MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2313d2be36cfe75bffced9e2221788cc4e21233ee304ecacf9da9e90a3b647c5. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



CoinMiner


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 2313d2be36cfe75bffced9e2221788cc4e21233ee304ecacf9da9e90a3b647c5
SHA3-384 hash: fc02fee28d0b3da58768dbab1e03d223397987d273f130c52463b3f17a6d949bf0d43678cbc2dcfcd75e04abfffd675a
SHA1 hash: e688851b21133fa464d3c71417748519e6e28ca1
MD5 hash: a51a23b60b5eb15e0c1ea23fb8786e44
humanhash: bluebird-lithium-stream-robert
File name:run-CN.sh
Download: download sample
Signature CoinMiner
File size:7'620 bytes
First seen:2025-09-08 14:56:00 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 192:F8HTKpZzzDN19xDkIam3qadayHDPMIYbMvlgYm:JzvLzaUbjU+gR
TLSH T159F1D706F6D09AB42998C568844A1840754F952B5D092C08F8FDB56DFF3872CB1FDBEB
Magika shell
Reporter abuse_ch
Tags:CoinMiner sh
URLMalware sample (SHA256 hash)SignatureTags
http://162.248.53.119:8000/yes.tar.gzn/an/aopendir
http://162.248.53.119:8000/mon.sh1e891ab1521b27923233e694f60fdbf0e1b840e657d8b1ffdefd8b5ef5e38964 CoinMinerCoinMiner
https://github.com/el3ctr0wqw1/xmrig-vrl2/releases/download/main/xmrig-vrln/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
35
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-09-08T12:02:00Z UTC
Last seen:
2025-09-08T12:02:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.bc
Status:
terminated
Behavior Graph:
%3 guuid=9e6a39e7-1a00-0000-d29e-ff3c880c0000 pid=3208 /usr/bin/sudo guuid=cdbb1eea-1a00-0000-d29e-ff3c890c0000 pid=3209 /tmp/sample.bin guuid=9e6a39e7-1a00-0000-d29e-ff3c880c0000 pid=3208->guuid=cdbb1eea-1a00-0000-d29e-ff3c890c0000 pid=3209 execve guuid=d01f28eb-1a00-0000-d29e-ff3c8a0c0000 pid=3210 /usr/bin/systemctl guuid=cdbb1eea-1a00-0000-d29e-ff3c890c0000 pid=3209->guuid=d01f28eb-1a00-0000-d29e-ff3c8a0c0000 pid=3210 execve guuid=8e48e4ec-1a00-0000-d29e-ff3c8c0c0000 pid=3212 /usr/bin/bash guuid=cdbb1eea-1a00-0000-d29e-ff3c890c0000 pid=3209->guuid=8e48e4ec-1a00-0000-d29e-ff3c8c0c0000 pid=3212 clone guuid=5ce0ccf7-1a00-0000-d29e-ff3c9c0c0000 pid=3228 /usr/bin/bash guuid=cdbb1eea-1a00-0000-d29e-ff3c890c0000 pid=3209->guuid=5ce0ccf7-1a00-0000-d29e-ff3c9c0c0000 pid=3228 clone guuid=5de8caf8-1a00-0000-d29e-ff3ca30c0000 pid=3235 /usr/bin/pgrep guuid=cdbb1eea-1a00-0000-d29e-ff3c890c0000 pid=3209->guuid=5de8caf8-1a00-0000-d29e-ff3ca30c0000 pid=3235 execve guuid=a564baff-1a00-0000-d29e-ff3ca70c0000 pid=3239 /usr/bin/pgrep guuid=cdbb1eea-1a00-0000-d29e-ff3c890c0000 pid=3209->guuid=a564baff-1a00-0000-d29e-ff3ca70c0000 pid=3239 execve guuid=a8357c03-1b00-0000-d29e-ff3cb00c0000 pid=3248 /usr/bin/pgrep guuid=cdbb1eea-1a00-0000-d29e-ff3c890c0000 pid=3209->guuid=a8357c03-1b00-0000-d29e-ff3cb00c0000 pid=3248 execve guuid=d3188403-1b00-0000-d29e-ff3cb10c0000 pid=3249 /usr/bin/grep guuid=cdbb1eea-1a00-0000-d29e-ff3c890c0000 pid=3209->guuid=d3188403-1b00-0000-d29e-ff3cb10c0000 pid=3249 execve guuid=b2948903-1b00-0000-d29e-ff3cb20c0000 pid=3250 /usr/bin/xargs guuid=cdbb1eea-1a00-0000-d29e-ff3c890c0000 pid=3209->guuid=b2948903-1b00-0000-d29e-ff3cb20c0000 pid=3250 execve guuid=c4288607-1b00-0000-d29e-ff3cbc0c0000 pid=3260 /usr/bin/id guuid=cdbb1eea-1a00-0000-d29e-ff3c890c0000 pid=3209->guuid=c4288607-1b00-0000-d29e-ff3cbc0c0000 pid=3260 execve guuid=ec0b3808-1b00-0000-d29e-ff3cbf0c0000 pid=3263 /usr/bin/apt-get delete-file write-file guuid=cdbb1eea-1a00-0000-d29e-ff3c890c0000 pid=3209->guuid=ec0b3808-1b00-0000-d29e-ff3cbf0c0000 pid=3263 execve guuid=80b9bc10-1f00-0000-d29e-ff3cec140000 pid=5356 /usr/bin/apt-get guuid=cdbb1eea-1a00-0000-d29e-ff3c890c0000 pid=3209->guuid=80b9bc10-1f00-0000-d29e-ff3cec140000 pid=5356 execve guuid=92687912-1f00-0000-d29e-ff3cee140000 pid=5358 /usr/bin/mkdir guuid=cdbb1eea-1a00-0000-d29e-ff3c890c0000 pid=3209->guuid=92687912-1f00-0000-d29e-ff3cee140000 pid=5358 execve guuid=d5cbdb12-1f00-0000-d29e-ff3cef140000 pid=5359 /usr/bin/wget dns net send-data write-file guuid=cdbb1eea-1a00-0000-d29e-ff3c890c0000 pid=3209->guuid=d5cbdb12-1f00-0000-d29e-ff3cef140000 pid=5359 execve guuid=6e171543-1f00-0000-d29e-ff3cf0140000 pid=5360 /usr/bin/mv guuid=cdbb1eea-1a00-0000-d29e-ff3c890c0000 pid=3209->guuid=6e171543-1f00-0000-d29e-ff3cf0140000 pid=5360 execve guuid=d3e8bb43-1f00-0000-d29e-ff3cf1140000 pid=5361 /usr/bin/rm guuid=cdbb1eea-1a00-0000-d29e-ff3c890c0000 pid=3209->guuid=d3e8bb43-1f00-0000-d29e-ff3cf1140000 pid=5361 execve guuid=e4fe0044-1f00-0000-d29e-ff3cf2140000 pid=5362 /usr/bin/chmod guuid=cdbb1eea-1a00-0000-d29e-ff3c890c0000 pid=3209->guuid=e4fe0044-1f00-0000-d29e-ff3cf2140000 pid=5362 execve guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5363 /usr/lib/dev/systemdev/dns-filter mprotect-exec net send-data guuid=cdbb1eea-1a00-0000-d29e-ff3c890c0000 pid=3209->guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5363 execve guuid=58576744-1f00-0000-d29e-ff3cf4140000 pid=5364 /usr/bin/sleep guuid=cdbb1eea-1a00-0000-d29e-ff3c890c0000 pid=3209->guuid=58576744-1f00-0000-d29e-ff3cf4140000 pid=5364 execve guuid=2530b56b-1f00-0000-d29e-ff3c00150000 pid=5376 /usr/bin/ps guuid=cdbb1eea-1a00-0000-d29e-ff3c890c0000 pid=3209->guuid=2530b56b-1f00-0000-d29e-ff3c00150000 pid=5376 execve guuid=afe45471-1f00-0000-d29e-ff3c01150000 pid=5377 /usr/bin/sleep guuid=cdbb1eea-1a00-0000-d29e-ff3c890c0000 pid=3209->guuid=afe45471-1f00-0000-d29e-ff3c01150000 pid=5377 execve guuid=60ef367e-2000-0000-d29e-ff3c32150000 pid=5426 /usr/bin/ps