MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6d1fe6ab3cd04ca5d1ab790339ee2b6577553bc042af3b7587ece0c195267c9b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 6d1fe6ab3cd04ca5d1ab790339ee2b6577553bc042af3b7587ece0c195267c9b
SHA3-384 hash: d93b624f1b5b307579443c5b4eab68b45e6b820d73a9f60c70d298bb6ba143a0ff682aa449771d80ea6f11be96e5a882
SHA1 hash: 7860246ba168278df0530433cd7bd09677efc8d1
MD5 hash: 5b8626055f1a2432258f39bd6aa469c9
humanhash: edward-network-lion-california
File name:iLFwqeyH
Download: download sample
File size:4'745 bytes
First seen:2025-11-08 11:46:13 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 96:URYZxQOBpLyxIcymLKY8M991wuIaQPYPS:URJObLyxIIYMdwuwPYPS
TLSH T101A1E750112C1AB17246697AD26FFA52B90EC81B0A7B7B358473A63C74F9DA8E0396C1
TrID 50.0% (.SH) Linux/UNIX shell script (7000/1)
28.5% (.PL) Perl script (4000/1/1)
21.4% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter NDA0E
Tags:irc sh


Avatar
NDA0E
SFTP upload by 139.47.14.220

Intelligence


File Origin
# of uploads :
1
# of downloads :
30
Origin country :
US US
Vendor Threat Intelligence
Gathering data
Verdict:
Malicious
File Type:
unix shell
First seen:
2017-11-28T17:01:00Z UTC
Last seen:
2025-07-06T04:54:00Z UTC
Hits:
~100
Detections:
HEUR:Backdoor.Linux.Agent.bc
Status:
terminated
Behavior Graph:
%3 guuid=f2d89c6b-1a00-0000-d11c-11c28a0a0000 pid=2698 /usr/bin/sudo guuid=3480546d-1a00-0000-d11c-11c2900a0000 pid=2704 /tmp/sample.bin write-config write-file guuid=f2d89c6b-1a00-0000-d11c-11c28a0a0000 pid=2698->guuid=3480546d-1a00-0000-d11c-11c2900a0000 pid=2704 execve guuid=3be0b16d-1a00-0000-d11c-11c2920a0000 pid=2706 /usr/bin/realpath guuid=3480546d-1a00-0000-d11c-11c2900a0000 pid=2704->guuid=3be0b16d-1a00-0000-d11c-11c2920a0000 pid=2706 execve guuid=479b0b6e-1a00-0000-d11c-11c2940a0000 pid=2708 /usr/bin/mktemp guuid=3480546d-1a00-0000-d11c-11c2900a0000 pid=2704->guuid=479b0b6e-1a00-0000-d11c-11c2940a0000 pid=2708 execve guuid=4ebb796e-1a00-0000-d11c-11c2970a0000 pid=2711 /usr/bin/killall guuid=3480546d-1a00-0000-d11c-11c2900a0000 pid=2704->guuid=4ebb796e-1a00-0000-d11c-11c2970a0000 pid=2711 execve guuid=f202be6f-1a00-0000-d11c-11c29b0a0000 pid=2715 /usr/bin/killall guuid=3480546d-1a00-0000-d11c-11c2900a0000 pid=2704->guuid=f202be6f-1a00-0000-d11c-11c29b0a0000 pid=2715 execve guuid=6e947e70-1a00-0000-d11c-11c29e0a0000 pid=2718 /usr/bin/killall guuid=3480546d-1a00-0000-d11c-11c2900a0000 pid=2704->guuid=6e947e70-1a00-0000-d11c-11c29e0a0000 pid=2718 execve guuid=50515972-1a00-0000-d11c-11c2a60a0000 pid=2726 /usr/bin/killall guuid=3480546d-1a00-0000-d11c-11c2900a0000 pid=2704->guuid=50515972-1a00-0000-d11c-11c2a60a0000 pid=2726 execve guuid=b3e01273-1a00-0000-d11c-11c2a80a0000 pid=2728 /usr/bin/killall guuid=3480546d-1a00-0000-d11c-11c2900a0000 pid=2704->guuid=b3e01273-1a00-0000-d11c-11c2a80a0000 pid=2728 execve guuid=21cbcf73-1a00-0000-d11c-11c2ac0a0000 pid=2732 /usr/bin/killall guuid=3480546d-1a00-0000-d11c-11c2900a0000 pid=2704->guuid=21cbcf73-1a00-0000-d11c-11c2ac0a0000 pid=2732 execve guuid=fc4b9174-1a00-0000-d11c-11c2ae0a0000 pid=2734 /usr/bin/killall guuid=3480546d-1a00-0000-d11c-11c2900a0000 pid=2704->guuid=fc4b9174-1a00-0000-d11c-11c2ae0a0000 pid=2734 execve guuid=be834e75-1a00-0000-d11c-11c2b20a0000 pid=2738 /usr/bin/killall guuid=3480546d-1a00-0000-d11c-11c2900a0000 pid=2704->guuid=be834e75-1a00-0000-d11c-11c2b20a0000 pid=2738 execve guuid=90131076-1a00-0000-d11c-11c2b60a0000 pid=2742 /usr/bin/killall guuid=3480546d-1a00-0000-d11c-11c2900a0000 pid=2704->guuid=90131076-1a00-0000-d11c-11c2b60a0000 pid=2742 execve