MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6cdc9ae50dac41db620137c6b9d33be81f0af07828b7f38c630419596f4c27f4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



CoinMiner


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 6cdc9ae50dac41db620137c6b9d33be81f0af07828b7f38c630419596f4c27f4
SHA3-384 hash: d7d8e33bfbd05e7e3e91628d6916a7e53ba15e82687ea90b8d1d1095970375e5c06134147d8b636c55db58ffa91975a1
SHA1 hash: 0542405f2ccdc55e9bc4b74af7d8edc144bdc0d8
MD5 hash: 17990220bb6e4d2ff5209ef5a22ce5d3
humanhash: white-comet-louisiana-sweet
File name:mon.sh
Download: download sample
Signature CoinMiner
File size:5'633 bytes
First seen:2025-08-30 14:33:04 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 96:l06z0citwocAUP7DTAiVjlhIAmx793jt0yjtgmu4Ip1qFQ2ZV7Raac27Sd6z0cd:l080cscDzDNj3Gd935XvIp1qFhH7RxcU
TLSH T172C1954AF690CAB0389D81A8A98F70863E06418B4E451D1DF86EF19C7F54758B1F87BF
Magika shell
Reporter abuse_ch
Tags:CoinMiner sh
URLMalware sample (SHA256 hash)SignatureTags
http://162.248.53.119:8000/mon.sh1e891ab1521b27923233e694f60fdbf0e1b840e657d8b1ffdefd8b5ef5e38964 CoinMinerCoinMiner
http://ip-api.com/json/n/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
33
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
fingerprint threat
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-08-30T11:40:00Z UTC
Last seen:
2025-08-30T11:40:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.bc
Status:
terminated
Behavior Graph:
%3 guuid=a4b34bd3-1600-0000-c4f0-0533690d0000 pid=3433 /usr/bin/sudo guuid=89fe14d5-1600-0000-c4f0-0533700d0000 pid=3440 /tmp/sample.bin guuid=a4b34bd3-1600-0000-c4f0-0533690d0000 pid=3433->guuid=89fe14d5-1600-0000-c4f0-0533700d0000 pid=3440 execve guuid=43266ed5-1600-0000-c4f0-0533720d0000 pid=3442 /usr/bin/whoami guuid=89fe14d5-1600-0000-c4f0-0533700d0000 pid=3440->guuid=43266ed5-1600-0000-c4f0-0533720d0000 pid=3442 execve guuid=340a01d6-1600-0000-c4f0-0533740d0000 pid=3444 /usr/bin/whoami guuid=89fe14d5-1600-0000-c4f0-0533700d0000 pid=3440->guuid=340a01d6-1600-0000-c4f0-0533740d0000 pid=3444 execve guuid=4ec26ad6-1600-0000-c4f0-0533770d0000 pid=3447 /usr/bin/whoami guuid=89fe14d5-1600-0000-c4f0-0533700d0000 pid=3440->guuid=4ec26ad6-1600-0000-c4f0-0533770d0000 pid=3447 execve guuid=62b10ad7-1600-0000-c4f0-05337a0d0000 pid=3450 /usr/bin/bash guuid=89fe14d5-1600-0000-c4f0-0533700d0000 pid=3440->guuid=62b10ad7-1600-0000-c4f0-05337a0d0000 pid=3450 clone guuid=384d47d7-1600-0000-c4f0-05337b0d0000 pid=3451 /usr/bin/id guuid=89fe14d5-1600-0000-c4f0-0533700d0000 pid=3440->guuid=384d47d7-1600-0000-c4f0-05337b0d0000 pid=3451 execve guuid=aae7edd7-1600-0000-c4f0-05337e0d0000 pid=3454 /usr/bin/systemctl guuid=89fe14d5-1600-0000-c4f0-0533700d0000 pid=3440->guuid=aae7edd7-1600-0000-c4f0-05337e0d0000 pid=3454 execve guuid=c3b5ecd9-1600-0000-c4f0-0533840d0000 pid=3460 /usr/bin/bash guuid=89fe14d5-1600-0000-c4f0-0533700d0000 pid=3440->guuid=c3b5ecd9-1600-0000-c4f0-0533840d0000 pid=3460 clone guuid=77bfc4da-1600-0000-c4f0-0533880d0000 pid=3464 /usr/bin/ps guuid=89fe14d5-1600-0000-c4f0-0533700d0000 pid=3440->guuid=77bfc4da-1600-0000-c4f0-0533880d0000 pid=3464 execve guuid=9d24ceda-1600-0000-c4f0-0533890d0000 pid=3465 /usr/bin/mawk guuid=89fe14d5-1600-0000-c4f0-0533700d0000 pid=3440->guuid=9d24ceda-1600-0000-c4f0-0533890d0000 pid=3465 execve guuid=1f70d5da-1600-0000-c4f0-05338a0d0000 pid=3466 /usr/bin/bash guuid=89fe14d5-1600-0000-c4f0-0533700d0000 pid=3440->guuid=1f70d5da-1600-0000-c4f0-05338a0d0000 pid=3466 clone guuid=8c1abbde-1600-0000-c4f0-0533960d0000 pid=3478 /usr/bin/bash guuid=89fe14d5-1600-0000-c4f0-0533700d0000 pid=3440->guuid=8c1abbde-1600-0000-c4f0-0533960d0000 pid=3478 clone guuid=675495e2-1600-0000-c4f0-0533a80d0000 pid=3496 /usr/bin/bash guuid=89fe14d5-1600-0000-c4f0-0533700d0000 pid=3440->guuid=675495e2-1600-0000-c4f0-0533a80d0000 pid=3496 clone guuid=ec79fae2-1600-0000-c4f0-0533ab0d0000 pid=3499 /usr/bin/curl net send-data guuid=89fe14d5-1600-0000-c4f0-0533700d0000 pid=3440->guuid=ec79fae2-1600-0000-c4f0-0533ab0d0000 pid=3499 execve guuid=f35400e3-1600-0000-c4f0-0533ac0d0000 pid=3500 /usr/bin/grep guuid=89fe14d5-1600-0000-c4f0-0533700d0000 pid=3440->guuid=f35400e3-1600-0000-c4f0-0533ac0d0000 pid=3500 execve guuid=852276f4-1600-0000-c4f0-0533c80d0000 pid=3528 /usr/bin/wget net send-data write-file guuid=89fe14d5-1600-0000-c4f0-0533700d0000 pid=3440->guuid=852276f4-1600-0000-c4f0-0533c80d0000 pid=3528 execve guuid=4d7f2205-1700-0000-c4f0-0533da0d0000 pid=3546 /usr/bin/chmod guuid=89fe14d5-1600-0000-c4f0-0533700d0000 pid=3440->guuid=4d7f2205-1700-0000-c4f0-0533da0d0000 pid=3546 execve guuid=12ba4106-1700-0000-c4f0-0533db0d0000 pid=3547 /usr/bin/bash guuid=89fe14d5-1600-0000-c4f0-0533700d0000 pid=3440->guuid=12ba4106-1700-0000-c4f0-0533db0d0000 pid=3547 execve guuid=a25b6e2b-1b00-0000-c4f0-053353150000 pid=5459 /usr/bin/rm delete-file guuid=89fe14d5-1600-0000-c4f0-0533700d0000 pid=3440->guuid=a25b6e2b-1b00-0000-c4f0-053353150000 pid=5459 execve guuid=6726cd2b-1b00-0000-c4f0-053354150000 pid=5460 /usr/bin/bash guuid=89fe14d5-1600-0000-c4f0-0533700d0000 pid=3440->guuid=6726cd2b-1b00-0000-c4f0-053354150000 pid=5460 clone guuid=9ff4d62b-1b00-0000-c4f0-053355150000 pid=5461 /usr/bin/grep guuid=89fe14d5-1600-0000-c4f0-0533700d0000 pid=3440->guuid=9ff4d62b-1b00-0000-c4f0-053355150000 pid=5461 execve guuid=c3ed592c-1b00-0000-c4f0-053356150000 pid=5462 /usr/bin/bash guuid=89fe14d5-1600-0000-c4f0-0533700d0000 pid=3440->guuid=c3ed592c-1b00-0000-c4f0-053356150000 pid=5462 clone guuid=8574632c-1b00-0000-c4f0-053357150000 pid=5463 /usr/bin/bash guuid=89fe14d5-1600-0000-c4f0-0533700d0000 pid=3440->guuid=8574632c-1b00-0000-c4f0-053357150000 pid=5463 clone guuid=5c8fab2c-1b00-0000-c4f0-053359150000 pid=5465 /usr/bin/whoami guuid=89fe14d5-1600-0000-c4f0-0533700d0000 pid=3440->guuid=5c8fab2c-1b00-0000-c4f0-053359150000 pid=5465 execve guuid=1492172d-1b00-0000-c4f0-05335a150000 pid=5466 /usr/bin/whoami guuid=89fe14d5-1600-0000-c4f0-0533700d0000 pid=3440->guuid=1492172d-1b00-0000-c4f0-05335a150000 pid=5466 execve guuid=ae807b2d-1b00-0000-c4f0-05335b150000 pid=5467 /usr/bin/whoami guuid=89fe14d5-1600-0000-c4f0-0533700d0000 pid=3440->guuid=ae807b2d-1b00-0000-c4f0-05335b150000 