MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6984add6a21fecc140603d7e8a5f6ce0956123892a2f4b4196306a7f9f22d364. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



CoinMiner


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 6984add6a21fecc140603d7e8a5f6ce0956123892a2f4b4196306a7f9f22d364
SHA3-384 hash: 4f339d5fa642f1a72365d1b9a3509dd1c09c3f79ae57cd45b0bfff2b5b106f4cb3777de8dcf61292929d0659eb8ef496
SHA1 hash: c11e4bd6ee5c74fe9515cf31271c35d3c6586b5a
MD5 hash: d3cbef4822dfde7002c653f80e40fdfb
humanhash: apart-edward-fruit-river
File name:run.sh
Download: download sample
Signature CoinMiner
File size:7'720 bytes
First seen:2025-08-24 14:39:10 UTC
Last seen:2025-08-25 14:10:33 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 192:F8XyzHWZzzDN19xDkIam3qarbayHDPMeYtMvlu:MzvLzaUNjnq+u
TLSH T15FF1D606F6D0DAB42988C168854A1840794F922B5D092C48F8FDB56DFF2876C71FDBEB
Magika shell
Reporter abuse_ch
Tags:CoinMiner sh
URLMalware sample (SHA256 hash)SignatureTags
http://162.248.53.119:8000/mon.sh1e891ab1521b27923233e694f60fdbf0e1b840e657d8b1ffdefd8b5ef5e38964 CoinMinerCoinMiner
http://162.248.53.119:8000/yes.tar.gzn/an/aopendir
https://github.com/el3ctr0wqw1/xmrig-vrl2/releases/download/main/xmrig-vrln/an/an/a

Intelligence


File Origin
# of uploads :
2
# of downloads :
32
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
Script
Detections:
HEUR:Trojan-Downloader.Shell.Agent.bc
Status:
terminated
Behavior Graph:
%3 guuid=6cd09a03-1900-0000-0fac-20be0c0e0000 pid=3596 /usr/bin/sudo guuid=0c217d05-1900-0000-0fac-20be130e0000 pid=3603 /tmp/sample.bin guuid=6cd09a03-1900-0000-0fac-20be0c0e0000 pid=3596->guuid=0c217d05-1900-0000-0fac-20be130e0000 pid=3603 execve guuid=0f34fb05-1900-0000-0fac-20be140e0000 pid=3604 /usr/bin/systemctl guuid=0c217d05-1900-0000-0fac-20be130e0000 pid=3603->guuid=0f34fb05-1900-0000-0fac-20be140e0000 pid=3604 execve guuid=980d8508-1900-0000-0fac-20be220e0000 pid=3618 /usr/bin/bash guuid=0c217d05-1900-0000-0fac-20be130e0000 pid=3603->guuid=980d8508-1900-0000-0fac-20be220e0000 pid=3618 clone guuid=b2757d0f-1900-0000-0fac-20be390e0000 pid=3641 /usr/bin/bash guuid=0c217d05-1900-0000-0fac-20be130e0000 pid=3603->guuid=b2757d0f-1900-0000-0fac-20be390e0000 pid=3641 clone guuid=f6676710-1900-0000-0fac-20be3d0e0000 pid=3645 /usr/bin/pgrep guuid=0c217d05-1900-0000-0fac-20be130e0000 pid=3603->guuid=f6676710-1900-0000-0fac-20be3d0e0000 pid=3645 execve guuid=e480f313-1900-0000-0fac-20be4a0e0000 pid=3658 /usr/bin/pgrep guuid=0c217d05-1900-0000-0fac-20be130e0000 pid=3603->guuid=e480f313-1900-0000-0fac-20be4a0e0000 pid=3658 execve guuid=90feda17-1900-0000-0fac-20be4b0e0000 pid=3659 /usr/bin/pgrep guuid=0c217d05-1900-0000-0fac-20be130e0000 pid=3603->guuid=90feda17-1900-0000-0fac-20be4b0e0000 pid=3659 execve guuid=7e1de417-1900-0000-0fac-20be4c0e0000 pid=3660 /usr/bin/grep guuid=0c217d05-1900-0000-0fac-20be130e0000 pid=3603->guuid=7e1de417-1900-0000-0fac-20be4c0e0000 pid=3660 execve guuid=f7f8fd17-1900-0000-0fac-20be4d0e0000 pid=3661 /usr/bin/xargs guuid=0c217d05-1900-0000-0fac-20be130e0000 pid=3603->guuid=f7f8fd17-1900-0000-0fac-20be4d0e0000 pid=3661 execve guuid=db2a2f1c-1900-0000-0fac-20be4e0e0000 pid=3662 /usr/bin/id guuid=0c217d05-1900-0000-0fac-20be130e0000 pid=3603->guuid=db2a2f1c-1900-0000-0fac-20be4e0e0000 pid=3662 execve guuid=99d7001d-1900-0000-0fac-20be4f0e0000 pid=3663 /usr/bin/apt-get delete-file write-file guuid=0c217d05-1900-0000-0fac-20be130e0000 pid=3603->guuid=99d7001d-1900-0000-0fac-20be4f0e0000 pid=3663 execve guuid=8fdaeeaa-1a00-0000-0fac-20be4c130000 pid=4940 /usr/bin/apt-get guuid=0c217d05-1900-0000-0fac-20be130e0000 pid=3603->guuid=8fdaeeaa-1a00-0000-0fac-20be4c130000 pid=4940 execve guuid=d0c4b4ac-1a00-0000-0fac-20be56130000 pid=4950 /usr/bin/mkdir guuid=0c217d05-1900-0000-0fac-20be130e0000 pid=3603->guuid=d0c4b4ac-1a00-0000-0fac-20be56130000 pid=4950 execve guuid=4a2617ad-1a00-0000-0fac-20be58130000 pid=4952 /usr/bin/wget dns net send-data write-file guuid=0c217d05-1900-0000-0fac-20be130e0000 pid=3603->guuid=4a2617ad-1a00-0000-0fac-20be58130000 pid=4952 execve guuid=5ff30adc-1a00-0000-0fac-20beb6130000 pid=5046 /usr/bin/mv guuid=0c217d05-1900-0000-0fac-20be130e0000 pid=3603->guuid=5ff30adc-1a00-0000-0fac-20beb6130000 pid=5046 execve guuid=0b058adc-1a00-0000-0fac-20beb8130000 pid=5048 /usr/bin/rm guuid=0c217d05-1900-0000-0fac-20be130e0000 pid=3603->guuid=0b058adc-1a00-0000-0fac-20beb8130000 pid=5048 execve guuid=59370fdd-1a00-0000-0fac-20bebb130000 pid=5051 /usr/bin/chmod guuid=0c217d05-1900-0000-0fac-20be130e0000 pid=3603->guuid=59370fdd-1a00-0000-0fac-20bebb130000 pid=5051 execve guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5053 /usr/lib/dev/systemdev/dns-filter mprotect-exec net send-data guuid=0c217d05-1900-0000-0fac-20be130e0000 pid=3603->guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5053 execve guuid=5bbdb5dd-1a00-0000-0fac-20bebe130000 pid=5054 /usr/bin/sleep guuid=0c217d05-1900-0000-0fac-20be130e0000 pid=3603->guuid=5bbdb5dd-1a00-0000-0fac-20bebe130000 pid=5054 execve guuid=300ad7fc-1a00-0000-0fac-20be29140000 pid=5161 /usr/bin/ps guuid=0c217d05-1900-0000-0fac-20be130e0000 pid=3603->guuid=300ad7fc-1a00-0000-0fac-20be29140000 pid=5161 execve guuid=df995fff-1a00-0000-0fac-20be30140000 pid=5168 /usr/bin/sleep guuid=0c217d05-1900-0000-0fac-20be130e0000 