MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5fb604a045443810d279a6955c2e4792a27d93dcce35908620030196fc4e9a79. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



CoinMiner


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 5fb604a045443810d279a6955c2e4792a27d93dcce35908620030196fc4e9a79
SHA3-384 hash: f9643382d6db31b3116738f1e0b318e241c9f06d24eda6f9818248ff30963b98f862c2a1aab8dd5bed3851edff303738
SHA1 hash: 6694075242a24d2fcc75474e307ba8839e4ba57c
MD5 hash: d900025c8b285392aeeead9ef61742de
humanhash: indigo-enemy-louisiana-uncle
File name:run-CN.sh
Download: download sample
Signature CoinMiner
File size:7'478 bytes
First seen:2025-09-07 14:21:26 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 192:F8XyzHWZzzDN19xDkIhvm3qadayHDPMeYaCFMvlu:MzvLzhvUbjn/CF+u
TLSH T16BF1B806F6D09AB429C8C578418A1880694F912B5D492C04F8EDF569BF3876C71FDBFB
Magika shell
Reporter abuse_ch
Tags:CoinMiner sh
URLMalware sample (SHA256 hash)SignatureTags
http://162.248.53.119:8000/mon.sh1e891ab1521b27923233e694f60fdbf0e1b840e657d8b1ffdefd8b5ef5e38964 CoinMinerCoinMiner
http://162.248.53.119:8000/yes.tar.gzn/an/aopendir
https://cdn.tempfile.pro/a6e7d30efad34e34/proto1.binn/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
38
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-09-07T12:44:00Z UTC
Last seen:
2025-09-07T12:44:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=8d6ceb1a-1900-0000-1e2c-23361f0c0000 pid=3103 /usr/bin/sudo guuid=2c45bb1c-1900-0000-1e2c-2336250c0000 pid=3109 /tmp/sample.bin guuid=8d6ceb1a-1900-0000-1e2c-23361f0c0000 pid=3103->guuid=2c45bb1c-1900-0000-1e2c-2336250c0000 pid=3109 execve guuid=6fbf0e1d-1900-0000-1e2c-2336270c0000 pid=3111 /usr/bin/systemctl guuid=2c45bb1c-1900-0000-1e2c-2336250c0000 pid=3109->guuid=6fbf0e1d-1900-0000-1e2c-2336270c0000 pid=3111 execve guuid=c2c91e1e-1900-0000-1e2c-23362b0c0000 pid=3115 /usr/bin/bash guuid=2c45bb1c-1900-0000-1e2c-2336250c0000 pid=3109->guuid=c2c91e1e-1900-0000-1e2c-23362b0c0000 pid=3115 clone guuid=d5730e27-1900-0000-1e2c-23364b0c0000 pid=3147 /usr/bin/bash guuid=2c45bb1c-1900-0000-1e2c-2336250c0000 pid=3109->guuid=d5730e27-1900-0000-1e2c-23364b0c0000 pid=3147 clone guuid=f37ce327-1900-0000-1e2c-23364f0c0000 pid=3151 /usr/bin/pgrep guuid=2c45bb1c-1900-0000-1e2c-2336250c0000 pid=3109->guuid=f37ce327-1900-0000-1e2c-23364f0c0000 pid=3151 execve guuid=ab42d92a-1900-0000-1e2c-2336570c0000 pid=3159 /usr/bin/pgrep guuid=2c45bb1c-1900-0000-1e2c-2336250c0000 pid=3109->guuid=ab42d92a-1900-0000-1e2c-2336570c0000 pid=3159 execve guuid=4c1d252e-1900-0000-1e2c-23365c0c0000 pid=3164 /usr/bin/pgrep guuid=2c45bb1c-1900-0000-1e2c-2336250c0000 pid=3109->guuid=4c1d252e-1900-0000-1e2c-23365c0c0000 pid=3164 execve guuid=dea42e2e-1900-0000-1e2c-23365d0c0000 pid=3165 /usr/bin/grep guuid=2c45bb1c-1900-0000-1e2c-2336250c0000 pid=3109->guuid=dea42e2e-1900-0000-1e2c-23365d0c0000 pid=3165 execve guuid=64a6352e-1900-0000-1e2c-23365e0c0000 pid=3166 /usr/bin/xargs guuid=2c45bb1c-1900-0000-1e2c-2336250c0000 pid=3109->guuid=64a6352e-1900-0000-1e2c-23365e0c0000 pid=3166 execve guuid=2b6f8331-1900-0000-1e2c-2336650c0000 pid=3173 /usr/bin/id guuid=2c45bb1c-1900-0000-1e2c-2336250c0000 pid=3109->guuid=2b6f8331-1900-0000-1e2c-2336650c0000 pid=3173 execve guuid=74722a32-1900-0000-1e2c-2336670c0000 pid=3175 /usr/bin/apt-get delete-file write-file guuid=2c45bb1c-1900-0000-1e2c-2336250c0000 pid=3109->guuid=74722a32-1900-0000-1e2c-2336670c0000 pid=3175 execve guuid=d03af6f7-1c00-0000-1e2c-2336ec140000 pid=5356 /usr/bin/apt-get guuid=2c45bb1c-1900-0000-1e2c-2336250c0000 pid=3109->guuid=d03af6f7-1c00-0000-1e2c-2336ec140000 pid=5356 execve guuid=a6837df9-1c00-0000-1e2c-2336ee140000 pid=5358 /usr/bin/mkdir guuid=2c45bb1c-1900-0000-1e2c-2336250c0000 pid=3109->guuid=a6837df9-1c00-0000-1e2c-2336ee140000 pid=5358 execve guuid=a2fdd4f9-1c00-0000-1e2c-2336ef140000 pid=5359 /usr/bin/wget dns net send-data write-file guuid=2c45bb1c-1900-0000-1e2c-2336250c0000 pid=3109->guuid=a2fdd4f9-1c00-0000-1e2c-2336ef140000 pid=5359 execve guuid=09013d5e-1e00-0000-1e2c-2336f8140000 pid=5368 /usr/bin/mv guuid=2c45bb1c-1900-0000-1e2c-2336250c0000 pid=3109->guuid=09013d5e-1e00-0000-1e2c-2336f8140000 pid=5368 execve guuid=af31de5e-1e00-0000-1e2c-2336f9140000 pid=5369 /usr/bin/rm guuid=2c45bb1c-1900-0000-1e2c-2336250c0000 pid=3109->guuid=af31de5e-1e00-0000-1e2c-2336f9140000 pid=5369 execve guuid=74ed4d5f-1e00-0000-1e2c-2336fa140000 pid=5370 /usr/bin/chmod guuid=2c45bb1c-1900-0000-1e2c-2336250c0000 pid=3109->guuid=74ed4d5f-1e00-0000-1e2c-2336fa140000 pid=5370 execve guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5372 /usr/lib/dev/systemdev/dns-filter mprotect-exec net send-data guuid=2c45bb1c-1900-0000-1e2c-2336250c0000 pid=3109->guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5372 execve guuid=1b63d35f-1e00-0000-1e2c-2336fe140000 pid=5374 /usr/bin/sleep guuid=2c45bb1c-1900-0000-1e2c-2336250c0000 pid=3109->guuid=1b63d35f-1e00-0000-1e2c-2336fe140000 pid=5374 execve guuid=bfb92f7e-1e00-0000-1e2c-233607150000 pid=5383 /usr/bin/ps guuid=2c45bb1c-1900-0000-1e2c-2336250c0000 pid=3109->guuid=bfb92f7e-1e00-0000-1e2c-233607150000 pid=5383 execve guuid=a0bfccd9-1e00-0000-1e2c-233638150000 pid=5432 /usr/bin/sleep guuid=2c45bb1c-1900-0000-1e2c-2336250c0000 pid=3109->guuid=a0bfccd9-1e00-0000-1e2c-233638150000 