IOCReport

loading gif

Files

File Path
Type
Category
Malicious
4ljhdTTyiA
ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, not stripped
initial sample
malicious
/etc/cron.hourly/gcc.sh
POSIX shell script, ASCII text executable
dropped
malicious
/etc/crontab
ASCII text
dropped
malicious
/etc/init.d/.depend.boot
ASCII text, with very long lines
dropped
malicious
/etc/init.d/.depend.start
ASCII text, with very long lines
dropped
malicious
/etc/init.d/.depend.stop
ASCII text, with very long lines
dropped
malicious
/etc/init.d/4ljhdTTyiA
POSIX shell script, ASCII text executable
dropped
malicious
/lib/libudev.so
ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, not stripped
dropped
malicious
/usr/bin/aspbnnkmso
ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, not stripped
dropped
malicious
/usr/bin/ctrygxclrx
ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, not stripped
dropped
malicious
/usr/bin/dxeguomyxc
ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, not stripped
dropped
malicious
/usr/bin/fcxqfstrdm
ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, not stripped
dropped
malicious
/usr/bin/gqczobuacc
ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, not stripped
dropped
malicious
/usr/bin/jjltawydwf
ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, not stripped
dropped
malicious
/usr/bin/lgnmbyzzlq
ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, not stripped
dropped
malicious
/usr/bin/nyavevzqtw
ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, not stripped
dropped
malicious
/usr/bin/ouhdchrbdz
ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, not stripped
dropped
malicious
/usr/bin/rlyjyybyum
ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, not stripped
dropped
malicious
/usr/bin/tjdqviitkh
ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, not stripped
dropped
malicious
/usr/bin/uoewtvxqdd
ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, for GNU/Linux 2.6.9, not stripped
dropped
malicious
/etc/sed4RcMLw
ASCII text
dropped
clean
/run/gcc.pid
ASCII text, with no line terminators
dropped
clean
There are 12 hidden files, click here to show them.