guuid=cdbb1eea-1a00-0000-d29e-ff3c890c0000 pid=3209->guuid=60ef367e-2000-0000-d29e-ff3c32150000 pid=5426 execve guuid=84ecb388-2000-0000-d29e-ff3c33150000 pid=5427 /usr/bin/bash guuid=cdbb1eea-1a00-0000-d29e-ff3c890c0000 pid=3209->guuid=84ecb388-2000-0000-d29e-ff3c33150000 pid=5427 clone guuid=d1dabf88-2000-0000-d29e-ff3c34150000 pid=5428 /usr/bin/grep guuid=cdbb1eea-1a00-0000-d29e-ff3c890c0000 pid=3209->guuid=d1dabf88-2000-0000-d29e-ff3c34150000 pid=5428 execve guuid=e6939c89-2000-0000-d29e-ff3c35150000 pid=5429 /usr/bin/bash guuid=cdbb1eea-1a00-0000-d29e-ff3c890c0000 pid=3209->guuid=e6939c89-2000-0000-d29e-ff3c35150000 pid=5429 clone guuid=88afaa89-2000-0000-d29e-ff3c36150000 pid=5430 /usr/bin/bash guuid=cdbb1eea-1a00-0000-d29e-ff3c890c0000 pid=3209->guuid=88afaa89-2000-0000-d29e-ff3c36150000 pid=5430 clone guuid=ab6e048a-2000-0000-d29e-ff3c38150000 pid=5432 /usr/bin/rm guuid=cdbb1eea-1a00-0000-d29e-ff3c890c0000 pid=3209->guuid=ab6e048a-2000-0000-d29e-ff3c38150000 pid=5432 execve guuid=8ad06c8a-2000-0000-d29e-ff3c39150000 pid=5433 /usr/bin/rm guuid=cdbb1eea-1a00-0000-d29e-ff3c890c0000 pid=3209->guuid=8ad06c8a-2000-0000-d29e-ff3c39150000 pid=5433 execve guuid=8819fcec-1a00-0000-d29e-ff3c8d0c0000 pid=3213 /usr/bin/wget dns net send-data guuid=8e48e4ec-1a00-0000-d29e-ff3c8c0c0000 pid=3212->guuid=8819fcec-1a00-0000-d29e-ff3c8d0c0000 pid=3213 execve 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=8819fcec-1a00-0000-d29e-ff3c8d0c0000 pid=3213->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 72B 0690ccd5-4816-5f11-94dc-7c585f38cdea ipv4.icanhazip.com:0 guuid=8819fcec-1a00-0000-d29e-ff3c8d0c0000 pid=3213->0690ccd5-4816-5f11-94dc-7c585f38cdea con d0ecfe49-aa79-583f-85c6-85ac97075256 ipv4.icanhazip.com:80 guuid=8819fcec-1a00-0000-d29e-ff3c8d0c0000 pid=3213->d0ecfe49-aa79-583f-85c6-85ac97075256 send: 133B guuid=de18e2f7-1a00-0000-d29e-ff3c9e0c0000 pid=3230 /usr/bin/bash guuid=5ce0ccf7-1a00-0000-d29e-ff3c9c0c0000 pid=3228->guuid=de18e2f7-1a00-0000-d29e-ff3c9e0c0000 pid=3230 clone guuid=a6d2ebf7-1a00-0000-d29e-ff3c9f0c0000 pid=3231 /usr/bin/sed guuid=5ce0ccf7-1a00-0000-d29e-ff3c9c0c0000 pid=3228->guuid=a6d2ebf7-1a00-0000-d29e-ff3c9f0c0000 pid=3231 execve guuid=1f5cf3f7-1a00-0000-d29e-ff3ca00c0000 pid=3232 /usr/bin/cut guuid=5ce0ccf7-1a00-0000-d29e-ff3c9c0c0000 pid=3228->guuid=1f5cf3f7-1a00-0000-d29e-ff3ca00c0000 pid=3232 execve guuid=bf75b00b-1b00-0000-d29e-ff3cc20c0000 pid=3266 /usr/bin/dpkg guuid=ec0b3808-1b00-0000-d29e-ff3cbf0c0000 pid=3263->guuid=bf75b00b-1b00-0000-d29e-ff3cc20c0000 pid=3266 execve guuid=3477c80c-1b00-0000-d29e-ff3cc30c0000 pid=3267 /usr/lib/apt/methods/mirror guuid=ec0b3808-1b00-0000-d29e-ff3cbf0c0000 pid=3263->guuid=3477c80c-1b00-0000-d29e-ff3cc30c0000 pid=3267 execve guuid=b7b60b0e-1b00-0000-d29e-ff3cc50c0000 pid=3269 /usr/lib/apt/methods/mirror guuid=ec0b3808-1b00-0000-d29e-ff3cbf0c0000 pid=3263->guuid=b7b60b0e-1b00-0000-d29e-ff3cc50c0000 pid=3269 execve guuid=1c69840f-1b00-0000-d29e-ff3cc60c0000 pid=3270 /usr/lib/apt/methods/file guuid=ec0b3808-1b00-0000-d29e-ff3cbf0c0000 pid=3263->guuid=1c69840f-1b00-0000-d29e-ff3cc60c0000 pid=3270 execve guuid=d9c9f210-1b00-0000-d29e-ff3cca0c0000 pid=3274 /usr/lib/apt/methods/file delete-file guuid=ec0b3808-1b00-0000-d29e-ff3cbf0c0000 pid=3263->guuid=d9c9f210-1b00-0000-d29e-ff3cca0c0000 pid=3274 execve guuid=6c424112-1b00-0000-d29e-ff3ccf0c0000 pid=3279 /usr/lib/apt/methods/http guuid=ec0b3808-1b00-0000-d29e-ff3cbf0c0000 pid=3263->guuid=6c424112-1b00-0000-d29e-ff3ccf0c0000 pid=3279 execve guuid=a0c78f14-1b00-0000-d29e-ff3cd50c0000 pid=3285 /usr/lib/apt/methods/http dns net send-data write-file guuid=ec0b3808-1b00-0000-d29e-ff3cbf0c0000 pid=3263->guuid=a0c78f14-1b00-0000-d29e-ff3cd50c0000 pid=3285 execve guuid=5b163b34-1b00-0000-d29e-ff3c100d0000 pid=3344 /usr/lib/apt/methods/gpgv guuid=ec0b3808-1b00-0000-d29e-ff3cbf0c0000 pid=3263->guuid=5b163b34-1b00-0000-d29e-ff3c100d0000 pid=3344 execve guuid=86f79636-1b00-0000-d29e-ff3c110d0000 pid=3345 /usr/lib/apt/methods/gpgv guuid=ec0b3808-1b00-0000-d29e-ff3cbf0c0000 pid=3263->guuid=86f79636-1b00-0000-d29e-ff3c110d0000 pid=3345 execve guuid=80dd668e-1b00-0000-d29e-ff3c300e0000 pid=3632 /usr/lib/apt/methods/store guuid=ec0b3808-1b00-0000-d29e-ff3cbf0c0000 pid=3263->guuid=80dd668e-1b00-0000-d29e-ff3c300e0000 pid=3632 execve guuid=5a815c8f-1b00-0000-d29e-ff3c320e0000 pid=3634 /usr/lib/apt/methods/store write-file guuid=ec0b3808-1b00-0000-d29e-ff3cbf0c0000 pid=3263->guuid=5a815c8f-1b00-0000-d29e-ff3c320e0000 pid=3634 execve guuid=a490a501-1c00-0000-d29e-ff3cd60e0000 pid=3798 /usr/lib/apt/methods/rred guuid=ec0b3808-1b00-0000-d29e-ff3cbf0c0000 pid=3263->guuid=a490a501-1c00-0000-d29e-ff3cd60e0000 pid=3798 execve guuid=6cc4a004-1c00-0000-d29e-ff3cd70e0000 pid=3799 /usr/lib/apt/methods/rred write-file guuid=ec0b3808-1b00-0000-d29e-ff3cbf0c0000 pid=3263->guuid=6cc4a004-1c00-0000-d29e-ff3cd70e0000 pid=3799 execve guuid=34980ea5-1e00-0000-d29e-ff3ce9140000 pid=5353 /usr/bin/dpkg guuid=ec0b3808-1b00-0000-d29e-ff3cbf0c0000 pid=3263->guuid=34980ea5-1e00-0000-d29e-ff3ce9140000 pid=5353 execve guuid=d724ea0c-1f00-0000-d29e-ff3ceb140000 pid=5355 /usr/bin/dpkg guuid=ec0b3808-1b00-0000-d29e-ff3cbf0c0000 pid=3263->guuid=d724ea0c-1f00-0000-d29e-ff3ceb140000 pid=5355 execve guuid=a0c78f14-1b00-0000-d29e-ff3cd50c0000 pid=3285->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 122B 869ebe88-8c1e-5fbb-adb0-cfe48d8d7faf debian.map.fastly.net:443 guuid=a0c78f14-1b00-0000-d29e-ff3cd50c0000 