pid=5432 execve guuid=c3e286e6-1f00-0000-1e2c-233653150000 pid=5459 /usr/bin/ps guuid=2c45bb1c-1900-0000-1e2c-2336250c0000 pid=3109->guuid=c3e286e6-1f00-0000-1e2c-233653150000 pid=5459 execve guuid=f5917eec-1f00-0000-1e2c-233654150000 pid=5460 /usr/bin/rm guuid=2c45bb1c-1900-0000-1e2c-2336250c0000 pid=3109->guuid=f5917eec-1f00-0000-1e2c-233654150000 pid=5460 execve guuid=f302e6ec-1f00-0000-1e2c-233655150000 pid=5461 /usr/bin/rm guuid=2c45bb1c-1900-0000-1e2c-2336250c0000 pid=3109->guuid=f302e6ec-1f00-0000-1e2c-233655150000 pid=5461 execve guuid=adc82e1e-1900-0000-1e2c-23362c0c0000 pid=3116 /usr/bin/wget dns net send-data guuid=c2c91e1e-1900-0000-1e2c-23362b0c0000 pid=3115->guuid=adc82e1e-1900-0000-1e2c-23362c0c0000 pid=3116 execve 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=adc82e1e-1900-0000-1e2c-23362c0c0000 pid=3116->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 72B 0690ccd5-4816-5f11-94dc-7c585f38cdea ipv4.icanhazip.com:0 guuid=adc82e1e-1900-0000-1e2c-23362c0c0000 pid=3116->0690ccd5-4816-5f11-94dc-7c585f38cdea con d0ecfe49-aa79-583f-85c6-85ac97075256 ipv4.icanhazip.com:80 guuid=adc82e1e-1900-0000-1e2c-23362c0c0000 pid=3116->d0ecfe49-aa79-583f-85c6-85ac97075256 send: 133B guuid=0e661f27-1900-0000-1e2c-23364c0c0000 pid=3148 /usr/bin/bash guuid=d5730e27-1900-0000-1e2c-23364b0c0000 pid=3147->guuid=0e661f27-1900-0000-1e2c-23364c0c0000 pid=3148 clone guuid=24a92727-1900-0000-1e2c-23364d0c0000 pid=3149 /usr/bin/sed guuid=d5730e27-1900-0000-1e2c-23364b0c0000 pid=3147->guuid=24a92727-1900-0000-1e2c-23364d0c0000 pid=3149 execve guuid=58322e27-1900-0000-1e2c-23364e0c0000 pid=3150 /usr/bin/cut guuid=d5730e27-1900-0000-1e2c-23364b0c0000 pid=3147->guuid=58322e27-1900-0000-1e2c-23364e0c0000 pid=3150 execve guuid=cdf39f33-1900-0000-1e2c-23366b0c0000 pid=3179 /usr/bin/dpkg guuid=74722a32-1900-0000-1e2c-2336670c0000 pid=3175->guuid=cdf39f33-1900-0000-1e2c-23366b0c0000 pid=3179 execve guuid=45d23934-1900-0000-1e2c-23366e0c0000 pid=3182 /usr/lib/apt/methods/mirror guuid=74722a32-1900-0000-1e2c-2336670c0000 pid=3175->guuid=45d23934-1900-0000-1e2c-23366e0c0000 pid=3182 execve guuid=a65d2035-1900-0000-1e2c-2336710c0000 pid=3185 /usr/lib/apt/methods/mirror guuid=74722a32-1900-0000-1e2c-2336670c0000 pid=3175->guuid=a65d2035-1900-0000-1e2c-2336710c0000 pid=3185 execve guuid=44113236-1900-0000-1e2c-2336720c0000 pid=3186 /usr/lib/apt/methods/file guuid=74722a32-1900-0000-1e2c-2336670c0000 pid=3175->guuid=44113236-1900-0000-1e2c-2336720c0000 pid=3186 execve guuid=ebac0337-1900-0000-1e2c-2336760c0000 pid=3190 /usr/lib/apt/methods/file delete-file guuid=74722a32-1900-0000-1e2c-2336670c0000 pid=3175->guuid=ebac0337-1900-0000-1e2c-2336760c0000 pid=3190 execve guuid=97c42038-1900-0000-1e2c-2336790c0000 pid=3193 /usr/lib/apt/methods/http guuid=74722a32-1900-0000-1e2c-2336670c0000 pid=3175->guuid=97c42038-1900-0000-1e2c-2336790c0000 pid=3193 execve guuid=933a9939-1900-0000-1e2c-23367b0c0000 pid=3195 /usr/lib/apt/methods/http dns net send-data write-file guuid=74722a32-1900-0000-1e2c-2336670c0000 pid=3175->guuid=933a9939-1900-0000-1e2c-23367b0c0000 pid=3195 execve guuid=1f9d2b5c-1900-0000-1e2c-23368f0c0000 pid=3215 /usr/lib/apt/methods/gpgv guuid=74722a32-1900-0000-1e2c-2336670c0000 pid=3175->guuid=1f9d2b5c-1900-0000-1e2c-23368f0c0000 pid=3215 execve guuid=87d8175e-1900-0000-1e2c-2336940c0000 pid=3220 /usr/lib/apt/methods/gpgv guuid=74722a32-1900-0000-1e2c-2336670c0000 pid=3175->guuid=87d8175e-1900-0000-1e2c-2336940c0000 pid=3220 execve guuid=3ecfa6bc-1900-0000-1e2c-23366f0d0000 pid=3439 /usr/lib/apt/methods/store guuid=74722a32-1900-0000-1e2c-2336670c0000 pid=3175->guuid=3ecfa6bc-1900-0000-1e2c-23366f0d0000 pid=3439 execve guuid=45a189bd-1900-0000-1e2c-2336730d0000 pid=3443 /usr/lib/apt/methods/store write-file guuid=74722a32-1900-0000-1e2c-2336670c0000 pid=3175->guuid=45a189bd-1900-0000-1e2c-2336730d0000 pid=3443 execve guuid=63253148-1a00-0000-1e2c-2336270e0000 pid=3623 /usr/lib/apt/methods/rred guuid=74722a32-1900-0000-1e2c-2336670c0000 pid=3175->guuid=63253148-1a00-0000-1e2c-2336270e0000 pid=3623 execve guuid=3113ab5a-1a00-0000-1e2c-23362f0e0000 pid=3631 /usr/lib/apt/methods/rred write-file guuid=74722a32-1900-0000-1e2c-2336670c0000 pid=3175->guuid=3113ab5a-1a00-0000-1e2c-23362f0e0000 pid=3631 execve guuid=6376d79c-1c00-0000-1e2c-233697140000 pid=5271 /usr/bin/dpkg guuid=74722a32-1900-0000-1e2c-2336670c0000 pid=3175->guuid=6376d79c-1c00-0000-1e2c-233697140000 pid=5271 execve guuid=bacd37f5-1c00-0000-1e2c-2336eb140000 pid=5355 /usr/bin/dpkg guuid=74722a32-1900-0000-1e2c-2336670c0000 pid=3175->guuid=bacd37f5-1c00-0000-1e2c-2336eb140000 pid=5355 execve guuid=933a9939-1900-0000-1e2c-23367b0c0000 pid=3195->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 122B 869ebe88-8c1e-5fbb-adb0-cfe48d8d7faf debian.map.fastly.net:443 guuid=933a9939-1900-0000-1e2c-23367b0c0000 pid=3195->869ebe88-8c1e-5fbb-adb0-cfe48d8d7faf send: 6247B guuid=143f205f-1900-0000-1e2c-2336970c0000 pid=3223 /usr/lib/apt/methods/gpgv delete-file write-file guuid=87d8175e-1900-0000-1e2c-2336940c0000 pid=3220->guuid=143f205f-1900-0000-1e2c-2336970c0000 pid=3223 clone guuid=6ea79e7c-1900-0000-1e2c-2336bf0c0000 pid=3263 /usr/lib/apt/methods/gpgv delete-file write-file guuid=87d8175e-1900-0000-1e2c-2336940c0000 pid=3220->guuid=6ea79e7c-1900-0000-1e2c-2336bf0c0000 