guuid=c028b976-1a00-0000-d11c-11c2ba0a0000 pid=2746 /usr/bin/killall guuid=3480546d-1a00-0000-d11c-11c2900a0000 pid=2704->guuid=c028b976-1a00-0000-d11c-11c2ba0a0000 pid=2746 execve guuid=e5747c77-1a00-0000-d11c-11c2bc0a0000 pid=2748 /usr/bin/killall guuid=3480546d-1a00-0000-d11c-11c2900a0000 pid=2704->guuid=e5747c77-1a00-0000-d11c-11c2bc0a0000 pid=2748 execve guuid=ad1d5478-1a00-0000-d11c-11c2bd0a0000 pid=2749 /usr/bin/killall guuid=3480546d-1a00-0000-d11c-11c2900a0000 pid=2704->guuid=ad1d5478-1a00-0000-d11c-11c2bd0a0000 pid=2749 execve guuid=a48d1e79-1a00-0000-d11c-11c2c00a0000 pid=2752 /usr/bin/killall guuid=3480546d-1a00-0000-d11c-11c2900a0000 pid=2704->guuid=a48d1e79-1a00-0000-d11c-11c2c00a0000 pid=2752 execve guuid=f352f179-1a00-0000-d11c-11c2c30a0000 pid=2755 /usr/bin/killall guuid=3480546d-1a00-0000-d11c-11c2900a0000 pid=2704->guuid=f352f179-1a00-0000-d11c-11c2c30a0000 pid=2755 execve guuid=6522b27a-1a00-0000-d11c-11c2c60a0000 pid=2758 /usr/bin/killall guuid=3480546d-1a00-0000-d11c-11c2900a0000 pid=2704->guuid=6522b27a-1a00-0000-d11c-11c2c60a0000 pid=2758 execve guuid=aa61087c-1a00-0000-d11c-11c2c80a0000 pid=2760 /usr/bin/killall guuid=3480546d-1a00-0000-d11c-11c2900a0000 pid=2704->guuid=aa61087c-1a00-0000-d11c-11c2c80a0000 pid=2760 execve guuid=6115207d-1a00-0000-d11c-11c2cb0a0000 pid=2763 /usr/bin/rm delete-file guuid=3480546d-1a00-0000-d11c-11c2900a0000 pid=2704->guuid=6115207d-1a00-0000-d11c-11c2cb0a0000 pid=2763 execve guuid=dc236f7d-1a00-0000-d11c-11c2cd0a0000 pid=2765 /usr/bin/rm guuid=3480546d-1a00-0000-d11c-11c2900a0000 pid=2704->guuid=dc236f7d-1a00-0000-d11c-11c2cd0a0000 pid=2765 execve guuid=d4d5bc7d-1a00-0000-d11c-11c2cf0a0000 pid=2767 /usr/sbin/usermod guuid=3480546d-1a00-0000-d11c-11c2900a0000 pid=2704->guuid=d4d5bc7d-1a00-0000-d11c-11c2cf0a0000 pid=2767 execve guuid=18ff7b7e-1a00-0000-d11c-11c2d30a0000 pid=2771 /usr/bin/mkdir guuid=3480546d-1a00-0000-d11c-11c2900a0000 pid=2704->guuid=18ff7b7e-1a00-0000-d11c-11c2d30a0000 pid=2771 execve guuid=7a0ede7e-1a00-0000-d11c-11c2d40a0000 pid=2772 /usr/bin/rm guuid=3480546d-1a00-0000-d11c-11c2900a0000 pid=2704->guuid=7a0ede7e-1a00-0000-d11c-11c2d40a0000 pid=2772 execve guuid=a584477f-1a00-0000-d11c-11c2d50a0000 pid=2773 /usr/bin/rm guuid=3480546d-1a00-0000-d11c-11c2900a0000 pid=2704->guuid=a584477f-1a00-0000-d11c-11c2d50a0000 pid=2773 execve guuid=d75ba27f-1a00-0000-d11c-11c2d70a0000 pid=2775 /usr/bin/rm guuid=3480546d-1a00-0000-d11c-11c2900a0000 pid=2704->guuid=d75ba27f-1a00-0000-d11c-11c2d70a0000 pid=2775 execve guuid=e24fe37f-1a00-0000-d11c-11c2d90a0000 pid=2777 /usr/bin/cat write-file guuid=3480546d-1a00-0000-d11c-11c2900a0000 pid=2704->guuid=e24fe37f-1a00-0000-d11c-11c2d90a0000 pid=2777 execve guuid=89993080-1a00-0000-d11c-11c2dc0a0000 pid=2780 /usr/bin/mktemp guuid=3480546d-1a00-0000-d11c-11c2900a0000 pid=2704->guuid=89993080-1a00-0000-d11c-11c2dc0a0000 pid=2780 execve guuid=53f29b80-1a00-0000-d11c-11c2de0a0000 pid=2782 /usr/bin/cat write-file guuid=3480546d-1a00-0000-d11c-11c2900a0000 pid=2704->guuid=53f29b80-1a00-0000-d11c-11c2de0a0000 pid=2782 execve guuid=64931581-1a00-0000-d11c-11c2e00a0000 pid=2784 /usr/bin/chmod guuid=3480546d-1a00-0000-d11c-11c2900a0000 pid=2704->guuid=64931581-1a00-0000-d11c-11c2e00a0000 pid=2784 execve guuid=a6a39181-1a00-0000-d11c-11c2e10a0000 pid=2785 /tmp/ykjiC7Xc dns net send-data write-file guuid=3480546d-1a00-0000-d11c-11c2900a0000 pid=2704->guuid=a6a39181-1a00-0000-d11c-11c2e10a0000 pid=2785 execve guuid=8d119c81-1a00-0000-d11c-11c2e20a0000 pid=2786 /usr/bin/rm guuid=3480546d-1a00-0000-d11c-11c2900a0000 pid=2704->guuid=8d119c81-1a00-0000-d11c-11c2e20a0000 