pid=3285->869ebe88-8c1e-5fbb-adb0-cfe48d8d7faf con guuid=6b79f937-1b00-0000-d29e-ff3c120d0000 pid=3346 /usr/lib/apt/methods/gpgv delete-file write-file guuid=86f79636-1b00-0000-d29e-ff3c110d0000 pid=3345->guuid=6b79f937-1b00-0000-d29e-ff3c120d0000 pid=3346 clone guuid=c7b40a52-1b00-0000-d29e-ff3c590d0000 pid=3417 /usr/lib/apt/methods/gpgv delete-file write-file guuid=86f79636-1b00-0000-d29e-ff3c110d0000 pid=3345->guuid=c7b40a52-1b00-0000-d29e-ff3c590d0000 pid=3417 clone guuid=21e88264-1b00-0000-d29e-ff3ca90d0000 pid=3497 /usr/lib/apt/methods/gpgv delete-file write-file guuid=86f79636-1b00-0000-d29e-ff3c110d0000 pid=3345->guuid=21e88264-1b00-0000-d29e-ff3ca90d0000 pid=3497 clone guuid=aa03ac75-1b00-0000-d29e-ff3cfd0d0000 pid=3581 /usr/lib/apt/methods/gpgv delete-file write-file guuid=86f79636-1b00-0000-d29e-ff3c110d0000 pid=3345->guuid=aa03ac75-1b00-0000-d29e-ff3cfd0d0000 pid=3581 clone guuid=8d71583b-1b00-0000-d29e-ff3c140d0000 pid=3348 /usr/bin/apt-key write-file guuid=6b79f937-1b00-0000-d29e-ff3c120d0000 pid=3346->guuid=8d71583b-1b00-0000-d29e-ff3c140d0000 pid=3348 execve guuid=b3b7f93b-1b00-0000-d29e-ff3c170d0000 pid=3351 /usr/bin/dash guuid=8d71583b-1b00-0000-d29e-ff3c140d0000 pid=3348->guuid=b3b7f93b-1b00-0000-d29e-ff3c170d0000 pid=3351 clone guuid=d2c0183c-1b00-0000-d29e-ff3c180d0000 pid=3352 /usr/bin/apt-config guuid=8d71583b-1b00-0000-d29e-ff3c140d0000 pid=3348->guuid=d2c0183c-1b00-0000-d29e-ff3c180d0000 pid=3352 execve guuid=fecc893e-1b00-0000-d29e-ff3c220d0000 pid=3362 /usr/bin/apt-config guuid=8d71583b-1b00-0000-d29e-ff3c140d0000 pid=3348->guuid=fecc893e-1b00-0000-d29e-ff3c220d0000 pid=3362 execve guuid=a7c0f73f-1b00-0000-d29e-ff3c240d0000 pid=3364 /usr/bin/apt-config guuid=8d71583b-1b00-0000-d29e-ff3c140d0000 pid=3348->guuid=a7c0f73f-1b00-0000-d29e-ff3c240d0000 pid=3364 execve guuid=1fc09741-1b00-0000-d29e-ff3c260d0000 pid=3366 /usr/bin/apt-config guuid=8d71583b-1b00-0000-d29e-ff3c140d0000 pid=3348->guuid=1fc09741-1b00-0000-d29e-ff3c260d0000 pid=3366 execve guuid=fc152043-1b00-0000-d29e-ff3c2a0d0000 pid=3370 /usr/bin/dash guuid=8d71583b-1b00-0000-d29e-ff3c140d0000 pid=3348->guuid=fc152043-1b00-0000-d29e-ff3c2a0d0000 pid=3370 clone guuid=f19b4243-1b00-0000-d29e-ff3c2c0d0000 pid=3372 /usr/bin/apt-config guuid=8d71583b-1b00-0000-d29e-ff3c140d0000 pid=3348->guuid=f19b4243-1b00-0000-d29e-ff3c2c0d0000 pid=3372 execve guuid=ffb9ea4a-1b00-0000-d29e-ff3c3a0d0000 pid=3386 /usr/bin/mktemp guuid=8d71583b-1b00-0000-d29e-ff3c140d0000 pid=3348->guuid=ffb9ea4a-1b00-0000-d29e-ff3c3a0d0000 pid=3386 execve guuid=d0ce214b-1b00-0000-d29e-ff3c3b0d0000 pid=3387 /usr/bin/chmod guuid=8d71583b-1b00-0000-d29e-ff3c140d0000 pid=3348->guuid=d0ce214b-1b00-0000-d29e-ff3c3b0d0000 pid=3387 execve guuid=69de594b-1b00-0000-d29e-ff3c3c0d0000 pid=3388 /usr/bin/dash guuid=8d71583b-1b00-0000-d29e-ff3c140d0000 pid=3348->guuid=69de594b-1b00-0000-d29e-ff3c3c0d0000 pid=3388 clone guuid=be846e4b-1b00-0000-d29e-ff3c3d0d0000 pid=3389 /usr/bin/dash guuid=8d71583b-1b00-0000-d29e-ff3c140d0000 pid=3348->guuid=be846e4b-1b00-0000-d29e-ff3c3d0d0000 pid=3389 clone guuid=de1afe4b-1b00-0000-d29e-ff3c420d0000 pid=3394 /usr/bin/dash guuid=8d71583b-1b00-0000-d29e-ff3c140d0000 pid=3348->guuid=de1afe4b-1b00-0000-d29e-ff3c420d0000 pid=3394 clone guuid=39a97c4c-1b00-0000-d29e-ff3c460d0000 pid=3398 /usr/bin/dash guuid=8d71583b-1b00-0000-d29e-ff3c140d0000 pid=3348->guuid=39a97c4c-1b00-0000-d29e-ff3c460d0000 pid=3398 clone guuid=69a48f4c-1b00-0000-d29e-ff3c470d0000 pid=3399 /usr/bin/gpgv guuid=8d71583b-1b00-0000-d29e-ff3c140d0000 pid=3348->guuid=69a48f4c-1b00-0000-d29e-ff3c470d0000 pid=3399 execve guuid=c473ed4e-1b00-0000-d29e-ff3c4f0d0000 pid=3407 /usr/bin/rm delete-file guuid=8d71583b-1b00-0000-d29e-ff3c140d0000 pid=3348->guuid=c473ed4e-1b00-0000-d29e-ff3c4f0d0000 pid=3407 execve guuid=4b71c43d-1b00-0000-d29e-ff3c1e0d0000 pid=3358 /usr/bin/dpkg guuid=d2c0183c-1b00-0000-d29e-ff3c180d0000 pid=3352->guuid=4b71c43d-1b00-0000-d29e-ff3c1e0d0000 pid=3358 execve guuid=4529793f-1b00-0000-d29e-ff3c230d0000 pid=3363 /usr/bin/dpkg guuid=fecc893e-1b00-0000-d29e-ff3c220d0000 pid=3362->guuid=4529793f-1b00-0000-d29e-ff3c230d0000 pid=3363 execve guuid=e9582141-1b00-0000-d29e-ff3c250d0000 pid=3365 /usr/bin/dpkg guuid=a7c0f73f-1b00-0000-d29e-ff3c240d0000 pid=3364->guuid=e9582141-1b00-0000-d29e-ff3c250d0000 pid=3365 execve guuid=6b888642-1b00-0000-d29e-ff3c280d0000 pid=3368 /usr/bin/dpkg guuid=1fc09741-1b00-0000-d29e-ff3c260d0000 pid=3366->guuid=6b888642-1b00-0000-d29e-ff3c280d0000 pid=3368 execve guuid=abf4d845-1b00-0000-d29e-ff3c320d0000 pid=3378 /usr/bin/dpkg guuid=f19b4243-1b00-0000-d29e-ff3c2c0d0000 pid=3372->guuid=abf4d845-1b00-0000-d29e-ff3c320d0000 pid=3378 execve guuid=d6e6764b-1b00-0000-d29e-ff3c3e0d0000 pid=3390 /usr/bin/dash guuid=be846e4b-1b00-0000-d29e-ff3c3d0d0000 pid=3389->guuid=d6e6764b-1b00-0000-d29e-ff3c3e0d0000 pid=3390 clone guuid=4e0f7c4b-1b00-0000-d29e-ff3c3f0d0000 pid=3391 /usr/bin/sed guuid=be846e4b-1b00-0000-d29e-ff3c3d0d0000 pid=3389->guuid=4e0f7c4b-1b00-0000-d29e-ff3c3f0d0000 pid=3391 execve guuid=7c410a4c-1b00-0000-d29e-ff3c430d0000 pid=3395 /usr/bin/dash guuid=de1afe4b-1b00-0000-d29e-ff3c420d0000 pid=3394->guuid=7c410a4c-1b00-0000-d29e-ff3c430d0000 pid=3395 clone guuid=ff61194c-1b00-0000-d29e-ff3c440d0000 pid=3396 /usr/bin/sed guuid=de1afe4b-1b00-0000-d29e-ff3c420d0000 pid=3394->guuid=ff61194c-1b00-0000-d29e-ff3c440d0000 pid=3396 execve guuid=bddec952-1b00-0000-d29e-ff3c5b0d0000 pid=3419 /usr/bin/apt-key write-file