pid=3263 clone guuid=c965b68e-1900-0000-1e2c-2336eb0c0000 pid=3307 /usr/lib/apt/methods/gpgv delete-file write-file guuid=87d8175e-1900-0000-1e2c-2336940c0000 pid=3220->guuid=c965b68e-1900-0000-1e2c-2336eb0c0000 pid=3307 clone guuid=879b80a1-1900-0000-1e2c-23361a0d0000 pid=3354 /usr/lib/apt/methods/gpgv delete-file write-file guuid=87d8175e-1900-0000-1e2c-2336940c0000 pid=3220->guuid=879b80a1-1900-0000-1e2c-23361a0d0000 pid=3354 clone guuid=fced2c63-1900-0000-1e2c-23369d0c0000 pid=3229 /usr/bin/apt-key write-file guuid=143f205f-1900-0000-1e2c-2336970c0000 pid=3223->guuid=fced2c63-1900-0000-1e2c-23369d0c0000 pid=3229 execve guuid=530f6063-1900-0000-1e2c-23369e0c0000 pid=3230 /usr/bin/dash guuid=fced2c63-1900-0000-1e2c-23369d0c0000 pid=3229->guuid=530f6063-1900-0000-1e2c-23369e0c0000 pid=3230 clone guuid=2d9e8163-1900-0000-1e2c-23369f0c0000 pid=3231 /usr/bin/apt-config guuid=fced2c63-1900-0000-1e2c-23369d0c0000 pid=3229->guuid=2d9e8163-1900-0000-1e2c-23369f0c0000 pid=3231 execve guuid=68de0266-1900-0000-1e2c-2336a40c0000 pid=3236 /usr/bin/apt-config guuid=fced2c63-1900-0000-1e2c-23369d0c0000 pid=3229->guuid=68de0266-1900-0000-1e2c-2336a40c0000 pid=3236 execve guuid=13a2a768-1900-0000-1e2c-2336a90c0000 pid=3241 /usr/bin/apt-config guuid=fced2c63-1900-0000-1e2c-23369d0c0000 pid=3229->guuid=13a2a768-1900-0000-1e2c-2336a90c0000 pid=3241 execve guuid=28ceb36b-1900-0000-1e2c-2336ab0c0000 pid=3243 /usr/bin/apt-config guuid=fced2c63-1900-0000-1e2c-23369d0c0000 pid=3229->guuid=28ceb36b-1900-0000-1e2c-2336ab0c0000 pid=3243 execve guuid=249b2372-1900-0000-1e2c-2336ad0c0000 pid=3245 /usr/bin/dash guuid=fced2c63-1900-0000-1e2c-23369d0c0000 pid=3229->guuid=249b2372-1900-0000-1e2c-2336ad0c0000 pid=3245 clone guuid=eadc6572-1900-0000-1e2c-2336ae0c0000 pid=3246 /usr/bin/apt-config guuid=fced2c63-1900-0000-1e2c-23369d0c0000 pid=3229->guuid=eadc6572-1900-0000-1e2c-2336ae0c0000 pid=3246 execve guuid=78febb75-1900-0000-1e2c-2336b00c0000 pid=3248 /usr/bin/mktemp guuid=fced2c63-1900-0000-1e2c-23369d0c0000 pid=3229->guuid=78febb75-1900-0000-1e2c-2336b00c0000 pid=3248 execve guuid=f06f0376-1900-0000-1e2c-2336b10c0000 pid=3249 /usr/bin/chmod guuid=fced2c63-1900-0000-1e2c-23369d0c0000 pid=3229->guuid=f06f0376-1900-0000-1e2c-2336b10c0000 pid=3249 execve guuid=f4e24076-1900-0000-1e2c-2336b20c0000 pid=3250 /usr/bin/dash guuid=fced2c63-1900-0000-1e2c-23369d0c0000 pid=3229->guuid=f4e24076-1900-0000-1e2c-2336b20c0000 pid=3250 clone guuid=7fb35b76-1900-0000-1e2c-2336b30c0000 pid=3251 /usr/bin/dash guuid=fced2c63-1900-0000-1e2c-23369d0c0000 pid=3229->guuid=7fb35b76-1900-0000-1e2c-2336b30c0000 pid=3251 clone guuid=a7b3d676-1900-0000-1e2c-2336b60c0000 pid=3254 /usr/bin/dash guuid=fced2c63-1900-0000-1e2c-23369d0c0000 pid=3229->guuid=a7b3d676-1900-0000-1e2c-2336b60c0000 pid=3254 clone guuid=40c55077-1900-0000-1e2c-2336b90c0000 pid=3257 /usr/bin/dash guuid=fced2c63-1900-0000-1e2c-23369d0c0000 pid=3229->guuid=40c55077-1900-0000-1e2c-2336b90c0000 pid=3257 clone guuid=434e6577-1900-0000-1e2c-2336ba0c0000 pid=3258 /usr/bin/gpgv guuid=fced2c63-1900-0000-1e2c-23369d0c0000 pid=3229->guuid=434e6577-1900-0000-1e2c-2336ba0c0000 pid=3258 execve guuid=480cad79-1900-0000-1e2c-2336bb0c0000 pid=3259 /usr/bin/rm delete-file guuid=fced2c63-1900-0000-1e2c-23369d0c0000 pid=3229->guuid=480cad79-1900-0000-1e2c-2336bb0c0000 pid=3259 execve guuid=2a104665-1900-0000-1e2c-2336a10c0000 pid=3233 /usr/bin/dpkg guuid=2d9e8163-1900-0000-1e2c-23369f0c0000 pid=3231->guuid=2a104665-1900-0000-1e2c-2336a10c0000 pid=3233 execve guuid=2f240e68-1900-0000-1e2c-2336a80c0000 pid=3240 /usr/bin/dpkg guuid=68de0266-1900-0000-1e2c-2336a40c0000 pid=3236->guuid=2f240e68-1900-0000-1e2c-2336a80c0000 pid=3240 execve guuid=ea22d66a-1900-0000-1e2c-2336aa0c0000 pid=3242 /usr/bin/dpkg guuid=13a2a768-1900-0000-1e2c-2336a90c0000 pid=3241->guuid=ea22d66a-1900-0000-1e2c-2336aa0c0000 pid=3242 execve guuid=9d6c1a6d-1900-0000-1e2c-2336ac0c0000 pid=3244 /usr/bin/dpkg guuid=28ceb36b-1900-0000-1e2c-2336ab0c0000 pid=3243->guuid=9d6c1a6d-1900-0000-1e2c-2336ac0c0000 pid=3244 execve guuid=63ca8774-1900-0000-1e2c-2336af0c0000 pid=3247 /usr/bin/dpkg guuid=eadc6572-1900-0000-1e2c-2336ae0c0000 pid=3246->guuid=63ca8774-1900-0000-1e2c-2336af0c0000 pid=3247 execve guuid=eeb86b76-1900-0000-1e2c-2336b40c0000 pid=3252 /usr/bin/dash guuid=7fb35b76-1900-0000-1e2c-2336b30c0000 pid=3251->guuid=eeb86b76-1900-0000-1e2c-2336b40c0000 pid=3252 clone guuid=abaa7276-1900-0000-1e2c-2336b50c0000 pid=3253 /usr/bin/sed guuid=7fb35b76-1900-0000-1e2c-2336b30c0000 pid=3251->guuid=abaa7276-1900-0000-1e2c-2336b50c0000 pid=3253 execve guuid=a993e276-1900-0000-1e2c-2336b70c0000 pid=3255 /usr/bin/dash guuid=a7b3d676-1900-0000-1e2c-2336b60c0000 pid=3254->guuid=a993e276-1900-0000-1e2c-2336b70c0000 pid=3255 clone guuid=4bdfe976-1900-0000-1e2c-2336b80c0000 pid=3256 /usr/bin/sed guuid=a7b3d676-1900-0000-1e2c-2336b60c0000 pid=3254->guuid=4bdfe976-1900-0000-1e2c-2336b80c0000 pid=3256 execve guuid=5c863e7d-1900-0000-1e2c-2336c30c0000 pid=3267 /usr/bin/apt-key write-file guuid=6ea79e7c-1900-0000-1e2c-2336bf0c0000 pid=3263->guuid=5c863e7d-1900-0000-1e2c-2336c30c0000 pid=3267 execve guuid=9d05a97d-1900-0000-1e2c-2336c50c0000 pid=3269 /usr/bin/dash guuid=5c863e7d-1900-0000-1e2c-2336c30c0000 pid=3267->guuid=9d05a97d-1900-0000-1e2c-2336c50c0000 