pid=3603->guuid=df995fff-1a00-0000-0fac-20be30140000 pid=5168 execve guuid=1e7ef10b-1c00-0000-0fac-20be24150000 pid=5412 /usr/bin/ps guuid=0c217d05-1900-0000-0fac-20be130e0000 pid=3603->guuid=1e7ef10b-1c00-0000-0fac-20be24150000 pid=5412 execve guuid=b834e00f-1c00-0000-0fac-20be25150000 pid=5413 /usr/bin/rm guuid=0c217d05-1900-0000-0fac-20be130e0000 pid=3603->guuid=b834e00f-1c00-0000-0fac-20be25150000 pid=5413 execve guuid=dbc76210-1c00-0000-0fac-20be26150000 pid=5414 /usr/bin/rm guuid=0c217d05-1900-0000-0fac-20be130e0000 pid=3603->guuid=dbc76210-1c00-0000-0fac-20be26150000 pid=5414 execve guuid=e2e7b608-1900-0000-0fac-20be240e0000 pid=3620 /usr/bin/wget dns net send-data guuid=980d8508-1900-0000-0fac-20be220e0000 pid=3618->guuid=e2e7b608-1900-0000-0fac-20be240e0000 pid=3620 execve 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=e2e7b608-1900-0000-0fac-20be240e0000 pid=3620->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 72B 0690ccd5-4816-5f11-94dc-7c585f38cdea ipv4.icanhazip.com:0 guuid=e2e7b608-1900-0000-0fac-20be240e0000 pid=3620->0690ccd5-4816-5f11-94dc-7c585f38cdea con d0ecfe49-aa79-583f-85c6-85ac97075256 ipv4.icanhazip.com:80 guuid=e2e7b608-1900-0000-0fac-20be240e0000 pid=3620->d0ecfe49-aa79-583f-85c6-85ac97075256 send: 133B guuid=9c1e890f-1900-0000-0fac-20be3a0e0000 pid=3642 /usr/bin/bash guuid=b2757d0f-1900-0000-0fac-20be390e0000 pid=3641->guuid=9c1e890f-1900-0000-0fac-20be3a0e0000 pid=3642 clone guuid=c24b8e0f-1900-0000-0fac-20be3b0e0000 pid=3643 /usr/bin/sed guuid=b2757d0f-1900-0000-0fac-20be390e0000 pid=3641->guuid=c24b8e0f-1900-0000-0fac-20be3b0e0000 pid=3643 execve guuid=6d8a930f-1900-0000-0fac-20be3c0e0000 pid=3644 /usr/bin/cut guuid=b2757d0f-1900-0000-0fac-20be390e0000 pid=3641->guuid=6d8a930f-1900-0000-0fac-20be3c0e0000 pid=3644 execve guuid=89dcf41e-1900-0000-0fac-20be510e0000 pid=3665 /usr/bin/dpkg guuid=99d7001d-1900-0000-0fac-20be4f0e0000 pid=3663->guuid=89dcf41e-1900-0000-0fac-20be510e0000 pid=3665 execve guuid=1f7e3d20-1900-0000-0fac-20be580e0000 pid=3672 /usr/lib/apt/methods/mirror guuid=99d7001d-1900-0000-0fac-20be4f0e0000 pid=3663->guuid=1f7e3d20-1900-0000-0fac-20be580e0000 pid=3672 execve guuid=5b449421-1900-0000-0fac-20be5b0e0000 pid=3675 /usr/lib/apt/methods/mirror guuid=99d7001d-1900-0000-0fac-20be4f0e0000 pid=3663->guuid=5b449421-1900-0000-0fac-20be5b0e0000 pid=3675 execve guuid=295ebc22-1900-0000-0fac-20be5f0e0000 pid=3679 /usr/lib/apt/methods/file guuid=99d7001d-1900-0000-0fac-20be4f0e0000 pid=3663->guuid=295ebc22-1900-0000-0fac-20be5f0e0000 pid=3679 execve guuid=35decb24-1900-0000-0fac-20be600e0000 pid=3680 /usr/lib/apt/methods/file delete-file guuid=99d7001d-1900-0000-0fac-20be4f0e0000 pid=3663->guuid=35decb24-1900-0000-0fac-20be600e0000 pid=3680 execve guuid=cee2ad26-1900-0000-0fac-20be610e0000 pid=3681 /usr/lib/apt/methods/http guuid=99d7001d-1900-0000-0fac-20be4f0e0000 pid=3663->guuid=cee2ad26-1900-0000-0fac-20be610e0000 pid=3681 execve guuid=1e873b2b-1900-0000-0fac-20be6d0e0000 pid=3693 /usr/lib/apt/methods/http dns net send-data write-file guuid=99d7001d-1900-0000-0fac-20be4f0e0000 pid=3663->guuid=1e873b2b-1900-0000-0fac-20be6d0e0000 pid=3693 execve guuid=501f8c43-1900-0000-0fac-20bec50e0000 pid=3781 /usr/lib/apt/methods/gpgv guuid=99d7001d-1900-0000-0fac-20be4f0e0000 pid=3663->guuid=501f8c43-1900-0000-0fac-20bec50e0000 pid=3781 execve guuid=cb392745-1900-0000-0fac-20bece0e0000 pid=3790 /usr/lib/apt/methods/gpgv guuid=99d7001d-1900-0000-0fac-20be4f0e0000 pid=3663->guuid=cb392745-1900-0000-0fac-20bece0e0000 pid=3790 execve guuid=8c24d66c-1900-0000-0fac-20beab0f0000 pid=4011 /usr/lib/apt/methods/store guuid=99d7001d-1900-0000-0fac-20be4f0e0000 pid=3663->guuid=8c24d66c-1900-0000-0fac-20beab0f0000 pid=4011 execve guuid=d86fbc6d-1900-0000-0fac-20beae0f0000 pid=4014 /usr/lib/apt/methods/store write-file guuid=99d7001d-1900-0000-0fac-20be4f0e0000 pid=3663->guuid=d86fbc6d-1900-0000-0fac-20beae0f0000 pid=4014 execve guuid=6c6e3889-1900-0000-0fac-20be21100000 pid=4129 /usr/lib/apt/methods/rred guuid=99d7001d-1900-0000-0fac-20be4f0e0000 pid=3663->guuid=6c6e3889-1900-0000-0fac-20be21100000 pid=4129 execve guuid=2aaa188c-1900-0000-0fac-20be2f100000 pid=4143 /usr/lib/apt/methods/rred write-file guuid=99d7001d-1900-0000-0fac-20be4f0e0000 pid=3663->guuid=2aaa188c-1900-0000-0fac-20be2f100000 pid=4143 execve guuid=819ce7b3-1900-0000-0fac-20be99100000 pid=4249 /usr/bin/dpkg guuid=99d7001d-1900-0000-0fac-20be4f0e0000 pid=3663->guuid=819ce7b3-1900-0000-0fac-20be99100000 pid=4249 execve guuid=8ce28ea6-1a00-0000-0fac-20be3f130000 pid=4927 /usr/bin/dpkg guuid=99d7001d-1900-0000-0fac-20be4f0e0000 pid=3663->guuid=8ce28ea6-1a00-0000-0fac-20be3f130000 pid=4927 execve guuid=1e873b2b-1900-0000-0fac-20be6d0e0000 pid=3693->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 122B 869ebe88-8c1e-5fbb-adb0-cfe48d8d7faf debian.map.fastly.net:443 guuid=1e873b2b-1900-0000-0fac-20be6d0e0000 pid=3693->869ebe88-8c1e-5fbb-adb0-cfe48d8d7faf send: 5645B guuid=86a75d47-1900-0000-0fac-20beda0e0000 pid=3802 /usr/lib/apt/methods/gpgv delete-file write-file guuid=cb392745-1900-0000-0fac-20bece0e0000 pid=3790->guuid=86a75d47-1900-0000-0fac-20beda0e0000 pid=3802 clone guuid=01c7845c-1900-0000-0fac-20be3d0f0000 pid=3901 /usr/lib/apt/methods/gpgv delete-file write-file guuid=cb392745-1900-0000-0fac-20bece0e0000 pid=3790->guuid=01c7845c-1900-0000-0fac-20be3d0f0000 