pid=5467 execve guuid=97d730da-1600-0000-c4f0-0533850d0000 pid=3461 /usr/bin/nproc guuid=c3b5ecd9-1600-0000-c4f0-0533840d0000 pid=3460->guuid=97d730da-1600-0000-c4f0-0533850d0000 pid=3461 execve guuid=1fd3c7de-1600-0000-c4f0-0533970d0000 pid=3479 /usr/bin/pgrep guuid=8c1abbde-1600-0000-c4f0-0533960d0000 pid=3478->guuid=1fd3c7de-1600-0000-c4f0-0533970d0000 pid=3479 execve guuid=44c2cede-1600-0000-c4f0-0533990d0000 pid=3481 /usr/bin/bash guuid=8c1abbde-1600-0000-c4f0-0533960d0000 pid=3478->guuid=44c2cede-1600-0000-c4f0-0533990d0000 pid=3481 clone guuid=65b2a2e2-1600-0000-c4f0-0533a90d0000 pid=3497 /usr/bin/grep guuid=675495e2-1600-0000-c4f0-0533a80d0000 pid=3496->guuid=65b2a2e2-1600-0000-c4f0-0533a90d0000 pid=3497 execve b60edd83-de97-543e-8c12-c815cb088ff2 ip-api.com:80 guuid=ec79fae2-1600-0000-c4f0-0533ab0d0000 pid=3499->b60edd83-de97-543e-8c12-c815cb088ff2 send: 79B guuid=ec79fae2-1600-0000-c4f0-0533ab0d0000 pid=3507 /usr/bin/curl dns net send-data guuid=ec79fae2-1600-0000-c4f0-0533ab0d0000 pid=3499->guuid=ec79fae2-1600-0000-c4f0-0533ab0d0000 pid=3507 clone 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=ec79fae2-1600-0000-c4f0-0533ab0d0000 pid=3507->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 28B 2f67bf0f-8453-5800-9e7b-37101ce5849f 162.248.53.119:8000 guuid=852276f4-1600-0000-c4f0-0533c80d0000 pid=3528->2f67bf0f-8453-5800-9e7b-37101ce5849f send: 140B guuid=824cbc06-1700-0000-c4f0-0533dc0d0000 pid=3548 /usr/bin/systemctl guuid=12ba4106-1700-0000-c4f0-0533db0d0000 pid=3547->guuid=824cbc06-1700-0000-c4f0-0533dc0d0000 pid=3548 execve guuid=1eb19709-1700-0000-c4f0-0533e00d0000 pid=3552 /usr/bin/bash guuid=12ba4106-1700-0000-c4f0-0533db0d0000 pid=3547->guuid=1eb19709-1700-0000-c4f0-0533e00d0000 pid=3552 clone guuid=b32a9410-1700-0000-c4f0-0533f20d0000 pid=3570 /usr/bin/bash guuid=12ba4106-1700-0000-c4f0-0533db0d0000 pid=3547->guuid=b32a9410-1700-0000-c4f0-0533f20d0000 pid=3570 clone guuid=838ed811-1700-0000-c4f0-0533f90d0000 pid=3577 /usr/bin/pgrep guuid=12ba4106-1700-0000-c4f0-0533db0d0000 pid=3547->guuid=838ed811-1700-0000-c4f0-0533f90d0000 pid=3577 execve guuid=5ebc9515-1700-0000-c4f0-0533060e0000 pid=3590 /usr/bin/pgrep guuid=12ba4106-1700-0000-c4f0-0533db0d0000 pid=3547->guuid=5ebc9515-1700-0000-c4f0-0533060e0000 pid=3590 execve guuid=f6853d19-1700-0000-c4f0-0533100e0000 pid=3600 /usr/bin/pgrep guuid=12ba4106-1700-0000-c4f0-0533db0d0000 pid=3547->guuid=f6853d19-1700-0000-c4f0-0533100e0000 pid=3600 execve guuid=12114819-1700-0000-c4f0-0533110e0000 pid=3601 /usr/bin/grep guuid=12ba4106-1700-0000-c4f0-0533db0d0000 pid=3547->guuid=12114819-1700-0000-c4f0-0533110e0000 pid=3601 execve guuid=f89a4f19-1700-0000-c4f0-0533120e0000 pid=3602 /usr/bin/xargs guuid=12ba4106-1700-0000-c4f0-0533db0d0000 pid=3547->guuid=f89a4f19-1700-0000-c4f0-0533120e0000 pid=3602 execve guuid=6b178c1d-1700-0000-c4f0-05331e0e0000 pid=3614 /usr/bin/id guuid=12ba4106-1700-0000-c4f0-0533db0d0000 pid=3547->guuid=6b178c1d-1700-0000-c4f0-05331e0e0000 pid=3614 execve guuid=85b2e21d-1700-0000-c4f0-0533210e0000 pid=3617 /usr/bin/apt-get delete-file write-file guuid=12ba4106-1700-0000-c4f0-0533db0d0000 pid=3547->guuid=85b2e21d-1700-0000-c4f0-0533210e0000 pid=3617 execve guuid=211afb87-1800-0000-c4f0-053314130000 pid=4884 /usr/bin/apt-get guuid=12ba4106-1700-0000-c4f0-0533db0d0000 pid=3547->guuid=211afb87-1800-0000-c4f0-053314130000 pid=4884 execve guuid=9bde8889-1800-0000-c4f0-05331d130000 pid=4893 /usr/bin/mkdir guuid=12ba4106-1700-0000-c4f0-0533db0d0000 pid=3547->guuid=9bde8889-1800-0000-c4f0-05331d130000 pid=4893 execve guuid=197fe489-1800-0000-c4f0-05331f130000 pid=4895 /usr/bin/wget dns net send-data write-file guuid=12ba4106-1700-0000-c4f0-0533db0d0000 pid=3547->guuid=197fe489-1800-0000-c4f0-05331f130000 pid=4895 execve guuid=93d1b1f2-1900-0000-c4f0-053308150000 pid=5384 /usr/bin/mv guuid=12ba4106-1700-0000-c4f0-0533db0d0000 pid=3547->guuid=93d1b1f2-1900-0000-c4f0-053308150000 pid=5384 execve guuid=237f14f3-1900-0000-c4f0-053309150000 pid=5385 /usr/bin/rm guuid=12ba4106-1700-0000-c4f0-0533db0d0000 pid=3547->guuid=237f14f3-1900-0000-c4f0-053309150000 pid=5385 execve guuid=ccf855f3-1900-0000-c4f0-05330a150000 pid=5386 /usr/bin/chmod guuid=12ba4106-1700-0000-c4f0-0533db0d0000 pid=3547->guuid=ccf855f3-1900-0000-c4f0-05330a150000 pid=5386 execve guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5387 /usr/lib/dev/systemdev/dns-filter mprotect-exec net send-data guuid=12ba4106-1700-0000-c4f0-0533db0d0000 pid=3547->guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5387 execve guuid=6c86a3f3-1900-0000-c4f0-05330c150000 pid=5388 /usr/bin/sleep guuid=12ba4106-1700-0000-c4f0-0533db0d0000 pid=3547->guuid=6c86a3f3-1900-0000-c4f0-05330c150000 pid=5388 execve guuid=611df411-1a00-0000-c4f0-053312150000 pid=5394 /usr/bin/ps guuid=12ba4106-1700-0000-c4f0-0533db0d0000 pid=3547->guuid=611df411-1a00-0000-c4f0-053312150000 pid=5394 execve guuid=ae208715-1a00-0000-c4f0-053313150000 pid=5395 /usr/bin/sleep guuid=12ba4106-1700-0000-c4f0-0533db0d0000 pid=3547->guuid=ae208715-1a00-0000-c4f0-053313150000 pid=5395 execve guuid=1da4c122-1b00-0000-c4f0-05334b150000 pid=5451 /usr/bin/ps guuid=12ba4106-1700-0000-c4f0-0533db0d0000 pid=3547->guuid=1da4c122-1b00-0000-c4f0-05334b150000 pid=5451 execve guuid=0ff1b129-1b00-0000-c4f0-05334c150000 pid=5452 /usr/bin/bash guuid=12ba4106-1700-0000-c4f0-0533db0d0000 pid=3547->guuid=0ff1b129-1b00-0000-c4f0-05334c150000 pid=5452 clone guuid=b5f7bc29-1b00-0000-c4f0-05334d150000 pid=5453 /usr/bin/grep guuid=12ba4106-1700-0000-c4f0-0533db0d0000 pid=3547->guuid=b5f7bc29-1b00-0000-c4f0-05334d150000 pid=5453 execve guuid=ce133e2a-1b00-0000-c4f0-05334e150000 pid=5454 /usr/bin/bash guuid=12ba4106-1700-0000-c4f0-0533db0d0000 pid=3547->guuid=ce133e2a-1b00-0000-c4f0-05334e150000 pid=5454 clone guuid=dbe1462a-1b00-0000-c4f0-05334f150000 pid=5455 /usr/bin/bash guuid=12ba4106-1700-0000-c4f0-0533db0d0000 pid=3547->guuid=dbe1462a-1b00-0000-c4f0-05334f150000 pid=5455 clone guuid=60bd7c2a-1b00-0000-c4f0-053351150000 pid=5457 /usr/bin/rm guuid=12ba4106-1700-0000-c4f0-0533db0d0000 pid=3547->guuid=60bd7c2a-1b00-0000-c4f0-053351150000 pid=5457 execve