MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 49f7c39a65dd92b1d4e266d99c239253197f48d07d5c8ca2dbcb086ddc9c4751. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



CoinMiner


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 49f7c39a65dd92b1d4e266d99c239253197f48d07d5c8ca2dbcb086ddc9c4751
SHA3-384 hash: 47c8bb6ec18717a7662f666b31e9d7a944d9a44d616b69717c126420e3094cb92dfe578fce2aa175a343332641e11acd
SHA1 hash: 5f18bdc2f66c9ccf8e3bd688fe2821052dfaa103
MD5 hash: 568c5af729e535d32086a14aad3aa74e
humanhash: london-winter-washington-cat
File name:proxy.sh
Download: download sample
Signature CoinMiner
File size:2'241 bytes
First seen:2026-04-04 16:59:44 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:eNI6nWQ7x8bD9NwV6vlId/IkKj4Q1d48OUG4nZILSwT/Nh:C9WQd89NxNCwzjrS8q57X
TLSH T1514131E12C5059B4279FCA2046BE5525E01301577A132828B4BFA01C7B7A996B1FEEB6
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:CoinMiner sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
43
Origin country :
DE DE
Vendor Threat Intelligence
Gathering data
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
base64 bash lolbin obfuscated
Verdict:
Adware
File Type:
unix shell
First seen:
2026-04-04T14:14:00Z UTC
Last seen:
2026-04-04T14:48:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=cb26c841-1a00-0000-97e2-11fc0c090000 pid=2316 /usr/bin/sudo guuid=cc13c944-1a00-0000-97e2-11fc0f090000 pid=2319 /tmp/sample.bin guuid=cb26c841-1a00-0000-97e2-11fc0c090000 pid=2316->guuid=cc13c944-1a00-0000-97e2-11fc0f090000 pid=2319 execve guuid=77992845-1a00-0000-97e2-11fc10090000 pid=2320 /usr/bin/hostname guuid=cc13c944-1a00-0000-97e2-11fc0f090000 pid=2319->guuid=77992845-1a00-0000-97e2-11fc10090000 pid=2320 execve guuid=3542d145-1a00-0000-97e2-11fc13090000 pid=2323 /usr/bin/uname guuid=cc13c944-1a00-0000-97e2-11fc0f090000 pid=2319->guuid=3542d145-1a00-0000-97e2-11fc13090000 pid=2323 execve guuid=6cb75146-1a00-0000-97e2-11fc15090000 pid=2325 /usr/bin/screen guuid=cc13c944-1a00-0000-97e2-11fc0f090000 pid=2319->guuid=6cb75146-1a00-0000-97e2-11fc15090000 pid=2325 execve guuid=35675846-1a00-0000-97e2-11fc16090000 pid=2326 /usr/bin/grep guuid=cc13c944-1a00-0000-97e2-11fc0f090000 pid=2319->guuid=35675846-1a00-0000-97e2-11fc16090000 pid=2326 execve guuid=0a6ae447-1a00-0000-97e2-11fc19090000 pid=2329 /usr/bin/apt-get delete-file write-file guuid=cc13c944-1a00-0000-97e2-11fc0f090000 pid=2319->guuid=0a6ae447-1a00-0000-97e2-11fc19090000 pid=2329 execve guuid=1728209d-1e00-0000-97e2-11fc62120000 pid=4706 /usr/bin/apt-get guuid=cc13c944-1a00-0000-97e2-11fc0f090000 pid=2319->guuid=1728209d-1e00-0000-97e2-11fc62120000 pid=4706 execve guuid=e89a1d9f-1e00-0000-97e2-11fc6f120000 pid=4719 /usr/bin/mkdir guuid=cc13c944-1a00-0000-97e2-11fc0f090000 pid=2319->guuid=e89a1d9f-1e00-0000-97e2-11fc6f120000 pid=4719 execve guuid=74c6769f-1e00-0000-97e2-11fc70120000 pid=4720 /usr/bin/wget dns net send-data write-file guuid=cc13c944-1a00-0000-97e2-11fc0f090000 pid=2319->guuid=74c6769f-1e00-0000-97e2-11fc70120000 pid=4720 execve guuid=714f809f-1e00-0000-97e2-11fc72120000 pid=4722 /usr/bin/tar write-file guuid=cc13c944-1a00-0000-97e2-11fc0f090000 pid=2319->guuid=714f809f-1e00-0000-97e2-11fc72120000 pid=4722 execve guuid=e1beddef-1e00-0000-97e2-11fc89120000 pid=4745 /usr/bin/mv guuid=cc13c944-1a00-0000-97e2-11fc0f090000 pid=2319->guuid=e1beddef-1e00-0000-97e2-11fc89120000 pid=4745 execve guuid=d12a72f0-1e00-0000-97e2-11fc8b120000 pid=4747 /usr/bin/chmod guuid=cc13c944-1a00-0000-97e2-11fc0f090000 pid=2319->guuid=d12a72f0-1e00-0000-97e2-11fc8b120000 pid=4747 execve guuid=3d24d8f0-1e00-0000-97e2-11fc8c120000 pid=4748 /usr/bin/nproc guuid=cc13c944-1a00-0000-97e2-11fc0f090000 pid=2319->guuid=3d24d8f0-1e00-0000-97e2-11fc8c120000 pid=4748 execve guuid=220a8cf1-1e00-0000-97e2-11fc8e120000 pid=4750 /usr/bin/screen guuid=cc13c944-1a00-0000-97e2-11fc0f090000 pid=2319->guuid=220a8cf1-1e00-0000-97e2-11fc8e120000 pid=4750 execve guuid=c2841bf2-1e00-0000-97e2-11fc91120000 pid=4753 /usr/bin/bash guuid=cc13c944-1a00-0000-97e2-11fc0f090000 pid=2319->guuid=c2841bf2-1e00-0000-97e2-11fc91120000 pid=4753 clone guuid=ee2b23f2-1e00-0000-97e2-11fc92120000 pid=4754 /usr/bin/bash guuid=cc13c944-1a00-0000-97e2-11fc0f090000 pid=2319->guuid=ee2b23f2-1e00-0000-97e2-11fc92120000 pid=4754 clone guuid=290e5a4a-1a00-0000-97e2-11fc1b090000 pid=2331 /usr/bin/dpkg guuid=0a6ae447-1a00-0000-97e2-11fc19090000 pid=2329->guuid=290e5a4a-1a00-0000-97e2-11fc1b090000 pid=2331 execve guuid=7cda2851-1a00-0000-97e2-11fc26090000 pid=2342 /usr/lib/apt/methods/mirror guuid=0a6ae447-1a00-0000-97e2-11fc19090000 pid=2329->guuid=7cda2851-1a00-0000-97e2-11fc26090000 pid=2342 execve guuid=3a5bfe52-1a00-0000-97e2-11fc2d090000 pid=2349 /usr/lib/apt/methods/mirror guuid=0a6ae447-1a00-0000-97e2-11fc19090000 pid=2329->guuid=3a5bfe52-1a00-0000-97e2-11fc2d090000 pid=2349 execve guuid=669a0455-1a00-0000-97e2-11fc31090000 pid=2353 /usr/lib/apt/methods/file guuid=0a6ae447-1a00-0000-97e2-11fc19090000 pid=2329->guuid=669a0455-1a00-0000-97e2-11fc31090000 pid=2353 execve guuid=52278157-1a00-0000-97e2-11fc37090000 pid=2359 /usr/lib/apt/methods/file delete-file