guuid=c7b40a52-1b00-0000-d29e-ff3c590d0000 pid=3417->guuid=bddec952-1b00-0000-d29e-ff3c5b0d0000 pid=3419 execve guuid=82700253-1b00-0000-d29e-ff3c5c0d0000 pid=3420 /usr/bin/dash guuid=bddec952-1b00-0000-d29e-ff3c5b0d0000 pid=3419->guuid=82700253-1b00-0000-d29e-ff3c5c0d0000 pid=3420 clone guuid=1fc01353-1b00-0000-d29e-ff3c5e0d0000 pid=3422 /usr/bin/apt-config guuid=bddec952-1b00-0000-d29e-ff3c5b0d0000 pid=3419->guuid=1fc01353-1b00-0000-d29e-ff3c5e0d0000 pid=3422 execve guuid=b3a0ce59-1b00-0000-d29e-ff3c700d0000 pid=3440 /usr/bin/apt-config guuid=bddec952-1b00-0000-d29e-ff3c5b0d0000 pid=3419->guuid=b3a0ce59-1b00-0000-d29e-ff3c700d0000 pid=3440 execve guuid=8be74f5c-1b00-0000-d29e-ff3c7a0d0000 pid=3450 /usr/bin/apt-config guuid=bddec952-1b00-0000-d29e-ff3c5b0d0000 pid=3419->guuid=8be74f5c-1b00-0000-d29e-ff3c7a0d0000 pid=3450 execve guuid=f682035e-1b00-0000-d29e-ff3c800d0000 pid=3456 /usr/bin/apt-config guuid=bddec952-1b00-0000-d29e-ff3c5b0d0000 pid=3419->guuid=f682035e-1b00-0000-d29e-ff3c800d0000 pid=3456 execve guuid=2e45615f-1b00-0000-d29e-ff3c880d0000 pid=3464 /usr/bin/dash guuid=bddec952-1b00-0000-d29e-ff3c5b0d0000 pid=3419->guuid=2e45615f-1b00-0000-d29e-ff3c880d0000 pid=3464 clone guuid=95737e5f-1b00-0000-d29e-ff3c890d0000 pid=3465 /usr/bin/apt-config guuid=bddec952-1b00-0000-d29e-ff3c5b0d0000 pid=3419->guuid=95737e5f-1b00-0000-d29e-ff3c890d0000 pid=3465 execve guuid=dedbea60-1b00-0000-d29e-ff3c910d0000 pid=3473 /usr/bin/mktemp guuid=bddec952-1b00-0000-d29e-ff3c5b0d0000 pid=3419->guuid=dedbea60-1b00-0000-d29e-ff3c910d0000 pid=3473 execve guuid=eff82061-1b00-0000-d29e-ff3c930d0000 pid=3475 /usr/bin/chmod guuid=bddec952-1b00-0000-d29e-ff3c5b0d0000 pid=3419->guuid=eff82061-1b00-0000-d29e-ff3c930d0000 pid=3475 execve guuid=6f5f4d61-1b00-0000-d29e-ff3c940d0000 pid=3476 /usr/bin/dash guuid=bddec952-1b00-0000-d29e-ff3c5b0d0000 pid=3419->guuid=6f5f4d61-1b00-0000-d29e-ff3c940d0000 pid=3476 clone guuid=4efa5961-1b00-0000-d29e-ff3c960d0000 pid=3478 /usr/bin/dash guuid=bddec952-1b00-0000-d29e-ff3c5b0d0000 pid=3419->guuid=4efa5961-1b00-0000-d29e-ff3c960d0000 pid=3478 clone guuid=618eb861-1b00-0000-d29e-ff3c9a0d0000 pid=3482 /usr/bin/dash guuid=bddec952-1b00-0000-d29e-ff3c5b0d0000 pid=3419->guuid=618eb861-1b00-0000-d29e-ff3c9a0d0000 pid=3482 clone guuid=84882062-1b00-0000-d29e-ff3c9f0d0000 pid=3487 /usr/bin/dash guuid=bddec952-1b00-0000-d29e-ff3c5b0d0000 pid=3419->guuid=84882062-1b00-0000-d29e-ff3c9f0d0000 pid=3487 clone guuid=69fe2a62-1b00-0000-d29e-ff3ca00d0000 pid=3488 /usr/bin/gpgv guuid=bddec952-1b00-0000-d29e-ff3c5b0d0000 pid=3419->guuid=69fe2a62-1b00-0000-d29e-ff3ca00d0000 pid=3488 execve guuid=a9f89e63-1b00-0000-d29e-ff3ca70d0000 pid=3495 /usr/bin/rm delete-file guuid=bddec952-1b00-0000-d29e-ff3c5b0d0000 pid=3419->guuid=a9f89e63-1b00-0000-d29e-ff3ca70d0000 pid=3495 execve guuid=c393b754-1b00-0000-d29e-ff3c640d0000 pid=3428 /usr/bin/dpkg guuid=1fc01353-1b00-0000-d29e-ff3c5e0d0000 pid=3422->guuid=c393b754-1b00-0000-d29e-ff3c640d0000 pid=3428 execve guuid=382e9e5b-1b00-0000-d29e-ff3c770d0000 pid=3447 /usr/bin/dpkg guuid=b3a0ce59-1b00-0000-d29e-ff3c700d0000 pid=3440->guuid=382e9e5b-1b00-0000-d29e-ff3c770d0000 pid=3447 execve guuid=ba51815d-1b00-0000-d29e-ff3c7d0d0000 pid=3453 /usr/bin/dpkg guuid=8be74f5c-1b00-0000-d29e-ff3c7a0d0000 pid=3450->guuid=ba51815d-1b00-0000-d29e-ff3c7d0d0000 pid=3453 execve guuid=a586045f-1b00-0000-d29e-ff3c850d0000 pid=3461 /usr/bin/dpkg guuid=f682035e-1b00-0000-d29e-ff3c800d0000 pid=3456->guuid=a586045f-1b00-0000-d29e-ff3c850d0000 pid=3461 execve guuid=d8897b60-1b00-0000-d29e-ff3c8e0d0000 pid=3470 /usr/bin/dpkg guuid=95737e5f-1b00-0000-d29e-ff3c890d0000 pid=3465->guuid=d8897b60-1b00-0000-d29e-ff3c8e0d0000 pid=3470 execve guuid=60745f61-1b00-0000-d29e-ff3c970d0000 pid=3479 /usr/bin/dash guuid=4efa5961-1b00-0000-d29e-ff3c960d0000 pid=3478->guuid=60745f61-1b00-0000-d29e-ff3c970d0000 pid=3479 clone guuid=f5946461-1b00-0000-d29e-ff3c980d0000 pid=3480 /usr/bin/sed guuid=4efa5961-1b00-0000-d29e-ff3c960d0000 pid=3478->guuid=f5946461-1b00-0000-d29e-ff3c980d0000 pid=3480 execve guuid=a6b9c161-1b00-0000-d29e-ff3c9b0d0000 pid=3483 /usr/bin/dash guuid=618eb861-1b00-0000-d29e-ff3c9a0d0000 pid=3482->guuid=a6b9c161-1b00-0000-d29e-ff3c9b0d0000 pid=3483 clone guuid=1db2c661-1b00-0000-d29e-ff3c9c0d0000 pid=3484 /usr/bin/sed guuid=618eb861-1b00-0000-d29e-ff3c9a0d0000 pid=3482->guuid=1db2c661-1b00-0000-d29e-ff3c9c0d0000 pid=3484 execve guuid=beeb4b65-1b00-0000-d29e-ff3cad0d0000 pid=3501 /usr/bin/apt-key write-file guuid=21e88264-1b00-0000-d29e-ff3ca90d0000 pid=3497->guuid=beeb4b65-1b00-0000-d29e-ff3cad0d0000 pid=3501 execve guuid=edb29b65-1b00-0000-d29e-ff3caf0d0000 pid=3503 /usr/bin/dash guuid=beeb4b65-1b00-0000-d29e-ff3cad0d0000 pid=3501->guuid=edb29b65-1b00-0000-d29e-ff3caf0d0000 pid=3503 clone guuid=02f4b265-1b00-0000-d29e-ff3cb00d0000 pid=3504 /usr/bin/apt-config guuid=beeb4b65-1b00-0000-d29e-ff3cad0d0000 pid=3501->guuid=02f4b265-1b00-0000-d29e-ff3cb00d0000 pid=3504 execve guuid=0392c669-1b00-0000-d29e-ff3cbe0d0000 pid=3518 /usr/bin/apt-config guuid=beeb4b65-1b00-0000-d29e-ff3cad0d0000 pid=3501->guuid=0392c669-1b00-0000-d29e-ff3cbe0d0000 pid=3518 execve guuid=d81e606b-1b00-0000-d29e-ff3cc60d0000 pid=3526 /usr/bin/apt-config guuid=beeb4b65-1b00-0000-d29e-ff3cad0d0000 pid=3501->guuid=d81e606b-1b00-0000-d29e-ff3cc60d0000 pid=3526 execve guuid=f78cea6c-1b00-0000-d29e-ff3cce0d0000 pid=3534 /usr/bin/apt-config guuid=beeb4b65-1b00-0000-d29e-ff3cad0d0000 