MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0ed758aeeb5596c9db5be5a67b608960461376cf0209cb60629e2ae7bc282419. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 0ed758aeeb5596c9db5be5a67b608960461376cf0209cb60629e2ae7bc282419
SHA3-384 hash: 34eaffe2200d9aec92a60e9d1d370a993c1f7f03552fdc826e586ce989b352bdbdb08227459810d115960b49cd9f013a
SHA1 hash: bfa1494a468af9e86915761340cedb9ad918e02c
MD5 hash: 5b944542e94f97078a7b20126b85e52d
humanhash: solar-delaware-four-neptune
File name:run.sh
Download: download sample
Signature Mirai
File size:7'578 bytes
First seen:2025-09-07 15:01:25 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 192:F8HTKpZzzDN19xDkIam3qadayHDPMTMvlgYm:JzvLzaUbjm+gR
TLSH T1E1F1C806F6D09AB42988C568844A1840754F952B5D092C08F8FDB56DFF3876CB1FDBEB
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://162.248.53.119:8000/yes.tar.gzn/an/aopendir
http://162.248.53.119:8000/mon.sh1e891ab1521b27923233e694f60fdbf0e1b840e657d8b1ffdefd8b5ef5e38964 CoinMinerCoinMiner
https://github.com/el3ctr0wqw1/xmrig-vrl2/releases/download/main/xmrig-vrln/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
31
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-09-07T12:10:00Z UTC
Last seen:
2025-09-07T12:10:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.bc
Status:
terminated
Behavior Graph:
%3 guuid=01bf553b-1800-0000-6958-d658e70d0000 pid=3559 /usr/bin/sudo guuid=3d5add3c-1800-0000-6958-d658ed0d0000 pid=3565 /tmp/sample.bin guuid=01bf553b-1800-0000-6958-d658e70d0000 pid=3559->guuid=3d5add3c-1800-0000-6958-d658ed0d0000 pid=3565 execve guuid=3826c33d-1800-0000-6958-d658ef0d0000 pid=3567 /usr/bin/systemctl guuid=3d5add3c-1800-0000-6958-d658ed0d0000 pid=3565->guuid=3826c33d-1800-0000-6958-d658ef0d0000 pid=3567 execve guuid=98a70340-1800-0000-6958-d658f70d0000 pid=3575 /usr/bin/bash guuid=3d5add3c-1800-0000-6958-d658ed0d0000 pid=3565->guuid=98a70340-1800-0000-6958-d658f70d0000 pid=3575 clone guuid=243eb648-1800-0000-6958-d658100e0000 pid=3600 /usr/bin/bash guuid=3d5add3c-1800-0000-6958-d658ed0d0000 pid=3565->guuid=243eb648-1800-0000-6958-d658100e0000 pid=3600 clone guuid=4003ed49-1800-0000-6958-d658150e0000 pid=3605 /usr/bin/pgrep guuid=3d5add3c-1800-0000-6958-d658ed0d0000 pid=3565->guuid=4003ed49-1800-0000-6958-d658150e0000 pid=3605 execve guuid=1536ee4e-1800-0000-6958-d658200e0000 pid=3616 /usr/bin/pgrep guuid=3d5add3c-1800-0000-6958-d658ed0d0000 pid=3565->guuid=1536ee4e-1800-0000-6958-d658200e0000 pid=3616 execve guuid=ee997c52-1800-0000-6958-d6582b0e0000 pid=3627 /usr/bin/pgrep guuid=3d5add3c-1800-0000-6958-d658ed0d0000 pid=3565->guuid=ee997c52-1800-0000-6958-d6582b0e0000 pid=3627 execve guuid=20318352-1800-0000-6958-d6582c0e0000 pid=3628 /usr/bin/grep guuid=3d5add3c-1800-0000-6958-d658ed0d0000 pid=3565->guuid=20318352-1800-0000-6958-d6582c0e0000 pid=3628 execve guuid=15a68952-1800-0000-6958-d6582e0e0000 pid=3630 /usr/bin/xargs guuid=3d5add3c-1800-0000-6958-d658ed0d0000 pid=3565->guuid=15a68952-1800-0000-6958-d6582e0e0000 pid=3630 execve guuid=3f783456-1800-0000-6958-d6583b0e0000 pid=3643 /usr/bin/id guuid=3d5add3c-1800-0000-6958-d658ed0d0000 pid=3565->guuid=3f783456-1800-0000-6958-d6583b0e0000 pid=3643 execve guuid=06f51e57-1800-0000-6958-d6583f0e0000 pid=3647 /usr/bin/apt-get delete-file write-file guuid=3d5add3c-1800-0000-6958-d658ed0d0000 pid=3565->guuid=06f51e57-1800-0000-6958-d6583f0e0000 pid=3647 execve guuid=f94dfd78-1c00-0000-6958-d658f8140000 pid=5368 /usr/bin/apt-get guuid=3d5add3c-1800-0000-6958-d658ed0d0000 pid=3565->guuid=f94dfd78-1c00-0000-6958-d658f8140000 pid=5368 execve guuid=5c5dcd7a-1c00-0000-6958-d658fa140000 pid=5370 /usr/bin/mkdir guuid=3d5add3c-1800-0000-6958-d658ed0d0000 pid=3565->guuid=5c5dcd7a-1c00-0000-6958-d658fa140000 pid=5370 execve guuid=9851417b-1c00-0000-6958-d658fb140000 pid=5371 /usr/bin/wget dns net send-data write-file guuid=3d5add3c-1800-0000-6958-d658ed0d0000 pid=3565->guuid=9851417b-1c00-0000-6958-d658fb140000 pid=5371 execve guuid=4ba7b8a9-1c00-0000-6958-d65804150000 pid=5380 /usr/bin/mv guuid=3d5add3c-1800-0000-6958-d658ed0d0000 pid=3565->guuid=4ba7b8a9-1c00-0000-6958-d65804150000 pid=5380 execve guuid=65151baa-1c00-0000-6958-d65805150000 pid=5381 /usr/bin/rm guuid=3d5add3c-1800-0000-6958-d658ed0d0000 pid=3565->guuid=65151baa-1c00-0000-6958-d65805150000 pid=5381 execve guuid=e7425aaa-1c00-0000-6958-d65806150000 pid=5382 /usr/bin/chmod guuid=3d5add3c-1800-0000-6958-d658ed0d0000 pid=3565->guuid=e7425aaa-1c00-0000-6958-d65806150000 pid=5382 execve guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5383 /usr/lib/dev/systemdev/dns-filter mprotect-exec net send-data guuid=3d5add3c-1800-0000-6958-d658ed0d0000 pid=3565->guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5383 execve guuid=5b30aaaa-1c00-0000-6958-d65808150000 pid=5384 /usr/bin/sleep guuid=3d5add3c-1800-0000-6958-d658ed0d0000 pid=3565->guuid=5b30aaaa-1c00-0000-6958-d65808150000 pid=5384 execve guuid=59bfdfc8-1c00-0000-6958-d65821150000 pid=5409 /usr/bin/ps guuid=3d5add3c-1800-0000-6958-d658ed0d0000 pid=3565->guuid=59bfdfc8-1c00-0000-6958-d65821150000 pid=5409 execve guuid=eb7423d3-1c00-0000-6958-d65825150000 pid=5413 /usr/bin/sleep guuid=3d5add3c-1800-0000-6958-d658ed0d0000 pid=3565->guuid=eb7423d3-1c00-0000-6958-d65825150000 pid=5413 execve guuid=82f2bbdf-1d00-0000-6958-d65852150000 pid=5458 /usr/bin/ps guuid=3d5add3c-1800-0000-6958-d658ed0d0000 pid=3565->guuid=82f2bbdf-1d00-0000-6958-d65852150000 pid=5458 execve guuid=3c585ae5-1d00-0000-6958-d65853150000 