guuid=0a6ae447-1a00-0000-97e2-11fc19090000 pid=2329->guuid=52278157-1a00-0000-97e2-11fc37090000 pid=2359 execve guuid=723b5259-1a00-0000-97e2-11fc3a090000 pid=2362 /usr/lib/apt/methods/http guuid=0a6ae447-1a00-0000-97e2-11fc19090000 pid=2329->guuid=723b5259-1a00-0000-97e2-11fc3a090000 pid=2362 execve guuid=47fe065b-1a00-0000-97e2-11fc3f090000 pid=2367 /usr/lib/apt/methods/http dns net send-data write-file guuid=0a6ae447-1a00-0000-97e2-11fc19090000 pid=2329->guuid=47fe065b-1a00-0000-97e2-11fc3f090000 pid=2367 execve guuid=5d697e74-1a00-0000-97e2-11fc69090000 pid=2409 /usr/lib/apt/methods/gpgv guuid=0a6ae447-1a00-0000-97e2-11fc19090000 pid=2329->guuid=5d697e74-1a00-0000-97e2-11fc69090000 pid=2409 execve guuid=ad591676-1a00-0000-97e2-11fc6a090000 pid=2410 /usr/lib/apt/methods/gpgv guuid=0a6ae447-1a00-0000-97e2-11fc19090000 pid=2329->guuid=ad591676-1a00-0000-97e2-11fc6a090000 pid=2410 execve guuid=be95fcca-1a00-0000-97e2-11fc580a0000 pid=2648 /usr/lib/apt/methods/store guuid=0a6ae447-1a00-0000-97e2-11fc19090000 pid=2329->guuid=be95fcca-1a00-0000-97e2-11fc580a0000 pid=2648 execve guuid=8ea38fcd-1a00-0000-97e2-11fc5f0a0000 pid=2655 /usr/lib/apt/methods/store write-file guuid=0a6ae447-1a00-0000-97e2-11fc19090000 pid=2329->guuid=8ea38fcd-1a00-0000-97e2-11fc5f0a0000 pid=2655 execve guuid=4cf6992b-1e00-0000-97e2-11fc9f100000 pid=4255 /usr/bin/dpkg guuid=0a6ae447-1a00-0000-97e2-11fc19090000 pid=2329->guuid=4cf6992b-1e00-0000-97e2-11fc9f100000 pid=4255 execve guuid=1928449b-1e00-0000-97e2-11fc58120000 pid=4696 /usr/bin/dpkg guuid=0a6ae447-1a00-0000-97e2-11fc19090000 pid=2329->guuid=1928449b-1e00-0000-97e2-11fc58120000 pid=4696 execve 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=47fe065b-1a00-0000-97e2-11fc3f090000 pid=2367->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 122B 869ebe88-8c1e-5fbb-adb0-cfe48d8d7faf debian.map.fastly.net:443 guuid=47fe065b-1a00-0000-97e2-11fc3f090000 pid=2367->869ebe88-8c1e-5fbb-adb0-cfe48d8d7faf send: 6038B guuid=90933f77-1a00-0000-97e2-11fc6b090000 pid=2411 /usr/lib/apt/methods/gpgv delete-file write-file guuid=ad591676-1a00-0000-97e2-11fc6a090000 pid=2410->guuid=90933f77-1a00-0000-97e2-11fc6b090000 pid=2411 clone guuid=6a108192-1a00-0000-97e2-11fcb2090000 pid=2482 /usr/lib/apt/methods/gpgv delete-file write-file guuid=ad591676-1a00-0000-97e2-11fc6a090000 pid=2410->guuid=6a108192-1a00-0000-97e2-11fcb2090000 pid=2482 clone guuid=a83b3fa9-1a00-0000-97e2-11fcf5090000 pid=2549 /usr/lib/apt/methods/gpgv delete-file write-file guuid=ad591676-1a00-0000-97e2-11fc6a090000 pid=2410->guuid=a83b3fa9-1a00-0000-97e2-11fcf5090000 pid=2549 clone guuid=2dcd5dc7-1a00-0000-97e2-11fc530a0000 pid=2643 /usr/lib/apt/methods/gpgv delete-file write-file guuid=ad591676-1a00-0000-97e2-11fc6a090000 pid=2410->guuid=2dcd5dc7-1a00-0000-97e2-11fc530a0000 pid=2643 clone guuid=b0bf7e7b-1a00-0000-97e2-11fc6d090000 pid=2413 /usr/bin/apt-key write-file guuid=90933f77-1a00-0000-97e2-11fc6b090000 pid=2411->guuid=b0bf7e7b-1a00-0000-97e2-11fc6d090000 pid=2413 execve guuid=289e697c-1a00-0000-97e2-11fc6f090000 pid=2415 /usr/bin/dash guuid=b0bf7e7b-1a00-0000-97e2-11fc6d090000 pid=2413->guuid=289e697c-1a00-0000-97e2-11fc6f090000 pid=2415 clone guuid=8027887c-1a00-0000-97e2-11fc71090000 pid=2417 /usr/bin/apt-config guuid=b0bf7e7b-1a00-0000-97e2-11fc6d090000 pid=2413->guuid=8027887c-1a00-0000-97e2-11fc71090000 pid=2417 execve guuid=e402c47e-1a00-0000-97e2-11fc77090000 pid=2423 /usr/bin/apt-config guuid=b0bf7e7b-1a00-0000-97e2-11fc6d090000 pid=2413->guuid=e402c47e-1a00-0000-97e2-11fc77090000 pid=2423 execve guuid=2bfb1987-1a00-0000-97e2-11fc85090000 pid=2437 /usr/bin/apt-config guuid=b0bf7e7b-1a00-0000-97e2-11fc6d090000 pid=2413->guuid=2bfb1987-1a00-0000-97e2-11fc85090000 pid=2437 execve guuid=3e1fbf88-1a00-0000-97e2-11fc8b090000 pid=2443 /usr/bin/apt-config guuid=b0bf7e7b-1a00-0000-97e2-11fc6d090000 pid=2413->guuid=3e1fbf88-1a00-0000-97e2-11fc8b090000 pid=2443 execve guuid=b650238a-1a00-0000-97e2-11fc91090000 pid=2449 /usr/bin/dash guuid=b0bf7e7b-1a00-0000-97e2-11fc6d090000 pid=2413->guuid=b650238a-1a00-0000-97e2-11fc91090000 pid=2449 clone guuid=97c14f8a-1a00-0000-97e2-11fc93090000 pid=2451 /usr/bin/apt-config guuid=b0bf7e7b-1a00-0000-97e2-11fc6d090000 pid=2413->guuid=97c14f8a-1a00-0000-97e2-11fc93090000 pid=2451 execve guuid=4af11e8d-1a00-0000-97e2-11fc97090000 pid=2455 /usr/bin/mktemp guuid=b0bf7e7b-1a00-0000-97e2-11fc6d090000 pid=2413->guuid=4af11e8d-1a00-0000-97e2-11fc97090000 pid=2455 execve guuid=86d45f8d-1a00-0000-97e2-11fc98090000 pid=2456 /usr/bin/chmod guuid=b0bf7e7b-1a00-0000-97e2-11fc6d090000 pid=2413->guuid=86d45f8d-1a00-0000-97e2-11fc98090000 pid=2456 execve guuid=3cd1938d-1a00-0000-97e2-11fc99090000 pid=2457 /usr/bin/dash guuid=b0bf7e7b-1a00-0000-97e2-11fc6d090000 pid=2413->guuid=3cd1938d-1a00-0000-97e2-11fc99090000 pid=2457 clone guuid=0711a88d-1a00-0000-97e2-11fc9a090000 pid=2458 /usr/bin/dash guuid=b0bf7e7b-1a00-0000-97e2-11fc6d090000 pid=2413->guuid=0711a88d-1a00-0000-97e2-11fc9a090000 pid=2458 clone guuid=d2b8148e-1a00-0000-97e2-11fc9e090000 pid=2462 /usr/bin/dash guuid=b0bf7e7b-1a00-0000-97e2-11fc6d090000 pid=2413->guuid=d2b8148e-1a00-0000-97e2-11fc9e090000 