Processes

Path
Cmdline
Malicious
/tmp/4ljhdTTyiA
/tmp/4ljhdTTyiA
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/sbin/update-rc.d
/usr/bin/perl /usr/sbin/update-rc.d 4ljhdTTyiA defaults
clean
/usr/sbin/update-rc.d
n/a
clean
/usr/lib/insserv/insserv
/usr/lib/insserv/insserv 4ljhdTTyiA
clean
/usr/sbin/update-rc.d
n/a
clean
/bin/systemctl
systemctl daemon-reload
clean
/tmp/4ljhdTTyiA
n/a
clean
/bin/dash
sh -c "sed -i '/\\/etc\\/cron.hourly\\/gcc.sh/d' /etc/crontab && echo '*/3 * * * * root /etc/cron.hourly/gcc.sh' >> /etc/crontab"
clean
/bin/dash
n/a
clean
/bin/sed
sed -i /\\/etc\\/cron.hourly\\/gcc.sh/d /etc/crontab
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/jjltawydwf
/usr/bin/jjltawydwf "ls -la" 4554
clean
/usr/bin/jjltawydwf
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/jjltawydwf
/usr/bin/jjltawydwf "ifconfig eth0" 4554
clean
/usr/bin/jjltawydwf
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/jjltawydwf
/usr/bin/jjltawydwf "sleep 1" 4554
clean
/usr/bin/jjltawydwf
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/jjltawydwf
/usr/bin/jjltawydwf "ps -ef" 4554
clean
/usr/bin/jjltawydwf
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/jjltawydwf
/usr/bin/jjltawydwf pwd 4554
clean
/usr/bin/jjltawydwf
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/ouhdchrbdz
/usr/bin/ouhdchrbdz sh 4554
clean
/usr/bin/ouhdchrbdz
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/ouhdchrbdz
/usr/bin/ouhdchrbdz whoami 4554
clean
/usr/bin/ouhdchrbdz
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/ouhdchrbdz
/usr/bin/ouhdchrbdz "echo \"find\"" 4554
clean
/usr/bin/ouhdchrbdz
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/ouhdchrbdz
/usr/bin/ouhdchrbdz "netstat -antop" 4554
clean
/usr/bin/ouhdchrbdz
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/ouhdchrbdz
/usr/bin/ouhdchrbdz "grep \"A\"" 4554
clean
/usr/bin/ouhdchrbdz
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/fcxqfstrdm
/usr/bin/fcxqfstrdm "netstat -an" 4554
clean
/usr/bin/fcxqfstrdm
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/fcxqfstrdm
/usr/bin/fcxqfstrdm uptime 4554
clean
/usr/bin/fcxqfstrdm
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/fcxqfstrdm
/usr/bin/fcxqfstrdm pwd 4554
clean
/usr/bin/fcxqfstrdm
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/fcxqfstrdm
/usr/bin/fcxqfstrdm bash 4554
clean
/usr/bin/fcxqfstrdm
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/fcxqfstrdm
/usr/bin/fcxqfstrdm ifconfig 4554
clean
/usr/bin/fcxqfstrdm
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/dxeguomyxc
/usr/bin/dxeguomyxc "sleep 1" 4554
clean
/usr/bin/dxeguomyxc
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/dxeguomyxc
/usr/bin/dxeguomyxc "ifconfig eth0" 4554
clean
/usr/bin/dxeguomyxc
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/dxeguomyxc
/usr/bin/dxeguomyxc "netstat -an" 4554
clean
/usr/bin/dxeguomyxc
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/dxeguomyxc
/usr/bin/dxeguomyxc top 4554
clean
/usr/bin/dxeguomyxc
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/dxeguomyxc
/usr/bin/dxeguomyxc ls 4554
clean
/usr/bin/dxeguomyxc
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/ctrygxclrx
/usr/bin/ctrygxclrx su 4554
clean
/usr/bin/ctrygxclrx
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/ctrygxclrx
/usr/bin/ctrygxclrx "ifconfig eth0" 4554
clean
/usr/bin/ctrygxclrx
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/ctrygxclrx
/usr/bin/ctrygxclrx "netstat -an" 4554
clean
/usr/bin/ctrygxclrx
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/ctrygxclrx
/usr/bin/ctrygxclrx "grep \"A\"" 4554
clean
/usr/bin/ctrygxclrx
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/ctrygxclrx
/usr/bin/ctrygxclrx "sleep 1" 4554
clean
/usr/bin/ctrygxclrx
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/gqczobuacc
/usr/bin/gqczobuacc "grep \"A\"" 4554
clean
/usr/bin/gqczobuacc
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/gqczobuacc
/usr/bin/gqczobuacc "sleep 1" 4554