pid=3501->guuid=f78cea6c-1b00-0000-d29e-ff3cce0d0000 pid=3534 execve guuid=b3fe736e-1b00-0000-d29e-ff3cd60d0000 pid=3542 /usr/bin/dash guuid=beeb4b65-1b00-0000-d29e-ff3cad0d0000 pid=3501->guuid=b3fe736e-1b00-0000-d29e-ff3cd60d0000 pid=3542 clone guuid=39bf926e-1b00-0000-d29e-ff3cd70d0000 pid=3543 /usr/bin/apt-config guuid=beeb4b65-1b00-0000-d29e-ff3cad0d0000 pid=3501->guuid=39bf926e-1b00-0000-d29e-ff3cd70d0000 pid=3543 execve guuid=b64e4670-1b00-0000-d29e-ff3ce00d0000 pid=3552 /usr/bin/mktemp guuid=beeb4b65-1b00-0000-d29e-ff3cad0d0000 pid=3501->guuid=b64e4670-1b00-0000-d29e-ff3ce00d0000 pid=3552 execve guuid=e1277d70-1b00-0000-d29e-ff3ce20d0000 pid=3554 /usr/bin/chmod guuid=beeb4b65-1b00-0000-d29e-ff3cad0d0000 pid=3501->guuid=e1277d70-1b00-0000-d29e-ff3ce20d0000 pid=3554 execve guuid=fbb6af70-1b00-0000-d29e-ff3ce30d0000 pid=3555 /usr/bin/dash guuid=beeb4b65-1b00-0000-d29e-ff3cad0d0000 pid=3501->guuid=fbb6af70-1b00-0000-d29e-ff3ce30d0000 pid=3555 clone guuid=1653c370-1b00-0000-d29e-ff3ce50d0000 pid=3557 /usr/bin/dash guuid=beeb4b65-1b00-0000-d29e-ff3cad0d0000 pid=3501->guuid=1653c370-1b00-0000-d29e-ff3ce50d0000 pid=3557 clone guuid=6d2c2971-1b00-0000-d29e-ff3ce90d0000 pid=3561 /usr/bin/dash guuid=beeb4b65-1b00-0000-d29e-ff3cad0d0000 pid=3501->guuid=6d2c2971-1b00-0000-d29e-ff3ce90d0000 pid=3561 clone guuid=a004e271-1b00-0000-d29e-ff3cef0d0000 pid=3567 /usr/bin/dash guuid=beeb4b65-1b00-0000-d29e-ff3cad0d0000 pid=3501->guuid=a004e271-1b00-0000-d29e-ff3cef0d0000 pid=3567 clone guuid=5925f071-1b00-0000-d29e-ff3cf00d0000 pid=3568 /usr/bin/gpgv guuid=beeb4b65-1b00-0000-d29e-ff3cad0d0000 pid=3501->guuid=5925f071-1b00-0000-d29e-ff3cf00d0000 pid=3568 execve guuid=67075f74-1b00-0000-d29e-ff3cf80d0000 pid=3576 /usr/bin/rm delete-file guuid=beeb4b65-1b00-0000-d29e-ff3cad0d0000 pid=3501->guuid=67075f74-1b00-0000-d29e-ff3cf80d0000 pid=3576 execve guuid=4ad0bd68-1b00-0000-d29e-ff3cba0d0000 pid=3514 /usr/bin/dpkg guuid=02f4b265-1b00-0000-d29e-ff3cb00d0000 pid=3504->guuid=4ad0bd68-1b00-0000-d29e-ff3cba0d0000 pid=3514 execve guuid=5e41ef6a-1b00-0000-d29e-ff3cc30d0000 pid=3523 /usr/bin/dpkg guuid=0392c669-1b00-0000-d29e-ff3cbe0d0000 pid=3518->guuid=5e41ef6a-1b00-0000-d29e-ff3cc30d0000 pid=3523 execve guuid=6460756c-1b00-0000-d29e-ff3ccb0d0000 pid=3531 /usr/bin/dpkg guuid=d81e606b-1b00-0000-d29e-ff3cc60d0000 pid=3526->guuid=6460756c-1b00-0000-d29e-ff3ccb0d0000 pid=3531 execve guuid=3f36fd6d-1b00-0000-d29e-ff3cd30d0000 pid=3539 /usr/bin/dpkg guuid=f78cea6c-1b00-0000-d29e-ff3cce0d0000 pid=3534->guuid=3f36fd6d-1b00-0000-d29e-ff3cd30d0000 pid=3539 execve guuid=9f94a56f-1b00-0000-d29e-ff3cdd0d0000 pid=3549 /usr/bin/dpkg guuid=39bf926e-1b00-0000-d29e-ff3cd70d0000 pid=3543->guuid=9f94a56f-1b00-0000-d29e-ff3cdd0d0000 pid=3549 execve guuid=ac78ce70-1b00-0000-d29e-ff3ce60d0000 pid=3558 /usr/bin/dash guuid=1653c370-1b00-0000-d29e-ff3ce50d0000 pid=3557->guuid=ac78ce70-1b00-0000-d29e-ff3ce60d0000 pid=3558 clone guuid=fc62d570-1b00-0000-d29e-ff3ce70d0000 pid=3559 /usr/bin/sed guuid=1653c370-1b00-0000-d29e-ff3ce50d0000 pid=3557->guuid=fc62d570-1b00-0000-d29e-ff3ce70d0000 pid=3559 execve guuid=a0c53271-1b00-0000-d29e-ff3cea0d0000 pid=3562 /usr/bin/dash guuid=6d2c2971-1b00-0000-d29e-ff3ce90d0000 pid=3561->guuid=a0c53271-1b00-0000-d29e-ff3cea0d0000 pid=3562 clone guuid=85a83771-1b00-0000-d29e-ff3cec0d0000 pid=3564 /usr/bin/sed guuid=6d2c2971-1b00-0000-d29e-ff3ce90d0000 pid=3561->guuid=85a83771-1b00-0000-d29e-ff3cec0d0000 pid=3564 execve guuid=6490b376-1b00-0000-d29e-ff3c020e0000 pid=3586 /usr/bin/apt-key write-file guuid=aa03ac75-1b00-0000-d29e-ff3cfd0d0000 pid=3581->guuid=6490b376-1b00-0000-d29e-ff3c020e0000 pid=3586 execve guuid=1caff976-1b00-0000-d29e-ff3c050e0000 pid=3589 /usr/bin/dash guuid=6490b376-1b00-0000-d29e-ff3c020e0000 pid=3586->guuid=1caff976-1b00-0000-d29e-ff3c050e0000 pid=3589 clone guuid=b2c90f77-1b00-0000-d29e-ff3c060e0000 pid=3590 /usr/bin/apt-config guuid=6490b376-1b00-0000-d29e-ff3c020e0000 pid=3586->guuid=b2c90f77-1b00-0000-d29e-ff3c060e0000 pid=3590 execve guuid=ef12a67b-1b00-0000-d29e-ff3c080e0000 pid=3592 /usr/bin/apt-config guuid=6490b376-1b00-0000-d29e-ff3c020e0000 pid=3586->guuid=ef12a67b-1b00-0000-d29e-ff3c080e0000 pid=3592 execve guuid=4ef1567d-1b00-0000-d29e-ff3c0a0e0000 pid=3594 /usr/bin/apt-config guuid=6490b376-1b00-0000-d29e-ff3c020e0000 pid=3586->guuid=4ef1567d-1b00-0000-d29e-ff3c0a0e0000 pid=3594 execve guuid=bb75cd7e-1b00-0000-d29e-ff3c0c0e0000 pid=3596 /usr/bin/apt-config guuid=6490b376-1b00-0000-d29e-ff3c020e0000 pid=3586->guuid=bb75cd7e-1b00-0000-d29e-ff3c0c0e0000 pid=3596 execve guuid=e8ef0886-1b00-0000-d29e-ff3c140e0000 pid=3604 /usr/bin/dash guuid=6490b376-1b00-0000-d29e-ff3c020e0000 pid=3586->guuid=e8ef0886-1b00-0000-d29e-ff3c140e0000 pid=3604 clone guuid=2bcd3086-1b00-0000-d29e-ff3c150e0000 pid=3605 /usr/bin/apt-config guuid=6490b376-1b00-0000-d29e-ff3c020e0000 pid=3586->guuid=2bcd3086-1b00-0000-d29e-ff3c150e0000 pid=3605 execve guuid=306b9287-1b00-0000-d29e-ff3c1b0e0000 pid=3611 /usr/bin/mktemp guuid=6490b376-1b00-0000-d29e-ff3c020e0000 pid=3586->guuid=306b9287-1b00-0000-d29e-ff3c1b0e0000 pid=3611 execve guuid=6a8ac987-1b00-0000-d29e-ff3c1c0e0000 pid=3612 /usr/bin/chmod guuid=6490b376-1b00-0000-d29e-ff3c020e0000 pid=3586->guuid=6a8ac987-1b00-0000-d29e-ff3c1c0e0000 pid=3612 execve guuid=5a600388-1b00-0000-d29e-ff3c1e0e0000 pid=3614 /usr/bin/dash guuid=6490b376-1b00-0000-d29e-ff3c020e0000 pid=3586->guuid=5a600388-1b00-0000-d29e-ff3c1e0e0000 pid=3614 clone