pid=2462 clone guuid=26e0848e-1a00-0000-97e2-11fca2090000 pid=2466 /usr/bin/dash guuid=b0bf7e7b-1a00-0000-97e2-11fc6d090000 pid=2413->guuid=26e0848e-1a00-0000-97e2-11fca2090000 pid=2466 clone guuid=0102958e-1a00-0000-97e2-11fca3090000 pid=2467 /usr/bin/gpgv guuid=b0bf7e7b-1a00-0000-97e2-11fc6d090000 pid=2413->guuid=0102958e-1a00-0000-97e2-11fca3090000 pid=2467 execve guuid=17559390-1a00-0000-97e2-11fcab090000 pid=2475 /usr/bin/rm delete-file guuid=b0bf7e7b-1a00-0000-97e2-11fc6d090000 pid=2413->guuid=17559390-1a00-0000-97e2-11fcab090000 pid=2475 execve guuid=f7a1967d-1a00-0000-97e2-11fc74090000 pid=2420 /usr/bin/dpkg guuid=8027887c-1a00-0000-97e2-11fc71090000 pid=2417->guuid=f7a1967d-1a00-0000-97e2-11fc74090000 pid=2420 execve guuid=683bcd7f-1a00-0000-97e2-11fc7a090000 pid=2426 /usr/bin/dpkg guuid=e402c47e-1a00-0000-97e2-11fc77090000 pid=2423->guuid=683bcd7f-1a00-0000-97e2-11fc7a090000 pid=2426 execve guuid=ce2dfe87-1a00-0000-97e2-11fc88090000 pid=2440 /usr/bin/dpkg guuid=2bfb1987-1a00-0000-97e2-11fc85090000 pid=2437->guuid=ce2dfe87-1a00-0000-97e2-11fc88090000 pid=2440 execve guuid=fb45b789-1a00-0000-97e2-11fc8f090000 pid=2447 /usr/bin/dpkg guuid=3e1fbf88-1a00-0000-97e2-11fc8b090000 pid=2443->guuid=fb45b789-1a00-0000-97e2-11fc8f090000 pid=2447 execve guuid=cf288d8c-1a00-0000-97e2-11fc96090000 pid=2454 /usr/bin/dpkg guuid=97c14f8a-1a00-0000-97e2-11fc93090000 pid=2451->guuid=cf288d8c-1a00-0000-97e2-11fc96090000 pid=2454 execve guuid=af69b28d-1a00-0000-97e2-11fc9b090000 pid=2459 /usr/bin/dash guuid=0711a88d-1a00-0000-97e2-11fc9a090000 pid=2458->guuid=af69b28d-1a00-0000-97e2-11fc9b090000 pid=2459 clone guuid=3cb3b88d-1a00-0000-97e2-11fc9c090000 pid=2460 /usr/bin/sed guuid=0711a88d-1a00-0000-97e2-11fc9a090000 pid=2458->guuid=3cb3b88d-1a00-0000-97e2-11fc9c090000 pid=2460 execve guuid=9e141d8e-1a00-0000-97e2-11fc9f090000 pid=2463 /usr/bin/dash guuid=d2b8148e-1a00-0000-97e2-11fc9e090000 pid=2462->guuid=9e141d8e-1a00-0000-97e2-11fc9f090000 pid=2463 clone guuid=391b238e-1a00-0000-97e2-11fca0090000 pid=2464 /usr/bin/sed guuid=d2b8148e-1a00-0000-97e2-11fc9e090000 pid=2462->guuid=391b238e-1a00-0000-97e2-11fca0090000 pid=2464 execve guuid=efd29093-1a00-0000-97e2-11fcb6090000 pid=2486 /usr/bin/apt-key write-file guuid=6a108192-1a00-0000-97e2-11fcb2090000 pid=2482->guuid=efd29093-1a00-0000-97e2-11fcb6090000 pid=2486 execve guuid=3f8cf893-1a00-0000-97e2-11fcb8090000 pid=2488 /usr/bin/dash guuid=efd29093-1a00-0000-97e2-11fcb6090000 pid=2486->guuid=3f8cf893-1a00-0000-97e2-11fcb8090000 pid=2488 clone guuid=8c360994-1a00-0000-97e2-11fcb9090000 pid=2489 /usr/bin/apt-config guuid=efd29093-1a00-0000-97e2-11fcb6090000 pid=2486->guuid=8c360994-1a00-0000-97e2-11fcb9090000 pid=2489 execve guuid=e7016298-1a00-0000-97e2-11fcc4090000 pid=2500 /usr/bin/apt-config guuid=efd29093-1a00-0000-97e2-11fcb6090000 pid=2486->guuid=e7016298-1a00-0000-97e2-11fcc4090000 pid=2500 execve guuid=2cc4709a-1a00-0000-97e2-11fcc8090000 pid=2504 /usr/bin/apt-config guuid=efd29093-1a00-0000-97e2-11fcb6090000 pid=2486->guuid=2cc4709a-1a00-0000-97e2-11fcc8090000 pid=2504 execve guuid=d913a69c-1a00-0000-97e2-11fccb090000 pid=2507 /usr/bin/apt-config guuid=efd29093-1a00-0000-97e2-11fcb6090000 pid=2486->guuid=d913a69c-1a00-0000-97e2-11fccb090000 pid=2507 execve guuid=f1f023a0-1a00-0000-97e2-11fcd2090000 pid=2514 /usr/bin/dash guuid=efd29093-1a00-0000-97e2-11fcb6090000 pid=2486->guuid=f1f023a0-1a00-0000-97e2-11fcd2090000 pid=2514 clone guuid=5abd48a0-1a00-0000-97e2-11fcd3090000 pid=2515 /usr/bin/apt-config guuid=efd29093-1a00-0000-97e2-11fcb6090000 pid=2486->guuid=5abd48a0-1a00-0000-97e2-11fcd3090000 pid=2515 execve guuid=58af36a3-1a00-0000-97e2-11fcdc090000 pid=2524 /usr/bin/mktemp guuid=efd29093-1a00-0000-97e2-11fcb6090000 pid=2486->guuid=58af36a3-1a00-0000-97e2-11fcdc090000 pid=2524 execve guuid=0f2c8da3-1a00-0000-97e2-11fcdd090000 pid=2525 /usr/bin/chmod guuid=efd29093-1a00-0000-97e2-11fcb6090000 pid=2486->guuid=0f2c8da3-1a00-0000-97e2-11fcdd090000 pid=2525 execve guuid=77c6d7a3-1a00-0000-97e2-11fcdf090000 pid=2527 /usr/bin/dash guuid=efd29093-1a00-0000-97e2-11fcb6090000 pid=2486->guuid=77c6d7a3-1a00-0000-97e2-11fcdf090000 pid=2527 clone guuid=0717f4a3-1a00-0000-97e2-11fce0090000 pid=2528 /usr/bin/dash guuid=efd29093-1a00-0000-97e2-11fcb6090000 pid=2486->guuid=0717f4a3-1a00-0000-97e2-11fce0090000 pid=2528 clone guuid=e8a28ea4-1a00-0000-97e2-11fce5090000 pid=2533 /usr/bin/dash guuid=efd29093-1a00-0000-97e2-11fcb6090000 pid=2486->guuid=e8a28ea4-1a00-0000-97e2-11fce5090000 pid=2533 clone guuid=f41b1ca5-1a00-0000-97e2-11fce9090000 pid=2537 /usr/bin/dash guuid=efd29093-1a00-0000-97e2-11fcb6090000 pid=2486->guuid=f41b1ca5-1a00-0000-97e2-11fce9090000 pid=2537 clone guuid=86363aa5-1a00-0000-97e2-11fceb090000 pid=2539 /usr/bin/gpgv guuid=efd29093-1a00-0000-97e2-11fcb6090000 pid=2486->guuid=86363aa5-1a00-0000-97e2-11fceb090000 pid=2539 execve guuid=c58cb3a7-1a00-0000-97e2-11fcf1090000 pid=2545 /usr/bin/rm delete-file guuid=efd29093-1a00-0000-97e2-11fcb6090000 pid=2486->guuid=c58cb3a7-1a00-0000-97e2-11fcf1090000 pid=2545 execve guuid=81977097-1a00-0000-97e2-11fcc2090000 pid=2498 /usr/bin/dpkg guuid=8c360994-1a00-0000-97e2-11fcb9090000 