clean
/usr/bin/gqczobuacc
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/gqczobuacc
/usr/bin/gqczobuacc su 4554
clean
/usr/bin/gqczobuacc
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/gqczobuacc
/usr/bin/gqczobuacc "netstat -an" 4554
clean
/usr/bin/gqczobuacc
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/gqczobuacc
/usr/bin/gqczobuacc "ps -ef" 4554
clean
/usr/bin/gqczobuacc
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/uoewtvxqdd
/usr/bin/uoewtvxqdd "ps -ef" 4554
clean
/usr/bin/uoewtvxqdd
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/uoewtvxqdd
/usr/bin/uoewtvxqdd gnome-terminal 4554
clean
/usr/bin/uoewtvxqdd
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/uoewtvxqdd
/usr/bin/uoewtvxqdd ifconfig 4554
clean
/usr/bin/uoewtvxqdd
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/uoewtvxqdd
/usr/bin/uoewtvxqdd id 4554
clean
/usr/bin/uoewtvxqdd
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/uoewtvxqdd
/usr/bin/uoewtvxqdd "route -n" 4554
clean
/usr/bin/uoewtvxqdd
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/rlyjyybyum
/usr/bin/rlyjyybyum "route -n" 4554
clean
/usr/bin/rlyjyybyum
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/rlyjyybyum
/usr/bin/rlyjyybyum "grep \"A\"" 4554
clean
/usr/bin/rlyjyybyum
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/rlyjyybyum
/usr/bin/rlyjyybyum "ls -la" 4554
clean
/usr/bin/rlyjyybyum
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/rlyjyybyum
/usr/bin/rlyjyybyum "sleep 1" 4554
clean
/usr/bin/rlyjyybyum
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/rlyjyybyum
/usr/bin/rlyjyybyum "cd /etc" 4554
clean
/usr/bin/rlyjyybyum
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/tjdqviitkh
/usr/bin/tjdqviitkh "netstat -antop" 4554
clean
/usr/bin/tjdqviitkh
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/tjdqviitkh
/usr/bin/tjdqviitkh "ps -ef" 4554
clean
/usr/bin/tjdqviitkh
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/tjdqviitkh
/usr/bin/tjdqviitkh "ps -ef" 4554
clean
/usr/bin/tjdqviitkh
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/tjdqviitkh
/usr/bin/tjdqviitkh who 4554
clean
/usr/bin/tjdqviitkh
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/tjdqviitkh
/usr/bin/tjdqviitkh "route -n" 4554
clean
/usr/bin/tjdqviitkh
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/aspbnnkmso
/usr/bin/aspbnnkmso top 4554
clean
/usr/bin/aspbnnkmso
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/aspbnnkmso
/usr/bin/aspbnnkmso whoami 4554
clean
/usr/bin/aspbnnkmso
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/aspbnnkmso
/usr/bin/aspbnnkmso "route -n" 4554
clean
/usr/bin/aspbnnkmso
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/aspbnnkmso
/usr/bin/aspbnnkmso bash 4554
clean
/usr/bin/aspbnnkmso
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/aspbnnkmso
/usr/bin/aspbnnkmso sh 4554
clean
/usr/bin/aspbnnkmso
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/lgnmbyzzlq
/usr/bin/lgnmbyzzlq bash 4554
clean
/usr/bin/lgnmbyzzlq
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/lgnmbyzzlq
/usr/bin/lgnmbyzzlq "sleep 1" 4554
clean
/usr/bin/lgnmbyzzlq
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/lgnmbyzzlq
/usr/bin/lgnmbyzzlq "ps -ef" 4554
clean
/usr/bin/lgnmbyzzlq
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/lgnmbyzzlq
/usr/bin/lgnmbyzzlq bash 4554
clean
/usr/bin/lgnmbyzzlq
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/lgnmbyzzlq
/usr/bin/lgnmbyzzlq ifconfig 4554
clean
/usr/bin/lgnmbyzzlq
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/nyavevzqtw
/usr/bin/nyavevzqtw "netstat -antop" 4554
clean
/usr/bin/nyavevzqtw
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/nyavevzqtw
/usr/bin/nyavevzqtw "cat resolv.conf" 4554
clean
/usr/bin/nyavevzqtw
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/nyavevzqtw
/usr/bin/nyavevzqtw "ls -la" 4554
clean
/usr/bin/nyavevzqtw
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/nyavevzqtw