pid=2786 execve guuid=8fb8ee81-1a00-0000-d11c-11c2e30a0000 pid=2787 /usr/bin/rm guuid=3480546d-1a00-0000-d11c-11c2900a0000 pid=2704->guuid=8fb8ee81-1a00-0000-d11c-11c2e30a0000 pid=2787 execve guuid=83aa3982-1a00-0000-d11c-11c2e40a0000 pid=2788 /usr/bin/sleep guuid=3480546d-1a00-0000-d11c-11c2900a0000 pid=2704->guuid=83aa3982-1a00-0000-d11c-11c2e40a0000 pid=2788 execve guuid=6f7a9335-1b00-0000-d11c-11c2450c0000 pid=3141 /usr/bin/rm delete-file guuid=3480546d-1a00-0000-d11c-11c2900a0000 pid=2704->guuid=6f7a9335-1b00-0000-d11c-11c2450c0000 pid=3141 execve guuid=48f3f135-1b00-0000-d11c-11c2460c0000 pid=3142 /usr/bin/mktemp guuid=3480546d-1a00-0000-d11c-11c2900a0000 pid=2704->guuid=48f3f135-1b00-0000-d11c-11c2460c0000 pid=3142 execve guuid=6ac25636-1b00-0000-d11c-11c2480c0000 pid=3144 /usr/bin/date write-file guuid=3480546d-1a00-0000-d11c-11c2900a0000 pid=2704->guuid=6ac25636-1b00-0000-d11c-11c2480c0000 pid=3144 execve guuid=8561bd36-1b00-0000-d11c-11c2490c0000 pid=3145 /usr/bin/apt-get delete-file write-file guuid=3480546d-1a00-0000-d11c-11c2900a0000 pid=2704->guuid=8561bd36-1b00-0000-d11c-11c2490c0000 pid=3145 execve guuid=b2cc9c07-1f00-0000-d11c-11c209150000 pid=5385 /usr/bin/apt-get guuid=3480546d-1a00-0000-d11c-11c2900a0000 pid=2704->guuid=b2cc9c07-1f00-0000-d11c-11c209150000 pid=5385 execve guuid=435c7609-1f00-0000-d11c-11c20b150000 pid=5387 /usr/bin/mktemp guuid=3480546d-1a00-0000-d11c-11c2900a0000 pid=2704->guuid=435c7609-1f00-0000-d11c-11c20b150000 pid=5387 execve guuid=670ac909-1f00-0000-d11c-11c20c150000 pid=5388 /usr/bin/bash guuid=3480546d-1a00-0000-d11c-11c2900a0000 pid=2704->guuid=670ac909-1f00-0000-d11c-11c20c150000 pid=5388 clone guuid=778ae409-1f00-0000-d11c-11c20d150000 pid=5389 /usr/bin/killall guuid=3480546d-1a00-0000-d11c-11c2900a0000 pid=2704->guuid=778ae409-1f00-0000-d11c-11c20d150000 pid=5389 execve guuid=c6d6aa0a-1f00-0000-d11c-11c20e150000 pid=5390 /usr/bin/cat guuid=3480546d-1a00-0000-d11c-11c2900a0000 pid=2704->guuid=c6d6aa0a-1f00-0000-d11c-11c20e150000 pid=5390 execve guuid=c6ca050b-1f00-0000-d11c-11c20f150000 pid=5391 /usr/bin/rm delete-file guuid=3480546d-1a00-0000-d11c-11c2900a0000 pid=2704->guuid=c6ca050b-1f00-0000-d11c-11c20f150000 pid=5391 execve guuid=0216560b-1f00-0000-d11c-11c210150000 pid=5392 /usr/bin/sleep guuid=3480546d-1a00-0000-d11c-11c2900a0000 pid=2704->guuid=0216560b-1f00-0000-d11c-11c210150000 pid=5392 execve guuid=5909bb5f-2100-0000-d11c-11c239150000 pid=5433 /usr/bin/mktemp guuid=3480546d-1a00-0000-d11c-11c2900a0000 pid=2704->guuid=5909bb5f-2100-0000-d11c-11c239150000 pid=5433 execve guuid=df875660-2100-0000-d11c-11c23a150000 pid=5434 /usr/bin/bash guuid=3480546d-1a00-0000-d11c-11c2900a0000 pid=2704->guuid=df875660-2100-0000-d11c-11c23a150000 pid=5434 clone guuid=22e37f60-2100-0000-d11c-11c23b150000 pid=5435 /usr/bin/killall guuid=3480546d-1a00-0000-d11c-11c2900a0000 pid=2704->guuid=22e37f60-2100-0000-d11c-11c23b150000 pid=5435 execve guuid=9118b261-2100-0000-d11c-11c23c150000 pid=5436 /usr/bin/cat guuid=3480546d-1a00-0000-d11c-11c2900a0000 pid=2704->guuid=9118b261-2100-0000-d11c-11c23c150000 pid=5436 execve guuid=fe370f62-2100-0000-d11c-11c23d150000 pid=5437 /usr/bin/rm delete-file guuid=3480546d-1a00-0000-d11c-11c2900a0000 pid=2704->guuid=fe370f62-2100-0000-d11c-11c23d150000 pid=5437 execve guuid=13886662-2100-0000-d11c-11c23e150000 pid=5438 /usr/bin/sleep guuid=3480546d-1a00-0000-d11c-11c2900a0000 pid=2704->guuid=13886662-2100-0000-d11c-11c23e150000 pid=5438 execve guuid=3eefddb6-2300-0000-d11c-11c240150000 pid=5440 /usr/bin/mktemp guuid=3480546d-1a00-0000-d11c-11c2900a0000 