guuid=bd01062b-1b00-0000-c4f0-053352150000 pid=5458 /usr/bin/rm guuid=12ba4106-1700-0000-c4f0-0533db0d0000 pid=3547->guuid=bd01062b-1b00-0000-c4f0-053352150000 pid=5458 execve guuid=b896a809-1700-0000-c4f0-0533e10d0000 pid=3553 /usr/bin/wget dns net send-data guuid=1eb19709-1700-0000-c4f0-0533e00d0000 pid=3552->guuid=b896a809-1700-0000-c4f0-0533e10d0000 pid=3553 execve guuid=b896a809-1700-0000-c4f0-0533e10d0000 pid=3553->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 72B 0690ccd5-4816-5f11-94dc-7c585f38cdea ipv4.icanhazip.com:0 guuid=b896a809-1700-0000-c4f0-0533e10d0000 pid=3553->0690ccd5-4816-5f11-94dc-7c585f38cdea con d0ecfe49-aa79-583f-85c6-85ac97075256 ipv4.icanhazip.com:80 guuid=b896a809-1700-0000-c4f0-0533e10d0000 pid=3553->d0ecfe49-aa79-583f-85c6-85ac97075256 send: 133B guuid=95a9ab10-1700-0000-c4f0-0533f30d0000 pid=3571 /usr/bin/bash guuid=b32a9410-1700-0000-c4f0-0533f20d0000 pid=3570->guuid=95a9ab10-1700-0000-c4f0-0533f30d0000 pid=3571 clone guuid=9005ba10-1700-0000-c4f0-0533f50d0000 pid=3573 /usr/bin/sed guuid=b32a9410-1700-0000-c4f0-0533f20d0000 pid=3570->guuid=9005ba10-1700-0000-c4f0-0533f50d0000 pid=3573 execve guuid=1800c610-1700-0000-c4f0-0533f60d0000 pid=3574 /usr/bin/cut guuid=b32a9410-1700-0000-c4f0-0533f20d0000 pid=3570->guuid=1800c610-1700-0000-c4f0-0533f60d0000 pid=3574 execve guuid=9659141f-1700-0000-c4f0-0533260e0000 pid=3622 /usr/bin/dpkg guuid=85b2e21d-1700-0000-c4f0-0533210e0000 pid=3617->guuid=9659141f-1700-0000-c4f0-0533260e0000 pid=3622 execve guuid=67808d1f-1700-0000-c4f0-0533290e0000 pid=3625 /usr/lib/apt/methods/mirror guuid=85b2e21d-1700-0000-c4f0-0533210e0000 pid=3617->guuid=67808d1f-1700-0000-c4f0-0533290e0000 pid=3625 execve guuid=70fd4f20-1700-0000-c4f0-05332d0e0000 pid=3629 /usr/lib/apt/methods/mirror guuid=85b2e21d-1700-0000-c4f0-0533210e0000 pid=3617->guuid=70fd4f20-1700-0000-c4f0-05332d0e0000 pid=3629 execve guuid=087e1a21-1700-0000-c4f0-0533310e0000 pid=3633 /usr/lib/apt/methods/file guuid=85b2e21d-1700-0000-c4f0-0533210e0000 pid=3617->guuid=087e1a21-1700-0000-c4f0-0533310e0000 pid=3633 execve guuid=8b5dc721-1700-0000-c4f0-0533350e0000 pid=3637 /usr/lib/apt/methods/file delete-file guuid=85b2e21d-1700-0000-c4f0-0533210e0000 pid=3617->guuid=8b5dc721-1700-0000-c4f0-0533350e0000 pid=3637 execve guuid=fd8d9d22-1700-0000-c4f0-0533390e0000 pid=3641 /usr/lib/apt/methods/http guuid=85b2e21d-1700-0000-c4f0-0533210e0000 pid=3617->guuid=fd8d9d22-1700-0000-c4f0-0533390e0000 pid=3641 execve guuid=a5d0f323-1700-0000-c4f0-05333c0e0000 pid=3644 /usr/lib/apt/methods/http dns net send-data write-file guuid=85b2e21d-1700-0000-c4f0-0533210e0000 pid=3617->guuid=a5d0f323-1700-0000-c4f0-05333c0e0000 pid=3644 execve guuid=69df0a33-1700-0000-c4f0-0533770e0000 pid=3703 /usr/lib/apt/methods/gpgv guuid=85b2e21d-1700-0000-c4f0-0533210e0000 pid=3617->guuid=69df0a33-1700-0000-c4f0-0533770e0000 pid=3703 execve guuid=819ecc33-1700-0000-c4f0-05337b0e0000 pid=3707 /usr/lib/apt/methods/gpgv guuid=85b2e21d-1700-0000-c4f0-0533210e0000 pid=3617->guuid=819ecc33-1700-0000-c4f0-05337b0e0000 pid=3707 execve guuid=04e76d58-1700-0000-c4f0-0533480f0000 pid=3912 /usr/lib/apt/methods/store guuid=85b2e21d-1700-0000-c4f0-0533210e0000 pid=3617->guuid=04e76d58-1700-0000-c4f0-0533480f0000 pid=3912 execve guuid=fcec7559-1700-0000-c4f0-0533510f0000 pid=3921 /usr/lib/apt/methods/store write-file guuid=85b2e21d-1700-0000-c4f0-0533210e0000 pid=3617->guuid=fcec7559-1700-0000-c4f0-0533510f0000 pid=3921 execve guuid=e7fe6272-1700-0000-c4f0-0533cb0f0000 pid=4043 /usr/lib/apt/methods/rred guuid=85b2e21d-1700-0000-c4f0-0533210e0000 pid=3617->guuid=e7fe6272-1700-0000-c4f0-0533cb0f0000 pid=4043 execve guuid=cd3b7078-1700-0000-c4f0-0533eb0f0000 pid=4075 /usr/lib/apt/methods/rred write-file guuid=85b2e21d-1700-0000-c4f0-0533210e0000 pid=3617->guuid=cd3b7078-1700-0000-c4f0-0533eb0f0000 pid=4075 execve guuid=6e58fb9f-1700-0000-c4f0-053376100000 pid=4214 /usr/bin/dpkg guuid=85b2e21d-1700-0000-c4f0-0533210e0000 pid=3617->guuid=6e58fb9f-1700-0000-c4f0-053376100000 pid=4214 execve guuid=10cdd583-1800-0000-c4f0-053309130000 pid=4873 /usr/bin/dpkg guuid=85b2e21d-1700-0000-c4f0-0533210e0000 pid=3617->guuid=10cdd583-1800-0000-c4f0-053309130000 pid=4873 execve guuid=a5d0f323-1700-0000-c4f0-05333c0e0000 pid=3644->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 122B 869ebe88-8c1e-5fbb-adb0-cfe48d8d7faf debian.map.fastly.net:443 guuid=a5d0f323-1700-0000-c4f0-05333c0e0000 pid=3644->869ebe88-8c1e-5fbb-adb0-cfe48d8d7faf send: 5667B guuid=aa5b9434-1700-0000-c4f0-0533800e0000 pid=3712 /usr/lib/apt/methods/gpgv delete-file write-file guuid=819ecc33-1700-0000-c4f0-05337b0e0000 pid=3707->guuid=aa5b9434-1700-0000-c4f0-0533800e0000 pid=3712 clone guuid=91f40647-1700-0000-c4f0-0533d70e0000 pid=3799 /usr/lib/apt/methods/gpgv delete-file write-file guuid=819ecc33-1700-0000-c4f0-05337b0e0000 pid=3707->guuid=91f40647-1700-0000-c4f0-0533d70e0000 pid=3799 clone guuid=8b5e3954-1700-0000-c4f0-05332d0f0000 pid=3885 /usr/lib/apt/methods/gpgv delete-file write-file guuid=819ecc33-1700-0000-c4f0-05337b0e0000 pid=3707->guuid=8b5e3954-1700-0000-c4f0-05332d0f0000 pid=3885 clone guuid=1acc0d67-1700-0000-c4f0-0533900f0000 pid=3984 /usr/lib/apt/methods/gpgv delete-file write-file guuid=819ecc33-1700-0000-c4f0-05337b0e0000 pid=3707->guuid=1acc0d67-1700-0000-c4f0-0533900f0000 pid=3984 clone guuid=8e191636-1700-0000-c4f0-0533860e0000 pid=3718 /usr/bin/apt-key write-file guuid=aa5b9434-1700-0000-c4f0-0533800e0000 pid=3712->guuid=8e191636-1700-0000-c4f0-0533860e0000 pid=3718 execve guuid=4fef5136-1700-0000-c4f0-0533870e0000 pid=3719 /usr/bin/dash guuid=8e191636-1700-0000-c4f0-0533860e0000 pid=3718->guuid=4fef5136-1700-0000-c4f0-0533870e0000 pid=3719 clone guuid=ccd76436-1700-0000-c4f0-0533880e0000 pid=3720 /usr/bin/apt-config guuid=8e191636-1700-0000-c4f0-0533860e0000 pid=3718->guuid=ccd76436-1700-0000-c4f0-0533880e0000 pid=3720 execve guuid=75e34039-1700-0000-c4f0-05338a0e0000 pid=3722 /usr/bin/apt-config guuid=8e191636-1700-0000-c4f0-0533860e0000 pid=3718->guuid=75e34039-1700-0000-c4f0-05338a0e0000 pid=3722 execve guuid=5c72093b-1700-0000-c4f0-0533920e0000 pid=3730 /usr/bin/apt-config guuid=8e191636-1700-0000-c4f0-0533860e0000 