pid=5459 /usr/bin/bash guuid=3d5add3c-1800-0000-6958-d658ed0d0000 pid=3565->guuid=3c585ae5-1d00-0000-6958-d65853150000 pid=5459 clone guuid=645f64e5-1d00-0000-6958-d65854150000 pid=5460 /usr/bin/grep guuid=3d5add3c-1800-0000-6958-d658ed0d0000 pid=3565->guuid=645f64e5-1d00-0000-6958-d65854150000 pid=5460 execve guuid=00e755e6-1d00-0000-6958-d65855150000 pid=5461 /usr/bin/bash guuid=3d5add3c-1800-0000-6958-d658ed0d0000 pid=3565->guuid=00e755e6-1d00-0000-6958-d65855150000 pid=5461 clone guuid=3d825fe6-1d00-0000-6958-d65856150000 pid=5462 /usr/bin/bash guuid=3d5add3c-1800-0000-6958-d658ed0d0000 pid=3565->guuid=3d825fe6-1d00-0000-6958-d65856150000 pid=5462 clone guuid=bae7c3e6-1d00-0000-6958-d65858150000 pid=5464 /usr/bin/rm guuid=3d5add3c-1800-0000-6958-d658ed0d0000 pid=3565->guuid=bae7c3e6-1d00-0000-6958-d65858150000 pid=5464 execve guuid=4bba23e7-1d00-0000-6958-d65859150000 pid=5465 /usr/bin/rm guuid=3d5add3c-1800-0000-6958-d658ed0d0000 pid=3565->guuid=4bba23e7-1d00-0000-6958-d65859150000 pid=5465 execve guuid=68261d40-1800-0000-6958-d658f80d0000 pid=3576 /usr/bin/wget dns net send-data guuid=98a70340-1800-0000-6958-d658f70d0000 pid=3575->guuid=68261d40-1800-0000-6958-d658f80d0000 pid=3576 execve 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=68261d40-1800-0000-6958-d658f80d0000 pid=3576->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 72B 0690ccd5-4816-5f11-94dc-7c585f38cdea ipv4.icanhazip.com:0 guuid=68261d40-1800-0000-6958-d658f80d0000 pid=3576->0690ccd5-4816-5f11-94dc-7c585f38cdea con d0ecfe49-aa79-583f-85c6-85ac97075256 ipv4.icanhazip.com:80 guuid=68261d40-1800-0000-6958-d658f80d0000 pid=3576->d0ecfe49-aa79-583f-85c6-85ac97075256 send: 133B guuid=9abcc648-1800-0000-6958-d658110e0000 pid=3601 /usr/bin/bash guuid=243eb648-1800-0000-6958-d658100e0000 pid=3600->guuid=9abcc648-1800-0000-6958-d658110e0000 pid=3601 clone guuid=c7f4cb48-1800-0000-6958-d658120e0000 pid=3602 /usr/bin/sed guuid=243eb648-1800-0000-6958-d658100e0000 pid=3600->guuid=c7f4cb48-1800-0000-6958-d658120e0000 pid=3602 execve guuid=1c02f648-1800-0000-6958-d658130e0000 pid=3603 /usr/bin/cut guuid=243eb648-1800-0000-6958-d658100e0000 pid=3600->guuid=1c02f648-1800-0000-6958-d658130e0000 pid=3603 execve guuid=46666858-1800-0000-6958-d658460e0000 pid=3654 /usr/bin/dpkg guuid=06f51e57-1800-0000-6958-d6583f0e0000 pid=3647->guuid=46666858-1800-0000-6958-d658460e0000 pid=3654 execve guuid=3dbc4c59-1800-0000-6958-d6584a0e0000 pid=3658 /usr/lib/apt/methods/mirror guuid=06f51e57-1800-0000-6958-d6583f0e0000 pid=3647->guuid=3dbc4c59-1800-0000-6958-d6584a0e0000 pid=3658 execve guuid=f038a15a-1800-0000-6958-d658500e0000 pid=3664 /usr/lib/apt/methods/mirror guuid=06f51e57-1800-0000-6958-d6583f0e0000 pid=3647->guuid=f038a15a-1800-0000-6958-d658500e0000 pid=3664 execve guuid=151ad45b-1800-0000-6958-d658570e0000 pid=3671 /usr/lib/apt/methods/file guuid=06f51e57-1800-0000-6958-d6583f0e0000 pid=3647->guuid=151ad45b-1800-0000-6958-d658570e0000 pid=3671 execve guuid=6116c65c-1800-0000-6958-d6585b0e0000 pid=3675 /usr/lib/apt/methods/file delete-file guuid=06f51e57-1800-0000-6958-d6583f0e0000 pid=3647->guuid=6116c65c-1800-0000-6958-d6585b0e0000 pid=3675 execve guuid=7400345e-1800-0000-6958-d6585c0e0000 pid=3676 /usr/lib/apt/methods/http guuid=06f51e57-1800-0000-6958-d6583f0e0000 pid=3647->guuid=7400345e-1800-0000-6958-d6585c0e0000 pid=3676 execve guuid=f32cd361-1800-0000-6958-d6585d0e0000 pid=3677 /usr/lib/apt/methods/http dns net send-data write-file guuid=06f51e57-1800-0000-6958-d6583f0e0000 pid=3647->guuid=f32cd361-1800-0000-6958-d6585d0e0000 pid=3677 execve guuid=94b9ff7a-1800-0000-6958-d6588d0e0000 pid=3725 /usr/lib/apt/methods/gpgv guuid=06f51e57-1800-0000-6958-d6583f0e0000 pid=3647->guuid=94b9ff7a-1800-0000-6958-d6588d0e0000 pid=3725 execve guuid=e2f63d7c-1800-0000-6958-d658930e0000 pid=3731 /usr/lib/apt/methods/gpgv guuid=06f51e57-1800-0000-6958-d6583f0e0000 pid=3647->guuid=e2f63d7c-1800-0000-6958-d658930e0000 pid=3731 execve guuid=40e242d5-1800-0000-6958-d65822100000 pid=4130 /usr/lib/apt/methods/store guuid=06f51e57-1800-0000-6958-d6583f0e0000 pid=3647->guuid=40e242d5-1800-0000-6958-d65822100000 pid=4130 execve guuid=991629d6-1800-0000-6958-d65828100000 pid=4136 /usr/lib/apt/methods/store write-file guuid=06f51e57-1800-0000-6958-d6583f0e0000 pid=3647->guuid=991629d6-1800-0000-6958-d65828100000 pid=4136 execve guuid=5325e93e-1900-0000-6958-d65857110000 pid=4439 /usr/lib/apt/methods/rred guuid=06f51e57-1800-0000-6958-d6583f0e0000 pid=3647->guuid=5325e93e-1900-0000-6958-d65857110000 pid=4439 execve guuid=9b345441-1900-0000-6958-d65860110000 pid=4448 /usr/lib/apt/methods/rred write-file guuid=06f51e57-1800-0000-6958-d6583f0e0000 pid=3647->guuid=9b345441-1900-0000-6958-d65860110000 pid=4448 execve guuid=f2e11906-1c00-0000-6958-d658f0140000 pid=5360 /usr/bin/dpkg guuid=06f51e57-1800-0000-6958-d6583f0e0000 pid=3647->guuid=f2e11906-1c00-0000-6958-d658f0140000 pid=5360 execve guuid=21d9f276-1c00-0000-6958-d658f7140000 pid=5367 /usr/bin/dpkg guuid=06f51e57-1800-0000-6958-d6583f0e0000 pid=3647->guuid=21d9f276-1c00-0000-6958-d658f7140000 pid=5367 execve guuid=f32cd361-1800-0000-6958-d6585d0e0000 pid=3677->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 122B 869ebe88-8c1e-5fbb-adb0-cfe48d8d7faf debian.map.fastly.net:443 guuid=f32cd361-1800-0000-6958-d6585d0e0000 pid=3677->869ebe88-8c1e-5fbb-adb0-cfe48d8d7faf send: 6269B guuid=64074c7d-1800-0000-6958-d658990e0000 pid=3737 /usr/lib/apt/methods/gpgv delete-file