin/softirq zombie guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5326->guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5365 clone guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5366 /usr/bin/softirq zombie guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5326->guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5366 clone guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5367 /usr/bin/softirq zombie guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5326->guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5367 clone guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5368 /usr/bin/softirq zombie guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5326->guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5368 clone guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5369 /usr/bin/softirq zombie guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5326->guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5369 clone guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5370 /usr/bin/softirq zombie guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5326->guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5370 clone guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5371 /usr/bin/softirq zombie guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5326->guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5371 clone guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5372 /usr/bin/softirq zombie guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5326->guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5372 clone guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5373 /usr/bin/softirq zombie guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5326->guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5373 clone guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5374 /usr/bin/softirq zombie guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5326->guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5374 clone guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5375 /usr/bin/softirq zombie guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5326->guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5375 clone guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5376 /usr/bin/softirq zombie guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5326->guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5376 clone guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5377 /usr/bin/softirq zombie guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5326->guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5377 clone guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5378 /usr/bin/softirq zombie guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5326->guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5378 clone guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5379 /usr/bin/softirq zombie guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5326->guuid=e743b8a8-1a00-0000-0e4d-559ace140000 pid=5379 clone
Threat name:
Linux.Trojan.Miner
Status:
Malicious
First seen:
2025-12-20 00:46:13 UTC
File Type:
Text (Shell)
AV detection:
7 of 24 (29.17%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion discovery linux persistence privilege_escalation
Behaviour
Enumerates kernel/hardware configuration
Reads runtime system information
Writes file to shm directory
Writes file to tmp directory
Reads CPU attributes
Write file to user bin folder
Writes file to system bin folder
Abuse Elevation Control Mechanism: Sudo and Sudo Caching
Deletes log files
Disables AppArmor
Disables SELinux
Enumerates running processes
File and Directory Permissions Modification
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

RondoDox

sh ee3b6aaa1edecd0ed27bcd9ab835ca41735c85263fc8219cc2a9c62f66cad920

(this sample)

  
Delivery method
Distributed via web download

Comments