pid=3718->guuid=5c72093b-1700-0000-c4f0-0533920e0000 pid=3730 execve guuid=7b7a793d-1700-0000-c4f0-05339b0e0000 pid=3739 /usr/bin/apt-config guuid=8e191636-1700-0000-c4f0-0533860e0000 pid=3718->guuid=7b7a793d-1700-0000-c4f0-05339b0e0000 pid=3739 execve guuid=08ac2e3f-1700-0000-c4f0-0533a10e0000 pid=3745 /usr/bin/dash guuid=8e191636-1700-0000-c4f0-0533860e0000 pid=3718->guuid=08ac2e3f-1700-0000-c4f0-0533a10e0000 pid=3745 clone guuid=d05a573f-1700-0000-c4f0-0533a20e0000 pid=3746 /usr/bin/apt-config guuid=8e191636-1700-0000-c4f0-0533860e0000 pid=3718->guuid=d05a573f-1700-0000-c4f0-0533a20e0000 pid=3746 execve guuid=a5a1be41-1700-0000-c4f0-0533ad0e0000 pid=3757 /usr/bin/mktemp guuid=8e191636-1700-0000-c4f0-0533860e0000 pid=3718->guuid=a5a1be41-1700-0000-c4f0-0533ad0e0000 pid=3757 execve guuid=0d83f041-1700-0000-c4f0-0533b00e0000 pid=3760 /usr/bin/chmod guuid=8e191636-1700-0000-c4f0-0533860e0000 pid=3718->guuid=0d83f041-1700-0000-c4f0-0533b00e0000 pid=3760 execve guuid=fe9c1f42-1700-0000-c4f0-0533b20e0000 pid=3762 /usr/bin/dash guuid=8e191636-1700-0000-c4f0-0533860e0000 pid=3718->guuid=fe9c1f42-1700-0000-c4f0-0533b20e0000 pid=3762 clone guuid=f2292f42-1700-0000-c4f0-0533b30e0000 pid=3763 /usr/bin/dash guuid=8e191636-1700-0000-c4f0-0533860e0000 pid=3718->guuid=f2292f42-1700-0000-c4f0-0533b30e0000 pid=3763 clone guuid=bdd48a42-1700-0000-c4f0-0533b90e0000 pid=3769 /usr/bin/dash guuid=8e191636-1700-0000-c4f0-0533860e0000 pid=3718->guuid=bdd48a42-1700-0000-c4f0-0533b90e0000 pid=3769 clone guuid=a14ddc42-1700-0000-c4f0-0533bc0e0000 pid=3772 /usr/bin/dash guuid=8e191636-1700-0000-c4f0-0533860e0000 pid=3718->guuid=a14ddc42-1700-0000-c4f0-0533bc0e0000 pid=3772 clone guuid=9609ea42-1700-0000-c4f0-0533bf0e0000 pid=3775 /usr/bin/gpgv guuid=8e191636-1700-0000-c4f0-0533860e0000 pid=3718->guuid=9609ea42-1700-0000-c4f0-0533bf0e0000 pid=3775 execve guuid=8bbaa344-1700-0000-c4f0-0533ca0e0000 pid=3786 /usr/bin/rm delete-file guuid=8e191636-1700-0000-c4f0-0533860e0000 pid=3718->guuid=8bbaa344-1700-0000-c4f0-0533ca0e0000 pid=3786 execve guuid=c3d35138-1700-0000-c4f0-0533890e0000 pid=3721 /usr/bin/dpkg guuid=ccd76436-1700-0000-c4f0-0533880e0000 pid=3720->guuid=c3d35138-1700-0000-c4f0-0533890e0000 pid=3721 execve guuid=f7e68f3a-1700-0000-c4f0-0533910e0000 pid=3729 /usr/bin/dpkg guuid=75e34039-1700-0000-c4f0-05338a0e0000 pid=3722->guuid=f7e68f3a-1700-0000-c4f0-0533910e0000 pid=3729 execve guuid=26ecea3c-1700-0000-c4f0-0533990e0000 pid=3737 /usr/bin/dpkg guuid=5c72093b-1700-0000-c4f0-0533920e0000 pid=3730->guuid=26ecea3c-1700-0000-c4f0-0533990e0000 pid=3737 execve guuid=2bafa83e-1700-0000-c4f0-05339e0e0000 pid=3742 /usr/bin/dpkg guuid=7b7a793d-1700-0000-c4f0-05339b0e0000 pid=3739->guuid=2bafa83e-1700-0000-c4f0-05339e0e0000 pid=3742 execve guuid=6c984c41-1700-0000-c4f0-0533aa0e0000 pid=3754 /usr/bin/dpkg guuid=d05a573f-1700-0000-c4f0-0533a20e0000 pid=3746->guuid=6c984c41-1700-0000-c4f0-0533aa0e0000 pid=3754 execve guuid=0f423a42-1700-0000-c4f0-0533b40e0000 pid=3764 /usr/bin/dash guuid=f2292f42-1700-0000-c4f0-0533b30e0000 pid=3763->guuid=0f423a42-1700-0000-c4f0-0533b40e0000 pid=3764 clone guuid=efdd3e42-1700-0000-c4f0-0533b50e0000 pid=3765 /usr/bin/sed guuid=f2292f42-1700-0000-c4f0-0533b30e0000 pid=3763->guuid=efdd3e42-1700-0000-c4f0-0533b50e0000 pid=3765 execve guuid=e2c89042-1700-0000-c4f0-0533ba0e0000 pid=3770 /usr/bin/dash guuid=bdd48a42-1700-0000-c4f0-0533b90e0000 pid=3769->guuid=e2c89042-1700-0000-c4f0-0533ba0e0000 pid=3770 clone guuid=f6e49542-1700-0000-c4f0-0533bb0e0000 pid=3771 /usr/bin/sed guuid=bdd48a42-1700-0000-c4f0-0533b90e0000 pid=3769->guuid=f6e49542-1700-0000-c4f0-0533bb0e0000 pid=3771 execve guuid=7bf8a647-1700-0000-c4f0-0533db0e0000 pid=3803 /usr/bin/apt-key write-file guuid=91f40647-1700-0000-c4f0-0533d70e0000 pid=3799->guuid=7bf8a647-1700-0000-c4f0-0533db0e0000 pid=3803 execve guuid=f9f0eb47-1700-0000-c4f0-0533dd0e0000 pid=3805 /usr/bin/dash guuid=7bf8a647-1700-0000-c4f0-0533db0e0000 pid=3803->guuid=f9f0eb47-1700-0000-c4f0-0533dd0e0000 pid=3805 clone guuid=66420148-1700-0000-c4f0-0533de0e0000 pid=3806 /usr/bin/apt-config guuid=7bf8a647-1700-0000-c4f0-0533db0e0000 pid=3803->guuid=66420148-1700-0000-c4f0-0533de0e0000 pid=3806 execve guuid=4684084a-1700-0000-c4f0-0533e90e0000 pid=3817 /usr/bin/apt-config guuid=7bf8a647-1700-0000-c4f0-0533db0e0000 pid=3803->guuid=4684084a-1700-0000-c4f0-0533e90e0000 pid=3817 execve guuid=c80cbb4b-1700-0000-c4f0-0533f10e0000 pid=3825 /usr/bin/apt-config guuid=7bf8a647-1700-0000-c4f0-0533db0e0000 pid=3803->guuid=c80cbb4b-1700-0000-c4f0-0533f10e0000 pid=3825 execve guuid=42fe444d-1700-0000-c4f0-0533f90e0000 pid=3833 /usr/bin/apt-config guuid=7bf8a647-1700-0000-c4f0-0533db0e0000 pid=3803->guuid=42fe444d-1700-0000-c4f0-0533f90e0000 pid=3833 execve guuid=56d6f44e-1700-0000-c4f0-0533020f0000 pid=3842 /usr/bin/dash guuid=7bf8a647-1700-0000-c4f0-0533db0e0000 pid=3803->guuid=56d6f44e-1700-0000-c4f0-0533020f0000 pid=3842 clone guuid=55d9224f-1700-0000-c4f0-0533040f0000 pid=3844 /usr/bin/apt-config guuid=7bf8a647-1700-0000-c4f0-0533db0e0000 pid=3803->guuid=55d9224f-1700-0000-c4f0-0533040f0000 pid=3844 execve guuid=dd22b350-1700-0000-c4f0-05330a0f0000 pid=3850 /usr/bin/mktemp guuid=7bf8a647-1700-0000-c4f0-0533db0e0000 pid=3803->guuid=dd22b350-1700-0000-c4f0-05330a0f0000 pid=3850 execve guuid=50d60251-1700-0000-c4f0-05330f0f0000 pid=3855 /usr/bin/chmod guuid=7bf8a647-1700-0000-c4f0-0533db0e0000 pid=3803->guuid=50d60251-1700-0000-c4f0-05330f0f0000 pid=3855 execve guuid=ef162e51-1700-0000-c4f0-0533110f0000 pid=3857 /usr/bin/dash guuid=7bf8a647-1700-0000-c4f0-0533db0e0000 pid=3803->guuid=ef162e51-1700-0000-c4f0-0533110f0000 pid=3857 clone guuid=83d53d51-1700-0000-c4f0-0533120f0000 pid=3858 /usr/bin/dash guuid=7bf8a647-1700-0000-c4f0-0533db0e0000 pid=3803->guuid=83d53d51-1700-0000-c4f0-0533120f0000 pid=3858 clone guuid=94bbaa51-1700-0000-c4f0-0533170f0000 pid=3863 /usr/bin/dash guuid=7bf8a647-1700-0000-c4f0-0533db0e0000 pid=3803->guuid=94bbaa51-1700-0000-c4f0-0533170f0000 pid=3863 clone guuid=506d1352-1700-0000-c4f0-05331c0f0000 pid=3868 /usr/bin/dash guuid=7bf8a647-1700-0000-c4f0-0533db0e0000 pid=3803->guuid=506d1352-1700-0000-c4f0-05331c0f0000 pid=3868 clone