pid=3269 clone guuid=b464dc7d-1900-0000-1e2c-2336c60c0000 pid=3270 /usr/bin/apt-config guuid=5c863e7d-1900-0000-1e2c-2336c30c0000 pid=3267->guuid=b464dc7d-1900-0000-1e2c-2336c60c0000 pid=3270 execve guuid=86743481-1900-0000-1e2c-2336cd0c0000 pid=3277 /usr/bin/apt-config guuid=5c863e7d-1900-0000-1e2c-2336c30c0000 pid=3267->guuid=86743481-1900-0000-1e2c-2336cd0c0000 pid=3277 execve guuid=d5971b84-1900-0000-1e2c-2336d20c0000 pid=3282 /usr/bin/apt-config guuid=5c863e7d-1900-0000-1e2c-2336c30c0000 pid=3267->guuid=d5971b84-1900-0000-1e2c-2336d20c0000 pid=3282 execve guuid=0ca71d86-1900-0000-1e2c-2336d50c0000 pid=3285 /usr/bin/apt-config guuid=5c863e7d-1900-0000-1e2c-2336c30c0000 pid=3267->guuid=0ca71d86-1900-0000-1e2c-2336d50c0000 pid=3285 execve guuid=8d30b087-1900-0000-1e2c-2336db0c0000 pid=3291 /usr/bin/dash guuid=5c863e7d-1900-0000-1e2c-2336c30c0000 pid=3267->guuid=8d30b087-1900-0000-1e2c-2336db0c0000 pid=3291 clone guuid=e95ad287-1900-0000-1e2c-2336dc0c0000 pid=3292 /usr/bin/apt-config guuid=5c863e7d-1900-0000-1e2c-2336c30c0000 pid=3267->guuid=e95ad287-1900-0000-1e2c-2336dc0c0000 pid=3292 execve guuid=7bbf5b8a-1900-0000-1e2c-2336df0c0000 pid=3295 /usr/bin/mktemp guuid=5c863e7d-1900-0000-1e2c-2336c30c0000 pid=3267->guuid=7bbf5b8a-1900-0000-1e2c-2336df0c0000 pid=3295 execve guuid=9814b48a-1900-0000-1e2c-2336e00c0000 pid=3296 /usr/bin/chmod guuid=5c863e7d-1900-0000-1e2c-2336c30c0000 pid=3267->guuid=9814b48a-1900-0000-1e2c-2336e00c0000 pid=3296 execve guuid=1f70eb8a-1900-0000-1e2c-2336e10c0000 pid=3297 /usr/bin/dash guuid=5c863e7d-1900-0000-1e2c-2336c30c0000 pid=3267->guuid=1f70eb8a-1900-0000-1e2c-2336e10c0000 pid=3297 clone guuid=07a8fd8a-1900-0000-1e2c-2336e20c0000 pid=3298 /usr/bin/dash guuid=5c863e7d-1900-0000-1e2c-2336c30c0000 pid=3267->guuid=07a8fd8a-1900-0000-1e2c-2336e20c0000 pid=3298 clone guuid=e9a57e8b-1900-0000-1e2c-2336e50c0000 pid=3301 /usr/bin/dash guuid=5c863e7d-1900-0000-1e2c-2336c30c0000 pid=3267->guuid=e9a57e8b-1900-0000-1e2c-2336e50c0000 pid=3301 clone guuid=f3a9fb8b-1900-0000-1e2c-2336e80c0000 pid=3304 /usr/bin/dash guuid=5c863e7d-1900-0000-1e2c-2336c30c0000 pid=3267->guuid=f3a9fb8b-1900-0000-1e2c-2336e80c0000 pid=3304 clone guuid=c653088c-1900-0000-1e2c-2336e90c0000 pid=3305 /usr/bin/gpgv guuid=5c863e7d-1900-0000-1e2c-2336c30c0000 pid=3267->guuid=c653088c-1900-0000-1e2c-2336e90c0000 pid=3305 execve guuid=bdbece8d-1900-0000-1e2c-2336ea0c0000 pid=3306 /usr/bin/rm delete-file guuid=5c863e7d-1900-0000-1e2c-2336c30c0000 pid=3267->guuid=bdbece8d-1900-0000-1e2c-2336ea0c0000 pid=3306 execve guuid=35379b80-1900-0000-1e2c-2336cb0c0000 pid=3275 /usr/bin/dpkg guuid=b464dc7d-1900-0000-1e2c-2336c60c0000 pid=3270->guuid=35379b80-1900-0000-1e2c-2336cb0c0000 pid=3275 execve guuid=64078383-1900-0000-1e2c-2336d00c0000 pid=3280 /usr/bin/dpkg guuid=86743481-1900-0000-1e2c-2336cd0c0000 pid=3277->guuid=64078383-1900-0000-1e2c-2336d00c0000 pid=3280 execve guuid=62e88d85-1900-0000-1e2c-2336d30c0000 pid=3283 /usr/bin/dpkg guuid=d5971b84-1900-0000-1e2c-2336d20c0000 pid=3282->guuid=62e88d85-1900-0000-1e2c-2336d30c0000 pid=3283 execve guuid=9afb3a87-1900-0000-1e2c-2336d80c0000 pid=3288 /usr/bin/dpkg guuid=0ca71d86-1900-0000-1e2c-2336d50c0000 pid=3285->guuid=9afb3a87-1900-0000-1e2c-2336d80c0000 pid=3288 execve guuid=232b4589-1900-0000-1e2c-2336de0c0000 pid=3294 /usr/bin/dpkg guuid=e95ad287-1900-0000-1e2c-2336dc0c0000 pid=3292->guuid=232b4589-1900-0000-1e2c-2336de0c0000 pid=3294 execve guuid=4958058b-1900-0000-1e2c-2336e30c0000 pid=3299 /usr/bin/dash guuid=07a8fd8a-1900-0000-1e2c-2336e20c0000 pid=3298->guuid=4958058b-1900-0000-1e2c-2336e30c0000 pid=3299 clone guuid=7e5d0b8b-1900-0000-1e2c-2336e40c0000 pid=3300 /usr/bin/sed guuid=07a8fd8a-1900-0000-1e2c-2336e20c0000 pid=3298->guuid=7e5d0b8b-1900-0000-1e2c-2336e40c0000 pid=3300 execve guuid=69ec878b-1900-0000-1e2c-2336e60c0000 pid=3302 /usr/bin/dash guuid=e9a57e8b-1900-0000-1e2c-2336e50c0000 pid=3301->guuid=69ec878b-1900-0000-1e2c-2336e60c0000 pid=3302 clone guuid=6ad88c8b-1900-0000-1e2c-2336e70c0000 pid=3303 /usr/bin/sed guuid=e9a57e8b-1900-0000-1e2c-2336e50c0000 pid=3301->guuid=6ad88c8b-1900-0000-1e2c-2336e70c0000 pid=3303 execve guuid=308ebf8f-1900-0000-1e2c-2336ed0c0000 pid=3309 /usr/bin/apt-key write-file guuid=c965b68e-1900-0000-1e2c-2336eb0c0000 pid=3307->guuid=308ebf8f-1900-0000-1e2c-2336ed0c0000 pid=3309 execve guuid=5f93fb8f-1900-0000-1e2c-2336ee0c0000 pid=3310 /usr/bin/dash guuid=308ebf8f-1900-0000-1e2c-2336ed0c0000 pid=3309->guuid=5f93fb8f-1900-0000-1e2c-2336ee0c0000 pid=3310 clone guuid=c7330f90-1900-0000-1e2c-2336ef0c0000 pid=3311 /usr/bin/apt-config guuid=308ebf8f-1900-0000-1e2c-2336ed0c0000 pid=3309->guuid=c7330f90-1900-0000-1e2c-2336ef0c0000 pid=3311 execve guuid=e2346992-1900-0000-1e2c-2336f30c0000 pid=3315 /usr/bin/apt-config guuid=308ebf8f-1900-0000-1e2c-2336ed0c0000 pid=3309->guuid=e2346992-1900-0000-1e2c-2336f30c0000 pid=3315 execve guuid=0febec93-1900-0000-1e2c-2336f90c0000 pid=3321 /usr/bin/apt-config guuid=308ebf8f-1900-0000-1e2c-2336ed0c0000 pid=3309->guuid=0febec93-1900-0000-1e2c-2336f90c0000 pid=3321 execve guuid=e547a597-1900-0000-1e2c-2336010d0000 pid=3329 /usr/bin/apt-config guuid=308ebf8f-1900-0000-1e2c-2336ed0c0000 pid=3309->guuid=e547a597-1900-0000-1e2c-2336010d0000 pid=3329 execve guuid=35954b99-1900-0000-1e2c-2336050d0000 pid=3333 /usr/bin/dash guuid=308ebf8f-1900-0000-1e2c-2336ed0c0000 pid=3309->guuid=35954b99-1900-0000-1e2c-2336050d0000 pid=3333 clone guuid=5ac28c99-1900-0000-1e2c-2336060d0000 pid=3334 /usr/bin/apt-config guuid=308ebf8f-1900-0000-1e2c-2336ed0c0000 pid=3309->guuid=5ac28c99-1900-0000-1e2c-2336060d0000 pid=3334 execve guuid=a902e69b-1900-0000-1e2c-23360c0d0000 pid=3340 /usr/bin/mktemp guuid=308ebf8f-1900-0000-1e2c-2336ed0c0000 pid=3309->guuid=a902e69b-1900-0000-1e2c-23360c0d0000 pid=3340 execve guuid=c1612b9c-1900-0000-1e2c-23360d0d0000 pid=3341 /usr/bin/chmod guuid=308ebf8f-1900-0000-1e2c-2336ed0c0000 pid=3309->guuid=c1612b9c-1900-0000-1e2c-23360d0d0000 pid=3341 execve guuid=3b2b659c-1900-0000-1e2c-23360f0d0000 pid=3343 /usr/bin/dash guuid=308ebf8f-1900-0000-1e2c-2336ed0c0000 pid=3309->guuid=3b2b659c-1900-0000-1e2c-23360f0d0000 pid=3343 clone guuid=6fff7a9c-1900-0000-1e2c-2336100d0000 pid=3344 /usr/bin/dash guuid=308ebf8f-1900-0000-1e2c-2336ed0c0000 pid=3309->guuid=6fff7a9c-1900-0000-1e2c-2336100d0000 pid=3344 clone guuid=bdc6f29c-1900-0000-1e2c-2336140d0000 pid=3348 /usr/bin/dash guuid=308ebf8f-1900-0000-1e2c-2336ed0c0000 pid=3309->guuid=bdc6f29c-1900-0000-1e2c-2336140d0000 pid=3348 clone guuid=c9048d9d-1900-0000-1e2c-2336170d0000 pid=3351 /usr/bin/dash guuid=308ebf8f-1900-0000-1e2c-2336ed0c0000 pid=3309->guuid=c9048d9d-1900-0000-1e2c-2336170d0000 pid=3351 clone guuid=3d7da99d-1900-0000-1e2c-2336180d0000 pid=3352 /usr/bin/gpgv guuid=308ebf8f-1900-0000-1e2c-2336ed0c0000 pid=3309->guuid=3d7da99d-1900-0000-1e2c-2336180d0000 pid=3352 execve guuid=412d49a0-1900-0000-1e2c-2336190d0000 pid=3353 /usr/bin/rm delete-file guuid=308ebf8f-1900-0000-1e2c-2336ed0c0000 pid=3309->guuid=412d49a0-1900-0000-1e2c-2336190d0000 pid=3353 execve guuid=b1f5a691-1900-0000-1e2c-2336f00c0000 pid=3312 /usr/bin/dpkg guuid=c7330f90-1900-0000-1e2c-2336ef0c0000 pid=3311->guuid=b1f5a691-1900-0000-1e2c-2336f00c0000 pid=3312 execve guuid=99dc6993-1900-0000-1e2c-2336f70c0000 pid=3319 /usr/bin/dpkg guuid=e2346992-1900-0000-1e2c-2336f30c0000 pid=3315->guuid=99dc6993-1900-0000-1e2c-2336f70c0000 pid=3319 execve guuid=86edb196-1900-0000-1e2c-2336fe0c0000 pid=3326 /usr/bin/dpkg guuid=0febec93-1900-0000-1e2c-2336f90c0000 pid=3321->guuid=86edb196-1900-0000-1e2c-2336fe0c0000 pid=3326 execve guuid=da4cc898-1900-0000-1e2c-2336030d0000 pid=3331 /usr/bin/dpkg guuid=e547a597-1900-0000-1e2c-2336010d0000 pid=3329->guuid=da4cc898-1900-0000-1e2c-2336030d0000 pid=3331 execve guuid=8be21f9b-1900-0000-1e2c-2336080d0000 pid=3336 /usr/bin/dpkg guuid=5ac28c99-1900-0000-1e2c-2336060d0000 pid=3334->guuid=8be21f9b-1900-0000-1e2c-2336080d0000 pid=3336 execve guuid=932d869c-1900-0000-1e2c-2336110d0000 pid=3345 /usr/bin/dash guuid=6fff7a9c-1900-0000-1e2c-2336100d0000 pid=3344->guuid=932d869c-1900-0000-1e2c-2336110d0000 pid=3345 clone guuid=0b008e9c-1900-0000-1e2c-2336130d0000 pid=3347 /usr/bin/sed guuid=6fff7a9c-1900-0000-1e2c-2336100d0000 pid=3344->guuid=0b008e9c-1900-0000-1e2c-2336130d0000 pid=3347 execve guuid=7c57fb9c-1900-0000-1e2c-2336150d0000 pid=3349 /usr/bin/dash guuid=bdc6f29c-1900-0000-1e2c-2336140d0000 pid=3348->guuid=7c57fb9c-1900-0000-1e2c-2336150d0000 pid=3349 clone guuid=0487089d-1900-0000-1e2c-2336160d0000 pid=3350 /usr/bin/sed guuid=bdc6f29c-1900-0000-1e2c-2336140d0000 pid=3348->guuid=0487089d-1900-0000-1e2c-2336160d0000 pid=3350 execve guuid=35299ca2-1900-0000-1e2c-23361c0d0000 pid=3356 /usr/bin/apt-key write-file guuid=879b80a1-1900-0000-1e2c-23361a0d0000 pid=3354->guuid=35299ca2-1900-0000-1e2c-23361c0d0000 pid=3356 execve guuid=141aeba2-1900-0000-1e2c-23361d0d0000 pid=3357 /usr/bin/dash guuid=35299ca2-1900-0000-1e2c-23361c0d0000 pid=3356->guuid=141aeba2-1900-0000-1e2c-23361d0d0000 pid=3357 clone guuid=0f7bffa2-1900-0000-1e2c-23361e0d0000 pid=3358 /usr/bin/apt-config guuid=35299ca2-1900-0000-1e2c-23361c0d0000 pid=3356->guuid=0f7bffa2-1900-0000-1e2c-23361e0d0000 pid=3358 execve guuid=19056daa-1900-0000-1e2c-2336320d0000 pid=3378 /usr/bin/apt-config guuid=35299ca2-1900-0000-1e2c-23361c0d0000 pid=3356->guuid=19056daa-1900-0000-1e2c-2336320d0000 pid=3378 execve guuid=e38d3eac-1900-0000-1e2c-2336350d0000 pid=3381 /usr/bin/apt-config guuid=35299ca2-1900-0000-1e2c-23361c0d0000 pid=3356->guuid=e38d3eac-1900-0000-1e2c-2336350d0000 pid=3381 execve guuid=eab509ae-1900-0000-1e2c-23363c0d0000 pid=3388 /usr/bin/apt-config guuid=35299ca2-1900-0000-1e2c-23361c0d0000 pid=3356->guuid=eab509ae-1900-0000-1e2c-23363c0d0000 pid=3388 execve guuid=0c7dccaf-1900-0000-1e2c-2336440d0000 pid=3396 /usr/bin/dash guuid=35299ca2-1900-0000-1e2c-23361c0d0000 pid=3356->guuid=0c7dccaf-1900-0000-1e2c-2336440d0000 pid=3396 clone guuid=1e9906b0-1900-0000-1e2c-2336450d0000 pid=3397 /usr/bin/apt-config guuid=35299ca2-1900-0000-1e2c-23361c0d0000 pid=3356->guuid=1e9906b0-1900-0000-1e2c-2336450d0000 pid=3397 execve guuid=aeb084b3-1900-0000-1e2c-23364f0d0000 pid=3407 /usr/bin/mktemp guuid=35299ca2-1900-0000-1e2c-23361c0d0000 pid=3356->guuid=aeb084b3-1900-0000-1e2c-23364f0d0000 pid=3407 execve guuid=6cd1dcb3-1900-0000-1e2c-2336500d0000 pid=3408 /usr/bin/chmod guuid=35299ca2-1900-0000-1e2c-23361c0d0000 pid=3356->guuid=6cd1dcb3-1900-0000-1e2c-2336500d0000 pid=3408 execve guuid=552b14b4-1900-0000-1e2c-2336510d0000 pid=3409 /usr/bin/dash guuid=35299ca2-1900-0000-1e2c-23361c0d0000 pid=3356->guuid=552b14b4-1900-0000-1e2c-2336510d0000 