/usr/bin/nyavevzqtw "ifconfig eth0" 4554
clean
/usr/bin/nyavevzqtw
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/nyavevzqtw
/usr/bin/nyavevzqtw "echo \"find\"" 4554
clean
/usr/bin/nyavevzqtw
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/tstbdpivhl
/usr/bin/tstbdpivhl "echo \"find\"" 4554
clean
/usr/bin/tstbdpivhl
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/tstbdpivhl
/usr/bin/tstbdpivhl "netstat -antop" 4554
clean
/usr/bin/tstbdpivhl
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/tstbdpivhl
/usr/bin/tstbdpivhl "netstat -antop" 4554
clean
/usr/bin/tstbdpivhl
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/tstbdpivhl
/usr/bin/tstbdpivhl "ifconfig eth0" 4554
clean
/usr/bin/tstbdpivhl
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/tstbdpivhl
/usr/bin/tstbdpivhl uptime 4554
clean
/usr/bin/tstbdpivhl
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/lndoiatrux
/usr/bin/lndoiatrux pwd 4554
clean
/usr/bin/lndoiatrux
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/lndoiatrux
/usr/bin/lndoiatrux id 4554
clean
/usr/bin/lndoiatrux
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/lndoiatrux
/usr/bin/lndoiatrux id 4554
clean
/usr/bin/lndoiatrux
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/lndoiatrux
/usr/bin/lndoiatrux "cd /etc" 4554
clean
/usr/bin/lndoiatrux
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/lndoiatrux
/usr/bin/lndoiatrux "grep \"A\"" 4554
clean
/usr/bin/lndoiatrux
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/nefhkhnwwh
/usr/bin/nefhkhnwwh whoami 4554
clean
/usr/bin/nefhkhnwwh
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/nefhkhnwwh
/usr/bin/nefhkhnwwh bash 4554
clean
/usr/bin/nefhkhnwwh
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/nefhkhnwwh
/usr/bin/nefhkhnwwh id 4554
clean
/usr/bin/nefhkhnwwh
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/nefhkhnwwh
/usr/bin/nefhkhnwwh uptime 4554
clean
/usr/bin/nefhkhnwwh
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/nefhkhnwwh
/usr/bin/nefhkhnwwh top 4554
clean
/usr/bin/nefhkhnwwh
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/bjhmdsecwa
/usr/bin/bjhmdsecwa pwd 4554
clean
/usr/bin/bjhmdsecwa
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/bjhmdsecwa
/usr/bin/bjhmdsecwa ifconfig 4554
clean
/usr/bin/bjhmdsecwa
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/bjhmdsecwa
/usr/bin/bjhmdsecwa "ifconfig eth0" 4554
clean
/usr/bin/bjhmdsecwa
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/bjhmdsecwa
/usr/bin/bjhmdsecwa whoami 4554
clean
/usr/bin/bjhmdsecwa
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/bjhmdsecwa
/usr/bin/bjhmdsecwa "route -n" 4554
clean
/usr/bin/bjhmdsecwa
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/otvvhyamws
/usr/bin/otvvhyamws pwd 4554
clean
/usr/bin/otvvhyamws
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/otvvhyamws
/usr/bin/otvvhyamws pwd 4554
clean
/usr/bin/otvvhyamws
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/otvvhyamws
/usr/bin/otvvhyamws ifconfig 4554
clean
/usr/bin/otvvhyamws
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/otvvhyamws
/usr/bin/otvvhyamws uptime 4554
clean
/usr/bin/otvvhyamws
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/otvvhyamws
/usr/bin/otvvhyamws pwd 4554
clean
/usr/bin/otvvhyamws
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/aysistkyqn
/usr/bin/aysistkyqn top 4554
clean
/usr/bin/aysistkyqn
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/aysistkyqn
/usr/bin/aysistkyqn who 4554
clean
/usr/bin/aysistkyqn
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/aysistkyqn
/usr/bin/aysistkyqn id 4554
clean
/usr/bin/aysistkyqn
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/aysistkyqn
/usr/bin/aysistkyqn uptime 4554
clean
/usr/bin/aysistkyqn
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/aysistkyqn
/usr/bin/aysistkyqn "route -n" 4554
clean
/usr/bin/aysistkyqn
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/flwslywqdx
/usr/bin/flwslywqdx uptime 4554
clean