pid=2704->guuid=3eefddb6-2300-0000-d11c-11c240150000 pid=5440 execve guuid=356c94b7-2300-0000-d11c-11c241150000 pid=5441 /usr/bin/bash guuid=3480546d-1a00-0000-d11c-11c2900a0000 pid=2704->guuid=356c94b7-2300-0000-d11c-11c241150000 pid=5441 clone guuid=cae1cbb7-2300-0000-d11c-11c242150000 pid=5442 /usr/bin/killall guuid=3480546d-1a00-0000-d11c-11c2900a0000 pid=2704->guuid=cae1cbb7-2300-0000-d11c-11c242150000 pid=5442 execve guuid=237f2fb9-2300-0000-d11c-11c243150000 pid=5443 /usr/bin/cat guuid=3480546d-1a00-0000-d11c-11c2900a0000 pid=2704->guuid=237f2fb9-2300-0000-d11c-11c243150000 pid=5443 execve guuid=923ccab9-2300-0000-d11c-11c244150000 pid=5444 /usr/bin/rm delete-file guuid=3480546d-1a00-0000-d11c-11c2900a0000 pid=2704->guuid=923ccab9-2300-0000-d11c-11c244150000 pid=5444 execve guuid=947f4fba-2300-0000-d11c-11c245150000 pid=5445 /usr/bin/sleep guuid=3480546d-1a00-0000-d11c-11c2900a0000 pid=2704->guuid=947f4fba-2300-0000-d11c-11c245150000 pid=5445 execve guuid=c803eb0e-2600-0000-d11c-11c247150000 pid=5447 /usr/bin/mktemp guuid=3480546d-1a00-0000-d11c-11c2900a0000 pid=2704->guuid=c803eb0e-2600-0000-d11c-11c247150000 pid=5447 execve guuid=98908a0f-2600-0000-d11c-11c248150000 pid=5448 /usr/bin/bash guuid=3480546d-1a00-0000-d11c-11c2900a0000 pid=2704->guuid=98908a0f-2600-0000-d11c-11c248150000 pid=5448 clone guuid=5a22ba0f-2600-0000-d11c-11c249150000 pid=5449 /usr/bin/killall guuid=3480546d-1a00-0000-d11c-11c2900a0000 pid=2704->guuid=5a22ba0f-2600-0000-d11c-11c249150000 pid=5449 execve guuid=666bf110-2600-0000-d11c-11c24a150000 pid=5450 /usr/bin/cat guuid=3480546d-1a00-0000-d11c-11c2900a0000 pid=2704->guuid=666bf110-2600-0000-d11c-11c24a150000 pid=5450 execve guuid=17a04c11-2600-0000-d11c-11c24b150000 pid=5451 /usr/bin/rm delete-file guuid=3480546d-1a00-0000-d11c-11c2900a0000 pid=2704->guuid=17a04c11-2600-0000-d11c-11c24b150000 pid=5451 execve guuid=e775d511-2600-0000-d11c-11c24c150000 pid=5452 /usr/bin/sleep guuid=3480546d-1a00-0000-d11c-11c2900a0000 pid=2704->guuid=e775d511-2600-0000-d11c-11c24c150000 pid=5452 execve guuid=7c167066-2800-0000-d11c-11c250150000 pid=5456 /usr/bin/mktemp guuid=3480546d-1a00-0000-d11c-11c2900a0000 pid=2704->guuid=7c167066-2800-0000-d11c-11c250150000 pid=5456 execve guuid=0f91f966-2800-0000-d11c-11c251150000 pid=5457 /usr/bin/bash guuid=3480546d-1a00-0000-d11c-11c2900a0000 pid=2704->guuid=0f91f966-2800-0000-d11c-11c251150000 pid=5457 clone guuid=d06a2267-2800-0000-d11c-11c252150000 pid=5458 /usr/bin/killall guuid=3480546d-1a00-0000-d11c-11c2900a0000 pid=2704->guuid=d06a2267-2800-0000-d11c-11c252150000 pid=5458 execve guuid=cee41868-2800-0000-d11c-11c256150000 pid=5462 /usr/bin/cat guuid=3480546d-1a00-0000-d11c-11c2900a0000 pid=2704->guuid=cee41868-2800-0000-d11c-11c256150000 pid=5462 execve guuid=ac1e7f68-2800-0000-d11c-11c258150000 pid=5464 /usr/bin/rm delete-file guuid=3480546d-1a00-0000-d11c-11c2900a0000 pid=2704->guuid=ac1e7f68-2800-0000-d11c-11c258150000 pid=5464 execve guuid=a20dc868-2800-0000-d11c-11c25a150000 pid=5466 /usr/bin/sleep guuid=3480546d-1a00-0000-d11c-11c2900a0000 pid=2704->guuid=a20dc868-2800-0000-d11c-11c25a150000 pid=5466 execve 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=a6a39181-1a00-0000-d11c-11c2e10a0000 pid=2785->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 520B be5b581b-372d-5cf4-bfdc-91f4c90faae2 Chicago.IL.US.Undernet.org:6667 guuid=a6a39181-1a00-0000-d11c-11c2e10a0000 pid=2785->be5b581b-372d-5cf4-bfdc-91f4c90faae2 send: 71B 7f90669c-4145-56ff-a8f4-4006b99fdd3c ix2.undernet.org:6667 guuid=a6a39181-1a00-0000-d11c-11c2e10a0000 