pid=2489->guuid=81977097-1a00-0000-97e2-11fcc2090000 pid=2498 execve guuid=5854ef99-1a00-0000-97e2-11fcc6090000 pid=2502 /usr/bin/dpkg guuid=e7016298-1a00-0000-97e2-11fcc4090000 pid=2500->guuid=5854ef99-1a00-0000-97e2-11fcc6090000 pid=2502 execve guuid=d9a1ec9b-1a00-0000-97e2-11fcc9090000 pid=2505 /usr/bin/dpkg guuid=2cc4709a-1a00-0000-97e2-11fcc8090000 pid=2504->guuid=d9a1ec9b-1a00-0000-97e2-11fcc9090000 pid=2505 execve guuid=8cc2bc9e-1a00-0000-97e2-11fccf090000 pid=2511 /usr/bin/dpkg guuid=d913a69c-1a00-0000-97e2-11fccb090000 pid=2507->guuid=8cc2bc9e-1a00-0000-97e2-11fccf090000 pid=2511 execve guuid=f49e01a2-1a00-0000-97e2-11fcd8090000 pid=2520 /usr/bin/dpkg guuid=5abd48a0-1a00-0000-97e2-11fcd3090000 pid=2515->guuid=f49e01a2-1a00-0000-97e2-11fcd8090000 pid=2520 execve guuid=cefe02a4-1a00-0000-97e2-11fce2090000 pid=2530 /usr/bin/dash guuid=0717f4a3-1a00-0000-97e2-11fce0090000 pid=2528->guuid=cefe02a4-1a00-0000-97e2-11fce2090000 pid=2530 clone guuid=e3af0ba4-1a00-0000-97e2-11fce3090000 pid=2531 /usr/bin/sed guuid=0717f4a3-1a00-0000-97e2-11fce0090000 pid=2528->guuid=e3af0ba4-1a00-0000-97e2-11fce3090000 pid=2531 execve guuid=4eb89fa4-1a00-0000-97e2-11fce6090000 pid=2534 /usr/bin/dash guuid=e8a28ea4-1a00-0000-97e2-11fce5090000 pid=2533->guuid=4eb89fa4-1a00-0000-97e2-11fce6090000 pid=2534 clone guuid=761aa8a4-1a00-0000-97e2-11fce7090000 pid=2535 /usr/bin/sed guuid=e8a28ea4-1a00-0000-97e2-11fce5090000 pid=2533->guuid=761aa8a4-1a00-0000-97e2-11fce7090000 pid=2535 execve guuid=1bd7f2aa-1a00-0000-97e2-11fcfb090000 pid=2555 /usr/bin/apt-key write-file guuid=a83b3fa9-1a00-0000-97e2-11fcf5090000 pid=2549->guuid=1bd7f2aa-1a00-0000-97e2-11fcfb090000 pid=2555 execve guuid=7d322dab-1a00-0000-97e2-11fcfd090000 pid=2557 /usr/bin/dash guuid=1bd7f2aa-1a00-0000-97e2-11fcfb090000 pid=2555->guuid=7d322dab-1a00-0000-97e2-11fcfd090000 pid=2557 clone guuid=ee8f4dab-1a00-0000-97e2-11fcfe090000 pid=2558 /usr/bin/apt-config guuid=1bd7f2aa-1a00-0000-97e2-11fcfb090000 pid=2555->guuid=ee8f4dab-1a00-0000-97e2-11fcfe090000 pid=2558 execve guuid=01ccd9ae-1a00-0000-97e2-11fc040a0000 pid=2564 /usr/bin/apt-config guuid=1bd7f2aa-1a00-0000-97e2-11fcfb090000 pid=2555->guuid=01ccd9ae-1a00-0000-97e2-11fc040a0000 pid=2564 execve guuid=a0b53cb6-1a00-0000-97e2-11fc190a0000 pid=2585 /usr/bin/apt-config guuid=1bd7f2aa-1a00-0000-97e2-11fcfb090000 pid=2555->guuid=a0b53cb6-1a00-0000-97e2-11fc190a0000 pid=2585 execve guuid=6f7911b8-1a00-0000-97e2-11fc1f0a0000 pid=2591 /usr/bin/apt-config guuid=1bd7f2aa-1a00-0000-97e2-11fcfb090000 pid=2555->guuid=6f7911b8-1a00-0000-97e2-11fc1f0a0000 pid=2591 execve guuid=55ba4abe-1a00-0000-97e2-11fc300a0000 pid=2608 /usr/bin/dash guuid=1bd7f2aa-1a00-0000-97e2-11fcfb090000 pid=2555->guuid=55ba4abe-1a00-0000-97e2-11fc300a0000 pid=2608 clone guuid=e1b56bbe-1a00-0000-97e2-11fc320a0000 pid=2610 /usr/bin/apt-config guuid=1bd7f2aa-1a00-0000-97e2-11fcfb090000 pid=2555->guuid=e1b56bbe-1a00-0000-97e2-11fc320a0000 pid=2610 execve guuid=277901c3-1a00-0000-97e2-11fc3a0a0000 pid=2618 /usr/bin/mktemp guuid=1bd7f2aa-1a00-0000-97e2-11fcfb090000 pid=2555->guuid=277901c3-1a00-0000-97e2-11fc3a0a0000 pid=2618 execve guuid=1b8842c3-1a00-0000-97e2-11fc3c0a0000 pid=2620 /usr/bin/chmod guuid=1bd7f2aa-1a00-0000-97e2-11fcfb090000 pid=2555->guuid=1b8842c3-1a00-0000-97e2-11fc3c0a0000 pid=2620 execve guuid=87fe76c3-1a00-0000-97e2-11fc3e0a0000 pid=2622 /usr/bin/dash guuid=1bd7f2aa-1a00-0000-97e2-11fcfb090000 pid=2555->guuid=87fe76c3-1a00-0000-97e2-11fc3e0a0000 pid=2622 clone guuid=6d5b8bc3-1a00-0000-97e2-11fc3f0a0000 pid=2623 /usr/bin/dash guuid=1bd7f2aa-1a00-0000-97e2-11fcfb090000 pid=2555->guuid=6d5b8bc3-1a00-0000-97e2-11fc3f0a0000 pid=2623 clone guuid=e20507c4-1a00-0000-97e2-11fc440a0000 pid=2628 /usr/bin/dash guuid=1bd7f2aa-1a00-0000-97e2-11fcfb090000 pid=2555->guuid=e20507c4-1a00-0000-97e2-11fc440a0000 pid=2628 clone guuid=8f07a8c4-1a00-0000-97e2-11fc490a0000 pid=2633 /usr/bin/dash guuid=1bd7f2aa-1a00-0000-97e2-11fcfb090000 pid=2555->guuid=8f07a8c4-1a00-0000-97e2-11fc490a0000 pid=2633 clone guuid=3f59b3c4-1a00-0000-97e2-11fc4a0a0000 pid=2634 /usr/bin/gpgv guuid=1bd7f2aa-1a00-0000-97e2-11fcfb090000 pid=2555->guuid=3f59b3c4-1a00-0000-97e2-11fc4a0a0000 pid=2634 execve guuid=bedf6dc6-1a00-0000-97e2-11fc4f0a0000 pid=2639 /usr/bin/rm delete-file guuid=1bd7f2aa-1a00-0000-97e2-11fcfb090000 pid=2555->guuid=bedf6dc6-1a00-0000-97e2-11fc4f0a0000 pid=2639 execve guuid=023925ad-1a00-0000-97e2-11fc030a0000 pid=2563 /usr/bin/dpkg guuid=ee8f4dab-1a00-0000-97e2-11fcfe090000 pid=2558->guuid=023925ad-1a00-0000-97e2-11fc030a0000 pid=2563 execve guuid=d02586b0-1a00-0000-97e2-11fc090a0000 pid=2569 /usr/bin/dpkg guuid=01ccd9ae-1a00-0000-97e2-11fc040a0000 pid=2564->guuid=d02586b0-1a00-0000-97e2-11fc090a0000 pid=2569 execve guuid=97c42db7-1a00-0000-97e2-11fc1d0a0000 pid=2589 /usr/bin/dpkg guuid=a0b53cb6-1a00-0000-97e2-11fc190a0000 pid=2585->guuid=97c42db7-1a00-0000-97e2-11fc1d0a0000 pid=2589 execve guuid=2b181bb9-1a00-0000-97e2-11fc240a0000 pid=2596 /usr/bin/dpkg guuid=6f7911b8-1a00-0000-97e2-11fc1f0a0000 pid=2591->guuid=2b181bb9-1a00-0000-97e2-11fc240a0000 pid=2596 execve guuid=d722dcc1-1a00-0000-97e2-11fc380a0000 