/usr/bin/flwslywqdx
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/flwslywqdx
/usr/bin/flwslywqdx "echo \"find\"" 4554
clean
/usr/bin/flwslywqdx
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/flwslywqdx
/usr/bin/flwslywqdx "echo \"find\"" 4554
clean
/usr/bin/flwslywqdx
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/flwslywqdx
/usr/bin/flwslywqdx bash 4554
clean
/usr/bin/flwslywqdx
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/flwslywqdx
/usr/bin/flwslywqdx ls 4554
clean
/usr/bin/flwslywqdx
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/neofzderab
/usr/bin/neofzderab gnome-terminal 4554
clean
/usr/bin/neofzderab
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/neofzderab
/usr/bin/neofzderab "cat resolv.conf" 4554
clean
/usr/bin/neofzderab
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/neofzderab
/usr/bin/neofzderab "grep \"A\"" 4554
clean
/usr/bin/neofzderab
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/neofzderab
/usr/bin/neofzderab "route -n" 4554
clean
/usr/bin/neofzderab
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/neofzderab
/usr/bin/neofzderab uptime 4554
clean
/usr/bin/neofzderab
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/yxfexdyggl
/usr/bin/yxfexdyggl bash 4554
clean
/usr/bin/yxfexdyggl
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/yxfexdyggl
/usr/bin/yxfexdyggl "ls -la" 4554
clean
/usr/bin/yxfexdyggl
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/yxfexdyggl
/usr/bin/yxfexdyggl "ps -ef" 4554
clean
/usr/bin/yxfexdyggl
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/yxfexdyggl
/usr/bin/yxfexdyggl whoami 4554
clean
/usr/bin/yxfexdyggl
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/yxfexdyggl
/usr/bin/yxfexdyggl ls 4554
clean
/usr/bin/yxfexdyggl
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/taocfwkdjv
/usr/bin/taocfwkdjv sh 4554
clean
/usr/bin/taocfwkdjv
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/taocfwkdjv
/usr/bin/taocfwkdjv "ls -la" 4554
clean
/usr/bin/taocfwkdjv
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/taocfwkdjv
/usr/bin/taocfwkdjv "netstat -antop" 4554
clean
/usr/bin/taocfwkdjv
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/taocfwkdjv
/usr/bin/taocfwkdjv whoami 4554
clean
/usr/bin/taocfwkdjv
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/taocfwkdjv
/usr/bin/taocfwkdjv "netstat -an" 4554
clean
/usr/bin/taocfwkdjv
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/vhplhrsffz
/usr/bin/vhplhrsffz "netstat -an" 4554
clean
/usr/bin/vhplhrsffz
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/vhplhrsffz
/usr/bin/vhplhrsffz id 4554
clean
/usr/bin/vhplhrsffz
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/vhplhrsffz
/usr/bin/vhplhrsffz "ps -ef" 4554
clean
/usr/bin/vhplhrsffz
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/vhplhrsffz
/usr/bin/vhplhrsffz whoami 4554
clean
/usr/bin/vhplhrsffz
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/vhplhrsffz
/usr/bin/vhplhrsffz "netstat -an" 4554
clean
/usr/bin/vhplhrsffz
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/vdaqfdcrtx
/usr/bin/vdaqfdcrtx "cd /etc" 4554
clean
/usr/bin/vdaqfdcrtx
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/vdaqfdcrtx
/usr/bin/vdaqfdcrtx id 4554
clean
/usr/bin/vdaqfdcrtx
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/vdaqfdcrtx
/usr/bin/vdaqfdcrtx top 4554
clean
/usr/bin/vdaqfdcrtx
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/vdaqfdcrtx
/usr/bin/vdaqfdcrtx whoami 4554
clean
/usr/bin/vdaqfdcrtx
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/vdaqfdcrtx
/usr/bin/vdaqfdcrtx sh 4554
clean
/usr/bin/vdaqfdcrtx
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/vyvijtmtnz
/usr/bin/vyvijtmtnz "ifconfig eth0" 4554
clean
/usr/bin/vyvijtmtnz
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/vyvijtmtnz
/usr/bin/vyvijtmtnz bash 4554
clean
/usr/bin/vyvijtmtnz
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/vyvijtmtnz
/usr/bin/vyvijtmtnz "netstat -antop" 4554