write-file guuid=e2f63d7c-1800-0000-6958-d658930e0000 pid=3731->guuid=64074c7d-1800-0000-6958-d658990e0000 pid=3737 clone guuid=d3c8de94-1800-0000-6958-d658180f0000 pid=3864 /usr/lib/apt/methods/gpgv delete-file write-file guuid=e2f63d7c-1800-0000-6958-d658930e0000 pid=3731->guuid=d3c8de94-1800-0000-6958-d658180f0000 pid=3864 clone guuid=f66bceb5-1800-0000-6958-d6587d0f0000 pid=3965 /usr/lib/apt/methods/gpgv delete-file write-file guuid=e2f63d7c-1800-0000-6958-d658930e0000 pid=3731->guuid=f66bceb5-1800-0000-6958-d6587d0f0000 pid=3965 clone guuid=5a1201c7-1800-0000-6958-d658cd0f0000 pid=4045 /usr/lib/apt/methods/gpgv delete-file write-file guuid=e2f63d7c-1800-0000-6958-d658930e0000 pid=3731->guuid=5a1201c7-1800-0000-6958-d658cd0f0000 pid=4045 clone guuid=2a87467f-1800-0000-6958-d658a50e0000 pid=3749 /usr/bin/apt-key write-file guuid=64074c7d-1800-0000-6958-d658990e0000 pid=3737->guuid=2a87467f-1800-0000-6958-d658a50e0000 pid=3749 execve guuid=3215947f-1800-0000-6958-d658a90e0000 pid=3753 /usr/bin/dash guuid=2a87467f-1800-0000-6958-d658a50e0000 pid=3749->guuid=3215947f-1800-0000-6958-d658a90e0000 pid=3753 clone guuid=faf0a47f-1800-0000-6958-d658aa0e0000 pid=3754 /usr/bin/apt-config guuid=2a87467f-1800-0000-6958-d658a50e0000 pid=3749->guuid=faf0a47f-1800-0000-6958-d658aa0e0000 pid=3754 execve guuid=7c18e681-1800-0000-6958-d658b40e0000 pid=3764 /usr/bin/apt-config guuid=2a87467f-1800-0000-6958-d658a50e0000 pid=3749->guuid=7c18e681-1800-0000-6958-d658b40e0000 pid=3764 execve guuid=fdb74885-1800-0000-6958-d658c00e0000 pid=3776 /usr/bin/apt-config guuid=2a87467f-1800-0000-6958-d658a50e0000 pid=3749->guuid=fdb74885-1800-0000-6958-d658c00e0000 pid=3776 execve guuid=25b3ed8b-1800-0000-6958-d658da0e0000 pid=3802 /usr/bin/apt-config guuid=2a87467f-1800-0000-6958-d658a50e0000 pid=3749->guuid=25b3ed8b-1800-0000-6958-d658da0e0000 pid=3802 execve guuid=4d9deb8d-1800-0000-6958-d658e50e0000 pid=3813 /usr/bin/dash guuid=2a87467f-1800-0000-6958-d658a50e0000 pid=3749->guuid=4d9deb8d-1800-0000-6958-d658e50e0000 pid=3813 clone guuid=ad82378e-1800-0000-6958-d658e80e0000 pid=3816 /usr/bin/apt-config guuid=2a87467f-1800-0000-6958-d658a50e0000 pid=3749->guuid=ad82378e-1800-0000-6958-d658e80e0000 pid=3816 execve guuid=3fc80390-1800-0000-6958-d658f50e0000 pid=3829 /usr/bin/mktemp guuid=2a87467f-1800-0000-6958-d658a50e0000 pid=3749->guuid=3fc80390-1800-0000-6958-d658f50e0000 pid=3829 execve guuid=bbc74090-1800-0000-6958-d658f70e0000 pid=3831 /usr/bin/chmod guuid=2a87467f-1800-0000-6958-d658a50e0000 pid=3749->guuid=bbc74090-1800-0000-6958-d658f70e0000 pid=3831 execve guuid=576d7090-1800-0000-6958-d658fa0e0000 pid=3834 /usr/bin/dash guuid=2a87467f-1800-0000-6958-d658a50e0000 pid=3749->guuid=576d7090-1800-0000-6958-d658fa0e0000 pid=3834 clone guuid=f1c68290-1800-0000-6958-d658fb0e0000 pid=3835 /usr/bin/dash guuid=2a87467f-1800-0000-6958-d658a50e0000 pid=3749->guuid=f1c68290-1800-0000-6958-d658fb0e0000 pid=3835 clone guuid=7b16e590-1800-0000-6958-d658010f0000 pid=3841 /usr/bin/dash guuid=2a87467f-1800-0000-6958-d658a50e0000 pid=3749->guuid=7b16e590-1800-0000-6958-d658010f0000 pid=3841 clone guuid=f21d9191-1800-0000-6958-d658090f0000 pid=3849 /usr/bin/dash guuid=2a87467f-1800-0000-6958-d658a50e0000 pid=3749->guuid=f21d9191-1800-0000-6958-d658090f0000 pid=3849 clone guuid=6992a291-1800-0000-6958-d6580a0f0000 pid=3850 /usr/bin/gpgv guuid=2a87467f-1800-0000-6958-d658a50e0000 pid=3749->guuid=6992a291-1800-0000-6958-d6580a0f0000 pid=3850 execve guuid=34919793-1800-0000-6958-d658150f0000 pid=3861 /usr/bin/rm delete-file guuid=2a87467f-1800-0000-6958-d658a50e0000 pid=3749->guuid=34919793-1800-0000-6958-d658150f0000 pid=3861 execve guuid=ed2d6681-1800-0000-6958-d658b00e0000 pid=3760 /usr/bin/dpkg guuid=faf0a47f-1800-0000-6958-d658aa0e0000 pid=3754->guuid=ed2d6681-1800-0000-6958-d658b00e0000 pid=3760 execve guuid=8394dd84-1800-0000-6958-d658be0e0000 pid=3774 /usr/bin/dpkg guuid=7c18e681-1800-0000-6958-d658b40e0000 pid=3764->guuid=8394dd84-1800-0000-6958-d658be0e0000 pid=3774 execve guuid=6aad2486-1800-0000-6958-d658c50e0000 pid=3781 /usr/bin/dpkg guuid=fdb74885-1800-0000-6958-d658c00e0000 pid=3776->guuid=6aad2486-1800-0000-6958-d658c50e0000 pid=3781 execve guuid=f2e0208d-1800-0000-6958-d658e20e0000 pid=3810 /usr/bin/dpkg guuid=25b3ed8b-1800-0000-6958-d658da0e0000 pid=3802->guuid=f2e0208d-1800-0000-6958-d658e20e0000 pid=3810 execve guuid=d8639e8f-1800-0000-6958-d658f10e0000 pid=3825 /usr/bin/dpkg guuid=ad82378e-1800-0000-6958-d658e80e0000 pid=3816->guuid=d8639e8f-1800-0000-6958-d658f10e0000 pid=3825 execve guuid=ce878c90-1800-0000-6958-d658fc0e0000 pid=3836 /usr/bin/dash guuid=f1c68290-1800-0000-6958-d658fb0e0000 pid=3835->guuid=ce878c90-1800-0000-6958-d658fc0e0000 pid=3836 clone guuid=418c9090-1800-0000-6958-d658fe0e0000 pid=3838 /usr/bin/sed guuid=f1c68290-1800-0000-6958-d658fb0e0000 pid=3835->guuid=418c9090-1800-0000-6958-d658fe0e0000 pid=3838 execve guuid=88cceb90-1800-0000-6958-d658030f0000 pid=3843 /usr/bin/dash guuid=7b16e590-1800-0000-6958-d658010f0000 pid=3841->guuid=88cceb90-1800-0000-6958-d658030f0000 pid=3843 clone guuid=ca63ef90-1800-0000-6958-d658040f0000 pid=3844 /usr/bin/sed guuid=7b16e590-1800-0000-6958-d658010f0000 pid=3841->guuid=ca63ef90-1800-0000-6958-d658040f0000 pid=3844 execve guuid=de858495-1800-0000-6958-d6581c0f0000 pid=3868 /usr/bin/apt-key write-file guuid=d3c8de94-1800-0000-6958-d658180f0000 pid=3864->guuid=de858495-1800-0000-6958-d6581c0f0000 pid=3868 execve guuid=e38eb895-1800-0000-6958-d6581e0f0000 