pid=2616 /usr/bin/dpkg guuid=e1b56bbe-1a00-0000-97e2-11fc320a0000 pid=2610->guuid=d722dcc1-1a00-0000-97e2-11fc380a0000 pid=2616 execve guuid=c6ee94c3-1a00-0000-97e2-11fc400a0000 pid=2624 /usr/bin/dash guuid=6d5b8bc3-1a00-0000-97e2-11fc3f0a0000 pid=2623->guuid=c6ee94c3-1a00-0000-97e2-11fc400a0000 pid=2624 clone guuid=a0489bc3-1a00-0000-97e2-11fc420a0000 pid=2626 /usr/bin/sed guuid=6d5b8bc3-1a00-0000-97e2-11fc3f0a0000 pid=2623->guuid=a0489bc3-1a00-0000-97e2-11fc420a0000 pid=2626 execve guuid=d8e40fc4-1a00-0000-97e2-11fc450a0000 pid=2629 /usr/bin/dash guuid=e20507c4-1a00-0000-97e2-11fc440a0000 pid=2628->guuid=d8e40fc4-1a00-0000-97e2-11fc450a0000 pid=2629 clone guuid=ba3314c4-1a00-0000-97e2-11fc460a0000 pid=2630 /usr/bin/sed guuid=e20507c4-1a00-0000-97e2-11fc440a0000 pid=2628->guuid=ba3314c4-1a00-0000-97e2-11fc460a0000 pid=2630 execve guuid=ba397dc8-1a00-0000-97e2-11fc540a0000 pid=2644 /usr/bin/apt-key write-file guuid=2dcd5dc7-1a00-0000-97e2-11fc530a0000 pid=2643->guuid=ba397dc8-1a00-0000-97e2-11fc540a0000 pid=2644 execve guuid=3b59d0c8-1a00-0000-97e2-11fc550a0000 pid=2645 /usr/bin/dash guuid=ba397dc8-1a00-0000-97e2-11fc540a0000 pid=2644->guuid=3b59d0c8-1a00-0000-97e2-11fc550a0000 pid=2645 clone guuid=b8bee4c8-1a00-0000-97e2-11fc560a0000 pid=2646 /usr/bin/apt-config guuid=ba397dc8-1a00-0000-97e2-11fc540a0000 pid=2644->guuid=b8bee4c8-1a00-0000-97e2-11fc560a0000 pid=2646 execve guuid=c27e20cc-1a00-0000-97e2-11fc5a0a0000 pid=2650 /usr/bin/apt-config guuid=ba397dc8-1a00-0000-97e2-11fc540a0000 pid=2644->guuid=c27e20cc-1a00-0000-97e2-11fc5a0a0000 pid=2650 execve guuid=e7cad0cd-1a00-0000-97e2-11fc610a0000 pid=2657 /usr/bin/apt-config guuid=ba397dc8-1a00-0000-97e2-11fc540a0000 pid=2644->guuid=e7cad0cd-1a00-0000-97e2-11fc610a0000 pid=2657 execve guuid=bb6926d0-1a00-0000-97e2-11fc690a0000 pid=2665 /usr/bin/apt-config guuid=ba397dc8-1a00-0000-97e2-11fc540a0000 pid=2644->guuid=bb6926d0-1a00-0000-97e2-11fc690a0000 pid=2665 execve guuid=f0a2c9d2-1a00-0000-97e2-11fc740a0000 pid=2676 /usr/bin/dash guuid=ba397dc8-1a00-0000-97e2-11fc540a0000 pid=2644->guuid=f0a2c9d2-1a00-0000-97e2-11fc740a0000 pid=2676 clone guuid=36dc01d3-1a00-0000-97e2-11fc760a0000 pid=2678 /usr/bin/apt-config guuid=ba397dc8-1a00-0000-97e2-11fc540a0000 pid=2644->guuid=36dc01d3-1a00-0000-97e2-11fc760a0000 pid=2678 execve guuid=7bc421d5-1a00-0000-97e2-11fc7f0a0000 pid=2687 /usr/bin/mktemp guuid=ba397dc8-1a00-0000-97e2-11fc540a0000 pid=2644->guuid=7bc421d5-1a00-0000-97e2-11fc7f0a0000 pid=2687 execve guuid=c46d63d5-1a00-0000-97e2-11fc810a0000 pid=2689 /usr/bin/chmod guuid=ba397dc8-1a00-0000-97e2-11fc540a0000 pid=2644->guuid=c46d63d5-1a00-0000-97e2-11fc810a0000 pid=2689 execve guuid=7e5a91d5-1a00-0000-97e2-11fc830a0000 pid=2691 /usr/bin/dash guuid=ba397dc8-1a00-0000-97e2-11fc540a0000 pid=2644->guuid=7e5a91d5-1a00-0000-97e2-11fc830a0000 pid=2691 clone guuid=5c459fd5-1a00-0000-97e2-11fc840a0000 pid=2692 /usr/bin/dash guuid=ba397dc8-1a00-0000-97e2-11fc540a0000 pid=2644->guuid=5c459fd5-1a00-0000-97e2-11fc840a0000 pid=2692 clone guuid=878123d6-1a00-0000-97e2-11fc890a0000 pid=2697 /usr/bin/dash guuid=ba397dc8-1a00-0000-97e2-11fc540a0000 pid=2644->guuid=878123d6-1a00-0000-97e2-11fc890a0000 pid=2697 clone guuid=feb6a1d6-1a00-0000-97e2-11fc8e0a0000 pid=2702 /usr/bin/dash guuid=ba397dc8-1a00-0000-97e2-11fc540a0000 pid=2644->guuid=feb6a1d6-1a00-0000-97e2-11fc8e0a0000 pid=2702 clone guuid=beaeb2d6-1a00-0000-97e2-11fc8f0a0000 pid=2703 /usr/bin/gpgv guuid=ba397dc8-1a00-0000-97e2-11fc540a0000 pid=2644->guuid=beaeb2d6-1a00-0000-97e2-11fc8f0a0000 pid=2703 execve guuid=d8176ad8-1a00-0000-97e2-11fc960a0000 pid=2710 /usr/bin/rm delete-file guuid=ba397dc8-1a00-0000-97e2-11fc540a0000 pid=2644->guuid=d8176ad8-1a00-0000-97e2-11fc960a0000 pid=2710 execve guuid=64ab56cb-1a00-0000-97e2-11fc590a0000 pid=2649 /usr/bin/dpkg guuid=b8bee4c8-1a00-0000-97e2-11fc560a0000 pid=2646->guuid=64ab56cb-1a00-0000-97e2-11fc590a0000 pid=2649 execve guuid=377b42cd-1a00-0000-97e2-11fc5e0a0000 pid=2654 /usr/bin/dpkg guuid=c27e20cc-1a00-0000-97e2-11fc5a0a0000 pid=2650->guuid=377b42cd-1a00-0000-97e2-11fc5e0a0000 pid=2654 execve guuid=50fb6ecf-1a00-0000-97e2-11fc660a0000 pid=2662 /usr/bin/dpkg guuid=e7cad0cd-1a00-0000-97e2-11fc610a0000 pid=2657->guuid=50fb6ecf-1a00-0000-97e2-11fc660a0000 pid=2662 execve guuid=782ef0d1-1a00-0000-97e2-11fc700a0000 pid=2672 /usr/bin/dpkg guuid=bb6926d0-1a00-0000-97e2-11fc690a0000 pid=2665->guuid=782ef0d1-1a00-0000-97e2-11fc700a0000 pid=2672 execve guuid=edc56fd4-1a00-0000-97e2-11fc7c0a0000 pid=2684 /usr/bin/dpkg guuid=36dc01d3-1a00-0000-97e2-11fc760a0000 pid=2678->guuid=edc56fd4-1a00-0000-97e2-11fc7c0a0000 pid=2684 execve guuid=707fadd5-1a00-0000-97e2-11fc850a0000 pid=2693 /usr/bin/dash guuid=5c459fd5-1a00-0000-97e2-11fc840a0000 pid=2692->guuid=707fadd5-1a00-0000-97e2-11fc850a0000 pid=2693 clone guuid=89bcb9d5-1a00-0000-97e2-11fc860a0000 pid=2694 /usr/bin/sed guuid=5c459fd5-1a00-0000-97e2-11fc840a0000 pid=2692->guuid=89bcb9d5-1a00-0000-97e2-11fc860a0000 pid=2694 execve guuid=daaa2ad6-1a00-0000-97e2-11fc8a0a0000 pid=2698 /usr/bin/dash guuid=878123d6-1a00-0000-97e2-11fc890a0000 pid=2697->guuid=daaa2ad6-1a00-0000-97e2-11fc8a0a0000 