guuid=a6dd2252-1700-0000-c4f0-05331d0f0000 pid=3869 /usr/bin/gpgv guuid=7bf8a647-1700-0000-c4f0-0533db0e0000 pid=3803->guuid=a6dd2252-1700-0000-c4f0-05331d0f0000 pid=3869 execve guuid=d1808d53-1700-0000-c4f0-0533260f0000 pid=3878 /usr/bin/rm delete-file guuid=7bf8a647-1700-0000-c4f0-0533db0e0000 pid=3803->guuid=d1808d53-1700-0000-c4f0-0533260f0000 pid=3878 execve guuid=2ea88c49-1700-0000-c4f0-0533e60e0000 pid=3814 /usr/bin/dpkg guuid=66420148-1700-0000-c4f0-0533de0e0000 pid=3806->guuid=2ea88c49-1700-0000-c4f0-0533e60e0000 pid=3814 execve guuid=845d114b-1700-0000-c4f0-0533ee0e0000 pid=3822 /usr/bin/dpkg guuid=4684084a-1700-0000-c4f0-0533e90e0000 pid=3817->guuid=845d114b-1700-0000-c4f0-0533ee0e0000 pid=3822 execve guuid=e8fec44c-1700-0000-c4f0-0533f70e0000 pid=3831 /usr/bin/dpkg guuid=c80cbb4b-1700-0000-c4f0-0533f10e0000 pid=3825->guuid=e8fec44c-1700-0000-c4f0-0533f70e0000 pid=3831 execve guuid=5b5e5a4e-1700-0000-c4f0-0533ff0e0000 pid=3839 /usr/bin/dpkg guuid=42fe444d-1700-0000-c4f0-0533f90e0000 pid=3833->guuid=5b5e5a4e-1700-0000-c4f0-0533ff0e0000 pid=3839 execve guuid=8b293b50-1700-0000-c4f0-0533090f0000 pid=3849 /usr/bin/dpkg guuid=55d9224f-1700-0000-c4f0-0533040f0000 pid=3844->guuid=8b293b50-1700-0000-c4f0-0533090f0000 pid=3849 execve guuid=57734451-1700-0000-c4f0-0533130f0000 pid=3859 /usr/bin/dash guuid=83d53d51-1700-0000-c4f0-0533120f0000 pid=3858->guuid=57734451-1700-0000-c4f0-0533130f0000 pid=3859 clone guuid=6c3f4951-1700-0000-c4f0-0533140f0000 pid=3860 /usr/bin/sed guuid=83d53d51-1700-0000-c4f0-0533120f0000 pid=3858->guuid=6c3f4951-1700-0000-c4f0-0533140f0000 pid=3860 execve guuid=0b7fb351-1700-0000-c4f0-0533180f0000 pid=3864 /usr/bin/dash guuid=94bbaa51-1700-0000-c4f0-0533170f0000 pid=3863->guuid=0b7fb351-1700-0000-c4f0-0533180f0000 pid=3864 clone guuid=5841b951-1700-0000-c4f0-0533190f0000 pid=3865 /usr/bin/sed guuid=94bbaa51-1700-0000-c4f0-0533170f0000 pid=3863->guuid=5841b951-1700-0000-c4f0-0533190f0000 pid=3865 execve guuid=2cc6e954-1700-0000-c4f0-0533320f0000 pid=3890 /usr/bin/apt-key write-file guuid=8b5e3954-1700-0000-c4f0-05332d0f0000 pid=3885->guuid=2cc6e954-1700-0000-c4f0-0533320f0000 pid=3890 execve guuid=544c2155-1700-0000-c4f0-0533350f0000 pid=3893 /usr/bin/dash guuid=2cc6e954-1700-0000-c4f0-0533320f0000 pid=3890->guuid=544c2155-1700-0000-c4f0-0533350f0000 pid=3893 clone guuid=bdd03255-1700-0000-c4f0-0533360f0000 pid=3894 /usr/bin/apt-config guuid=2cc6e954-1700-0000-c4f0-0533320f0000 pid=3890->guuid=bdd03255-1700-0000-c4f0-0533360f0000 pid=3894 execve guuid=ff2d1e58-1700-0000-c4f0-0533470f0000 pid=3911 /usr/bin/apt-config guuid=2cc6e954-1700-0000-c4f0-0533320f0000 pid=3890->guuid=ff2d1e58-1700-0000-c4f0-0533470f0000 pid=3911 execve guuid=15df375e-1700-0000-c4f0-0533570f0000 pid=3927 /usr/bin/apt-config guuid=2cc6e954-1700-0000-c4f0-0533320f0000 pid=3890->guuid=15df375e-1700-0000-c4f0-0533570f0000 pid=3927 execve guuid=3a7e685f-1700-0000-c4f0-0533600f0000 pid=3936 /usr/bin/apt-config guuid=2cc6e954-1700-0000-c4f0-0533320f0000 pid=3890->guuid=3a7e685f-1700-0000-c4f0-0533600f0000 pid=3936 execve guuid=de8cb660-1700-0000-c4f0-0533640f0000 pid=3940 /usr/bin/dash guuid=2cc6e954-1700-0000-c4f0-0533320f0000 pid=3890->guuid=de8cb660-1700-0000-c4f0-0533640f0000 pid=3940 clone guuid=3ab6db60-1700-0000-c4f0-0533660f0000 pid=3942 /usr/bin/apt-config guuid=2cc6e954-1700-0000-c4f0-0533320f0000 pid=3890->guuid=3ab6db60-1700-0000-c4f0-0533660f0000 pid=3942 execve guuid=ab914e63-1700-0000-c4f0-0533740f0000 pid=3956 /usr/bin/mktemp guuid=2cc6e954-1700-0000-c4f0-0533320f0000 pid=3890->guuid=ab914e63-1700-0000-c4f0-0533740f0000 pid=3956 execve guuid=1bf87f63-1700-0000-c4f0-0533760f0000 pid=3958 /usr/bin/chmod guuid=2cc6e954-1700-0000-c4f0-0533320f0000 pid=3890->guuid=1bf87f63-1700-0000-c4f0-0533760f0000 pid=3958 execve guuid=ec28af63-1700-0000-c4f0-0533780f0000 pid=3960 /usr/bin/dash guuid=2cc6e954-1700-0000-c4f0-0533320f0000 pid=3890->guuid=ec28af63-1700-0000-c4f0-0533780f0000 pid=3960 clone guuid=e4d6bf63-1700-0000-c4f0-0533790f0000 pid=3961 /usr/bin/dash guuid=2cc6e954-1700-0000-c4f0-0533320f0000 pid=3890->guuid=e4d6bf63-1700-0000-c4f0-0533790f0000 pid=3961 clone guuid=d76b1964-1700-0000-c4f0-05337d0f0000 pid=3965 /usr/bin/dash guuid=2cc6e954-1700-0000-c4f0-0533320f0000 pid=3890->guuid=d76b1964-1700-0000-c4f0-05337d0f0000 pid=3965 clone guuid=8efa8364-1700-0000-c4f0-0533820f0000 pid=3970 /usr/bin/dash guuid=2cc6e954-1700-0000-c4f0-0533320f0000 pid=3890->guuid=8efa8364-1700-0000-c4f0-0533820f0000 pid=3970 clone guuid=14ff9464-1700-0000-c4f0-0533830f0000 pid=3971 /usr/bin/gpgv guuid=2cc6e954-1700-0000-c4f0-0533320f0000 pid=3890->guuid=14ff9464-1700-0000-c4f0-0533830f0000 pid=3971 execve guuid=2aec1c66-1700-0000-c4f0-05338d0f0000 pid=3981 /usr/bin/rm delete-file guuid=2cc6e954-1700-0000-c4f0-0533320f0000 pid=3890->guuid=2aec1c66-1700-0000-c4f0-05338d0f0000 pid=3981 execve guuid=9909b157-1700-0000-c4f0-0533450f0000 pid=3909 /usr/bin/dpkg guuid=bdd03255-1700-0000-c4f0-0533360f0000 pid=3894->guuid=9909b157-1700-0000-c4f0-0533450f0000 pid=3909 execve guuid=faeb6059-1700-0000-c4f0-05334f0f0000 pid=3919 /usr/bin/dpkg guuid=ff2d1e58-1700-0000-c4f0-0533470f0000 pid=3911->guuid=faeb6059-1700-0000-c4f0-05334f0f0000 pid=3919 execve guuid=9254135f-1700-0000-c4f0-05335c0f0000 pid=3932 /usr/bin/dpkg guuid=15df375e-1700-0000-c4f0-0533570f0000 pid=3927->guuid=9254135f-1700-0000-c4f0-05335c0f0000 pid=3932 execve guuid=47dc4860-1700-0000-c4f0-0533620f0000 pid=3938 /usr/bin/dpkg guuid=3a7e685f-1700-0000-c4f0-0533600f0000 pid=3936->guuid=47dc4860-1700-0000-c4f0-0533620f0000 pid=3938 execve guuid=0f0cd462-1700-0000-c4f0-0533710f0000 pid=3953 /usr/bin/dpkg guuid=3ab6db60-1700-0000-c4f0-0533660f0000 pid=3942->guuid=0f0cd462-1700-0000-c4f0-0533710f0000 pid=3953 execve guuid=95aec863-1700-0000-c4f0-05337a0f0000 pid=3962 /usr/bin/dash guuid=e4d6bf63-1700-0000-c4f0-0533790f0000 pid=3961->guuid=95aec863-1700-0000-c4f0-05337a0f0000 pid=3962 clone guuid=3b8dcd63-1700-0000-c4f0-05337b0f0000 pid=3963 /usr/bin/sed guuid=e4d6bf63-1700-0000-c4f0-0533790f0000 pid=3961->guuid=3b8dcd63-1700-0000-c4f0-05337b0f0000 pid=3963 execve guuid=ad8d2264-1700-0000-c4f0-05337e0f0000 pid=3966 /usr/bin/dash