pid=3901 clone guuid=9dccfa68-1900-0000-0fac-20be930f0000 pid=3987 /usr/lib/apt/methods/gpgv delete-file write-file guuid=cb392745-1900-0000-0fac-20bece0e0000 pid=3790->guuid=9dccfa68-1900-0000-0fac-20be930f0000 pid=3987 clone guuid=cdd9917a-1900-0000-0fac-20beed0f0000 pid=4077 /usr/lib/apt/methods/gpgv delete-file write-file guuid=cb392745-1900-0000-0fac-20bece0e0000 pid=3790->guuid=cdd9917a-1900-0000-0fac-20beed0f0000 pid=4077 clone guuid=c3b93349-1900-0000-0fac-20bee40e0000 pid=3812 /usr/bin/apt-key write-file guuid=86a75d47-1900-0000-0fac-20beda0e0000 pid=3802->guuid=c3b93349-1900-0000-0fac-20bee40e0000 pid=3812 execve guuid=3809cc49-1900-0000-0fac-20bee90e0000 pid=3817 /usr/bin/dash guuid=c3b93349-1900-0000-0fac-20bee40e0000 pid=3812->guuid=3809cc49-1900-0000-0fac-20bee90e0000 pid=3817 clone guuid=8c1df149-1900-0000-0fac-20beeb0e0000 pid=3819 /usr/bin/apt-config guuid=c3b93349-1900-0000-0fac-20bee40e0000 pid=3812->guuid=8c1df149-1900-0000-0fac-20beeb0e0000 pid=3819 execve guuid=5043af4d-1900-0000-0fac-20befa0e0000 pid=3834 /usr/bin/apt-config guuid=c3b93349-1900-0000-0fac-20bee40e0000 pid=3812->guuid=5043af4d-1900-0000-0fac-20befa0e0000 pid=3834 execve guuid=4ff3ce50-1900-0000-0fac-20be000f0000 pid=3840 /usr/bin/apt-config guuid=c3b93349-1900-0000-0fac-20bee40e0000 pid=3812->guuid=4ff3ce50-1900-0000-0fac-20be000f0000 pid=3840 execve guuid=43124052-1900-0000-0fac-20be070f0000 pid=3847 /usr/bin/apt-config guuid=c3b93349-1900-0000-0fac-20bee40e0000 pid=3812->guuid=43124052-1900-0000-0fac-20be070f0000 pid=3847 execve guuid=e9267e53-1900-0000-0fac-20be0c0f0000 pid=3852 /usr/bin/dash guuid=c3b93349-1900-0000-0fac-20bee40e0000 pid=3812->guuid=e9267e53-1900-0000-0fac-20be0c0f0000 pid=3852 clone guuid=3975b253-1900-0000-0fac-20be0d0f0000 pid=3853 /usr/bin/apt-config guuid=c3b93349-1900-0000-0fac-20bee40e0000 pid=3812->guuid=3975b253-1900-0000-0fac-20be0d0f0000 pid=3853 execve guuid=92bfd855-1900-0000-0fac-20be1b0f0000 pid=3867 /usr/bin/mktemp guuid=c3b93349-1900-0000-0fac-20bee40e0000 pid=3812->guuid=92bfd855-1900-0000-0fac-20be1b0f0000 pid=3867 execve guuid=1e701556-1900-0000-0fac-20be1c0f0000 pid=3868 /usr/bin/chmod guuid=c3b93349-1900-0000-0fac-20bee40e0000 pid=3812->guuid=1e701556-1900-0000-0fac-20be1c0f0000 pid=3868 execve guuid=cec54356-1900-0000-0fac-20be1d0f0000 pid=3869 /usr/bin/dash guuid=c3b93349-1900-0000-0fac-20bee40e0000 pid=3812->guuid=cec54356-1900-0000-0fac-20be1d0f0000 pid=3869 clone guuid=c9b35656-1900-0000-0fac-20be1e0f0000 pid=3870 /usr/bin/dash guuid=c3b93349-1900-0000-0fac-20bee40e0000 pid=3812->guuid=c9b35656-1900-0000-0fac-20be1e0f0000 pid=3870 clone guuid=4da1c056-1900-0000-0fac-20be230f0000 pid=3875 /usr/bin/dash guuid=c3b93349-1900-0000-0fac-20bee40e0000 pid=3812->guuid=4da1c056-1900-0000-0fac-20be230f0000 pid=3875 clone guuid=b82e3c57-1900-0000-0fac-20be270f0000 pid=3879 /usr/bin/dash guuid=c3b93349-1900-0000-0fac-20bee40e0000 pid=3812->guuid=b82e3c57-1900-0000-0fac-20be270f0000 pid=3879 clone guuid=e3b14d57-1900-0000-0fac-20be280f0000 pid=3880 /usr/bin/gpgv guuid=c3b93349-1900-0000-0fac-20bee40e0000 pid=3812->guuid=e3b14d57-1900-0000-0fac-20be280f0000 pid=3880 execve guuid=87d76c59-1900-0000-0fac-20be340f0000 pid=3892 /usr/bin/rm delete-file guuid=c3b93349-1900-0000-0fac-20bee40e0000 pid=3812->guuid=87d76c59-1900-0000-0fac-20be340f0000 pid=3892 execve guuid=7792d84c-1900-0000-0fac-20bef90e0000 pid=3833 /usr/bin/dpkg guuid=8c1df149-1900-0000-0fac-20beeb0e0000 pid=3819->guuid=7792d84c-1900-0000-0fac-20bef90e0000 pid=3833 execve guuid=98bc674f-1900-0000-0fac-20befb0e0000 pid=3835 /usr/bin/dpkg guuid=5043af4d-1900-0000-0fac-20befa0e0000 pid=3834->guuid=98bc674f-1900-0000-0fac-20befb0e0000 pid=3835 execve guuid=e3d1aa51-1900-0000-0fac-20be040f0000 pid=3844 /usr/bin/dpkg guuid=4ff3ce50-1900-0000-0fac-20be000f0000 pid=3840->guuid=e3d1aa51-1900-0000-0fac-20be040f0000 pid=3844 execve guuid=bccf1653-1900-0000-0fac-20be0b0f0000 pid=3851 /usr/bin/dpkg guuid=43124052-1900-0000-0fac-20be070f0000 pid=3847->guuid=bccf1653-1900-0000-0fac-20be0b0f0000 pid=3851 execve guuid=a4986955-1900-0000-0fac-20be170f0000 pid=3863 /usr/bin/dpkg guuid=3975b253-1900-0000-0fac-20be0d0f0000 pid=3853->guuid=a4986955-1900-0000-0fac-20be170f0000 pid=3863 execve guuid=34ff6156-1900-0000-0fac-20be200f0000 pid=3872 /usr/bin/dash guuid=c9b35656-1900-0000-0fac-20be1e0f0000 pid=3870->guuid=34ff6156-1900-0000-0fac-20be200f0000 pid=3872 clone guuid=0ff76756-1900-0000-0fac-20be210f0000 pid=3873 /usr/bin/sed guuid=c9b35656-1900-0000-0fac-20be1e0f0000 pid=3870->guuid=0ff76756-1900-0000-0fac-20be210f0000 pid=3873 execve guuid=1af3cc56-1900-0000-0fac-20be240f0000 pid=3876 /usr/bin/dash guuid=4da1c056-1900-0000-0fac-20be230f0000 pid=3875->guuid=1af3cc56-1900-0000-0fac-20be240f0000 pid=3876 clone guuid=93e9db56-1900-0000-0fac-20be250f0000 pid=3877 /usr/bin/sed guuid=4da1c056-1900-0000-0fac-20be230f0000 pid=3875->guuid=93e9db56-1900-0000-0fac-20be250f0000 pid=3877 execve guuid=66691e5d-1900-0000-0fac-20be440f0000 pid=3908 /usr/bin/apt-key write-file guuid=01c7845c-1900-0000-0fac-20be3d0f0000 pid=3901->guuid=66691e5d-1900-0000-0fac-20be440f0000 pid=3908 execve guuid=86164e5d-1900-0000-0fac-20be460f0000 pid=3910 /usr/bin/dash guuid=66691e5d-1900-0000-0fac-20be440f0000 pid=3908->guuid=86164e5d-1900-0000-0fac-20be460f0000 pid=3910 clone guuid=39df5f5d-1900-0000-0fac-20be470f0000 pid=3911 /usr/bin/apt-config guuid=66691e5d-1900-0000-0fac-20be440f0000 pid=3908->guuid=39df5f5d-1900-0000-0fac-20be470f0000 pid=3911 execve guuid=8703cb5f-1900-0000-0fac-20be550f0000 pid=3925 /usr/bin/apt-config guuid=66691e5d-1900-0000-0fac-20be440f0000 pid=3908->guuid=8703cb5f-1900-0000-0fac-20be550f0000 pid=3925 execve guuid=0b510261-1900-0000-0fac-20be5e0f0000 pid=3934 /usr/bin/apt-config guuid=66691e5d-1900-0000-0fac-20be440f0000 pid=3908->guuid=0b510261-1900-0000-0fac-20be5e0f0000 pid=3934 execve guuid=d4166062-1900-0000-0fac-20be650f0000 pid=3941 /usr/bin/apt-config guuid=66691e5d-1900-0000-0fac-20be440f0000 pid=3908->guuid=d4166062-1900-0000-0fac-20be650f0000 pid=3941 execve guuid=c26b8563-1900-0000-0fac-20be6d0f0000 pid=3949 /usr/bin/dash guuid=66691e5d-1900-0000-0fac-20be440f0000 pid=3908->guuid=c26b8563-1900-0000-0fac-20be6d0f0000 pid=3949 clone guuid=77c8aa63-1900-0000-0fac-20be6f0f0000 pid=3951 /usr/bin/apt-config guuid=66691e5d-1900-0000-0fac-20be440f0000 pid=3908->guuid=77c8aa63-1900-0000-0fac-20be6f0f0000 pid=3951 execve guuid=7aac0565-1900-0000-0fac-20be750f0000 pid=3957 /usr/bin/mktemp guuid=66691e5d-1900-0000-0fac-20be440f0000 pid=3908->guuid=7aac0565-1900-0000-0fac-20be750f0000 pid=3957 execve guuid=d27a3f65-1900-0000-0fac-20be760f0000 pid=3958 /usr/bin/chmod guuid=66691e5d-1900-0000-0fac-20be440f0000 pid=3908->guuid=d27a3f65-1900-0000-0fac-20be760f0000 pid=3958 execve guuid=a4696e65-1900-0000-0fac-20be780f0000 pid=3960 /usr/bin/dash guuid=66691e5d-1900-0000-0fac-20be440f0000 pid=3908->guuid=a4696e65-1900-0000-0fac-20be780f0000 pid=3960 clone guuid=c7c67f65-1900-0000-0fac-20be790f0000 pid=3961 /usr/bin/dash guuid=66691e5d-1900-0000-0fac-20be440f0000 pid=3908->guuid=c7c67f65-1900-0000-0fac-20be790f0000 pid=3961 clone guuid=e6ded465-1900-0000-0fac-20be7d0f0000 pid=3965 /usr/bin/dash guuid=66691e5d-1900-0000-0fac-20be440f0000 pid=3908->guuid=e6ded465-1900-0000-0fac-20be7d0f0000 pid=3965 clone guuid=a3864366-1900-0000-0fac-20be820f0000 pid=3970 /usr/bin/dash guuid=66691e5d-1900-0000-0fac-20be440f0000 pid=3908->guuid=a3864366-1900-0000-0fac-20be820f0000 pid=3970 clone guuid=bf6d5366-1900-0000-0fac-20be840f0000 pid=3972 /usr/bin/gpgv guuid=66691e5d-1900-0000-0fac-20be440f0000 pid=3908->guuid=bf6d5366-1900-0000-0fac-20be840f0000 pid=3972 execve guuid=fdbc3768-1900-0000-0fac-20be8c0f0000 pid=3980 /usr/bin/rm delete-file guuid=66691e5d-1900-0000-0fac-20be440f0000 pid=3908->guuid=fdbc3768-1900-0000-0fac-20be8c0f0000 pid=3980 execve guuid=cf715e5f-1900-0000-0fac-20be520f0000 pid=3922 /usr/bin/dpkg guuid=39df5f5d-1900-0000-0fac-20be470f0000 pid=3911->guuid=cf715e5f-1900-0000-0fac-20be520f0000 pid=3922 execve guuid=5a269960-1900-0000-0fac-20be5a0f0000 pid=3930 /usr/bin/dpkg guuid=8703cb5f-1900-0000-0fac-20be550f0000 pid=3925->guuid=5a269960-1900-0000-0fac-20be5a0f0000 pid=3930 execve guuid=7acef961-1900-0000-0fac-20be620f0000 pid=3938 /usr/bin/dpkg guuid=0b510261-1900-0000-0fac-20be5e0f0000 pid=3934->guuid=7acef961-1900-0000-0fac-20be620f0000 pid=3938 execve guuid=cfad2263-1900-0000-0fac-20be6a0f0000 pid=3946 /usr/bin/dpkg guuid=d4166062-1900-0000-0fac-20be650f0000 pid=3941->guuid=cfad2263-1900-0000-0fac-20be6a0f0000 pid=3946 execve guuid=7be08864-1900-0000-0fac-20be730f0000 pid=3955 /usr/bin/dpkg guuid=77c8aa63-1900-0000-0fac-20be6f0f0000 pid=3951->guuid=7be08864-1900-0000-0fac-20be730f0000 pid=3955 execve guuid=ee478865-1900-0000-0fac-20be7a0f0000 pid=3962 /usr/bin/dash guuid=c7c67f65-1900-0000-0fac-20be790f0000 pid=3961->guuid=ee478865-1900-0000-0fac-20be7a0f0000 pid=3962 clone guuid=dddf8c65-1900-0000-0fac-20be7b0f0000 pid=3963 /usr/bin/sed guuid=c7c67f65-1900-0000-0fac-20be790f0000 pid=3961->guuid=dddf8c65-1900-0000-0fac-20be7b0f0000 pid=3963 execve guuid=800edd65-1900-0000-0fac-20be7f0f0000 pid=3967 /usr/bin/dash guuid=e6ded465-1900-0000-0fac-20be7d0f0000 pid=3965->guuid=800edd65-1900-0000-0fac-20be7f0f0000 pid=3967 clone guuid=90a4e265-1900-0000-0fac-20be800f0000 pid=3968 /usr/bin/sed guuid=e6ded465-1900-0000-0fac-20be7d0f0000 pid=3965->guuid=90a4e265-1900-0000-0fac-20be800f0000 pid=3968 execve guuid=8949a969-1900-0000-0fac-20be970f0000 pid=3991 /usr/bin/apt-key write-file guuid=9dccfa68-1900-0000-0fac-20be930f0000 pid=3987->guuid=8949a969-1900-0000-0fac-20be970f0000 pid=3991 execve guuid=b163dd69-1900-0000-0fac-20be990f0000 pid=3993 /usr/bin/dash guuid=8949a969-1900-0000-0fac-20be970f0000 pid=3991->guuid=b163dd69-1900-0000-0fac-20be990f0000 pid=3993 clone guuid=29ebec69-1900-0000-0fac-20be9a0f0000 pid=3994 /usr/bin/apt-config guuid=8949a969-1900-0000-0fac-20be970f0000 pid=3991->guuid=29ebec69-1900-0000-0fac-20be9a0f0000 pid=3994 execve guuid=d8cbe16b-1900-0000-0fac-20bea60f0000 pid=4006 /usr/bin/apt-config guuid=8949a969-1900-0000-0fac-20be970f0000 pid=3991->guuid=d8cbe16b-1900-0000-0fac-20bea60f0000 pid=4006 execve guuid=d3971f6e-1900-0000-0fac-20beb00f0000 pid=4016 /usr/bin/apt-config guuid=8949a969-1900-0000-0fac-20be970f0000 pid=3991->guuid=d3971f6e-1900-0000-0fac-20beb00f0000 pid=4016 execve guuid=611f9d73-1900-0000-0fac-20bebd0f0000 pid=4029 /usr/bin/apt-config guuid=8949a969-1900-0000-0fac-20be970f0000 pid=3991->guuid=611f9d73-1900-0000-0fac-20bebd0f0000 pid=4029 execve guuid=22b2b075-1900-0000-0fac-20bec80f0000 pid=4040 /usr/bin/dash guuid=8949a969-1900-0000-0fac-20be970f0000 pid=3991->guuid=22b2b075-1900-0000-0fac-20bec80f0000 pid=4040 clone guuid=8f99da75-1900-0000-0fac-20bec90f0000 pid=4041 /usr/bin/apt-config guuid=8949a969-1900-0000-0fac-20be970f0000 pid=3991->guuid=8f99da75-1900-0000-0fac-20bec90f0000 pid=4041 execve guuid=54145477-1900-0000-0fac-20bed20f0000 pid=4050 /usr/bin/mktemp guuid=8949a969-1900-0000-0fac-20be970f0000 pid=3991->guuid=54145477-1900-0000-0fac-20bed20f0000 pid=4050 execve guuid=ebdc8477-1900-0000-0fac-20bed40f0000 pid=4052 /usr/bin/chmod guuid=8949a969-1900-0000-0fac-20be970f0000 pid=3991->guuid=ebdc8477-1900-0000-0fac-20bed40f0000 pid=4052 execve guuid=3cb3b577-1900-0000-0fac-20bed50f0000 pid=4053 /usr/bin/dash guuid=8949a969-1900-0000-0fac-20be970f0000 pid=3991->guuid=3cb3b577-1900-0000-0fac-20bed50f0000 pid=4053 clone guuid=6bf3c577-1900-0000-0fac-20bed60f0000 pid=4054 /usr/bin/dash guuid=8949a969-1900-0000-0fac-20be970f0000 pid=3991->guuid=6bf3c577-1900-0000-0fac-20bed60f0000 pid=4054 clone guuid=10e71878-1900-0000-0fac-20bedc0f0000 pid=4060 /usr/bin/dash guuid=8949a969-1900-0000-0fac-20be970f0000 pid=3991->guuid=10e71878-1900-0000-0fac-20bedc0f0000 pid=4060 clone guuid=24487378-1900-0000-0fac-20bee10f0000 pid=4065 /usr/bin/dash guuid=8949a969-1900-0000-0fac-20be970f0000 pid=3991->guuid=24487378-1900-0000-0fac-20bee10f0000 pid=4065 clone guuid=944b8178-1900-0000-0fac-20bee20f0000 pid=4066 /usr/bin/gpgv guuid=8949a969-1900-0000-0fac-20be970f0000 pid=3991->guuid=944b8178-1900-0000-0fac-20bee20f0000 pid=4066 execve guuid=8347c879-1900-0000-0fac-20bee80f0000 pid=4072 /usr/bin/rm delete-file guuid=8949a969-1900-0000-0fac-20be970f0000 pid=3991->guuid=8347c879-1900-0000-0fac-20bee80f0000 pid=4072 execve guuid=0955196b-1900-0000-0fac-20bea20f0000 pid=4002 /usr/bin/dpkg guuid=29ebec69-1900-0000-0fac-20be9a0f0000 pid=3994->guuid=0955196b-1900-0000-0fac-20bea20f0000 pid=4002 execve guuid=de126c6d-1900-0000-0fac-20bead0f0000 pid=4013 /usr/bin/dpkg guuid=d8cbe16b-1900-0000-0fac-20bea60f0000 pid=4006->guuid=de126c6d-1900-0000-0fac-20bead0f0000 pid=4013 execve guuid=1ceaf16e-1900-0000-0fac-20beb30f0000 pid=4019 /usr/bin/dpkg guuid=d3971f6e-1900-0000-0fac-20beb00f0000 pid=4016->guuid=1ceaf16e-1900-0000-0fac-20beb30f0000 pid=4019 execve guuid=00cb2675-1900-0000-0fac-20bec60f0000 pid=4038 /usr/bin/dpkg guuid=611f9d73-1900-0000-0fac-20bebd0f0000 pid=4029->guuid=00cb2675-1900-0000-0fac-20bec60f0000 pid=4038 execve guuid=c86ecd76-1900-0000-0fac-20bece0f0000 pid=4046 /usr/bin/dpkg guuid=8f99da75-1900-0000-0fac-20bec90f0000 pid=4041->guuid=c86ecd76-1900-0000-0fac-20bece0f0000 pid=4046 execve guuid=5a59d077-1900-0000-0fac-20bed80f0000 pid=4056 /usr/bin/dash guuid=6bf3c577-1900-0000-0fac-20bed60f0000 pid=4054->guuid=5a59d077-1900-0000-0fac-20bed80f0000 pid=4056 clone guuid=2d41d577-1900-0000-0fac-20beda0f0000 pid=4058 /usr/bin/sed guuid=6bf3c577-1900-0000-0fac-20bed60f0000 pid=4054->guuid=2d41d577-1900-0000-0fac-20beda0f0000 pid=4058 execve guuid=96062078-1900-0000-0fac-20bedd0f0000 pid=4061 /usr/bin/dash guuid=10e71878-1900-0000-0fac-20bedc0f0000 pid=4060->guuid=96062078-1900-0000-0fac-20bedd0f0000 pid=4061 clone guuid=02c32478-1900-0000-0fac-20bede0f0000 pid=4062 /usr/bin/sed guuid=10e71878-1900-0000-0fac-20bedc0f0000 pid=4060->guuid=02c32478-1900-0000-0fac-20bede0f0000 pid=4062 execve guuid=f34d407b-1900-0000-0fac-20bef10f0000 pid=4081 /usr/bin/apt-key write-file guuid=cdd9917a-1900-0000-0fac-20beed0f0000 pid=4077->guuid=f34d407b-1900-0000-0fac-20bef10f0000 pid=4081 execve guuid=4a747b7b-1900-0000-0fac-20bef20f0000 pid=4082 /usr/bin/dash guuid=f34d407b-1900-0000-0fac-20bef10f0000 pid=4081->guuid=4a747b7b-1900-0000-0fac-20bef20f0000 pid=4082 clone guuid=ec89987b-1900-0000-0fac-20bef40f0000 pid=4084 /usr/bin/apt-config guuid=f34d407b-1900-0000-0fac-20bef10f0000 pid=4081->guuid=ec89987b-1900-0000-0fac-20bef40f0000 pid=4084 execve guuid=a621147e-1900-0000-0fac-20be00100000 pid=4096 /usr/bin/apt-config guuid=f34d407b-1900-0000-0fac-20bef10f0000 pid=4081->guuid=a621147e-1900-0000-0fac-20be00100000 pid=4096 execve guuid=0f32c783-1900-0000-0fac-20be0d100000 pid=4109 /usr/bin/apt-config guuid=f34d407b-1900-0000-0fac-20bef10f0000 pid=4081->guuid=0f32c783-1900-0000-0fac-20be0d100000 pid=4109 execve guuid=e9011e87-1900-0000-0fac-20be17100000 pid=4119 /usr/bin/apt-config guuid=f34d407b-1900-0000-0fac-20bef10f0000 pid=4081->guuid=e9011e87-1900-0000-0fac-20be17100000 pid=4119 execve guuid=7198d189-1900-0000-0fac-20be25100000 pid=4133 /usr/bin/dash guuid=f34d407b-1900-0000-0fac-20bef10f0000 pid=4081->guuid=7198d189-1900-0000-0fac-20be25100000 pid=4133 clone guuid=9c430e8a-1900-0000-0fac-20be29100000 pid=4137 /usr/bin/apt-config guuid=f34d407b-1900-0000-0fac-20bef10f0000 pid=4081->guuid=9c430e8a-1900-0000-0fac-20be29100000 pid=4137 execve guuid=b8066f92-1900-0000-0fac-20be32100000 pid=4146 /usr/bin/mktemp guuid=f34d407b-1900-0000-0fac-20bef10f0000 pid=4081->guuid=b8066f92-1900-0000-0fac-20be32100000 pid=4146 execve guuid=dea98193-1900-0000-0fac-20be35100000 pid=4149 /usr/bin/chmod guuid=f34d407b-1900-0000-0fac-20bef10f0000 pid=4081->guuid=dea98193-1900-0000-0fac-20be35100000 pid=4149 execve guuid=5a01a794-1900-0000-0fac-20be3a100000 pid=4154 /usr/bin/dash guuid=f34d407b-1900-0000-0fac-20bef10f0000 pid=4081->guuid=5a01a794-1900-0000-0fac-20be3a100000 pid=4154 clone guuid=1c6bd794-1900-0000-0fac-20be3b100000 pid=4155 /usr/bin/dash