pid=2785->7f90669c-4145-56ff-a8f4-4006b99fdd3c send: 213B 5d2dbbe1-c343-581d-952d-c13d641c4cef ix1.undernet.org:6667 guuid=a6a39181-1a00-0000-d11c-11c2e10a0000 pid=2785->5d2dbbe1-c343-581d-952d-c13d641c4cef send: 142B ceded979-c90b-5528-b14a-7148e5f99d7f EU.Undernet.Org:6667 guuid=a6a39181-1a00-0000-d11c-11c2e10a0000 pid=2785->ceded979-c90b-5528-b14a-7148e5f99d7f send: 71B guuid=03e7ec82-1a00-0000-d11c-11c2e50a0000 pid=2789 /usr/bin/bash guuid=a6a39181-1a00-0000-d11c-11c2e10a0000 pid=2785->guuid=03e7ec82-1a00-0000-d11c-11c2e50a0000 pid=2789 clone guuid=cae9c494-1a00-0000-d11c-11c2060b0000 pid=2822 /usr/bin/sleep guuid=a6a39181-1a00-0000-d11c-11c2e10a0000 pid=2785->guuid=cae9c494-1a00-0000-d11c-11c2060b0000 pid=2822 execve guuid=5c1ac9ae-1c00-0000-d11c-11c2410e0000 pid=3649 /usr/bin/sleep guuid=a6a39181-1a00-0000-d11c-11c2e10a0000 pid=2785->guuid=5c1ac9ae-1c00-0000-d11c-11c2410e0000 pid=3649 execve guuid=e05d38b0-1e00-0000-d11c-11c22c140000 pid=5164 /usr/bin/sleep guuid=a6a39181-1a00-0000-d11c-11c2e10a0000 pid=2785->guuid=e05d38b0-1e00-0000-d11c-11c22c140000 pid=5164 execve guuid=6ff0dfc9-2000-0000-d11c-11c218150000 pid=5400 /usr/bin/sleep guuid=a6a39181-1a00-0000-d11c-11c2e10a0000 pid=2785->guuid=6ff0dfc9-2000-0000-d11c-11c218150000 pid=5400 execve guuid=586f05e4-2200-0000-d11c-11c23f150000 pid=5439 /usr/bin/sleep guuid=a6a39181-1a00-0000-d11c-11c2e10a0000 pid=2785->guuid=586f05e4-2200-0000-d11c-11c23f150000 pid=5439 execve guuid=62fb5cfd-2400-0000-d11c-11c246150000 pid=5446 /usr/bin/sleep guuid=a6a39181-1a00-0000-d11c-11c2e10a0000 pid=2785->guuid=62fb5cfd-2400-0000-d11c-11c246150000 pid=5446 execve guuid=7db76f14-2700-0000-d11c-11c24d150000 pid=5453 /usr/bin/sleep guuid=a6a39181-1a00-0000-d11c-11c2e10a0000 pid=2785->guuid=7db76f14-2700-0000-d11c-11c24d150000 pid=5453 execve guuid=2783fe82-1a00-0000-d11c-11c2e60a0000 pid=2790 /usr/bin/uname guuid=03e7ec82-1a00-0000-d11c-11c2e50a0000 pid=2789->guuid=2783fe82-1a00-0000-d11c-11c2e60a0000 pid=2790 execve guuid=7c240883-1a00-0000-d11c-11c2e70a0000 pid=2791 /usr/bin/md5sum guuid=03e7ec82-1a00-0000-d11c-11c2e50a0000 pid=2789->guuid=7c240883-1a00-0000-d11c-11c2e70a0000 pid=2791 execve guuid=1cf80e83-1a00-0000-d11c-11c2e80a0000 pid=2792 /usr/bin/mawk guuid=03e7ec82-1a00-0000-d11c-11c2e50a0000 pid=2789->guuid=1cf80e83-1a00-0000-d11c-11c2e80a0000 pid=2792 execve guuid=0ed94938-1b00-0000-d11c-11c24e0c0000 pid=3150 /usr/bin/dpkg guuid=8561bd36-1b00-0000-d11c-11c2490c0000 pid=3145->guuid=0ed94938-1b00-0000-d11c-11c24e0c0000 pid=3150 execve guuid=e276f738-1b00-0000-d11c-11c2510c0000 pid=3153 /usr/lib/apt/methods/mirror guuid=8561bd36-1b00-0000-d11c-11c2490c0000 pid=3145->guuid=e276f738-1b00-0000-d11c-11c2510c0000 pid=3153 execve guuid=7f54f939-1b00-0000-d11c-11c2550c0000 pid=3157 /usr/lib/apt/methods/mirror guuid=8561bd36-1b00-0000-d11c-11c2490c0000 pid=3145->guuid=7f54f939-1b00-0000-d11c-11c2550c0000 pid=3157 execve guuid=b16cc13b-1b00-0000-d11c-11c25b0c0000 pid=3163 /usr/lib/apt/methods/file guuid=8561bd36-1b00-0000-d11c-11c2490c0000 pid=3145->guuid=b16cc13b-1b00-0000-d11c-11c25b0c0000 pid=3163 execve guuid=9ff0643d-1b00-0000-d11c-11c2620c0000 pid=3170 /usr/lib/apt/methods/file delete-file guuid=8561bd36-1b00-0000-d11c-11c2490c0000 pid=3145->guuid=9ff0643d-1b00-0000-d11c-11c2620c0000 pid=3170 execve guuid=ab32a83e-1b00-0000-d11c-11c2660c0000 pid=3174 /usr/lib/apt/methods/http guuid=8561bd36-1b00-0000-d11c-11c2490c0000 pid=3145->guuid=ab32a83e-1b00-0000-d11c-11c2660c0000 pid=3174 execve guuid=a4a19540-1b00-0000-d11c-11c26d0c0000 pid=3181 /usr/lib/apt/methods/http dns net send-data write-file