guuid=d76b1964-1700-0000-c4f0-05337d0f0000 pid=3965->guuid=ad8d2264-1700-0000-c4f0-05337e0f0000 pid=3966 clone guuid=e1992864-1700-0000-c4f0-0533800f0000 pid=3968 /usr/bin/sed guuid=d76b1964-1700-0000-c4f0-05337d0f0000 pid=3965->guuid=e1992864-1700-0000-c4f0-0533800f0000 pid=3968 execve guuid=d79da867-1700-0000-c4f0-0533940f0000 pid=3988 /usr/bin/apt-key write-file guuid=1acc0d67-1700-0000-c4f0-0533900f0000 pid=3984->guuid=d79da867-1700-0000-c4f0-0533940f0000 pid=3988 execve guuid=bfcced67-1700-0000-c4f0-0533950f0000 pid=3989 /usr/bin/dash guuid=d79da867-1700-0000-c4f0-0533940f0000 pid=3988->guuid=bfcced67-1700-0000-c4f0-0533950f0000 pid=3989 clone guuid=a8eafd67-1700-0000-c4f0-0533970f0000 pid=3991 /usr/bin/apt-config guuid=d79da867-1700-0000-c4f0-0533940f0000 pid=3988->guuid=a8eafd67-1700-0000-c4f0-0533970f0000 pid=3991 execve guuid=8bc07d6a-1700-0000-c4f0-0533a30f0000 pid=4003 /usr/bin/apt-config guuid=d79da867-1700-0000-c4f0-0533940f0000 pid=3988->guuid=8bc07d6a-1700-0000-c4f0-0533a30f0000 pid=4003 execve guuid=b09eca6b-1700-0000-c4f0-0533ab0f0000 pid=4011 /usr/bin/apt-config guuid=d79da867-1700-0000-c4f0-0533940f0000 pid=3988->guuid=b09eca6b-1700-0000-c4f0-0533ab0f0000 pid=4011 execve guuid=b367476d-1700-0000-c4f0-0533b30f0000 pid=4019 /usr/bin/apt-config guuid=d79da867-1700-0000-c4f0-0533940f0000 pid=3988->guuid=b367476d-1700-0000-c4f0-0533b30f0000 pid=4019 execve guuid=8e93b16f-1700-0000-c4f0-0533c00f0000 pid=4032 /usr/bin/dash guuid=d79da867-1700-0000-c4f0-0533940f0000 pid=3988->guuid=8e93b16f-1700-0000-c4f0-0533c00f0000 pid=4032 clone guuid=107ed76f-1700-0000-c4f0-0533c20f0000 pid=4034 /usr/bin/apt-config guuid=d79da867-1700-0000-c4f0-0533940f0000 pid=3988->guuid=107ed76f-1700-0000-c4f0-0533c20f0000 pid=4034 execve guuid=24942676-1700-0000-c4f0-0533d30f0000 pid=4051 /usr/bin/mktemp guuid=d79da867-1700-0000-c4f0-0533940f0000 pid=3988->guuid=24942676-1700-0000-c4f0-0533d30f0000 pid=4051 execve guuid=199d0077-1700-0000-c4f0-0533d60f0000 pid=4054 /usr/bin/chmod guuid=d79da867-1700-0000-c4f0-0533940f0000 pid=3988->guuid=199d0077-1700-0000-c4f0-0533d60f0000 pid=4054 execve guuid=7e09a677-1700-0000-c4f0-0533dd0f0000 pid=4061 /usr/bin/dash guuid=d79da867-1700-0000-c4f0-0533940f0000 pid=3988->guuid=7e09a677-1700-0000-c4f0-0533dd0f0000 pid=4061 clone guuid=6686b377-1700-0000-c4f0-0533de0f0000 pid=4062 /usr/bin/dash guuid=d79da867-1700-0000-c4f0-0533940f0000 pid=3988->guuid=6686b377-1700-0000-c4f0-0533de0f0000 pid=4062 clone guuid=bf1c1178-1700-0000-c4f0-0533e40f0000 pid=4068 /usr/bin/dash guuid=d79da867-1700-0000-c4f0-0533940f0000 pid=3988->guuid=bf1c1178-1700-0000-c4f0-0533e40f0000 pid=4068 clone guuid=af1d6a78-1700-0000-c4f0-0533ea0f0000 pid=4074 /usr/bin/dash guuid=d79da867-1700-0000-c4f0-0533940f0000 pid=3988->guuid=af1d6a78-1700-0000-c4f0-0533ea0f0000 pid=4074 clone guuid=961f7578-1700-0000-c4f0-0533ec0f0000 pid=4076 /usr/bin/gpgv guuid=d79da867-1700-0000-c4f0-0533940f0000 pid=3988->guuid=961f7578-1700-0000-c4f0-0533ec0f0000 pid=4076 execve guuid=0c50777a-1700-0000-c4f0-0533f70f0000 pid=4087 /usr/bin/rm delete-file guuid=d79da867-1700-0000-c4f0-0533940f0000 pid=3988->guuid=0c50777a-1700-0000-c4f0-0533f70f0000 pid=4087 execve guuid=b6c6f669-1700-0000-c4f0-0533a20f0000 pid=4002 /usr/bin/dpkg guuid=a8eafd67-1700-0000-c4f0-0533970f0000 pid=3991->guuid=b6c6f669-1700-0000-c4f0-0533a20f0000 pid=4002 execve guuid=ccca5d6b-1700-0000-c4f0-0533a90f0000 pid=4009 /usr/bin/dpkg guuid=8bc07d6a-1700-0000-c4f0-0533a30f0000 pid=4003->guuid=ccca5d6b-1700-0000-c4f0-0533a90f0000 pid=4009 execve guuid=5121dc6c-1700-0000-c4f0-0533b10f0000 pid=4017 /usr/bin/dpkg guuid=b09eca6b-1700-0000-c4f0-0533ab0f0000 pid=4011->guuid=5121dc6c-1700-0000-c4f0-0533b10f0000 pid=4017 execve guuid=52d5226f-1700-0000-c4f0-0533bc0f0000 pid=4028 /usr/bin/dpkg guuid=b367476d-1700-0000-c4f0-0533b30f0000 pid=4019->guuid=52d5226f-1700-0000-c4f0-0533bc0f0000 pid=4028 execve guuid=63422d71-1700-0000-c4f0-0533c80f0000 pid=4040 /usr/bin/dpkg guuid=107ed76f-1700-0000-c4f0-0533c20f0000 pid=4034->guuid=63422d71-1700-0000-c4f0-0533c80f0000 pid=4040 execve guuid=7ff1b877-1700-0000-c4f0-0533df0f0000 pid=4063 /usr/bin/dash guuid=6686b377-1700-0000-c4f0-0533de0f0000 pid=4062->guuid=7ff1b877-1700-0000-c4f0-0533df0f0000 pid=4063 clone guuid=4d5bbd77-1700-0000-c4f0-0533e00f0000 pid=4064 /usr/bin/sed guuid=6686b377-1700-0000-c4f0-0533de0f0000 pid=4062->guuid=4d5bbd77-1700-0000-c4f0-0533e00f0000 pid=4064 execve guuid=16361978-1700-0000-c4f0-0533e50f0000 pid=4069 /usr/bin/dash guuid=bf1c1178-1700-0000-c4f0-0533e40f0000 pid=4068->guuid=16361978-1700-0000-c4f0-0533e50f0000 pid=4069 clone guuid=38bc1c78-1700-0000-c4f0-0533e60f0000 pid=4070 /usr/bin/sed guuid=bf1c1178-1700-0000-c4f0-0533e40f0000 pid=4068->guuid=38bc1c78-1700-0000-c4f0-0533e60f0000 pid=4070 execve guuid=ab41fd88-1800-0000-c4f0-053319130000 pid=4889 /usr/bin/dpkg guuid=211afb87-1800-0000-c4f0-053314130000 pid=4884->guuid=ab41fd88-1800-0000-c4f0-053319130000 pid=4889 execve guuid=197fe489-1800-0000-c4f0-05331f130000 pid=4895->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 272B 75aab096-419b-50ef-be46-7d76b6a90e4c github.com:443 guuid=197fe489-1800-0000-c4f0-05331f130000 pid=4895->75aab096-419b-50ef-be46-7d76b6a90e4c send: 783B f8c5e44f-328d-5324-8bbd-da50752b9120 release-assets.githubusercontent.com:0 guuid=197fe489-1800-0000-c4f0-05331f130000 pid=4895->f8c5e44f-328d-5324-8bbd-da50752b9120 con f0eebea5-e97d-507c-a771-59cac353877c release-assets.githubusercontent.com:443 guuid=197fe489-1800-0000-c4f0-05331f130000 pid=4895->f0eebea5-e97d-507c-a771-59cac353877c send: 1608B 2f50a59f-2358-5b5c-aa0a-c8fc64202aee hosts-to-ignore.ignorelist.com:1443 guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5387->2f50a59f-2358-5b5c-aa0a-c8fc64202aee send: 859B guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5389 /usr/lib/dev/systemdev/dns-filter write-file guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5387->guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5389 clone guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5390 /usr/lib/dev/systemdev/dns-filter dns net send-data guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5387->guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5390 