clean
/usr/bin/vyvijtmtnz
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/vyvijtmtnz
/usr/bin/vyvijtmtnz "ifconfig eth0" 4554
clean
/usr/bin/vyvijtmtnz
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/vyvijtmtnz
/usr/bin/vyvijtmtnz "ifconfig eth0" 4554
clean
/usr/bin/vyvijtmtnz
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/vggdimllrz
/usr/bin/vggdimllrz who 4554
clean
/usr/bin/vggdimllrz
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/vggdimllrz
/usr/bin/vggdimllrz "sleep 1" 4554
clean
/usr/bin/vggdimllrz
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/vggdimllrz
/usr/bin/vggdimllrz sh 4554
clean
/usr/bin/vggdimllrz
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/vggdimllrz
/usr/bin/vggdimllrz bash 4554
clean
/usr/bin/vggdimllrz
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/vggdimllrz
/usr/bin/vggdimllrz "grep \"A\"" 4554
clean
/usr/bin/vggdimllrz
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/dowmukqhnk
/usr/bin/dowmukqhnk ifconfig 4554
clean
/usr/bin/dowmukqhnk
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/dowmukqhnk
/usr/bin/dowmukqhnk ls 4554
clean
/usr/bin/dowmukqhnk
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/dowmukqhnk
/usr/bin/dowmukqhnk "ps -ef" 4554
clean
/usr/bin/dowmukqhnk
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/dowmukqhnk
/usr/bin/dowmukqhnk "sleep 1" 4554
clean
/usr/bin/dowmukqhnk
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/dowmukqhnk
/usr/bin/dowmukqhnk ls 4554
clean
/usr/bin/dowmukqhnk
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/ejrpibbjio
/usr/bin/ejrpibbjio "echo \"find\"" 4554
clean
/usr/bin/ejrpibbjio
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/ejrpibbjio
/usr/bin/ejrpibbjio "cd /etc" 4554
clean
/usr/bin/ejrpibbjio
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/ejrpibbjio
/usr/bin/ejrpibbjio "grep \"A\"" 4554
clean
/usr/bin/ejrpibbjio
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/ejrpibbjio
/usr/bin/ejrpibbjio "ls -la" 4554
clean
/usr/bin/ejrpibbjio
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/ejrpibbjio
/usr/bin/ejrpibbjio "sleep 1" 4554
clean
/usr/bin/ejrpibbjio
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/ztfvwcbmzm
/usr/bin/ztfvwcbmzm "echo \"find\"" 4554
clean
/usr/bin/ztfvwcbmzm
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/ztfvwcbmzm
/usr/bin/ztfvwcbmzm whoami 4554
clean
/usr/bin/ztfvwcbmzm
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/ztfvwcbmzm
/usr/bin/ztfvwcbmzm gnome-terminal 4554
clean
/usr/bin/ztfvwcbmzm
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/ztfvwcbmzm
/usr/bin/ztfvwcbmzm sh 4554
clean
/usr/bin/ztfvwcbmzm
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/ztfvwcbmzm
/usr/bin/ztfvwcbmzm sh 4554
clean
/usr/bin/ztfvwcbmzm
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/getzgxvgyl
/usr/bin/getzgxvgyl "cat resolv.conf" 4554
clean
/usr/bin/getzgxvgyl
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/getzgxvgyl
/usr/bin/getzgxvgyl "echo \"find\"" 4554
clean
/usr/bin/getzgxvgyl
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/getzgxvgyl
/usr/bin/getzgxvgyl "ls -la" 4554
clean
/usr/bin/getzgxvgyl
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/getzgxvgyl
/usr/bin/getzgxvgyl gnome-terminal 4554
clean
/usr/bin/getzgxvgyl
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/tmp/4ljhdTTyiA
n/a
clean
/usr/bin/getzgxvgyl
/usr/bin/getzgxvgyl "netstat -antop" 4554
clean
/usr/bin/getzgxvgyl
n/a
clean
There are 605 hidden processes, click here to show them.

URLs

Name
IP
Malicious
http://aaa.dsaj2a.org/config.rar
23.253.46.64
malicious
http://www.gnu.org/software/libc/bugs.html
unknown
clean
http://aaa.dsaj2a.org/config.rar7.com:53
unknown
clean

Domains

Name
IP
Malicious
aaa.dsaj2a.org
23.253.46.64
malicious
ww.dnstells.com
204.11.56.48
malicious
ww.gzcfr5axf6.com
104.161.25.33
malicious
ww.gzcfr5axf7.com
unknown
clean

IPs

IP
Domain
Country
Malicious
23.253.46.64
aaa.dsaj2a.org
United States
malicious