pid=2698 clone guuid=222c2fd6-1a00-0000-97e2-11fc8b0a0000 pid=2699 /usr/bin/sed guuid=878123d6-1a00-0000-97e2-11fc890a0000 pid=2697->guuid=222c2fd6-1a00-0000-97e2-11fc8b0a0000 pid=2699 execve guuid=7b6a829e-1e00-0000-97e2-11fc6a120000 pid=4714 /usr/bin/dpkg guuid=1728209d-1e00-0000-97e2-11fc62120000 pid=4706->guuid=7b6a829e-1e00-0000-97e2-11fc6a120000 pid=4714 execve guuid=74c6769f-1e00-0000-97e2-11fc70120000 pid=4720->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 164B 75aab096-419b-50ef-be46-7d76b6a90e4c github.com:443 guuid=74c6769f-1e00-0000-97e2-11fc70120000 pid=4720->75aab096-419b-50ef-be46-7d76b6a90e4c send: 806B f8c5e44f-328d-5324-8bbd-da50752b9120 release-assets.githubusercontent.com:0 guuid=74c6769f-1e00-0000-97e2-11fc70120000 pid=4720->f8c5e44f-328d-5324-8bbd-da50752b9120 con f0eebea5-e97d-507c-a771-59cac353877c release-assets.githubusercontent.com:443 guuid=74c6769f-1e00-0000-97e2-11fc70120000 pid=4720->f0eebea5-e97d-507c-a771-59cac353877c send: 1658B guuid=47d1fe9f-1e00-0000-97e2-11fc76120000 pid=4726 /usr/bin/tar guuid=714f809f-1e00-0000-97e2-11fc72120000 pid=4722->guuid=47d1fe9f-1e00-0000-97e2-11fc76120000 pid=4726 clone guuid=293507a0-1e00-0000-97e2-11fc77120000 pid=4727 /usr/bin/gzip guuid=47d1fe9f-1e00-0000-97e2-11fc76120000 pid=4726->guuid=293507a0-1e00-0000-97e2-11fc77120000 pid=4727 execve guuid=bedc0af2-1e00-0000-97e2-11fc90120000 pid=4752 /usr/bin/screen zombie guuid=220a8cf1-1e00-0000-97e2-11fc8e120000 pid=4750->guuid=bedc0af2-1e00-0000-97e2-11fc90120000 pid=4752 clone guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4760 /dev/shm/.sys-config/java-build-agent mprotect-exec net send-data guuid=bedc0af2-1e00-0000-97e2-11fc90120000 pid=4752->guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4760 execve guuid=960625f2-1e00-0000-97e2-11fc93120000 pid=4755 /usr/bin/bash guuid=c2841bf2-1e00-0000-97e2-11fc91120000 pid=4753->guuid=960625f2-1e00-0000-97e2-11fc93120000 pid=4755 clone guuid=46fb36f2-1e00-0000-97e2-11fc95120000 pid=4757 /usr/bin/grep guuid=c2841bf2-1e00-0000-97e2-11fc91120000 pid=4753->guuid=46fb36f2-1e00-0000-97e2-11fc95120000 pid=4757 execve 571c50e0-80e0-5568-adf1-93a8e6a607e6 176.65.139.42:8443 guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4760->571c50e0-80e0-5568-adf1-93a8e6a607e6 send: 1837B guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4779 /dev/shm/.sys-config/java-build-agent write-file guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4760->guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4779 clone guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4781 /dev/shm/.sys-config/java-build-agent guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4760->guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4781 clone guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4782 /dev/shm/.sys-config/java-build-agent guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4760->guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4782 clone guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4783 /dev/shm/.sys-config/java-build-agent guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4760->guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4783 clone guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4784 /dev/shm/.sys-config/java-build-agent guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4760->guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4784 clone guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4799 /dev/shm/.sys-config/java-build-agent guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4760->guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4799 clone guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4800 /dev/shm/.sys-config/java-build-agent guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4760->guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4800 clone guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4801 /dev/shm/.sys-config/java-build-agent guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4760->guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4801 clone guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4802 /dev/shm/.sys-config/java-build-agent guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4760->guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4802 clone guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4826 /dev/shm/.sys-config/java-build-agent guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4760->guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4826 clone guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4827 /dev/shm/.sys-config/java-build-agent guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4760->guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4827 clone guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4828 /dev/shm/.sys-config/java-build-agent guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4760->guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4828 clone guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4829 /dev/shm/.sys-config/java-build-agent guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4760->guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4829 clone guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4846 /dev/shm/.sys-config/java-build-agent guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4760->guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4846 clone guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4848 /dev/shm/.sys-config/java-build-agent guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4760->guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4848 clone guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4849 /dev/shm/.sys-config/java-build-agent guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4760->guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4849 clone guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4850 /dev/shm/.sys-config/java-build-agent guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4760->guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4850 clone guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4871 /dev/shm/.sys-config/java-build-agent guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4760->guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4871 clone guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4873 /dev/shm/.sys-config/java-build-agent guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4760->guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4873 clone guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4875 /dev/shm/.sys-config/java-build-agent guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4760->guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4875 clone guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4876 /dev/shm/.sys-config/java-build-agent guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4760->guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4876 clone guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4891 /dev/shm/.sys-config/java-build-agent guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4760->guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4891 clone guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4892 /dev/shm/.sys-config/java-build-agent guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4760->guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4892 clone guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4893 /dev/shm/.sys-config/java-build-agent guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4760->guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4893 clone guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4894 /dev/shm/.sys-config/java-build-agent guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4760->guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4894 clone guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4918 /dev/shm/.sys-config/java-build-agent guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4760->guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4918 clone guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4919 /dev/shm/.sys-config/java-build-agent guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4760->guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4919 clone guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4920 /dev/shm/.sys-config/java-build-agent guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4760->guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4920 clone guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4921 /dev/shm/.sys-config/java-build-agent guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4760->guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4921 clone guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4952 /dev/shm/.sys-config/java-build-agent guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4760->guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4952 clone guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4953 /dev/shm/.sys-config/java-build-agent guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4760->guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4953 clone guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4954 /dev/shm/.sys-config/java-build-agent guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4760->guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4954 clone guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4955 /dev/shm/.sys-config/java-build-agent guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4760->guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4955 clone guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4987 /dev/shm/.sys-config/java-build-agent guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4760->guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4987 clone guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4988 /dev/shm/.sys-config/java-build-agent guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4760->guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4988 clone guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4989 /dev/shm/.sys-config/java-build-agent guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4760->guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4989 clone guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4991 /dev/shm/.sys-config/java-build-agent guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4760->guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4991 clone guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=5011 /dev/shm/.sys-config/java-build-agent guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4760->guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=5011 clone guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=5012 /dev/shm/.sys-config/java-build-agent guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4760->guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=5012 clone guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=5013 /dev/shm/.sys-config/java-build-agent guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4760->guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=5013 clone guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=5014 /dev/shm/.sys-config/java-build-agent guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4760->guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=5014 clone guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=5036 /dev/shm/.sys-config/java-build-agent guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4760->guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=5036 clone guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=5037 /dev/shm/.sys-config/java-build-agent guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4760->guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=5037 clone guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=5038 /dev/shm/.sys-config/java-build-agent guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4760->guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=5038 clone guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=5039 /dev/shm/.sys-config/java-build-agent guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4760->guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=5039 clone guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=5060 /dev/shm/.sys-config/java-build-agent guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4760->guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=5060 clone guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=5061 /dev/shm/.sys-config/java-build-agent guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4760->guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=5061 clone guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=5062 /dev/shm/.sys-config/java-build-agent guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4760->guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=5062 clone guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=5063 /dev/shm/.sys-config/java-build-agent guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4760->guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=5063 clone guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=5088 /dev/shm/.sys-config/java-build-agent guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4760->guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=5088 clone guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=5090 /dev/shm/.sys-config/java-build-agent guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4760->guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=5090 clone guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=5091 /dev/shm/.sys-config/java-build-agent guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4760->guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=5091 clone guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=5092 /dev/shm/.sys-config/java-build-agent guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=4760->guuid=96b6c7f2-1e00-0000-97e2-11fc98120000 pid=5092 clone
Threat name:
Win32.Trojan.Vigorf
Status:
Malicious
First seen:
2026-04-04 17:00:26 UTC
File Type:
Text (Shell)
AV detection:
5 of 24 (20.83%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:xmrig antivm credential_access defense_evasion discovery execution linux miner persistence privilege_escalation
Behaviour
Software Deployment Tools
Enumerates kernel/hardware configuration
Reads runtime system information
System Network Configuration Discovery
Writes file to shm directory
Writes file to tmp directory
Deobfuscate/Decode Files or Information
Changes its process name
Checks CPU configuration
Reads CPU attributes
Checks hardware identifiers (DMI)
Creates/modifies Cron job
Deletes log files
Modifies init.d
Reads hardware information
Write file to user bin folder
Writes file to system bin folder
File and Directory Permissions Modification
Executes dropped EXE
Modifies PAM framework files
OS Credential Dumping
XMRig Miner payload
Xmrig family
xmrig
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

CoinMiner

sh 49f7c39a65dd92b1d4e266d99c239253197f48d07d5c8ca2dbcb086ddc9c4751

(this sample)

  
Delivery method
Distributed via web download

Comments