clone guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5391 /usr/lib/dev/systemdev/dns-filter guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5387->guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5391 clone guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5392 /usr/lib/dev/systemdev/dns-filter guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5387->guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5392 clone guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5393 /usr/lib/dev/systemdev/dns-filter guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5387->guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5393 clone guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5396 /usr/lib/dev/systemdev/dns-filter guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5387->guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5396 clone guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5397 /usr/lib/dev/systemdev/dns-filter guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5387->guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5397 clone guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5398 /usr/lib/dev/systemdev/dns-filter guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5387->guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5398 clone guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5399 /usr/lib/dev/systemdev/dns-filter guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5387->guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5399 clone guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5400 /usr/lib/dev/systemdev/dns-filter guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5387->guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5400 clone guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5401 /usr/lib/dev/systemdev/dns-filter guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5387->guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5401 clone guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5402 /usr/lib/dev/systemdev/dns-filter guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5387->guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5402 clone guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5403 /usr/lib/dev/systemdev/dns-filter guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5387->guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5403 clone guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5404 /usr/lib/dev/systemdev/dns-filter guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5387->guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5404 clone guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5405 /usr/lib/dev/systemdev/dns-filter guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5387->guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5405 clone guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5406 /usr/lib/dev/systemdev/dns-filter guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5387->guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5406 clone guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5407 /usr/lib/dev/systemdev/dns-filter guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5387->guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5407 clone guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5413 /usr/lib/dev/systemdev/dns-filter guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5387->guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5413 clone guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5414 /usr/lib/dev/systemdev/dns-filter guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5387->guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5414 clone guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5415 /usr/lib/dev/systemdev/dns-filter guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5387->guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5415 clone guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5416 /usr/lib/dev/systemdev/dns-filter guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5387->guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5416 clone guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5419 /usr/lib/dev/systemdev/dns-filter guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5387->guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5419 clone guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5420 /usr/lib/dev/systemdev/dns-filter guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5387->guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5420 clone guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5421 /usr/lib/dev/systemdev/dns-filter guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5387->guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5421 clone guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5422 /usr/lib/dev/systemdev/dns-filter guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5387->guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5422 clone guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5423 /usr/lib/dev/systemdev/dns-filter guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5387->guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5423 clone guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5424 /usr/lib/dev/systemdev/dns-filter guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5387->guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5424 clone guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5425 /usr/lib/dev/systemdev/dns-filter guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5387->guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5425 clone guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5426 /usr/lib/dev/systemdev/dns-filter guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5387->guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5426 clone guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5427 /usr/lib/dev/systemdev/dns-filter guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5387->guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5427 