guuid=4ed51388-1b00-0000-d29e-ff3c1f0e0000 pid=3615 /usr/bin/dash guuid=6490b376-1b00-0000-d29e-ff3c020e0000 pid=3586->guuid=4ed51388-1b00-0000-d29e-ff3c1f0e0000 pid=3615 clone guuid=376f6a88-1b00-0000-d29e-ff3c230e0000 pid=3619 /usr/bin/dash guuid=6490b376-1b00-0000-d29e-ff3c020e0000 pid=3586->guuid=376f6a88-1b00-0000-d29e-ff3c230e0000 pid=3619 clone guuid=6fa4ca88-1b00-0000-d29e-ff3c270e0000 pid=3623 /usr/bin/dash guuid=6490b376-1b00-0000-d29e-ff3c020e0000 pid=3586->guuid=6fa4ca88-1b00-0000-d29e-ff3c270e0000 pid=3623 clone guuid=fe51d888-1b00-0000-d29e-ff3c280e0000 pid=3624 /usr/bin/gpgv guuid=6490b376-1b00-0000-d29e-ff3c020e0000 pid=3586->guuid=fe51d888-1b00-0000-d29e-ff3c280e0000 pid=3624 execve guuid=cc0a898a-1b00-0000-d29e-ff3c290e0000 pid=3625 /usr/bin/rm delete-file guuid=6490b376-1b00-0000-d29e-ff3c020e0000 pid=3586->guuid=cc0a898a-1b00-0000-d29e-ff3c290e0000 pid=3625 execve guuid=f6303e7a-1b00-0000-d29e-ff3c070e0000 pid=3591 /usr/bin/dpkg guuid=b2c90f77-1b00-0000-d29e-ff3c060e0000 pid=3590->guuid=f6303e7a-1b00-0000-d29e-ff3c070e0000 pid=3591 execve guuid=7fd5d17c-1b00-0000-d29e-ff3c090e0000 pid=3593 /usr/bin/dpkg guuid=ef12a67b-1b00-0000-d29e-ff3c080e0000 pid=3592->guuid=7fd5d17c-1b00-0000-d29e-ff3c090e0000 pid=3593 execve guuid=6ce2607e-1b00-0000-d29e-ff3c0b0e0000 pid=3595 /usr/bin/dpkg guuid=4ef1567d-1b00-0000-d29e-ff3c0a0e0000 pid=3594->guuid=6ce2607e-1b00-0000-d29e-ff3c0b0e0000 pid=3595 execve guuid=c56f1581-1b00-0000-d29e-ff3c0d0e0000 pid=3597 /usr/bin/dpkg guuid=bb75cd7e-1b00-0000-d29e-ff3c0c0e0000 pid=3596->guuid=c56f1581-1b00-0000-d29e-ff3c0d0e0000 pid=3597 execve guuid=becf2287-1b00-0000-d29e-ff3c190e0000 pid=3609 /usr/bin/dpkg guuid=2bcd3086-1b00-0000-d29e-ff3c150e0000 pid=3605->guuid=becf2287-1b00-0000-d29e-ff3c190e0000 pid=3609 execve guuid=19041a88-1b00-0000-d29e-ff3c200e0000 pid=3616 /usr/bin/dash guuid=4ed51388-1b00-0000-d29e-ff3c1f0e0000 pid=3615->guuid=19041a88-1b00-0000-d29e-ff3c200e0000 pid=3616 clone guuid=9b281e88-1b00-0000-d29e-ff3c210e0000 pid=3617 /usr/bin/sed guuid=4ed51388-1b00-0000-d29e-ff3c1f0e0000 pid=3615->guuid=9b281e88-1b00-0000-d29e-ff3c210e0000 pid=3617 execve guuid=35af7288-1b00-0000-d29e-ff3c240e0000 pid=3620 /usr/bin/dash guuid=376f6a88-1b00-0000-d29e-ff3c230e0000 pid=3619->guuid=35af7288-1b00-0000-d29e-ff3c240e0000 pid=3620 clone guuid=6d877788-1b00-0000-d29e-ff3c250e0000 pid=3621 /usr/bin/sed guuid=376f6a88-1b00-0000-d29e-ff3c230e0000 pid=3619->guuid=6d877788-1b00-0000-d29e-ff3c250e0000 pid=3621 execve guuid=7e86e911-1f00-0000-d29e-ff3ced140000 pid=5357 /usr/bin/dpkg guuid=80b9bc10-1f00-0000-d29e-ff3cec140000 pid=5356->guuid=7e86e911-1f00-0000-d29e-ff3ced140000 pid=5357 execve guuid=d5cbdb12-1f00-0000-d29e-ff3cef140000 pid=5359->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 60B ee824bb6-9d7f-509d-a4f0-fd51354eb3c4 gh-proxy.com:0 guuid=d5cbdb12-1f00-0000-d29e-ff3cef140000 pid=5359->ee824bb6-9d7f-509d-a4f0-fd51354eb3c4 con b8bc6989-015e-543d-9893-4b9e05bf42bb gh-proxy.com:443 guuid=d5cbdb12-1f00-0000-d29e-ff3cef140000 pid=5359->b8bc6989-015e-543d-9893-4b9e05bf42bb send: 820B 2f50a59f-2358-5b5c-aa0a-c8fc64202aee hosts-to-ignore.ignorelist.com:1443 guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5363->2f50a59f-2358-5b5c-aa0a-c8fc64202aee send: 859B guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5371 /usr/lib/dev/systemdev/dns-filter write-file guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5363->guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5371 clone guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5372 /usr/lib/dev/systemdev/dns-filter dns net send-data guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5363->guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5372 clone guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5373 /usr/lib/dev/systemdev/dns-filter guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5363->guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5373 clone guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5374 /usr/lib/dev/systemdev/dns-filter guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5363->guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5374 clone guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5375 /usr/lib/dev/systemdev/dns-filter guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5363->guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5375 clone guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5378 /usr/lib/dev/systemdev/dns-filter guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5363->guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5378 clone guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5379 /usr/lib/dev/systemdev/dns-filter guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5363->guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5379 clone guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5380 /usr/lib/dev/systemdev/dns-filter guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5363->guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5380 clone guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5381 /usr/lib/dev/systemdev/dns-filter guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5363->guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5381 clone guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5382 /usr/lib/dev/systemdev/dns-filter guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5363->guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5382 