guuid=8561bd36-1b00-0000-d11c-11c2490c0000 pid=3145->guuid=a4a19540-1b00-0000-d11c-11c26d0c0000 pid=3181 execve guuid=8c6e7d5c-1b00-0000-d11c-11c2970c0000 pid=3223 /usr/lib/apt/methods/gpgv guuid=8561bd36-1b00-0000-d11c-11c2490c0000 pid=3145->guuid=8c6e7d5c-1b00-0000-d11c-11c2970c0000 pid=3223 execve guuid=eab1aa5d-1b00-0000-d11c-11c2980c0000 pid=3224 /usr/lib/apt/methods/gpgv guuid=8561bd36-1b00-0000-d11c-11c2490c0000 pid=3145->guuid=eab1aa5d-1b00-0000-d11c-11c2980c0000 pid=3224 execve guuid=c9aa30bb-1b00-0000-d11c-11c2310d0000 pid=3377 /usr/lib/apt/methods/store guuid=8561bd36-1b00-0000-d11c-11c2490c0000 pid=3145->guuid=c9aa30bb-1b00-0000-d11c-11c2310d0000 pid=3377 execve guuid=d230fdbb-1b00-0000-d11c-11c23a0d0000 pid=3386 /usr/lib/apt/methods/store write-file guuid=8561bd36-1b00-0000-d11c-11c2490c0000 pid=3145->guuid=d230fdbb-1b00-0000-d11c-11c23a0d0000 pid=3386 execve guuid=bfc6175a-1c00-0000-d11c-11c2980d0000 pid=3480 /usr/lib/apt/methods/rred guuid=8561bd36-1b00-0000-d11c-11c2490c0000 pid=3145->guuid=bfc6175a-1c00-0000-d11c-11c2980d0000 pid=3480 execve guuid=2cdb0f5d-1c00-0000-d11c-11c2990d0000 pid=3481 /usr/lib/apt/methods/rred write-file guuid=8561bd36-1b00-0000-d11c-11c2490c0000 pid=3145->guuid=2cdb0f5d-1c00-0000-d11c-11c2990d0000 pid=3481 execve guuid=e26778a7-1e00-0000-d11c-11c208140000 pid=5128 /usr/bin/dpkg guuid=8561bd36-1b00-0000-d11c-11c2490c0000 pid=3145->guuid=e26778a7-1e00-0000-d11c-11c208140000 pid=5128 execve guuid=3f8cca05-1f00-0000-d11c-11c208150000 pid=5384 /usr/bin/dpkg guuid=8561bd36-1b00-0000-d11c-11c2490c0000 pid=3145->guuid=3f8cca05-1f00-0000-d11c-11c208150000 pid=5384 execve guuid=a4a19540-1b00-0000-d11c-11c26d0c0000 pid=3181->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 122B 869ebe88-8c1e-5fbb-adb0-cfe48d8d7faf debian.map.fastly.net:443 guuid=a4a19540-1b00-0000-d11c-11c26d0c0000 pid=3181->869ebe88-8c1e-5fbb-adb0-cfe48d8d7faf send: 6313B guuid=2d2e0d5f-1b00-0000-d11c-11c2990c0000 pid=3225 /usr/lib/apt/methods/gpgv delete-file write-file guuid=eab1aa5d-1b00-0000-d11c-11c2980c0000 pid=3224->guuid=2d2e0d5f-1b00-0000-d11c-11c2990c0000 pid=3225 clone guuid=897d9a7f-1b00-0000-d11c-11c2d70c0000 pid=3287 /usr/lib/apt/methods/gpgv delete-file write-file guuid=eab1aa5d-1b00-0000-d11c-11c2980c0000 pid=3224->guuid=897d9a7f-1b00-0000-d11c-11c2d70c0000 pid=3287 clone guuid=aa6fb6a4-1b00-0000-d11c-11c2060d0000 pid=3334 /usr/lib/apt/methods/gpgv delete-file write-file guuid=eab1aa5d-1b00-0000-d11c-11c2980c0000 pid=3224->guuid=aa6fb6a4-1b00-0000-d11c-11c2060d0000 pid=3334 clone guuid=cfce34c1-1b00-0000-d11c-11c24a0d0000 pid=3402 /usr/lib/apt/methods/gpgv delete-file write-file guuid=eab1aa5d-1b00-0000-d11c-11c2980c0000 pid=3224->guuid=cfce34c1-1b00-0000-d11c-11c24a0d0000 pid=3402 clone guuid=0e422b62-1b00-0000-d11c-11c29a0c0000 pid=3226 /usr/bin/apt-key write-file guuid=2d2e0d5f-1b00-0000-d11c-11c2990c0000 pid=3225->guuid=0e422b62-1b00-0000-d11c-11c29a0c0000 pid=3226 execve guuid=a9f8c862-1b00-0000-d11c-11c29b0c0000 pid=3227 /usr/bin/dash guuid=0e422b62-1b00-0000-d11c-11c29a0c0000 pid=3226->guuid=a9f8c862-1b00-0000-d11c-11c29b0c0000 pid=3227 clone guuid=979cf662-1b00-0000-d11c-11c29c0c0000 pid=3228 /usr/bin/apt-config guuid=0e422b62-1b00-0000-d11c-11c29a0c0000 pid=3226->guuid=979cf662-1b00-0000-d11c-11c29c0c0000 pid=3228 execve guuid=5670076b-1b00-0000-d11c-11c29e0c0000 pid=3230 /usr/bin/apt-config guuid=0e422b62-1b00-0000-d11c-11c29a0c0000 pid=3226->guuid=5670076b-1b00-0000-d11c-11c29e0c0000 pid=3230 execve guuid=b2ade46d-1b00-0000-d11c-11c2a10c0000 pid=3233 /usr/bin/apt-config guuid=0e422b62-1b00-0000-d11c-11c29a0c0000 