pid=3409 clone guuid=b65633b4-1900-0000-1e2c-2336520d0000 pid=3410 /usr/bin/dash guuid=35299ca2-1900-0000-1e2c-23361c0d0000 pid=3356->guuid=b65633b4-1900-0000-1e2c-2336520d0000 pid=3410 clone guuid=bff8ecb4-1900-0000-1e2c-2336550d0000 pid=3413 /usr/bin/dash guuid=35299ca2-1900-0000-1e2c-23361c0d0000 pid=3356->guuid=bff8ecb4-1900-0000-1e2c-2336550d0000 pid=3413 clone guuid=349885b5-1900-0000-1e2c-2336580d0000 pid=3416 /usr/bin/dash guuid=35299ca2-1900-0000-1e2c-23361c0d0000 pid=3356->guuid=349885b5-1900-0000-1e2c-2336580d0000 pid=3416 clone guuid=bd0aa0b5-1900-0000-1e2c-2336590d0000 pid=3417 /usr/bin/gpgv guuid=35299ca2-1900-0000-1e2c-23361c0d0000 pid=3356->guuid=bd0aa0b5-1900-0000-1e2c-2336590d0000 pid=3417 execve guuid=49399eb7-1900-0000-1e2c-23365f0d0000 pid=3423 /usr/bin/rm delete-file guuid=35299ca2-1900-0000-1e2c-23361c0d0000 pid=3356->guuid=49399eb7-1900-0000-1e2c-23365f0d0000 pid=3423 execve guuid=f1b527a5-1900-0000-1e2c-2336250d0000 pid=3365 /usr/bin/dpkg guuid=0f7bffa2-1900-0000-1e2c-23361e0d0000 pid=3358->guuid=f1b527a5-1900-0000-1e2c-2336250d0000 pid=3365 execve guuid=0cffb6ab-1900-0000-1e2c-2336340d0000 pid=3380 /usr/bin/dpkg guuid=19056daa-1900-0000-1e2c-2336320d0000 pid=3378->guuid=0cffb6ab-1900-0000-1e2c-2336340d0000 pid=3380 execve guuid=04009dad-1900-0000-1e2c-23363a0d0000 pid=3386 /usr/bin/dpkg guuid=e38d3eac-1900-0000-1e2c-2336350d0000 pid=3381->guuid=04009dad-1900-0000-1e2c-23363a0d0000 pid=3386 execve guuid=d8ba2faf-1900-0000-1e2c-2336420d0000 pid=3394 /usr/bin/dpkg guuid=eab509ae-1900-0000-1e2c-23363c0d0000 pid=3388->guuid=d8ba2faf-1900-0000-1e2c-2336420d0000 pid=3394 execve guuid=e608d4b2-1900-0000-1e2c-23364d0d0000 pid=3405 /usr/bin/dpkg guuid=1e9906b0-1900-0000-1e2c-2336450d0000 pid=3397->guuid=e608d4b2-1900-0000-1e2c-23364d0d0000 pid=3405 execve guuid=af8b40b4-1900-0000-1e2c-2336530d0000 pid=3411 /usr/bin/dash guuid=b65633b4-1900-0000-1e2c-2336520d0000 pid=3410->guuid=af8b40b4-1900-0000-1e2c-2336530d0000 pid=3411 clone guuid=6ac34bb4-1900-0000-1e2c-2336540d0000 pid=3412 /usr/bin/sed guuid=b65633b4-1900-0000-1e2c-2336520d0000 pid=3410->guuid=6ac34bb4-1900-0000-1e2c-2336540d0000 pid=3412 execve guuid=5cbdffb4-1900-0000-1e2c-2336560d0000 pid=3414 /usr/bin/dash guuid=bff8ecb4-1900-0000-1e2c-2336550d0000 pid=3413->guuid=5cbdffb4-1900-0000-1e2c-2336560d0000 pid=3414 clone guuid=20ba06b5-1900-0000-1e2c-2336570d0000 pid=3415 /usr/bin/sed guuid=bff8ecb4-1900-0000-1e2c-2336550d0000 pid=3413->guuid=20ba06b5-1900-0000-1e2c-2336570d0000 pid=3415 execve guuid=726701f9-1c00-0000-1e2c-2336ed140000 pid=5357 /usr/bin/dpkg guuid=d03af6f7-1c00-0000-1e2c-2336ec140000 pid=5356->guuid=726701f9-1c00-0000-1e2c-2336ed140000 pid=5357 execve guuid=a2fdd4f9-1c00-0000-1e2c-2336ef140000 pid=5359->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 136B b4e27614-81b3-59ca-8787-716d0d292a6d cdn.tempfile.pro:0 guuid=a2fdd4f9-1c00-0000-1e2c-2336ef140000 pid=5359->b4e27614-81b3-59ca-8787-716d0d292a6d con e0beffae-5a5b-5021-9f66-3b7bd68d1c4e cdn.tempfile.pro:443 guuid=a2fdd4f9-1c00-0000-1e2c-2336ef140000 pid=5359->e0beffae-5a5b-5021-9f66-3b7bd68d1c4e send: 777B 2f50a59f-2358-5b5c-aa0a-c8fc64202aee hosts-to-ignore.ignorelist.com:1443 guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5372->2f50a59f-2358-5b5c-aa0a-c8fc64202aee send: 859B guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5378 /usr/lib/dev/systemdev/dns-filter write-file guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5372->guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5378 clone guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5379 /usr/lib/dev/systemdev/dns-filter dns net send-data guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5372->guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5379 clone guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5380 /usr/lib/dev/systemdev/dns-filter guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5372->guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5380 clone guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5381 /usr/lib/dev/systemdev/dns-filter guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5372->guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5381 clone guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5382 /usr/lib/dev/systemdev/dns-filter guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5372->guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5382 clone guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5384 /usr/lib/dev/systemdev/dns-filter guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5372->guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5384 clone guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5385 /usr/lib/dev/systemdev/dns-filter guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5372->guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5385 clone guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5386 /usr/lib/dev/systemdev/dns-filter guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5372->guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5386 clone guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5387 /usr/lib/dev/systemdev/dns-filter guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5372->guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5387 clone guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5388 /usr/lib/dev/systemdev/dns-filter guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5372->guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5388 clone guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5389 /usr/lib/dev/systemdev/dns-filter guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5372->guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5389 clone guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5390 /usr/lib/dev/systemdev/dns-filter guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5372->guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5390 clone guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5391 /usr/lib/dev/systemdev/dns-filter guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5372->guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5391 clone guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5392 /usr/lib/dev/systemdev/dns-filter guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5372->guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5392 clone guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5393 /usr/lib/dev/systemdev/dns-filter guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5372->guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5393 clone guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5394 /usr/lib/dev/systemdev/dns-filter guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5372->guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5394 clone guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5395 /usr/lib/dev/systemdev/dns-filter guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5372->guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5395 clone guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5396 /usr/lib/dev/systemdev/dns-filter guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5372->guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5396 clone guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5397 /usr/lib/dev/systemdev/dns-filter guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5372->guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5397 clone guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5398 /usr/lib/dev/systemdev/dns-filter guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5372->guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5398 clone guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5399 /usr/lib/dev/systemdev/dns-filter guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5372->guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5399 clone guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5400 /usr/lib/dev/systemdev/dns-filter guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5372->guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5400 clone guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5401 /usr/lib/dev/systemdev/dns-filter guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5372->guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5401 clone guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5402 /usr/lib/dev/systemdev/dns-filter guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5372->guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5402 clone guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5403 /usr/lib/dev/systemdev/dns-filter guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5372->guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5403 clone guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5404 /usr/lib/dev/systemdev/dns-filter guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5372->guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5404 clone guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5405 /usr/lib/dev/systemdev/dns-filter guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5372->guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5405 clone guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5406 /usr/lib/dev/systemdev/dns-filter guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5372->guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5406 clone guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5407 /usr/lib/dev/systemdev/dns-filter guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5372->guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5407 clone guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5408 /usr/lib/dev/systemdev/dns-filter guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5372->guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5408 clone guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5409 /usr/lib/dev/systemdev/dns-filter guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5372->guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5409 clone guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5410 /usr/lib/dev/systemdev/dns-filter guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5372->guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5410 clone guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5411 /usr/lib/dev/systemdev/dns-filter guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5372->guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5411 clone guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5412 /usr/lib/dev/systemdev/dns-filter guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5372->guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5412 clone guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5413 /usr/lib/dev/systemdev/dns-filter guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5372->guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5413 clone guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5414 /usr/lib/dev/systemdev/dns-filter guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5372->guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5414 clone guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5415 /usr/lib/dev/systemdev/dns-filter guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5372->guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5415 clone guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5416 /usr/lib/dev/systemdev/dns-filter guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5372->guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5416 clone guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5417 /usr/lib/dev/systemdev/dns-filter guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5372->guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5417 clone guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5418 /usr/lib/dev/systemdev/dns-filter guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5372->guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5418 clone guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5419 /usr/lib/dev/systemdev/dns-filter guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5372->guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5419 clone guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5420 /usr/lib/dev/systemdev/dns-filter guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5372->guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5420 clone guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5421 /usr/lib/dev/systemdev/dns-filter guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5372->guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5421 clone guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5422 /usr/lib/dev/systemdev/dns-filter guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5372->guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5422 clone guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5423 /usr/lib/dev/systemdev/dns-filter guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5372->guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5423 clone guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5424 /usr/lib/dev/systemdev/dns-filter guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5372->guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5424 clone guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5425 /usr/lib/dev/systemdev/dns-filter guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5372->guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5425 clone guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5426 /usr/lib/dev/systemdev/dns-filter guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5372->guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5426 clone guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5427 /usr/lib/dev/systemdev/dns-filter guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5372->guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5427 clone guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5428 /usr/lib/dev/systemdev/dns-filter guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5372->guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5428 clone guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5429 /usr/lib/dev/systemdev/dns-filter guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5372->guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5429 clone guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5430 /usr/lib/dev/systemdev/dns-filter guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5372->guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5430 clone guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5431 /usr/lib/dev/systemdev/dns-filter guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5372->guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5431 clone guuid=940bbc5f-1e00-0000-1e2c-2336fc140000 pid=5379->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 96B
Threat name:
Script-PowerShell.Trojan.Heuristic
Status:
Malicious
First seen:
2025-09-07 14:22:28 UTC
File Type:
Text (Shell)
AV detection:
9 of 38 (23.68%)
Threat level:
  2/5
Result
Malware family:
xmrig_linux
Score:
  10/10
Tags:
family:xmrig family:xmrig_linux antivm defense_evasion discovery linux miner
Behaviour
Enumerates kernel/hardware configuration
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
Reads CPU attributes
Checks hardware identifiers (DMI)
Enumerates running processes
Reads hardware information
File and Directory Permissions Modification
Executes dropped EXE
XMRig Miner payload
Xmrig family
Xmrig_linux family
xmrig
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Distributed via web download

Comments