pid=3870 /usr/bin/dash guuid=de858495-1800-0000-6958-d6581c0f0000 pid=3868->guuid=e38eb895-1800-0000-6958-d6581e0f0000 pid=3870 clone guuid=fc1cc595-1800-0000-6958-d6581f0f0000 pid=3871 /usr/bin/apt-config guuid=de858495-1800-0000-6958-d6581c0f0000 pid=3868->guuid=fc1cc595-1800-0000-6958-d6581f0f0000 pid=3871 execve guuid=ee831f98-1800-0000-6958-d6582c0f0000 pid=3884 /usr/bin/apt-config guuid=de858495-1800-0000-6958-d6581c0f0000 pid=3868->guuid=ee831f98-1800-0000-6958-d6582c0f0000 pid=3884 execve guuid=c290e299-1800-0000-6958-d658350f0000 pid=3893 /usr/bin/apt-config guuid=de858495-1800-0000-6958-d6581c0f0000 pid=3868->guuid=c290e299-1800-0000-6958-d658350f0000 pid=3893 execve guuid=cbfddb9b-1800-0000-6958-d6583d0f0000 pid=3901 /usr/bin/apt-config guuid=de858495-1800-0000-6958-d6581c0f0000 pid=3868->guuid=cbfddb9b-1800-0000-6958-d6583d0f0000 pid=3901 execve guuid=6908729d-1800-0000-6958-d658440f0000 pid=3908 /usr/bin/dash guuid=de858495-1800-0000-6958-d6581c0f0000 pid=3868->guuid=6908729d-1800-0000-6958-d658440f0000 pid=3908 clone guuid=96d4969d-1800-0000-6958-d658450f0000 pid=3909 /usr/bin/apt-config guuid=de858495-1800-0000-6958-d6581c0f0000 pid=3868->guuid=96d4969d-1800-0000-6958-d658450f0000 pid=3909 execve guuid=a273b5a0-1800-0000-6958-d658510f0000 pid=3921 /usr/bin/mktemp guuid=de858495-1800-0000-6958-d6581c0f0000 pid=3868->guuid=a273b5a0-1800-0000-6958-d658510f0000 pid=3921 execve guuid=af37e4a0-1800-0000-6958-d658530f0000 pid=3923 /usr/bin/chmod guuid=de858495-1800-0000-6958-d6581c0f0000 pid=3868->guuid=af37e4a0-1800-0000-6958-d658530f0000 pid=3923 execve guuid=6e5f13a1-1800-0000-6958-d658540f0000 pid=3924 /usr/bin/dash guuid=de858495-1800-0000-6958-d6581c0f0000 pid=3868->guuid=6e5f13a1-1800-0000-6958-d658540f0000 pid=3924 clone guuid=c5d024a1-1800-0000-6958-d658550f0000 pid=3925 /usr/bin/dash guuid=de858495-1800-0000-6958-d6581c0f0000 pid=3868->guuid=c5d024a1-1800-0000-6958-d658550f0000 pid=3925 clone guuid=38bca5a1-1800-0000-6958-d6585b0f0000 pid=3931 /usr/bin/dash guuid=de858495-1800-0000-6958-d6581c0f0000 pid=3868->guuid=38bca5a1-1800-0000-6958-d6585b0f0000 pid=3931 clone guuid=760926a2-1800-0000-6958-d658610f0000 pid=3937 /usr/bin/dash guuid=de858495-1800-0000-6958-d6581c0f0000 pid=3868->guuid=760926a2-1800-0000-6958-d658610f0000 pid=3937 clone guuid=905037a2-1800-0000-6958-d658630f0000 pid=3939 /usr/bin/gpgv guuid=de858495-1800-0000-6958-d6581c0f0000 pid=3868->guuid=905037a2-1800-0000-6958-d658630f0000 pid=3939 execve guuid=951dc1b4-1800-0000-6958-d658780f0000 pid=3960 /usr/bin/rm delete-file guuid=de858495-1800-0000-6958-d6581c0f0000 pid=3868->guuid=951dc1b4-1800-0000-6958-d658780f0000 pid=3960 execve guuid=1b96a397-1800-0000-6958-d658290f0000 pid=3881 /usr/bin/dpkg guuid=fc1cc595-1800-0000-6958-d6581f0f0000 pid=3871->guuid=1b96a397-1800-0000-6958-d658290f0000 pid=3881 execve guuid=19f57399-1800-0000-6958-d658310f0000 pid=3889 /usr/bin/dpkg guuid=ee831f98-1800-0000-6958-d6582c0f0000 pid=3884->guuid=19f57399-1800-0000-6958-d658310f0000 pid=3889 execve guuid=7cee539b-1800-0000-6958-d6583a0f0000 pid=3898 /usr/bin/dpkg guuid=c290e299-1800-0000-6958-d658350f0000 pid=3893->guuid=7cee539b-1800-0000-6958-d6583a0f0000 pid=3898 execve guuid=8107f79c-1800-0000-6958-d658400f0000 pid=3904 /usr/bin/dpkg guuid=cbfddb9b-1800-0000-6958-d6583d0f0000 pid=3901->guuid=8107f79c-1800-0000-6958-d658400f0000 pid=3904 execve guuid=1ac7c89f-1800-0000-6958-d6584d0f0000 pid=3917 /usr/bin/dpkg guuid=96d4969d-1800-0000-6958-d658450f0000 pid=3909->guuid=1ac7c89f-1800-0000-6958-d6584d0f0000 pid=3917 execve guuid=a6e945a1-1800-0000-6958-d658570f0000 pid=3927 /usr/bin/dash guuid=c5d024a1-1800-0000-6958-d658550f0000 pid=3925->guuid=a6e945a1-1800-0000-6958-d658570f0000 pid=3927 clone guuid=93744ca1-1800-0000-6958-d658590f0000 pid=3929 /usr/bin/sed guuid=c5d024a1-1800-0000-6958-d658550f0000 pid=3925->guuid=93744ca1-1800-0000-6958-d658590f0000 pid=3929 execve guuid=00c2aba1-1800-0000-6958-d6585c0f0000 pid=3932 /usr/bin/dash guuid=38bca5a1-1800-0000-6958-d6585b0f0000 pid=3931->guuid=00c2aba1-1800-0000-6958-d6585c0f0000 pid=3932 clone guuid=97daafa1-1800-0000-6958-d6585d0f0000 pid=3933 /usr/bin/sed guuid=38bca5a1-1800-0000-6958-d6585b0f0000 pid=3931->guuid=97daafa1-1800-0000-6958-d6585d0f0000 pid=3933 execve guuid=d9f01bb7-1800-0000-6958-d658820f0000 pid=3970 /usr/bin/apt-key write-file guuid=f66bceb5-1800-0000-6958-d6587d0f0000 pid=3965->guuid=d9f01bb7-1800-0000-6958-d658820f0000 pid=3970 execve guuid=2803aab7-1800-0000-6958-d658850f0000 pid=3973 /usr/bin/dash guuid=d9f01bb7-1800-0000-6958-d658820f0000 pid=3970->guuid=2803aab7-1800-0000-6958-d658850f0000 pid=3973 clone guuid=e927feb7-1800-0000-6958-d658870f0000 pid=3975 /usr/bin/apt-config guuid=d9f01bb7-1800-0000-6958-d658820f0000 pid=3970->guuid=e927feb7-1800-0000-6958-d658870f0000 pid=3975 execve guuid=942c33bc-1800-0000-6958-d658920f0000 pid=3986 /usr/bin/apt-config guuid=d9f01bb7-1800-0000-6958-d658820f0000 pid=3970->guuid=942c33bc-1800-0000-6958-d658920f0000 pid=3986 execve guuid=781cc4bd-1800-0000-6958-d658980f0000 pid=3992 /usr/bin/apt-config guuid=d9f01bb7-1800-0000-6958-d658820f0000 pid=3970->guuid=781cc4bd-1800-0000-6958-d658980f0000 pid=3992 execve guuid=45400dc0-1800-0000-6958-d658a30f0000 pid=4003 /usr/bin/apt-config guuid=d9f01bb7-1800-0000-6958-d658820f0000 pid=3970->guuid=45400dc0-1800-0000-6958-d658a30f0000 pid=4003 execve guuid=ba847ec1-1800-0000-6958-d658ad0f0000 pid=4013 /usr/bin/dash guuid=d9f01bb7-1800-0000-6958-d658820f0000 pid=3970->guuid=ba847ec1-1800-0000-6958-d658ad0f0000 pid=4013 clone guuid=ce53a7c1-1800-0000-6958-d658ae0f0000 pid=4014 /usr/bin/apt-config guuid=d9f01bb7-1800-0000-6958-d658820f0000 pid=3970->guuid=ce53a7c1-1800-0000-6958-d658ae0f0000 pid=4014 execve guuid=49241cc3-1800-0000-6958-d658b70f0000 pid=4023 /usr/bin/mktemp guuid=d9f01bb7-1800-0000-6958-d658820f0000 pid=3970->guuid=49241cc3-1800-0000-6958-d658b70f0000 pid=4023 execve guuid=914b4ec3-1800-0000-6958-d658b90f0000 pid=4025 /usr/bin/chmod guuid=d9f01bb7-1800-0000-6958-d658820f0000 pid=3970->guuid=914b4ec3-1800-0000-6958-d658b90f0000 pid=4025 execve guuid=243a78c3-1800-0000-6958-d658bb0f0000 pid=4027 /usr/bin/dash guuid=d9f01bb7-1800-0000-6958-d658820f0000 pid=3970->guuid=243a78c3-1800-0000-6958-d658bb0f0000 pid=4027 clone guuid=6a2b88c3-1800-0000-6958-d658bc0f0000 pid=4028 /usr/bin/dash guuid=d9f01bb7-1800-0000-6958-d658820f0000 pid=3970->guuid=6a2b88c3-1800-0000-6958-d658bc0f0000 pid=4028 clone guuid=4553e2c3-1800-0000-6958-d658c00f0000 pid=4032 /usr/bin/dash guuid=d9f01bb7-1800-0000-6958-d658820f0000 pid=3970->guuid=4553e2c3-1800-0000-6958-d658c00f0000 pid=4032 clone guuid=73db4dc4-1800-0000-6958-d658c50f0000 pid=4037 /usr/bin/dash guuid=d9f01bb7-1800-0000-6958-d658820f0000 pid=3970->guuid=73db4dc4-1800-0000-6958-d658c50f0000 pid=4037 clone guuid=60be5ac4-1800-0000-6958-d658c60f0000 pid=4038 /usr/bin/gpgv guuid=d9f01bb7-1800-0000-6958-d658820f0000 pid=3970->guuid=60be5ac4-1800-0000-6958-d658c60f0000 pid=4038 execve guuid=273e06c6-1800-0000-6958-d658cc0f0000 pid=4044 /usr/bin/rm delete-file guuid=d9f01bb7-1800-0000-6958-d658820f0000 pid=3970->guuid=273e06c6-1800-0000-6958-d658cc0f0000 pid=4044 execve guuid=6ead63bb-1800-0000-6958-d6588f0f0000 pid=3983 /usr/bin/dpkg guuid=e927feb7-1800-0000-6958-d658870f0000 pid=3975->guuid=6ead63bb-1800-0000-6958-d6588f0f0000 pid=3983 execve guuid=2c8f4ebd-1800-0000-6958-d658970f0000 pid=3991 /usr/bin/dpkg guuid=942c33bc-1800-0000-6958-d658920f0000 pid=3986->guuid=2c8f4ebd-1800-0000-6958-d658970f0000 pid=3991 execve guuid=5f2659bf-1800-0000-6958-d6589e0f0000 pid=3998 /usr/bin/dpkg guuid=781cc4bd-1800-0000-6958-d658980f0000 pid=3992->guuid=5f2659bf-1800-0000-6958-d6589e0f0000 pid=3998 execve guuid=e4a010c1-1800-0000-6958-d658a90f0000 pid=4009 /usr/bin/dpkg guuid=45400dc0-1800-0000-6958-d658a30f0000 pid=4003->guuid=e4a010c1-1800-0000-6958-d658a90f0000 pid=4009 execve guuid=428db6c2-1800-0000-6958-d658b40f0000 pid=4020 /usr/bin/dpkg guuid=ce53a7c1-1800-0000-6958-d658ae0f0000 pid=4014->guuid=428db6c2-1800-0000-6958-d658b40f0000 pid=4020 execve guuid=0e5792c3-1800-0000-6958-d658bd0f0000 pid=4029 /usr/bin/dash guuid=6a2b88c3-1800-0000-6958-d658bc0f0000 pid=4028->guuid=0e5792c3-1800-0000-6958-d658bd0f0000 pid=4029 clone guuid=dcd397c3-1800-0000-6958-d658be0f0000 pid=4030 /usr/bin/sed guuid=6a2b88c3-1800-0000-6958-d658bc0f0000 pid=4028->guuid=dcd397c3-1800-0000-6958-d658be0f0000 pid=4030 execve guuid=1edfe8c3-1800-0000-6958-d658c10f0000 pid=4033 /usr/bin/dash guuid=4553e2c3-1800-0000-6958-d658c00f0000 pid=4032->guuid=1edfe8c3-1800-0000-6958-d658c10f0000 pid=4033 clone guuid=488fecc3-1800-0000-6958-d658c20f0000 pid=4034 /usr/bin/sed guuid=4553e2c3-1800-0000-6958-d658c00f0000 pid=4032->guuid=488fecc3-1800-0000-6958-d658c20f0000 pid=4034 execve guuid=d110c5c7-1800-0000-6958-d658d40f0000 pid=4052 /usr/bin/apt-key write-file guuid=5a1201c7-1800-0000-6958-d658cd0f0000 pid=4045->guuid=d110c5c7-1800-0000-6958-d658d40f0000 pid=4052 execve guuid=55b01cc8-1800-0000-6958-d658d50f0000 pid=4053 /usr/bin/dash guuid=d110c5c7-1800-0000-6958-d658d40f0000 pid=4052->guuid=55b01cc8-1800-0000-6958-d658d50f0000 pid=4053 clone guuid=b5aa44c8-1800-0000-6958-d658d60f0000 pid=4054 /usr/bin/apt-config guuid=d110c5c7-1800-0000-6958-d658d40f0000 pid=4052->guuid=b5aa44c8-1800-0000-6958-d658d60f0000 pid=4054 execve guuid=dedc9bca-1800-0000-6958-d658e30f0000 pid=4067 /usr/bin/apt-config guuid=d110c5c7-1800-0000-6958-d658d40f0000 pid=4052->guuid=dedc9bca-1800-0000-6958-d658e30f0000 pid=4067 execve guuid=7cdb25cc-1800-0000-6958-d658ea0f0000 pid=4074 /usr/bin/apt-config guuid=d110c5c7-1800-0000-6958-d658d40f0000 pid=4052->guuid=7cdb25cc-1800-0000-6958-d658ea0f0000 pid=4074 execve guuid=4dd7b5cd-1800-0000-6958-d658f10f0000 pid=4081 /usr/bin/apt-config guuid=d110c5c7-1800-0000-6958-d658d40f0000 pid=4052->guuid=4dd7b5cd-1800-0000-6958-d658f10f0000 pid=4081 execve guuid=fff522cf-1800-0000-6958-d658f80f0000 pid=4088 /usr/bin/dash guuid=d110c5c7-1800-0000-6958-d658d40f0000 pid=4052->guuid=fff522cf-1800-0000-6958-d658f80f0000 pid=4088 clone guuid=78104acf-1800-0000-6958-d658fa0f0000 pid=4090 /usr/bin/apt-config guuid=d110c5c7-1800-0000-6958-d658d40f0000 pid=4052->guuid=78104acf-1800-0000-6958-d658fa0f0000 pid=4090 execve guuid=e93bf3d0-1800-0000-6958-d65804100000 pid=4100 /usr/bin/mktemp guuid=d110c5c7-1800-0000-6958-d658d40f0000 pid=4052->guuid=e93bf3d0-1800-0000-6958-d65804100000 pid=4100 execve guuid=880f2cd1-1800-0000-6958-d65806100000 pid=4102 /usr/bin/chmod guuid=d110c5c7-1800-0000-6958-d658d40f0000 pid=4052->guuid=880f2cd1-1800-0000-6958-d65806100000 pid=4102 execve guuid=2a2756d1-1800-0000-6958-d65807100000 pid=4103 /usr/bin/dash guuid=d110c5c7-1800-0000-6958-d658d40f0000 pid=4052->guuid=2a2756d1-1800-0000-6958-d65807100000 pid=4103 clone guuid=017467d1-1800-0000-6958-d65808100000 pid=4104 /usr/bin/dash guuid=d110c5c7-1800-0000-6958-d658d40f0000 pid=4052->guuid=017467d1-1800-0000-6958-d65808100000 