pid=3226->guuid=b2ade46d-1b00-0000-d11c-11c2a10c0000 pid=3233 execve guuid=142c0274-1b00-0000-d11c-11c2b30c0000 pid=3251 /usr/bin/apt-config guuid=0e422b62-1b00-0000-d11c-11c29a0c0000 pid=3226->guuid=142c0274-1b00-0000-d11c-11c2b30c0000 pid=3251 execve guuid=56287b76-1b00-0000-d11c-11c2b90c0000 pid=3257 /usr/bin/dash guuid=0e422b62-1b00-0000-d11c-11c29a0c0000 pid=3226->guuid=56287b76-1b00-0000-d11c-11c2b90c0000 pid=3257 clone guuid=6982a576-1b00-0000-d11c-11c2bb0c0000 pid=3259 /usr/bin/apt-config guuid=0e422b62-1b00-0000-d11c-11c29a0c0000 pid=3226->guuid=6982a576-1b00-0000-d11c-11c2bb0c0000 pid=3259 execve guuid=25c2a778-1b00-0000-d11c-11c2c10c0000 pid=3265 /usr/bin/mktemp guuid=0e422b62-1b00-0000-d11c-11c29a0c0000 pid=3226->guuid=25c2a778-1b00-0000-d11c-11c2c10c0000 pid=3265 execve guuid=6e78d978-1b00-0000-d11c-11c2c20c0000 pid=3266 /usr/bin/chmod guuid=0e422b62-1b00-0000-d11c-11c29a0c0000 pid=3226->guuid=6e78d978-1b00-0000-d11c-11c2c20c0000 pid=3266 execve guuid=df991279-1b00-0000-d11c-11c2c30c0000 pid=3267 /usr/bin/dash guuid=0e422b62-1b00-0000-d11c-11c29a0c0000 pid=3226->guuid=df991279-1b00-0000-d11c-11c2c30c0000 pid=3267 clone guuid=3ccb3279-1b00-0000-d11c-11c2c40c0000 pid=3268 /usr/bin/dash guuid=0e422b62-1b00-0000-d11c-11c29a0c0000 pid=3226->guuid=3ccb3279-1b00-0000-d11c-11c2c40c0000 pid=3268 clone guuid=04409679-1b00-0000-d11c-11c2c80c0000 pid=3272 /usr/bin/dash guuid=0e422b62-1b00-0000-d11c-11c29a0c0000 pid=3226->guuid=04409679-1b00-0000-d11c-11c2c80c0000 pid=3272 clone guuid=dc40f979-1b00-0000-d11c-11c2cc0c0000 pid=3276 /usr/bin/dash guuid=0e422b62-1b00-0000-d11c-11c29a0c0000 pid=3226->guuid=dc40f979-1b00-0000-d11c-11c2cc0c0000 pid=3276 clone guuid=252c107a-1b00-0000-d11c-11c2cd0c0000 pid=3277 /usr/bin/gpgv guuid=0e422b62-1b00-0000-d11c-11c29a0c0000 pid=3226->guuid=252c107a-1b00-0000-d11c-11c2cd0c0000 pid=3277 execve guuid=0d07497c-1b00-0000-d11c-11c2d40c0000 pid=3284 /usr/bin/rm delete-file guuid=0e422b62-1b00-0000-d11c-11c29a0c0000 pid=3226->guuid=0d07497c-1b00-0000-d11c-11c2d40c0000 pid=3284 execve guuid=a8e6f465-1b00-0000-d11c-11c29d0c0000 pid=3229 /usr/bin/dpkg guuid=979cf662-1b00-0000-d11c-11c29c0c0000 pid=3228->guuid=a8e6f465-1b00-0000-d11c-11c29d0c0000 pid=3229 execve guuid=61a4676d-1b00-0000-d11c-11c2a00c0000 pid=3232 /usr/bin/dpkg guuid=5670076b-1b00-0000-d11c-11c29e0c0000 pid=3230->guuid=61a4676d-1b00-0000-d11c-11c2a00c0000 pid=3232 execve guuid=1140616f-1b00-0000-d11c-11c2a80c0000 pid=3240 /usr/bin/dpkg guuid=b2ade46d-1b00-0000-d11c-11c2a10c0000 pid=3233->guuid=1140616f-1b00-0000-d11c-11c2a80c0000 pid=3240 execve guuid=c0dfb975-1b00-0000-d11c-11c2b60c0000 pid=3254 /usr/bin/dpkg guuid=142c0274-1b00-0000-d11c-11c2b30c0000 pid=3251->guuid=c0dfb975-1b00-0000-d11c-11c2b60c0000 pid=3254 execve guuid=3ce61578-1b00-0000-d11c-11c2bf0c0000 pid=3263 /usr/bin/dpkg guuid=6982a576-1b00-0000-d11c-11c2bb0c0000 pid=3259->guuid=3ce61578-1b00-0000-d11c-11c2bf0c0000 pid=3263 execve guuid=69363f79-1b00-0000-d11c-11c2c50c0000 pid=3269 /usr/bin/dash guuid=3ccb3279-1b00-0000-d11c-11c2c40c0000 pid=3268->guuid=69363f79-1b00-0000-d11c-11c2c50c0000 pid=3269 clone guuid=f7384479-1b00-0000-d11c-11c2c60c0000 pid=3270 /usr/bin/sed guuid=3ccb3279-1b00-0000-d11c-11c2c40c0000 pid=3268->guuid=f7384479-1b00-0000-d11c-11c2c60c0000 pid=3270 execve guuid=15a39f79-1b00-0000-d11c-11c2c90c0000 pid=3273 /usr/bin/dash guuid=04409679-1b00-0000-d11c-11c2c80c0000 pid=3272->guuid=15a39f79-1b00-0000-d11c-11c2c90c0000 pid=3273 clone guuid=cb79a479-1b00-0000-d11c-11c2ca0c0000 pid=3274 /usr/bin/sed guuid=04409679-1b00-0000-d11c-11c2c80c0000 