clone guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5428 /usr/lib/dev/systemdev/dns-filter guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5387->guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5428 clone guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5429 /usr/lib/dev/systemdev/dns-filter guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5387->guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5429 clone guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5430 /usr/lib/dev/systemdev/dns-filter guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5387->guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5430 clone guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5431 /usr/lib/dev/systemdev/dns-filter guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5387->guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5431 clone guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5432 /usr/lib/dev/systemdev/dns-filter guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5387->guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5432 clone guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5433 /usr/lib/dev/systemdev/dns-filter guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5387->guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5433 clone guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5434 /usr/lib/dev/systemdev/dns-filter guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5387->guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5434 clone guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5435 /usr/lib/dev/systemdev/dns-filter guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5387->guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5435 clone guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5436 /usr/lib/dev/systemdev/dns-filter guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5387->guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5436 clone guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5437 /usr/lib/dev/systemdev/dns-filter guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5387->guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5437 clone guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5438 /usr/lib/dev/systemdev/dns-filter guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5387->guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5438 clone guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5439 /usr/lib/dev/systemdev/dns-filter guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5387->guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5439 clone guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5440 /usr/lib/dev/systemdev/dns-filter guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5387->guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5440 clone guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5441 /usr/lib/dev/systemdev/dns-filter guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5387->guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5441 clone guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5442 /usr/lib/dev/systemdev/dns-filter guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5387->guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5442 clone guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5443 /usr/lib/dev/systemdev/dns-filter guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5387->guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5443 clone guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5444 /usr/lib/dev/systemdev/dns-filter guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5387->guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5444 clone guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5445 /usr/lib/dev/systemdev/dns-filter guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5387->guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5445 clone guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5446 /usr/lib/dev/systemdev/dns-filter guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5387->guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5446 clone guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5447 /usr/lib/dev/systemdev/dns-filter guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5387->guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5447 clone guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5448 /usr/lib/dev/systemdev/dns-filter guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5387->guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5448 clone guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5449 /usr/lib/dev/systemdev/dns-filter guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5387->guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5449 clone guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5450 /usr/lib/dev/systemdev/dns-filter guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5387->guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5450 clone guuid=379498f3-1900-0000-c4f0-05330b150000 pid=5390->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 96B guuid=700a4f2a-1b00-0000-c4f0-053350150000 pid=5456 /usr/bin/bash guuid=ce133e2a-1b00-0000-c4f0-05334e150000 pid=5454->guuid=700a4f2a-1b00-0000-c4f0-053350150000 pid=5456 clone guuid=d953842c-1b00-0000-c4f0-053358150000 pid=5464 /usr/bin/bash guuid=c3ed592c-1b00-0000-c4f0-053356150000 pid=5462->guuid=d953842c-1b00-0000-c4f0-053358150000 pid=5464 clone
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Script-PowerShell.Trojan.Heuristic
Status:
Malicious
First seen:
2025-08-30 14:33:37 UTC
File Type:
Text (Shell)
AV detection:
8 of 24 (33.33%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  6/10
Tags:
antivm discovery execution linux persistence privilege_escalation
Behaviour
Enumerates kernel/hardware configuration
Reads runtime system information
Checks CPU configuration
Reads CPU attributes
Creates/modifies Cron job
Enumerates running processes
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments