MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6bfcf6860490b0952ee283f22b0f5cb536a48a6e3d8676b2596e68651929fed2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA 1 File information Comments

SHA256 hash: 6bfcf6860490b0952ee283f22b0f5cb536a48a6e3d8676b2596e68651929fed2
SHA3-384 hash: ef71ceb037cd0041d124aa105a1319dfb2482c89dd7d60078ac6cf5f7e9393fe63e455befbc59566329f553b098d6628
SHA1 hash: 956184d31f475d077c1d3287d4bf14111e064b1c
MD5 hash: ce57af9dd1804eb766c95e31423e60fa
humanhash: green-kentucky-arkansas-chicken
File name:get1.sh
Download: download sample
File size:2'310 bytes
First seen:2026-04-04 16:59:45 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:LnWQ7xBAjHeD2z4wV6vlId/IkKj4Q1d48OcKQZJnVILSwTph:jWQdBA7LsxNCwzjrS8E/
TLSH T1A44176E57C5058B86ACBC9304AB65432E02311277E02346C70BFE01C7B7AD55B1BDDB6
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
32
Origin country :
DE DE
Vendor Threat Intelligence
Gathering data
Gathering data
Verdict:
Adware
File Type:
unix shell
First seen:
2026-04-04T14:10:00Z UTC
Last seen:
2026-04-04T14:48:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=f54b98d3-1a00-0000-9cac-8f21970a0000 pid=2711 /usr/bin/sudo guuid=58d944d6-1a00-0000-9cac-8f219f0a0000 pid=2719 /tmp/sample.bin guuid=f54b98d3-1a00-0000-9cac-8f21970a0000 pid=2711->guuid=58d944d6-1a00-0000-9cac-8f219f0a0000 pid=2719 execve guuid=b83bd6d6-1a00-0000-9cac-8f21a10a0000 pid=2721 /usr/bin/uname guuid=58d944d6-1a00-0000-9cac-8f219f0a0000 pid=2719->guuid=b83bd6d6-1a00-0000-9cac-8f21a10a0000 pid=2721 execve guuid=d36339d7-1a00-0000-9cac-8f21a30a0000 pid=2723 /usr/bin/screen guuid=58d944d6-1a00-0000-9cac-8f219f0a0000 pid=2719->guuid=d36339d7-1a00-0000-9cac-8f21a30a0000 pid=2723 execve guuid=397641d7-1a00-0000-9cac-8f21a50a0000 pid=2725 /usr/bin/grep guuid=58d944d6-1a00-0000-9cac-8f219f0a0000 pid=2719->guuid=397641d7-1a00-0000-9cac-8f21a50a0000 pid=2725 execve guuid=4d7472d9-1a00-0000-9cac-8f21aa0a0000 pid=2730 /usr/bin/apt-get delete-file write-file guuid=58d944d6-1a00-0000-9cac-8f219f0a0000 pid=2719->guuid=4d7472d9-1a00-0000-9cac-8f21aa0a0000 pid=2730 execve guuid=b062336d-2300-0000-9cac-8f21fe140000 pid=5374 /usr/bin/apt-get guuid=58d944d6-1a00-0000-9cac-8f219f0a0000 pid=2719->guuid=b062336d-2300-0000-9cac-8f21fe140000 pid=5374 execve guuid=14dfd96e-2300-0000-9cac-8f2101150000 pid=5377 /usr/bin/mkdir guuid=58d944d6-1a00-0000-9cac-8f219f0a0000 pid=2719->guuid=14dfd96e-2300-0000-9cac-8f2101150000 pid=5377 execve guuid=5bf22f6f-2300-0000-9cac-8f2102150000 pid=5378 /usr/bin/wget dns net send-data write-file guuid=58d944d6-1a00-0000-9cac-8f219f0a0000 pid=2719->guuid=5bf22f6f-2300-0000-9cac-8f2102150000 pid=5378 execve guuid=6cdd3a6f-2300-0000-9cac-8f2103150000 pid=5379 /usr/bin/tar write-file guuid=58d944d6-1a00-0000-9cac-8f219f0a0000 pid=2719->guuid=6cdd3a6f-2300-0000-9cac-8f2103150000 pid=5379 execve guuid=c8e4378d-2300-0000-9cac-8f2108150000 pid=5384 /usr/bin/mv guuid=58d944d6-1a00-0000-9cac-8f219f0a0000 pid=2719->guuid=c8e4378d-2300-0000-9cac-8f2108150000 pid=5384 execve guuid=a3c7a48d-2300-0000-9cac-8f2109150000 pid=5385 /usr/bin/chmod guuid=58d944d6-1a00-0000-9cac-8f219f0a0000 pid=2719->guuid=a3c7a48d-2300-0000-9cac-8f2109150000 pid=5385 execve guuid=7435ee8d-2300-0000-9cac-8f210a150000 pid=5386 /usr/bin/nproc guuid=58d944d6-1a00-0000-9cac-8f219f0a0000 pid=2719->guuid=7435ee8d-2300-0000-9cac-8f210a150000 pid=5386 execve guuid=7fd96a8e-2300-0000-9cac-8f210b150000 pid=5387 /usr/bin/screen guuid=58d944d6-1a00-0000-9cac-8f219f0a0000 pid=2719->guuid=7fd96a8e-2300-0000-9cac-8f210b150000 pid=5387 execve guuid=409cf38e-2300-0000-9cac-8f210e150000 pid=5390 /usr/bin/bash guuid=58d944d6-1a00-0000-9cac-8f219f0a0000 pid=2719->guuid=409cf38e-2300-0000-9cac-8f210e150000 pid=5390 clone guuid=614efb8e-2300-0000-9cac-8f210f150000 pid=5391 /usr/bin/bash guuid=58d944d6-1a00-0000-9cac-8f219f0a0000 pid=2719->guuid=614efb8e-2300-0000-9cac-8f210f150000 pid=5391 clone guuid=9b34978f-2300-0000-9cac-8f2114150000 pid=5396 /usr/bin/nproc guuid=58d944d6-1a00-0000-9cac-8f219f0a0000 pid=2719->guuid=9b34978f-2300-0000-9cac-8f2114150000 pid=5396 execve guuid=07dceddb-1a00-0000-9cac-8f21b10a0000 pid=2737 /usr/bin/dpkg guuid=4d7472d9-1a00-0000-9cac-8f21aa0a0000 pid=2730->guuid=07dceddb-1a00-0000-9cac-8f21b10a0000 pid=2737 execve guuid=17e59bdc-1a00-0000-9cac-8f21b20a0000 pid=2738 /usr/lib/apt/methods/mirror guuid=4d7472d9-1a00-0000-9cac-8f21aa0a0000 pid=2730->guuid=17e59bdc-1a00-0000-9cac-8f21b20a0000 pid=2738 execve guuid=9e7c1cde-1a00-0000-9cac-8f21b60a0000 pid=2742 /usr/lib/apt/methods/mirror guuid=4d7472d9-1a00-0000-9cac-8f21aa0a0000 pid=2730->guuid=9e7c1cde-1a00-0000-9cac-8f21b60a0000 pid=2742 execve guuid=e6e69be0-1a00-0000-9cac-8f21bd0a0000 pid=2749 /usr/lib/apt/methods/file guuid=4d7472d9-1a00-0000-9cac-8f21aa0a0000 pid=2730->guuid=e6e69be0-1a00-0000-9cac-8f21bd0a0000 pid=2749 execve guuid=49b298e1-1a00-0000-9cac-8f21c00a0000 pid=2752 /usr/lib/apt/methods/file delete-file guuid=4d7472d9-1a00-0000-9cac-8f21aa0a0000 pid=2730->guuid=49b298e1-1a00-0000-9cac-8f21c00a0000 pid=2752 execve guuid=5d9ecfe2-1a00-0000-9cac-8f21c40a0000 pid=2756 /usr/lib/apt/methods/http guuid=4d7472d9-1a00-0000-9cac-8f21aa0a0000 pid=2730->guuid=5d9ecfe2-1a00-0000-9cac-8f21c40a0000 pid=2756 execve guuid=ccc115e6-1a00-0000-9cac-8f21c80a0000 pid=2760 /usr/lib/apt/methods/http dns net send-data write-file guuid=4d7472d9-1a00-0000-9cac-8f21aa0a0000 pid=2730->guuid=ccc115e6-1a00-0000-9cac-8f21c80a0000 pid=2760 execve guuid=412b6b03-1b00-0000-9cac-8f21ef0a0000 pid=2799 /usr/lib/apt/methods/gpgv guuid=4d7472d9-1a00-0000-9cac-8f21aa0a0000 pid=2730->guuid=412b6b03-1b00-0000-9cac-8f21ef0a0000 pid=2799 execve guuid=8fc18c05-1b00-0000-9cac-8f21f40a0000 pid=2804 /usr/lib/apt/methods/gpgv guuid=4d7472d9-1a00-0000-9cac-8f21aa0a0000 pid=2730->guuid=8fc18c05-1b00-0000-9cac-8f21f40a0000 pid=2804 execve guuid=5acaff54-1b00-0000-9cac-8f21c10b0000 pid=3009 /usr/lib/apt/methods/store guuid=4d7472d9-1a00-0000-9cac-8f21aa0a0000 pid=2730->guuid=5acaff54-1b00-0000-9cac-8f21c10b0000 pid=3009 execve guuid=0c8d4457-1b00-0000-9cac-8f21c60b0000 pid=3014 /usr/lib/apt/methods/store write-file guuid=4d7472d9-1a00-0000-9cac-8f21aa0a0000 pid=2730->guuid=0c8d4457-1b00-0000-9cac-8f21c60b0000 pid=3014 execve guuid=27b1850c-2300-0000-9cac-8f21f5140000 pid=5365 /usr/bin/dpkg guuid=4d7472d9-1a00-0000-9cac-8f21aa0a0000 pid=2730->guuid=27b1850c-2300-0000-9cac-8f21f5140000 pid=5365 execve guuid=d5babc6a-2300-0000-9cac-8f21fd140000 pid=5373 /usr/bin/dpkg guuid=4d7472d9-1a00-0000-9cac-8f21aa0a0000 pid=2730->guuid=d5babc6a-2300-0000-9cac-8f21fd140000 pid=5373 execve 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=ccc115e6-1a00-0000-9cac-8f21c80a0000 pid=2760->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 166B 869ebe88-8c1e-5fbb-adb0-cfe48d8d7faf debian.map.fastly.net:443 guuid=ccc115e6-1a00-0000-9cac-8f21c80a0000 pid=2760->869ebe88-8c1e-5fbb-adb0-cfe48d8d7faf send: 6062B guuid=05c8a306-1b00-0000-9cac-8f21f80a0000 pid=2808 /usr/lib/apt/methods/gpgv delete-file write-file guuid=8fc18c05-1b00-0000-9cac-8f21f40a0000 pid=2804->guuid=05c8a306-1b00-0000-9cac-8f21f80a0000 pid=2808 clone guuid=adaaea1e-1b00-0000-9cac-8f212d0b0000 pid=2861 /usr/lib/apt/methods/gpgv delete-file write-file guuid=8fc18c05-1b00-0000-9cac-8f21f40a0000 pid=2804->guuid=adaaea1e-1b00-0000-9cac-8f212d0b0000 pid=2861 clone guuid=6e357b37-1b00-0000-9cac-8f21670b0000 pid=2919 /usr/lib/apt/methods/gpgv delete-file write-file guuid=8fc18c05-1b00-0000-9cac-8f21f40a0000 pid=2804->guuid=6e357b37-1b00-0000-9cac-8f21670b0000 pid=2919 clone guuid=45586a51-1b00-0000-9cac-8f21b90b0000 pid=3001 /usr/lib/apt/methods/gpgv delete-file write-file guuid=8fc18c05-1b00-0000-9cac-8f21f40a0000 pid=2804->guuid=45586a51-1b00-0000-9cac-8f21b90b0000 pid=3001 clone guuid=366c9b08-1b00-0000-9cac-8f21fd0a0000 pid=2813 /usr/bin/apt-key write-file guuid=05c8a306-1b00-0000-9cac-8f21f80a0000 pid=2808->guuid=366c9b08-1b00-0000-9cac-8f21fd0a0000 pid=2813 execve guuid=bb400009-1b00-0000-9cac-8f21fe0a0000 pid=2814 /usr/bin/dash guuid=366c9b08-1b00-0000-9cac-8f21fd0a0000 pid=2813->guuid=bb400009-1b00-0000-9cac-8f21fe0a0000 pid=2814 clone guuid=363b2809-1b00-0000-9cac-8f21ff0a0000 pid=2815 /usr/bin/apt-config guuid=366c9b08-1b00-0000-9cac-8f21fd0a0000 pid=2813->guuid=363b2809-1b00-0000-9cac-8f21ff0a0000 pid=2815 execve guuid=91eef60c-1b00-0000-9cac-8f21010b0000 pid=2817 /usr/bin/apt-config guuid=366c9b08-1b00-0000-9cac-8f21fd0a0000 pid=2813->guuid=91eef60c-1b00-0000-9cac-8f21010b0000 pid=2817 execve guuid=c371ce10-1b00-0000-9cac-8f21060b0000 pid=2822 /usr/bin/apt-config guuid=366c9b08-1b00-0000-9cac-8f21fd0a0000 pid=2813->guuid=c371ce10-1b00-0000-9cac-8f21060b0000 pid=2822 execve guuid=00cae812-1b00-0000-9cac-8f210c0b0000 pid=2828 /usr/bin/apt-config guuid=366c9b08-1b00-0000-9cac-8f21fd0a0000 pid=2813->guuid=00cae812-1b00-0000-9cac-8f210c0b0000 pid=2828 execve guuid=e1184e16-1b00-0000-9cac-8f210e0b0000 pid=2830 /usr/bin/dash guuid=366c9b08-1b00-0000-9cac-8f21fd0a0000 pid=2813->guuid=e1184e16-1b00-0000-9cac-8f210e0b0000 pid=2830 clone guuid=059da816-1b00-0000-9cac-8f210f0b0000 pid=2831 /usr/bin/apt-config guuid=366c9b08-1b00-0000-9cac-8f21fd0a0000 pid=2813->guuid=059da816-1b00-0000-9cac-8f210f0b0000 pid=2831 execve guuid=d8992818-1b00-0000-9cac-8f21120b0000 pid=2834 /usr/bin/mktemp guuid=366c9b08-1b00-0000-9cac-8f21fd0a0000 pid=2813->guuid=d8992818-1b00-0000-9cac-8f21120b0000 pid=2834 execve guuid=2ec65c18-1b00-0000-9cac-8f21140b0000 pid=2836 /usr/bin/chmod guuid=366c9b08-1b00-0000-9cac-8f21fd0a0000 pid=2813->guuid=2ec65c18-1b00-0000-9cac-8f21140b0000 pid=2836 execve guuid=d26c8a18-1b00-0000-9cac-8f21150b0000 pid=2837 /usr/bin/dash guuid=366c9b08-1b00-0000-9cac-8f21fd0a0000 pid=2813->guuid=d26c8a18-1b00-0000-9cac-8f21150b0000 pid=2837 clone guuid=1080a018-1b00-0000-9cac-8f21160b0000 pid=2838 /usr/bin/dash guuid=366c9b08-1b00-0000-9cac-8f21fd0a0000 pid=2813->guuid=1080a018-1b00-0000-9cac-8f21160b0000 pid=2838 clone guuid=10f30219-1b00-0000-9cac-8f211b0b0000 pid=2843 /usr/bin/dash guuid=366c9b08-1b00-0000-9cac-8f21fd0a0000 pid=2813->guuid=10f30219-1b00-0000-9cac-8f211b0b0000 pid=2843 clone guuid=17887619-1b00-0000-9cac-8f211f0b0000 pid=2847 /usr/bin/dash guuid=366c9b08-1b00-0000-9cac-8f21fd0a0000 pid=2813->guuid=17887619-1b00-0000-9cac-8f211f0b0000 pid=2847 clone guuid=08c59019-1b00-0000-9cac-8f21200b0000 pid=2848 /usr/bin/gpgv guuid=366c9b08-1b00-0000-9cac-8f21fd0a0000 pid=2813->guuid=08c59019-1b00-0000-9cac-8f21200b0000 pid=2848 execve guuid=814eda1b-1b00-0000-9cac-8f21240b0000 pid=2852 /usr/bin/rm delete-file guuid=366c9b08-1b00-0000-9cac-8f21fd0a0000 pid=2813->guuid=814eda1b-1b00-0000-9cac-8f21240b0000 pid=2852 execve guuid=cf85fc0b-1b00-0000-9cac-8f21000b0000 pid=2816 /usr/bin/dpkg guuid=363b2809-1b00-0000-9cac-8f21ff0a0000 pid=2815->guuid=cf85fc0b-1b00-0000-9cac-8f21000b0000 pid=2816 execve guuid=b6633b10-1b00-0000-9cac-8f21040b0000 pid=2820 /usr/bin/dpkg guuid=91eef60c-1b00-0000-9cac-8f21010b0000 pid=2817->guuid=b6633b10-1b00-0000-9cac-8f21040b0000 pid=2820 execve guuid=0b0f6d12-1b00-0000-9cac-8f210b0b0000 pid=2827 /usr/bin/dpkg guuid=c371ce10-1b00-0000-9cac-8f21060b0000 pid=2822->guuid=0b0f6d12-1b00-0000-9cac-8f210b0b0000 pid=2827 execve guuid=8e700815-1b00-0000-9cac-8f210d0b0000 pid=2829 /usr/bin/dpkg guuid=00cae812-1b00-0000-9cac-8f210c0b0000 pid=2828->guuid=8e700815-1b00-0000-9cac-8f210d0b0000 pid=2829 execve guuid=bfcdb517-1b00-0000-9cac-8f21110b0000 pid=2833 /usr/bin/dpkg guuid=059da816-1b00-0000-9cac-8f210f0b0000 pid=2831->guuid=bfcdb517-1b00-0000-9cac-8f21110b0000 pid=2833 execve guuid=8b7fa818-1b00-0000-9cac-8f21170b0000 pid=2839 /usr/bin/dash guuid=1080a018-1b00-0000-9cac-8f21160b0000 pid=2838->guuid=8b7fa818-1b00-0000-9cac-8f21170b0000 pid=2839 clone guuid=816ead18-1b00-0000-9cac-8f21190b0000 pid=2841 /usr/bin/sed guuid=1080a018-1b00-0000-9cac-8f21160b0000 pid=2838->guuid=816ead18-1b00-0000-9cac-8f21190b0000 pid=2841 execve guuid=6a581519-1b00-0000-9cac-8f211c0b0000 pid=2844 /usr/bin/dash guuid=10f30219-1b00-0000-9cac-8f211b0b0000 pid=2843->guuid=6a581519-1b00-0000-9cac-8f211c0b0000 pid=2844 clone guuid=f7651d19-1b00-0000-9cac-8f211d0b0000 pid=2845 /usr/bin/sed guuid=10f30219-1b00-0000-9cac-8f211b0b0000 pid=2843->guuid=f7651d19-1b00-0000-9cac-8f211d0b0000 pid=2845 execve guuid=db7b1820-1b00-0000-9cac-8f212f0b0000 pid=2863 /usr/bin/apt-key write-file guuid=adaaea1e-1b00-0000-9cac-8f212d0b0000 pid=2861->guuid=db7b1820-1b00-0000-9cac-8f212f0b0000 pid=2863 execve guuid=ec667d20-1b00-0000-9cac-8f21300b0000 pid=2864 /usr/bin/dash guuid=db7b1820-1b00-0000-9cac-8f212f0b0000 pid=2863->guuid=ec667d20-1b00-0000-9cac-8f21300b0000 pid=2864 clone guuid=d906b520-1b00-0000-9cac-8f21310b0000 pid=2865 /usr/bin/apt-config guuid=db7b1820-1b00-0000-9cac-8f212f0b0000 pid=2863->guuid=d906b520-1b00-0000-9cac-8f21310b0000 pid=2865 execve guuid=b2332025-1b00-0000-9cac-8f213a0b0000 pid=2874 /usr/bin/apt-config guuid=db7b1820-1b00-0000-9cac-8f212f0b0000 pid=2863->guuid=b2332025-1b00-0000-9cac-8f213a0b0000 pid=2874 execve guuid=908ee227-1b00-0000-9cac-8f213d0b0000 pid=2877 /usr/bin/apt-config guuid=db7b1820-1b00-0000-9cac-8f212f0b0000 pid=2863->guuid=908ee227-1b00-0000-9cac-8f213d0b0000 pid=2877 execve guuid=19dc9b2a-1b00-0000-9cac-8f21440b0000 pid=2884 /usr/bin/apt-config guuid=db7b1820-1b00-0000-9cac-8f212f0b0000 pid=2863->guuid=19dc9b2a-1b00-0000-9cac-8f21440b0000 pid=2884 execve guuid=0028982d-1b00-0000-9cac-8f21480b0000 pid=2888 /usr/bin/dash guuid=db7b1820-1b00-0000-9cac-8f212f0b0000 pid=2863->guuid=0028982d-1b00-0000-9cac-8f21480b0000 pid=2888 clone guuid=250fdb2d-1b00-0000-9cac-8f214a0b0000 pid=2890 /usr/bin/apt-config guuid=db7b1820-1b00-0000-9cac-8f212f0b0000 pid=2863->guuid=250fdb2d-1b00-0000-9cac-8f214a0b0000 pid=2890 execve guuid=3d54ed30-1b00-0000-9cac-8f21510b0000 pid=2897 /usr/bin/mktemp guuid=db7b1820-1b00-0000-9cac-8f212f0b0000 pid=2863->guuid=3d54ed30-1b00-0000-9cac-8f21510b0000 pid=2897 execve guuid=6b7c4f31-1b00-0000-9cac-8f21520b0000 pid=2898 /usr/bin/chmod guuid=db7b1820-1b00-0000-9cac-8f212f0b0000 pid=2863->guuid=6b7c4f31-1b00-0000-9cac-8f21520b0000 pid=2898 execve guuid=e46fb631-1b00-0000-9cac-8f21530b0000 pid=2899 /usr/bin/dash guuid=db7b1820-1b00-0000-9cac-8f212f0b0000 pid=2863->guuid=e46fb631-1b00-0000-9cac-8f21530b0000 pid=2899 clone guuid=bce5c831-1b00-0000-9cac-8f21540b0000 pid=2900 /usr/bin/dash guuid=db7b1820-1b00-0000-9cac-8f212f0b0000 pid=2863->guuid=bce5c831-1b00-0000-9cac-8f21540b0000 pid=2900 clone guuid=e7d44b32-1b00-0000-9cac-8f21580b0000 pid=2904 /usr/bin/dash guuid=db7b1820-1b00-0000-9cac-8f212f0b0000 pid=2863->guuid=e7d44b32-1b00-0000-9cac-8f21580b0000 pid=2904 clone guuid=2d03ca32-1b00-0000-9cac-8f215c0b0000 pid=2908 /usr/bin/dash guuid=db7b1820-1b00-0000-9cac-8f212f0b0000 pid=2863->guuid=2d03ca32-1b00-0000-9cac-8f215c0b0000 pid=2908 clone guuid=46b8d732-1b00-0000-9cac-8f215e0b0000 pid=2910 /usr/bin/gpgv guuid=db7b1820-1b00-0000-9cac-8f212f0b0000 pid=2863->guuid=46b8d732-1b00-0000-9cac-8f215e0b0000 pid=2910 execve guuid=a479ae34-1b00-0000-9cac-8f21620b0000 pid=2914 /usr/bin/rm delete-file guuid=db7b1820-1b00-0000-9cac-8f212f0b0000 pid=2863->guuid=a479ae34-1b00-0000-9cac-8f21620b0000 pid=2914 execve guuid=148e5224-1b00-0000-9cac-8f21380b0000 pid=2872 /usr/bin/dpkg guuid=d906b520-1b00-0000-9cac-8f21310b0000 pid=2865->guuid=148e5224-1b00-0000-9cac-8f21380b0000 pid=2872 execve guuid=e923b326-1b00-0000-9cac-8f213b0b0000 pid=2875 /usr/bin/dpkg guuid=b2332025-1b00-0000-9cac-8f213a0b0000 pid=2874->guuid=e923b326-1b00-0000-9cac-8f213b0b0000 pid=2875 execve guuid=ad50d329-1b00-0000-9cac-8f21410b0000 pid=2881 /usr/bin/dpkg guuid=908ee227-1b00-0000-9cac-8f213d0b0000 pid=2877->guuid=ad50d329-1b00-0000-9cac-8f21410b0000 pid=2881 execve guuid=4f2ca72c-1b00-0000-9cac-8f21460b0000 pid=2886 /usr/bin/dpkg guuid=19dc9b2a-1b00-0000-9cac-8f21440b0000 pid=2884->guuid=4f2ca72c-1b00-0000-9cac-8f21460b0000 pid=2886 execve guuid=b87d852f-1b00-0000-9cac-8f214e0b0000 pid=2894 /usr/bin/dpkg guuid=250fdb2d-1b00-0000-9cac-8f214a0b0000 pid=2890->guuid=b87d852f-1b00-0000-9cac-8f214e0b0000 pid=2894 execve guuid=3083d631-1b00-0000-9cac-8f21560b0000 pid=2902 /usr/bin/dash guuid=bce5c831-1b00-0000-9cac-8f21540b0000 pid=2900->guuid=3083d631-1b00-0000-9cac-8f21560b0000 pid=2902 clone guuid=e0f7dd31-1b00-0000-9cac-8f21570b0000 pid=2903 /usr/bin/sed guuid=bce5c831-1b00-0000-9cac-8f21540b0000 pid=2900->guuid=e0f7dd31-1b00-0000-9cac-8f21570b0000 pid=2903 execve guuid=beba5532-1b00-0000-9cac-8f21590b0000 pid=2905 /usr/bin/dash guuid=e7d44b32-1b00-0000-9cac-8f21580b0000 pid=2904->guuid=beba5532-1b00-0000-9cac-8f21590b0000 pid=2905 clone guuid=513b5b32-1b00-0000-9cac-8f215a0b0000 pid=2906 /usr/bin/sed guuid=e7d44b32-1b00-0000-9cac-8f21580b0000 pid=2904->guuid=513b5b32-1b00-0000-9cac-8f215a0b0000 pid=2906 execve guuid=2854a439-1b00-0000-9cac-8f216c0b0000 pid=2924 /usr/bin/apt-key write-file guuid=6e357b37-1b00-0000-9cac-8f21670b0000 pid=2919->guuid=2854a439-1b00-0000-9cac-8f216c0b0000 pid=2924 execve guuid=72b46c3a-1b00-0000-9cac-8f216e0b0000 pid=2926 /usr/bin/dash guuid=2854a439-1b00-0000-9cac-8f216c0b0000 pid=2924->guuid=72b46c3a-1b00-0000-9cac-8f216e0b0000 pid=2926 clone guuid=f9fd933a-1b00-0000-9cac-8f21700b0000 pid=2928 /usr/bin/apt-config guuid=2854a439-1b00-0000-9cac-8f216c0b0000 pid=2924->guuid=f9fd933a-1b00-0000-9cac-8f21700b0000 pid=2928 execve guuid=ddf33f45-1b00-0000-9cac-8f21850b0000 pid=2949 /usr/bin/apt-config guuid=2854a439-1b00-0000-9cac-8f216c0b0000 pid=2924->guuid=ddf33f45-1b00-0000-9cac-8f21850b0000 pid=2949 execve guuid=149a1a48-1b00-0000-9cac-8f218c0b0000 pid=2956 /usr/bin/apt-config guuid=2854a439-1b00-0000-9cac-8f216c0b0000 pid=2924->guuid=149a1a48-1b00-0000-9cac-8f218c0b0000 pid=2956 execve guuid=2428aa49-1b00-0000-9cac-8f21930b0000 pid=2963 /usr/bin/apt-config guuid=2854a439-1b00-0000-9cac-8f216c0b0000 pid=2924->guuid=2428aa49-1b00-0000-9cac-8f21930b0000 pid=2963 execve guuid=00dc9f4b-1b00-0000-9cac-8f219b0b0000 pid=2971 /usr/bin/dash guuid=2854a439-1b00-0000-9cac-8f216c0b0000 pid=2924->guuid=00dc9f4b-1b00-0000-9cac-8f219b0b0000 pid=2971 clone guuid=3c2ac94b-1b00-0000-9cac-8f219d0b0000 pid=2973 /usr/bin/apt-config guuid=2854a439-1b00-0000-9cac-8f216c0b0000 pid=2924->guuid=3c2ac94b-1b00-0000-9cac-8f219d0b0000 pid=2973 execve guuid=ab0c774d-1b00-0000-9cac-8f21a40b0000 pid=2980 /usr/bin/mktemp guuid=2854a439-1b00-0000-9cac-8f216c0b0000 pid=2924->guuid=ab0c774d-1b00-0000-9cac-8f21a40b0000 pid=2980 execve guuid=0d87c84d-1b00-0000-9cac-8f21a60b0000 pid=2982 /usr/bin/chmod guuid=2854a439-1b00-0000-9cac-8f216c0b0000 pid=2924->guuid=0d87c84d-1b00-0000-9cac-8f21a60b0000 pid=2982 execve guuid=f99df14d-1b00-0000-9cac-8f21a90b0000 pid=2985 /usr/bin/dash guuid=2854a439-1b00-0000-9cac-8f216c0b0000 pid=2924->guuid=f99df14d-1b00-0000-9cac-8f21a90b0000 pid=2985 clone guuid=b86f024e-1b00-0000-9cac-8f21aa0b0000 pid=2986 /usr/bin/dash guuid=2854a439-1b00-0000-9cac-8f216c0b0000 pid=2924->guuid=b86f024e-1b00-0000-9cac-8f21aa0b0000 pid=2986 clone guuid=b5a0834e-1b00-0000-9cac-8f21ad0b0000 pid=2989 /usr/bin/dash guuid=2854a439-1b00-0000-9cac-8f216c0b0000 pid=2924->guuid=b5a0834e-1b00-0000-9cac-8f21ad0b0000 pid=2989 clone guuid=f404f04e-1b00-0000-9cac-8f21b10b0000 pid=2993 /usr/bin/dash guuid=2854a439-1b00-0000-9cac-8f216c0b0000 pid=2924->guuid=f404f04e-1b00-0000-9cac-8f21b10b0000 pid=2993 clone guuid=5480fb4e-1b00-0000-9cac-8f21b20b0000 pid=2994 /usr/bin/gpgv guuid=2854a439-1b00-0000-9cac-8f216c0b0000 pid=2924->guuid=5480fb4e-1b00-0000-9cac-8f21b20b0000 pid=2994 execve guuid=ab806250-1b00-0000-9cac-8f21b60b0000 pid=2998 /usr/bin/rm delete-file guuid=2854a439-1b00-0000-9cac-8f216c0b0000 pid=2924->guuid=ab806250-1b00-0000-9cac-8f21b60b0000 pid=2998 execve guuid=b596bd3e-1b00-0000-9cac-8f21790b0000 pid=2937 /usr/bin/dpkg guuid=f9fd933a-1b00-0000-9cac-8f21700b0000 pid=2928->guuid=b596bd3e-1b00-0000-9cac-8f21790b0000 pid=2937 execve guuid=1351a546-1b00-0000-9cac-8f21890b0000 pid=2953 /usr/bin/dpkg guuid=ddf33f45-1b00-0000-9cac-8f21850b0000 pid=2949->guuid=1351a546-1b00-0000-9cac-8f21890b0000 pid=2953 execve guuid=4fbb2749-1b00-0000-9cac-8f21900b0000 pid=2960 /usr/bin/dpkg guuid=149a1a48-1b00-0000-9cac-8f218c0b0000 pid=2956->guuid=4fbb2749-1b00-0000-9cac-8f21900b0000 pid=2960 execve guuid=4e7cba4a-1b00-0000-9cac-8f21970b0000 pid=2967 /usr/bin/dpkg guuid=2428aa49-1b00-0000-9cac-8f21930b0000 pid=2963->guuid=4e7cba4a-1b00-0000-9cac-8f21970b0000 pid=2967 execve guuid=283ade4c-1b00-0000-9cac-8f21a20b0000 pid=2978 /usr/bin/dpkg guuid=3c2ac94b-1b00-0000-9cac-8f219d0b0000 pid=2973->guuid=283ade4c-1b00-0000-9cac-8f21a20b0000 pid=2978 execve guuid=4942084e-1b00-0000-9cac-8f21ab0b0000 pid=2987 /usr/bin/dash guuid=b86f024e-1b00-0000-9cac-8f21aa0b0000 pid=2986->guuid=4942084e-1b00-0000-9cac-8f21ab0b0000 pid=2987 clone guuid=6104104e-1b00-0000-9cac-8f21ac0b0000 pid=2988 /usr/bin/sed guuid=b86f024e-1b00-0000-9cac-8f21aa0b0000 pid=2986->guuid=6104104e-1b00-0000-9cac-8f21ac0b0000 pid=2988 execve guuid=41fd8f4e-1b00-0000-9cac-8f21ae0b0000 pid=2990 /usr/bin/dash guuid=b5a0834e-1b00-0000-9cac-8f21ad0b0000 pid=2989->guuid=41fd8f4e-1b00-0000-9cac-8f21ae0b0000 pid=2990 clone guuid=025f984e-1b00-0000-9cac-8f21af0b0000 pid=2991 /usr/bin/sed guuid=b5a0834e-1b00-0000-9cac-8f21ad0b0000 pid=2989->guuid=025f984e-1b00-0000-9cac-8f21af0b0000 pid=2991 execve guuid=bf5b4552-1b00-0000-9cac-8f21bb0b0000 pid=3003 /usr/bin/apt-key write-file guuid=45586a51-1b00-0000-9cac-8f21b90b0000 pid=3001->guuid=bf5b4552-1b00-0000-9cac-8f21bb0b0000 pid=3003 execve guuid=8e96a552-1b00-0000-9cac-8f21bc0b0000 pid=3004 /usr/bin/dash guuid=bf5b4552-1b00-0000-9cac-8f21bb0b0000 pid=3003->guuid=8e96a552-1b00-0000-9cac-8f21bc0b0000 pid=3004 clone guuid=2917eb52-1b00-0000-9cac-8f21bd0b0000 pid=3005 /usr/bin/apt-config guuid=bf5b4552-1b00-0000-9cac-8f21bb0b0000 pid=3003->guuid=2917eb52-1b00-0000-9cac-8f21bd0b0000 pid=3005 execve guuid=98026b57-1b00-0000-9cac-8f21c70b0000 pid=3015 /usr/bin/apt-config guuid=bf5b4552-1b00-0000-9cac-8f21bb0b0000 pid=3003->guuid=98026b57-1b00-0000-9cac-8f21c70b0000 pid=3015 execve guuid=49c4c65f-1b00-0000-9cac-8f21d40b0000 pid=3028 /usr/bin/apt-config guuid=bf5b4552-1b00-0000-9cac-8f21bb0b0000 pid=3003->guuid=49c4c65f-1b00-0000-9cac-8f21d40b0000 pid=3028 execve guuid=f443b262-1b00-0000-9cac-8f21d60b0000 pid=3030 /usr/bin/apt-config guuid=bf5b4552-1b00-0000-9cac-8f21bb0b0000 pid=3003->guuid=f443b262-1b00-0000-9cac-8f21d60b0000 pid=3030 execve guuid=1a6ffa64-1b00-0000-9cac-8f21d80b0000 pid=3032 /usr/bin/dash guuid=bf5b4552-1b00-0000-9cac-8f21bb0b0000 pid=3003->guuid=1a6ffa64-1b00-0000-9cac-8f21d80b0000 pid=3032 clone guuid=c9242765-1b00-0000-9cac-8f21d90b0000 pid=3033 /usr/bin/apt-config guuid=bf5b4552-1b00-0000-9cac-8f21bb0b0000 pid=3003->guuid=c9242765-1b00-0000-9cac-8f21d90b0000 pid=3033 execve guuid=df901f67-1b00-0000-9cac-8f21db0b0000 pid=3035 /usr/bin/mktemp guuid=bf5b4552-1b00-0000-9cac-8f21bb0b0000 pid=3003->guuid=df901f67-1b00-0000-9cac-8f21db0b0000 pid=3035 execve guuid=d1346567-1b00-0000-9cac-8f21dc0b0000 pid=3036 /usr/bin/chmod guuid=bf5b4552-1b00-0000-9cac-8f21bb0b0000 pid=3003->guuid=d1346567-1b00-0000-9cac-8f21dc0b0000 pid=3036 execve guuid=31f49767-1b00-0000-9cac-8f21dd0b0000 pid=3037 /usr/bin/dash guuid=bf5b4552-1b00-0000-9cac-8f21bb0b0000 pid=3003->guuid=31f49767-1b00-0000-9cac-8f21dd0b0000 pid=3037 clone guuid=69dea667-1b00-0000-9cac-8f21de0b0000 pid=3038 /usr/bin/dash guuid=bf5b4552-1b00-0000-9cac-8f21bb0b0000 pid=3003->guuid=69dea667-1b00-0000-9cac-8f21de0b0000 pid=3038 clone guuid=88492568-1b00-0000-9cac-8f21e10b0000 pid=3041 /usr/bin/dash guuid=bf5b4552-1b00-0000-9cac-8f21bb0b0000 pid=3003->guuid=88492568-1b00-0000-9cac-8f21e10b0000 pid=3041 clone guuid=70ea1f69-1b00-0000-9cac-8f21e40b0000 pid=3044 /usr/bin/dash guuid=bf5b4552-1b00-0000-9cac-8f21bb0b0000 pid=3003->guuid=70ea1f69-1b00-0000-9cac-8f21e40b0000 pid=3044 clone guuid=f9053c69-1b00-0000-9cac-8f21e50b0000 pid=3045 /usr/bin/gpgv guuid=bf5b4552-1b00-0000-9cac-8f21bb0b0000 pid=3003->guuid=f9053c69-1b00-0000-9cac-8f21e50b0000 pid=3045 execve guuid=1fa67f6b-1b00-0000-9cac-8f21e60b0000 pid=3046 /usr/bin/rm delete-file guuid=bf5b4552-1b00-0000-9cac-8f21bb0b0000 pid=3003->guuid=1fa67f6b-1b00-0000-9cac-8f21e60b0000 pid=3046 execve guuid=f6a42056-1b00-0000-9cac-8f21c40b0000 pid=3012 /usr/bin/dpkg guuid=2917eb52-1b00-0000-9cac-8f21bd0b0000 pid=3005->guuid=f6a42056-1b00-0000-9cac-8f21c40b0000 pid=3012 execve guuid=59753c59-1b00-0000-9cac-8f21cc0b0000 pid=3020 /usr/bin/dpkg guuid=98026b57-1b00-0000-9cac-8f21c70b0000 pid=3015->guuid=59753c59-1b00-0000-9cac-8f21cc0b0000 pid=3020 execve guuid=d3362661-1b00-0000-9cac-8f21d50b0000 pid=3029 /usr/bin/dpkg guuid=49c4c65f-1b00-0000-9cac-8f21d40b0000 pid=3028->guuid=d3362661-1b00-0000-9cac-8f21d50b0000 pid=3029 execve guuid=fad37f64-1b00-0000-9cac-8f21d70b0000 pid=3031 /usr/bin/dpkg guuid=f443b262-1b00-0000-9cac-8f21d60b0000 pid=3030->guuid=fad37f64-1b00-0000-9cac-8f21d70b0000 pid=3031 execve guuid=9eb66f66-1b00-0000-9cac-8f21da0b0000 pid=3034 /usr/bin/dpkg guuid=c9242765-1b00-0000-9cac-8f21d90b0000 pid=3033->guuid=9eb66f66-1b00-0000-9cac-8f21da0b0000 pid=3034 execve guuid=d670b067-1b00-0000-9cac-8f21df0b0000 pid=3039 /usr/bin/dash guuid=69dea667-1b00-0000-9cac-8f21de0b0000 pid=3038->guuid=d670b067-1b00-0000-9cac-8f21df0b0000 pid=3039 clone guuid=6b27b867-1b00-0000-9cac-8f21e00b0000 pid=3040 /usr/bin/sed guuid=69dea667-1b00-0000-9cac-8f21de0b0000 pid=3038->guuid=6b27b867-1b00-0000-9cac-8f21e00b0000 pid=3040 execve guuid=27bf3268-1b00-0000-9cac-8f21e20b0000 pid=3042 /usr/bin/dash guuid=88492568-1b00-0000-9cac-8f21e10b0000 pid=3041->guuid=27bf3268-1b00-0000-9cac-8f21e20b0000 pid=3042 clone guuid=b5fb3b68-1b00-0000-9cac-8f21e30b0000 pid=3043 /usr/bin/sed guuid=88492568-1b00-0000-9cac-8f21e10b0000 pid=3041->guuid=b5fb3b68-1b00-0000-9cac-8f21e30b0000 pid=3043 execve guuid=a1824c6e-2300-0000-9cac-8f2100150000 pid=5376 /usr/bin/dpkg guuid=b062336d-2300-0000-9cac-8f21fe140000 pid=5374->guuid=a1824c6e-2300-0000-9cac-8f2100150000 pid=5376 execve guuid=5bf22f6f-2300-0000-9cac-8f2102150000 pid=5378->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 164B 75aab096-419b-50ef-be46-7d76b6a90e4c github.com:443 guuid=5bf22f6f-2300-0000-9cac-8f2102150000 pid=5378->75aab096-419b-50ef-be46-7d76b6a90e4c send: 806B f8c5e44f-328d-5324-8bbd-da50752b9120 release-assets.githubusercontent.com:0 guuid=5bf22f6f-2300-0000-9cac-8f2102150000 pid=5378->f8c5e44f-328d-5324-8bbd-da50752b9120 con f0eebea5-e97d-507c-a771-59cac353877c release-assets.githubusercontent.com:443 guuid=5bf22f6f-2300-0000-9cac-8f2102150000 pid=5378->f0eebea5-e97d-507c-a771-59cac353877c send: 1658B guuid=0e20d06f-2300-0000-9cac-8f2104150000 pid=5380 /usr/bin/tar guuid=6cdd3a6f-2300-0000-9cac-8f2103150000 pid=5379->guuid=0e20d06f-2300-0000-9cac-8f2104150000 pid=5380 clone guuid=929eea6f-2300-0000-9cac-8f2105150000 pid=5381 /usr/bin/gzip guuid=0e20d06f-2300-0000-9cac-8f2104150000 pid=5380->guuid=929eea6f-2300-0000-9cac-8f2105150000 pid=5381 execve guuid=dc9ee08e-2300-0000-9cac-8f210c150000 pid=5388 /usr/bin/screen zombie guuid=7fd96a8e-2300-0000-9cac-8f210b150000 pid=5387->guuid=dc9ee08e-2300-0000-9cac-8f210c150000 pid=5388 clone guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5394 /dev/shm/.sys-config/java-build-agent mprotect-exec net send-data guuid=dc9ee08e-2300-0000-9cac-8f210c150000 pid=5388->guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5394 execve guuid=65f1fe8e-2300-0000-9cac-8f2110150000 pid=5392 /usr/bin/bash guuid=409cf38e-2300-0000-9cac-8f210e150000 pid=5390->guuid=65f1fe8e-2300-0000-9cac-8f2110150000 pid=5392 clone guuid=8109138f-2300-0000-9cac-8f2111150000 pid=5393 /usr/bin/grep guuid=409cf38e-2300-0000-9cac-8f210e150000 pid=5390->guuid=8109138f-2300-0000-9cac-8f2111150000 pid=5393 execve 13df41d7-8c91-59a8-813d-0f6c37691985 8.8.4.4:443 guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5394->13df41d7-8c91-59a8-813d-0f6c37691985 send: 1906B 03b6ccfa-529b-59ce-b0b0-bce778da7190 8.8.8.8:443 guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5394->03b6ccfa-529b-59ce-b0b0-bce778da7190 send: 1911B 0c1e2ea4-60e3-563a-9fc8-969794f997f9 198.251.90.217:443 guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5394->0c1e2ea4-60e3-563a-9fc8-969794f997f9 send: 1924B a9f4150a-602c-5d9e-9c5e-53ba9aefca52 185.84.98.5:443 guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5394->a9f4150a-602c-5d9e-9c5e-53ba9aefca52 send: 1914B guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5400 /dev/shm/.sys-config/java-build-agent write-file guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5394->guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5400 clone guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5401 /dev/shm/.sys-config/java-build-agent net send-data guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5394->guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5401 clone guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5402 /dev/shm/.sys-config/java-build-agent guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5394->guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5402 clone guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5403 /dev/shm/.sys-config/java-build-agent guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5394->guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5403 clone guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5404 /dev/shm/.sys-config/java-build-agent guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5394->guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5404 clone guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5416 /dev/shm/.sys-config/java-build-agent guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5394->guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5416 clone guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5417 /dev/shm/.sys-config/java-build-agent guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5394->guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5417 clone guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5418 /dev/shm/.sys-config/java-build-agent guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5394->guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5418 clone guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5419 /dev/shm/.sys-config/java-build-agent guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5394->guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5419 clone guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5420 /dev/shm/.sys-config/java-build-agent guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5394->guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5420 clone guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5421 /dev/shm/.sys-config/java-build-agent guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5394->guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5421 clone guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5422 /dev/shm/.sys-config/java-build-agent guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5394->guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5422 clone guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5423 /dev/shm/.sys-config/java-build-agent guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5394->guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5423 clone guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5424 /dev/shm/.sys-config/java-build-agent guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5394->guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5424 clone guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5425 /dev/shm/.sys-config/java-build-agent guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5394->guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5425 clone guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5426 /dev/shm/.sys-config/java-build-agent guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5394->guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5426 clone guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5427 /dev/shm/.sys-config/java-build-agent guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5394->guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5427 clone guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5428 /dev/shm/.sys-config/java-build-agent guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5394->guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5428 clone guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5429 /dev/shm/.sys-config/java-build-agent guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5394->guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5429 clone guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5430 /dev/shm/.sys-config/java-build-agent guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5394->guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5430 clone guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5431 /dev/shm/.sys-config/java-build-agent guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5394->guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5431 clone guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5432 /dev/shm/.sys-config/java-build-agent guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5394->guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5432 clone guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5433 /dev/shm/.sys-config/java-build-agent guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5394->guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5433 clone guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5434 /dev/shm/.sys-config/java-build-agent guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5394->guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5434 clone guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5435 /dev/shm/.sys-config/java-build-agent guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5394->guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5435 clone guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5436 /dev/shm/.sys-config/java-build-agent guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5394->guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5436 clone guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5437 /dev/shm/.sys-config/java-build-agent guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5394->guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5437 clone guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5438 /dev/shm/.sys-config/java-build-agent guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5394->guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5438 clone guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5439 /dev/shm/.sys-config/java-build-agent guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5394->guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5439 clone guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5440 /dev/shm/.sys-config/java-build-agent guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5394->guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5440 clone guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5441 /dev/shm/.sys-config/java-build-agent guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5394->guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5441 clone guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5442 /dev/shm/.sys-config/java-build-agent guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5394->guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5442 clone guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5443 /dev/shm/.sys-config/java-build-agent guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5394->guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5443 clone guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5444 /dev/shm/.sys-config/java-build-agent guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5394->guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5444 clone guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5445 /dev/shm/.sys-config/java-build-agent guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5394->guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5445 clone guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5446 /dev/shm/.sys-config/java-build-agent guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5394->guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5446 clone guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5447 /dev/shm/.sys-config/java-build-agent guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5394->guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5447 clone guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5448 /dev/shm/.sys-config/java-build-agent guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5394->guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5448 clone guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5449 /dev/shm/.sys-config/java-build-agent guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5394->guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5449 clone guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5450 /dev/shm/.sys-config/java-build-agent guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5394->guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5450 clone guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5451 /dev/shm/.sys-config/java-build-agent guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5394->guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5451 clone guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5452 /dev/shm/.sys-config/java-build-agent guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5394->guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5452 clone guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5453 /dev/shm/.sys-config/java-build-agent guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5394->guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5453 clone guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5454 /dev/shm/.sys-config/java-build-agent guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5394->guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5454 clone guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5455 /dev/shm/.sys-config/java-build-agent guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5394->guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5455 clone guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5456 /dev/shm/.sys-config/java-build-agent guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5394->guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5456 clone guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5457 /dev/shm/.sys-config/java-build-agent guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5394->guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5457 clone guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5458 /dev/shm/.sys-config/java-build-agent guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5394->guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5458 clone guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5459 /dev/shm/.sys-config/java-build-agent guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5394->guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5459 clone guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5460 /dev/shm/.sys-config/java-build-agent guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5394->guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5460 clone guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5461 /dev/shm/.sys-config/java-build-agent guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5394->guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5461 clone guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5462 /dev/shm/.sys-config/java-build-agent guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5394->guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5462 clone guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5463 /dev/shm/.sys-config/java-build-agent guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5394->guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5463 clone guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5401->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 56B 904d0937-69f5-5ec1-a333-bc567729fabb 2001:4860:4860::8888:65535 guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5401->904d0937-69f5-5ec1-a333-bc567729fabb con 374e8fc9-c9ee-5a04-9676-ebe2e26d03d0 2001:4860:4860::8844:65535 guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5401->374e8fc9-c9ee-5a04-9676-ebe2e26d03d0 con d8361160-8f0d-5f9d-a6d9-123a1d779ddf 8.8.4.4:65535 guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5401->d8361160-8f0d-5f9d-a6d9-123a1d779ddf con 33b06f6d-a9fa-51ce-9576-b32deef819e1 8.8.8.8:65535 guuid=afe15f8f-2300-0000-9cac-8f2112150000 pid=5401->33b06f6d-a9fa-51ce-9576-b32deef819e1 con
Result
Malware family:
Score:
  10/10
Tags:
family:xmrig antivm credential_access defense_evasion discovery execution linux miner persistence privilege_escalation
Behaviour
Software Deployment Tools
Enumerates kernel/hardware configuration
Reads runtime system information
System Network Configuration Discovery
Writes file to shm directory
Writes file to tmp directory
Deobfuscate/Decode Files or Information
Changes its process name
Checks CPU configuration
Reads CPU attributes
Checks hardware identifiers (DMI)
Creates/modifies Cron job
Deletes log files
Modifies init.d
Reads hardware information
Write file to user bin folder
Writes file to system bin folder
File and Directory Permissions Modification
Executes dropped EXE
Modifies PAM framework files
OS Credential Dumping
XMRig Miner payload
Xmrig family
xmrig
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:PUA_Crypto_Mining_CommandLine_Indicators_Oct21
Author:Florian Roth (Nextron Systems)
Description:Detects command line parameters often used by crypto mining software
Reference:https://www.poolwatch.io/coin/monero

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 6bfcf6860490b0952ee283f22b0f5cb536a48a6e3d8676b2596e68651929fed2

(this sample)

  
Delivery method
Distributed via web download

Comments