guuid=f34d407b-1900-0000-0fac-20bef10f0000 pid=4081->guuid=1c6bd794-1900-0000-0fac-20be3b100000 pid=4155 clone guuid=c84c6095-1900-0000-0fac-20be3e100000 pid=4158 /usr/bin/dash guuid=f34d407b-1900-0000-0fac-20bef10f0000 pid=4081->guuid=c84c6095-1900-0000-0fac-20be3e100000 pid=4158 clone guuid=2c08fa95-1900-0000-0fac-20be41100000 pid=4161 /usr/bin/dash guuid=f34d407b-1900-0000-0fac-20bef10f0000 pid=4081->guuid=2c08fa95-1900-0000-0fac-20be41100000 pid=4161 clone guuid=18334996-1900-0000-0fac-20be44100000 pid=4164 /usr/bin/gpgv guuid=f34d407b-1900-0000-0fac-20bef10f0000 pid=4081->guuid=18334996-1900-0000-0fac-20be44100000 pid=4164 execve guuid=a2600b98-1900-0000-0fac-20be46100000 pid=4166 /usr/bin/rm delete-file guuid=f34d407b-1900-0000-0fac-20bef10f0000 pid=4081->guuid=a2600b98-1900-0000-0fac-20be46100000 pid=4166 execve guuid=4b67577d-1900-0000-0fac-20befd0f0000 pid=4093 /usr/bin/dpkg guuid=ec89987b-1900-0000-0fac-20bef40f0000 pid=4084->guuid=4b67577d-1900-0000-0fac-20befd0f0000 pid=4093 execve guuid=0762017f-1900-0000-0fac-20be06100000 pid=4102 /usr/bin/dpkg guuid=a621147e-1900-0000-0fac-20be00100000 pid=4096->guuid=0762017f-1900-0000-0fac-20be06100000 pid=4102 execve guuid=a2b7ed85-1900-0000-0fac-20be14100000 pid=4116 /usr/bin/dpkg guuid=0f32c783-1900-0000-0fac-20be0d100000 pid=4109->guuid=a2b7ed85-1900-0000-0fac-20be14100000 pid=4116 execve guuid=8323c988-1900-0000-0fac-20be20100000 pid=4128 /usr/bin/dpkg guuid=e9011e87-1900-0000-0fac-20be17100000 pid=4119->guuid=8323c988-1900-0000-0fac-20be20100000 pid=4128 execve guuid=8fbcb190-1900-0000-0fac-20be31100000 pid=4145 /usr/bin/dpkg guuid=9c430e8a-1900-0000-0fac-20be29100000 pid=4137->guuid=8fbcb190-1900-0000-0fac-20be31100000 pid=4145 execve guuid=a5b4e094-1900-0000-0fac-20be3c100000 pid=4156 /usr/bin/dash guuid=1c6bd794-1900-0000-0fac-20be3b100000 pid=4155->guuid=a5b4e094-1900-0000-0fac-20be3c100000 pid=4156 clone guuid=0f87ed94-1900-0000-0fac-20be3d100000 pid=4157 /usr/bin/sed guuid=1c6bd794-1900-0000-0fac-20be3b100000 pid=4155->guuid=0f87ed94-1900-0000-0fac-20be3d100000 pid=4157 execve guuid=cb536995-1900-0000-0fac-20be3f100000 pid=4159 /usr/bin/dash guuid=c84c6095-1900-0000-0fac-20be3e100000 pid=4158->guuid=cb536995-1900-0000-0fac-20be3f100000 pid=4159 clone guuid=59176f95-1900-0000-0fac-20be40100000 pid=4160 /usr/bin/sed guuid=c84c6095-1900-0000-0fac-20be3e100000 pid=4158->guuid=59176f95-1900-0000-0fac-20be40100000 pid=4160 execve guuid=bf1af6ab-1a00-0000-0fac-20be52130000 pid=4946 /usr/bin/dpkg guuid=8fdaeeaa-1a00-0000-0fac-20be4c130000 pid=4940->guuid=bf1af6ab-1a00-0000-0fac-20be52130000 pid=4946 execve guuid=4a2617ad-1a00-0000-0fac-20be58130000 pid=4952->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 164B 75aab096-419b-50ef-be46-7d76b6a90e4c github.com:443 guuid=4a2617ad-1a00-0000-0fac-20be58130000 pid=4952->75aab096-419b-50ef-be46-7d76b6a90e4c send: 783B f8c5e44f-328d-5324-8bbd-da50752b9120 release-assets.githubusercontent.com:0 guuid=4a2617ad-1a00-0000-0fac-20be58130000 pid=4952->f8c5e44f-328d-5324-8bbd-da50752b9120 con f0eebea5-e97d-507c-a771-59cac353877c release-assets.githubusercontent.com:443 guuid=4a2617ad-1a00-0000-0fac-20be58130000 pid=4952->f0eebea5-e97d-507c-a771-59cac353877c send: 1610B 2f50a59f-2358-5b5c-aa0a-c8fc64202aee hosts-to-ignore.ignorelist.com:1443 guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5053->2f50a59f-2358-5b5c-aa0a-c8fc64202aee send: 859B guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5066 /usr/lib/dev/systemdev/dns-filter write-file zombie guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5053->guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5066 clone guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5067 /usr/lib/dev/systemdev/dns-filter dns net send-data guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5053->guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5067 clone guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5068 /usr/lib/dev/systemdev/dns-filter guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5053->guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5068 clone guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5069 /usr/lib/dev/systemdev/dns-filter guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5053->guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5069 clone guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5070 /usr/lib/dev/systemdev/dns-filter guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5053->guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5070 clone guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5229 /usr/lib/dev/systemdev/dns-filter guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5053->guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5229 clone guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5230 /usr/lib/dev/systemdev/dns-filter guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5053->guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5230 clone guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5231 /usr/lib/dev/systemdev/dns-filter guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5053->guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5231 clone guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5232 /usr/lib/dev/systemdev/dns-filter guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5053->guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5232 clone guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5250 /usr/lib/dev/systemdev/dns-filter guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5053->guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5250 clone guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5251 /usr/lib/dev/systemdev/dns-filter guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5053->guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5251 clone guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5252 /usr/lib/dev/systemdev/dns-filter guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5053->guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5252 clone guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5253 /usr/lib/dev/systemdev/dns-filter guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5053->guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5253 clone guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5277 /usr/lib/dev/systemdev/dns-filter guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5053->guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5277 clone guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5278 /usr/lib/dev/systemdev/dns-filter guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5053->guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5278 clone guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5279 /usr/lib/dev/systemdev/dns-filter guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5053->guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5279 clone guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5280 /usr/lib/dev/systemdev/dns-filter guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5053->guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5280 clone guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5304 /usr/lib/dev/systemdev/dns-filter guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5053->guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5304 clone guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5305 /usr/lib/dev/systemdev/dns-filter guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5053->guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5305 clone guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5306 /usr/lib/dev/systemdev/dns-filter guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5053->guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5306 clone guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5307 /usr/lib/dev/systemdev/dns-filter guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5053->guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5307 clone guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5334 /usr/lib/dev/systemdev/dns-filter guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5053->guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5334 clone guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5335 /usr/lib/dev/systemdev/dns-filter guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5053->guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5335 clone guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5336 /usr/lib/dev/systemdev/dns-filter guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5053->guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5336 clone guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5337 /usr/lib/dev/systemdev/dns-filter guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5053->guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5337 clone guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5370 /usr/lib/dev/systemdev/dns-filter guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5053->guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5370 clone guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5371 /usr/lib/dev/systemdev/dns-filter guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5053->guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5371 clone guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5372 /usr/lib/dev/systemdev/dns-filter guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5053->guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5372 clone guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5373 /usr/lib/dev/systemdev/dns-filter guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5053->guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5373 clone guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5377 /usr/lib/dev/systemdev/dns-filter guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5053->guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5377 clone guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5378 /usr/lib/dev/systemdev/dns-filter guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5053->guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5378 clone guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5379 /usr/lib/dev/systemdev/dns-filter guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5053->guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5379 clone guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5380 /usr/lib/dev/systemdev/dns-filter guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5053->guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5380 clone guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5384 /usr/lib/dev/systemdev/dns-filter guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5053->guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5384 clone guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5385 /usr/lib/dev/systemdev/dns-filter guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5053->guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5385 clone guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5386 /usr/lib/dev/systemdev/dns-filter guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5053->guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5386 clone guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5387 /usr/lib/dev/systemdev/dns-filter guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5053->guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5387 clone guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5396 /usr/lib/dev/systemdev/dns-filter guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5053->guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5396 clone guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5397 /usr/lib/dev/systemdev/dns-filter guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5053->guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5397 clone guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5398 /usr/lib/dev/systemdev/dns-filter guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5053->guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5398 clone guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5399 /usr/lib/dev/systemdev/dns-filter guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5053->guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5399 clone guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5400 /usr/lib/dev/systemdev/dns-filter guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5053->guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5400 clone guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5401 /usr/lib/dev/systemdev/dns-filter guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5053->guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5401 clone guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5402 /usr/lib/dev/systemdev/dns-filter guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5053->guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5402 clone guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5403 /usr/lib/dev/systemdev/dns-filter guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5053->guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5403 clone guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5404 /usr/lib/dev/systemdev/dns-filter guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5053->guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5404 clone guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5405 /usr/lib/dev/systemdev/dns-filter guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5053->guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5405 clone guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5406 /usr/lib/dev/systemdev/dns-filter guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5053->guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5406 clone guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5407 /usr/lib/dev/systemdev/dns-filter guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5053->guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5407 clone guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5408 /usr/lib/dev/systemdev/dns-filter guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5053->guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5408 clone guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5409 /usr/lib/dev/systemdev/dns-filter guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5053->guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5409 clone guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5410 /usr/lib/dev/systemdev/dns-filter guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5053->guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5410 clone guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5411 /usr/lib/dev/systemdev/dns-filter guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5053->guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5411 clone guuid=b9ac96dd-1a00-0000-0fac-20bebd130000 pid=5067->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 96B
Threat name:
Script-PowerShell.Trojan.Heuristic
Status:
Malicious
First seen:
2025-08-24 14:40:51 UTC
File Type:
Text (Shell)
AV detection:
10 of 24 (41.67%)
Threat level:
  2/5
Result
Malware family:
xmrig_linux
Score:
  10/10
Tags:
family:xmrig family:xmrig_linux antivm defense_evasion discovery linux miner
Behaviour
Enumerates kernel/hardware configuration
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads CPU attributes
Checks hardware identifiers (DMI)
Enumerates running processes
Reads hardware information
File and Directory Permissions Modification
Executes dropped EXE
XMRig Miner payload
Xmrig family
Xmrig_linux family
xmrig
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Distributed via web download

Comments