pid=4104 clone guuid=77d0ced1-1800-0000-6958-d6580e100000 pid=4110 /usr/bin/dash guuid=d110c5c7-1800-0000-6958-d658d40f0000 pid=4052->guuid=77d0ced1-1800-0000-6958-d6580e100000 pid=4110 clone guuid=393e3ed2-1800-0000-6958-d65814100000 pid=4116 /usr/bin/dash guuid=d110c5c7-1800-0000-6958-d658d40f0000 pid=4052->guuid=393e3ed2-1800-0000-6958-d65814100000 pid=4116 clone guuid=46ec49d2-1800-0000-6958-d65815100000 pid=4117 /usr/bin/gpgv guuid=d110c5c7-1800-0000-6958-d658d40f0000 pid=4052->guuid=46ec49d2-1800-0000-6958-d65815100000 pid=4117 execve guuid=f088dfd3-1800-0000-6958-d6581b100000 pid=4123 /usr/bin/rm delete-file guuid=d110c5c7-1800-0000-6958-d658d40f0000 pid=4052->guuid=f088dfd3-1800-0000-6958-d6581b100000 pid=4123 execve guuid=2a1ac6c9-1800-0000-6958-d658df0f0000 pid=4063 /usr/bin/dpkg guuid=b5aa44c8-1800-0000-6958-d658d60f0000 pid=4054->guuid=2a1ac6c9-1800-0000-6958-d658df0f0000 pid=4063 execve guuid=9ea199cb-1800-0000-6958-d658e70f0000 pid=4071 /usr/bin/dpkg guuid=dedc9bca-1800-0000-6958-d658e30f0000 pid=4067->guuid=9ea199cb-1800-0000-6958-d658e70f0000 pid=4071 execve guuid=926e43cd-1800-0000-6958-d658ef0f0000 pid=4079 /usr/bin/dpkg guuid=7cdb25cc-1800-0000-6958-d658ea0f0000 pid=4074->guuid=926e43cd-1800-0000-6958-d658ef0f0000 pid=4079 execve guuid=4eeeb5ce-1800-0000-6958-d658f60f0000 pid=4086 /usr/bin/dpkg guuid=4dd7b5cd-1800-0000-6958-d658f10f0000 pid=4081->guuid=4eeeb5ce-1800-0000-6958-d658f60f0000 pid=4086 execve guuid=aaff4cd0-1800-0000-6958-d658ff0f0000 pid=4095 /usr/bin/dpkg guuid=78104acf-1800-0000-6958-d658fa0f0000 pid=4090->guuid=aaff4cd0-1800-0000-6958-d658ff0f0000 pid=4095 execve guuid=40c86ed1-1800-0000-6958-d65809100000 pid=4105 /usr/bin/dash guuid=017467d1-1800-0000-6958-d65808100000 pid=4104->guuid=40c86ed1-1800-0000-6958-d65809100000 pid=4105 clone guuid=d2f673d1-1800-0000-6958-d6580b100000 pid=4107 /usr/bin/sed guuid=017467d1-1800-0000-6958-d65808100000 pid=4104->guuid=d2f673d1-1800-0000-6958-d6580b100000 pid=4107 execve guuid=06dfd4d1-1800-0000-6958-d6580f100000 pid=4111 /usr/bin/dash guuid=77d0ced1-1800-0000-6958-d6580e100000 pid=4110->guuid=06dfd4d1-1800-0000-6958-d6580f100000 pid=4111 clone guuid=6177d9d1-1800-0000-6958-d65810100000 pid=4112 /usr/bin/sed guuid=77d0ced1-1800-0000-6958-d6580e100000 pid=4110->guuid=6177d9d1-1800-0000-6958-d65810100000 pid=4112 execve guuid=c0c7ff79-1c00-0000-6958-d658f9140000 pid=5369 /usr/bin/dpkg guuid=f94dfd78-1c00-0000-6958-d658f8140000 pid=5368->guuid=c0c7ff79-1c00-0000-6958-d658f9140000 pid=5369 execve guuid=9851417b-1c00-0000-6958-d658fb140000 pid=5371->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 164B 75aab096-419b-50ef-be46-7d76b6a90e4c github.com:443 guuid=9851417b-1c00-0000-6958-d658fb140000 pid=5371->75aab096-419b-50ef-be46-7d76b6a90e4c send: 783B f8c5e44f-328d-5324-8bbd-da50752b9120 release-assets.githubusercontent.com:0 guuid=9851417b-1c00-0000-6958-d658fb140000 pid=5371->f8c5e44f-328d-5324-8bbd-da50752b9120 con f0eebea5-e97d-507c-a771-59cac353877c release-assets.githubusercontent.com:443 guuid=9851417b-1c00-0000-6958-d658fb140000 pid=5371->f0eebea5-e97d-507c-a771-59cac353877c send: 1608B 2f50a59f-2358-5b5c-aa0a-c8fc64202aee hosts-to-ignore.ignorelist.com:1443 guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5383->2f50a59f-2358-5b5c-aa0a-c8fc64202aee send: 859B guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5386 /usr/lib/dev/systemdev/dns-filter write-file guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5383->guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5386 clone guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5387 /usr/lib/dev/systemdev/dns-filter dns net send-data guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5383->guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5387 clone guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5388 /usr/lib/dev/systemdev/dns-filter guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5383->guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5388 clone guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5389 /usr/lib/dev/systemdev/dns-filter guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5383->guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5389 clone guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5390 /usr/lib/dev/systemdev/dns-filter guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5383->guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5390 clone guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5400 /usr/lib/dev/systemdev/dns-filter guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5383->guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5400 clone guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5401 /usr/lib/dev/systemdev/dns-filter guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5383->guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5401 clone guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5402 /usr/lib/dev/systemdev/dns-filter guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5383->guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5402 clone guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5403 /usr/lib/dev/systemdev/dns-filter guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5383->guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5403 clone guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5414 /usr/lib/dev/systemdev/dns-filter guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5383->guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5414 clone guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5415 /usr/lib/dev/systemdev/dns-filter guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5383->guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5415 clone guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5416 /usr/lib/dev/systemdev/dns-filter guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5383->guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5416 clone guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5417 /usr/lib/dev/systemdev/dns-filter guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5383->guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5417 clone guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5418 /usr/lib/dev/systemdev/dns-filter guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5383->guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5418 clone guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5419 /usr/lib/dev/systemdev/dns-filter guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5383->guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5419 clone guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5420 /usr/lib/dev/systemdev/dns-filter guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5383->guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5420 clone guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5421 /usr/lib/dev/systemdev/dns-filter guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5383->guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5421 clone guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5422 /usr/lib/dev/systemdev/dns-filter guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5383->guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5422 clone guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5423 /usr/lib/dev/systemdev/dns-filter guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5383->guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5423 clone guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5424 /usr/lib/dev/systemdev/dns-filter guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5383->guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5424 clone guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5425 /usr/lib/dev/systemdev/dns-filter guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5383->guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5425 clone guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5426 /usr/lib/dev/systemdev/dns-filter guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5383->guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5426 clone guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5427 /usr/lib/dev/systemdev/dns-filter guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5383->guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5427 clone guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5428 /usr/lib/dev/systemdev/dns-filter guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5383->guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5428 clone guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5429 /usr/lib/dev/systemdev/dns-filter guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5383->guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5429 clone guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5430 /usr/lib/dev/systemdev/dns-filter guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5383->guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5430 clone guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5431 /usr/lib/dev/systemdev/dns-filter guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5383->guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5431 clone guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5432 /usr/lib/dev/systemdev/dns-filter guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5383->guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5432 clone guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5433 /usr/lib/dev/systemdev/dns-filter guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5383->guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5433 clone guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5434 /usr/lib/dev/systemdev/dns-filter guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5383->guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5434 clone guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5435 /usr/lib/dev/systemdev/dns-filter guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5383->guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5435 clone guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5436 /usr/lib/dev/systemdev/dns-filter guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5383->guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5436 clone guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5437 /usr/lib/dev/systemdev/dns-filter guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5383->guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5437 clone guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5438 /usr/lib/dev/systemdev/dns-filter guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5383->guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5438 clone guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5439 /usr/lib/dev/systemdev/dns-filter guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5383->guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5439 clone guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5440 /usr/lib/dev/systemdev/dns-filter guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5383->guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5440 clone guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5441 /usr/lib/dev/systemdev/dns-filter guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5383->guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5441 clone guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5442 /usr/lib/dev/systemdev/dns-filter guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5383->guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5442 clone guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5443 /usr/lib/dev/systemdev/dns-filter guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5383->guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5443 clone guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5444 /usr/lib/dev/systemdev/dns-filter guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5383->guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5444 clone guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5445 /usr/lib/dev/systemdev/dns-filter guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5383->guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5445 clone guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5446 /usr/lib/dev/systemdev/dns-filter guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5383->guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5446 clone guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5447 /usr/lib/dev/systemdev/dns-filter guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5383->guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5447 clone guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5448 /usr/lib/dev/systemdev/dns-filter guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5383->guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5448 clone guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5449 /usr/lib/dev/systemdev/dns-filter guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5383->guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5449 clone guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5450 /usr/lib/dev/systemdev/dns-filter guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5383->guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5450 clone guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5451 /usr/lib/dev/systemdev/dns-filter guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5383->guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5451 clone guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5452 /usr/lib/dev/systemdev/dns-filter guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5383->guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5452 clone guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5453 /usr/lib/dev/systemdev/dns-filter guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5383->guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5453 clone guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5454 /usr/lib/dev/systemdev/dns-filter guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5383->guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5454 clone guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5455 /usr/lib/dev/systemdev/dns-filter guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5383->guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5455 clone guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5456 /usr/lib/dev/systemdev/dns-filter guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5383->guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5456 clone guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5457 /usr/lib/dev/systemdev/dns-filter guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5383->guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5457 clone guuid=f9be9eaa-1c00-0000-6958-d65807150000 pid=5387->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 96B guuid=857775e6-1d00-0000-6958-d65857150000 pid=5463 /usr/bin/bash guuid=00e755e6-1d00-0000-6958-d65855150000 pid=5461->guuid=857775e6-1d00-0000-6958-d65857150000 pid=5463 clone
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2025-09-07 15:02:34 UTC
File Type:
Text (Shell)
AV detection:
9 of 38 (23.68%)
Threat level:
  5/5
Result
Malware family:
xmrig_linux
Score:
  10/10
Tags:
family:xmrig family:xmrig_linux antivm defense_evasion discovery execution linux miner persistence privilege_escalation
Behaviour
Enumerates kernel/hardware configuration
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads CPU attributes
Checks hardware identifiers (DMI)
Creates/modifies Cron job
Enumerates running processes
Reads hardware information
File and Directory Permissions Modification
Executes dropped EXE
XMRig Miner payload
Xmrig family
Xmrig_linux family
xmrig
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 0ed758aeeb5596c9db5be5a67b608960461376cf0209cb60629e2ae7bc282419

(this sample)

4537e474274cf7e7e1920f0ba0ccd7fc219b2698a5af85689649ceb7962953ce

  
Delivery method
Distributed via web download
  
Dropping
MD5 0782916ee8c331309e8fd467529ed93d
  
Dropping
SHA256 4537e474274cf7e7e1920f0ba0ccd7fc219b2698a5af85689649ceb7962953ce

Comments