clone guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5383 /usr/lib/dev/systemdev/dns-filter guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5363->guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5383 clone guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5384 /usr/lib/dev/systemdev/dns-filter guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5363->guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5384 clone guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5385 /usr/lib/dev/systemdev/dns-filter guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5363->guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5385 clone guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5386 /usr/lib/dev/systemdev/dns-filter guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5363->guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5386 clone guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5387 /usr/lib/dev/systemdev/dns-filter guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5363->guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5387 clone guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5388 /usr/lib/dev/systemdev/dns-filter guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5363->guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5388 clone guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5389 /usr/lib/dev/systemdev/dns-filter guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5363->guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5389 clone guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5390 /usr/lib/dev/systemdev/dns-filter guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5363->guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5390 clone guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5391 /usr/lib/dev/systemdev/dns-filter guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5363->guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5391 clone guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5392 /usr/lib/dev/systemdev/dns-filter guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5363->guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5392 clone guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5393 /usr/lib/dev/systemdev/dns-filter guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5363->guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5393 clone guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5394 /usr/lib/dev/systemdev/dns-filter guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5363->guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5394 clone guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5395 /usr/lib/dev/systemdev/dns-filter guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5363->guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5395 clone guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5396 /usr/lib/dev/systemdev/dns-filter guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5363->guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5396 clone guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5397 /usr/lib/dev/systemdev/dns-filter guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5363->guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5397 clone guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5398 /usr/lib/dev/systemdev/dns-filter guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5363->guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5398 clone guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5399 /usr/lib/dev/systemdev/dns-filter guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5363->guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5399 clone guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5400 /usr/lib/dev/systemdev/dns-filter guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5363->guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5400 clone guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5401 /usr/lib/dev/systemdev/dns-filter guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5363->guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5401 clone guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5402 /usr/lib/dev/systemdev/dns-filter guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5363->guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5402 clone guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5403 /usr/lib/dev/systemdev/dns-filter guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5363->guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5403 clone guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5404 /usr/lib/dev/systemdev/dns-filter guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5363->guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5404 clone guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5405 /usr/lib/dev/systemdev/dns-filter guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5363->guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5405 clone guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5406 /usr/lib/dev/systemdev/dns-filter guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5363->guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5406 clone guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5407 /usr/lib/dev/systemdev/dns-filter guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5363->guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5407 clone guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5408 /usr/lib/dev/systemdev/dns-filter guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5363->guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5408 clone guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5409 /usr/lib/dev/systemdev/dns-filter guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5363->guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5409 clone guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5410 /usr/lib/dev/systemdev/dns-filter guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5363->guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5410 clone guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5411 /usr/lib/dev/systemdev/dns-filter guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5363->guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5411 clone guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5412 /usr/lib/dev/systemdev/dns-filter guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5363->guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5412 clone guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5413 /usr/lib/dev/systemdev/dns-filter guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5363->guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5413 clone guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5414 /usr/lib/dev/systemdev/dns-filter guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5363->guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5414 clone guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5415 /usr/lib/dev/systemdev/dns-filter guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5363->guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5415 clone guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5416 /usr/lib/dev/systemdev/dns-filter guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5363->guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5416 clone guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5417 /usr/lib/dev/systemdev/dns-filter guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5363->guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5417 clone guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5418 /usr/lib/dev/systemdev/dns-filter guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5363->guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5418 clone guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5419 /usr/lib/dev/systemdev/dns-filter guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5363->guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5419 clone guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5420 /usr/lib/dev/systemdev/dns-filter guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5363->guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5420 clone guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5421 /usr/lib/dev/systemdev/dns-filter guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5363->guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5421 clone guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5422 /usr/lib/dev/systemdev/dns-filter guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5363->guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5422 clone guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5423 /usr/lib/dev/systemdev/dns-filter guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5363->guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5423 clone guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5424 /usr/lib/dev/systemdev/dns-filter guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5363->guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5424 clone guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5425 /usr/lib/dev/systemdev/dns-filter guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5363->guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5425 clone guuid=85d45844-1f00-0000-d29e-ff3cf3140000 pid=5372->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 96B guuid=ba7ed289-2000-0000-d29e-ff3c37150000 pid=5431 /usr/bin/bash guuid=e6939c89-2000-0000-d29e-ff3c35150000 pid=5429->guuid=ba7ed289-2000-0000-d29e-ff3c37150000 pid=5431 clone
Threat name:
Script-PowerShell.Trojan.Heuristic
Status:
Malicious
First seen:
2025-09-08 14:57:40 UTC
File Type:
Text (Shell)
AV detection:
9 of 38 (23.68%)
Threat level:
  2/5
Result
Malware family:
xmrig_linux
Score:
  10/10
Tags:
family:xmrig family:xmrig_linux antivm defense_evasion discovery execution linux miner persistence privilege_escalation
Behaviour
Enumerates kernel/hardware configuration
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads CPU attributes
Checks hardware identifiers (DMI)
Creates/modifies Cron job
Enumerates running processes
Reads hardware information
File and Directory Permissions Modification
Executes dropped EXE
XMRig Miner payload
Xmrig family
Xmrig_linux family
xmrig
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

CoinMiner

sh 2313d2be36cfe75bffced9e2221788cc4e21233ee304ecacf9da9e90a3b647c5

(this sample)

4537e474274cf7e7e1920f0ba0ccd7fc219b2698a5af85689649ceb7962953ce

  
Delivery method
Distributed via web download
  
Dropping
MD5 0782916ee8c331309e8fd467529ed93d
  
Dropping
SHA256 4537e474274cf7e7e1920f0ba0ccd7fc219b2698a5af85689649ceb7962953ce

Comments