pid=3272->guuid=cb79a479-1b00-0000-d11c-11c2ca0c0000 pid=3274 execve guuid=53eb0181-1b00-0000-d11c-11c2d80c0000 pid=3288 /usr/bin/apt-key write-file guuid=897d9a7f-1b00-0000-d11c-11c2d70c0000 pid=3287->guuid=53eb0181-1b00-0000-d11c-11c2d80c0000 pid=3288 execve guuid=4ce45d81-1b00-0000-d11c-11c2d90c0000 pid=3289 /usr/bin/dash guuid=53eb0181-1b00-0000-d11c-11c2d80c0000 pid=3288->guuid=4ce45d81-1b00-0000-d11c-11c2d90c0000 pid=3289 clone guuid=1ae08e81-1b00-0000-d11c-11c2da0c0000 pid=3290 /usr/bin/apt-config guuid=53eb0181-1b00-0000-d11c-11c2d80c0000 pid=3288->guuid=1ae08e81-1b00-0000-d11c-11c2da0c0000 pid=3290 execve guuid=137c0289-1b00-0000-d11c-11c2dc0c0000 pid=3292 /usr/bin/apt-config guuid=53eb0181-1b00-0000-d11c-11c2d80c0000 pid=3288->guuid=137c0289-1b00-0000-d11c-11c2dc0c0000 pid=3292 execve guuid=717c9791-1b00-0000-d11c-11c2df0c0000 pid=3295 /usr/bin/apt-config guuid=53eb0181-1b00-0000-d11c-11c2d80c0000 pid=3288->guuid=717c9791-1b00-0000-d11c-11c2df0c0000 pid=3295 execve guuid=23782399-1b00-0000-d11c-11c2ec0c0000 pid=3308 /usr/bin/apt-config guuid=53eb0181-1b00-0000-d11c-11c2d80c0000 pid=3288->guuid=23782399-1b00-0000-d11c-11c2ec0c0000 pid=3308 execve guuid=c249a29b-1b00-0000-d11c-11c2f00c0000 pid=3312 /usr/bin/dash guuid=53eb0181-1b00-0000-d11c-11c2d80c0000 pid=3288->guuid=c249a29b-1b00-0000-d11c-11c2f00c0000 pid=3312 clone guuid=6483c89b-1b00-0000-d11c-11c2f20c0000 pid=3314 /usr/bin/apt-config guuid=53eb0181-1b00-0000-d11c-11c2d80c0000 pid=3288->guuid=6483c89b-1b00-0000-d11c-11c2f20c0000 pid=3314 execve guuid=9067ff9d-1b00-0000-d11c-11c2f50c0000 pid=3317 /usr/bin/mktemp guuid=53eb0181-1b00-0000-d11c-11c2d80c0000 pid=3288->guuid=9067ff9d-1b00-0000-d11c-11c2f50c0000 pid=3317 execve guuid=a8f53b9e-1b00-0000-d11c-11c2f70c0000 pid=3319 /usr/bin/chmod guuid=53eb0181-1b00-0000-d11c-11c2d80c0000 pid=3288->guuid=a8f53b9e-1b00-0000-d11c-11c2f70c0000 pid=3319 execve guuid=0455769e-1b00-0000-d11c-11c2f80c0000 pid=3320 /usr/bin/dash guuid=53eb0181-1b00-0000-d11c-11c2d80c0000 pid=3288->guuid=0455769e-1b00-0000-d11c-11c2f80c0000 pid=3320 clone guuid=a2ef859e-1b00-0000-d11c-11c2fa0c0000 pid=3322 /usr/bin/dash guuid=53eb0181-1b00-0000-d11c-11c2d80c0000 pid=3288->guuid=a2ef859e-1b00-0000-d11c-11c2fa0c0000 pid=3322 clone guuid=e657329f-1b00-0000-d11c-11c2fe0c0000 pid=3326 /usr/bin/dash guuid=53eb0181-1b00-0000-d11c-11c2d80c0000 pid=3288->guuid=e657329f-1b00-0000-d11c-11c2fe0c0000 pid=3326 clone guuid=c2533ea0-1b00-0000-d11c-11c2030d0000 pid=3331 /usr/bin/dash guuid=53eb0181-1b00-0000-d11c-11c2d80c0000 pid=3288->guuid=c2533ea0-1b00-0000-d11c-11c2030d0000 pid=3331 clone guuid=6b224fa0-1b00-0000-d11c-11c2040d0000 pid=3332 /usr/bin/gpgv guuid=53eb0181-1b00-0000-d11c-11c2d80c0000 pid=3288->guuid=6b224fa0-1b00-0000-d11c-11c2040d0000 pid=3332 execve guuid=cbdfcfa2-1b00-0000-d11c-11c2050d0000 pid=3333 /usr/bin/rm delete-file guuid=53eb0181-1b00-0000-d11c-11c2d80c0000 pid=3288->guuid=cbdfcfa2-1b00-0000-d11c-11c2050d0000 pid=3333 execve guuid=3b8c5d86-1b00-0000-d11c-11c2db0c0000 pid=3291 /usr/bin/dpkg guuid=1ae08e81-1b00-0000-d11c-11c2da0c0000 pid=3290->guuid=3b8c5d86-1b00-0000-d11c-11c2db0c0000 pid=3291 execve guuid=c8e3048c-1b00-0000-d11c-11c2dd0c0000 pid=3293 /usr/bin/dpkg guuid=137c0289-1b00-0000-d11c-11c2dc0c0000 pid=3292->guuid=c8e3048c-1b00-0000-d11c-11c2dd0c0000 pid=3293 execve guuid=b9a02e93-1b00-0000-d11c-11c2e20c0000 pid=3298 /usr/bin/dpkg guuid=717c9791-1b00-0000-d11c-11c2df0c0000 pid=3295->guuid=b9a02e93-1b00-0000-d11c-11c2e20c0000 pid=3298 execve guuid=a8d7839a-1b00-0000-d11c-11c2ef0c0000 pid=3311 /usr/bin/dpkg guuid=23782399-1b00-0000-d11c-11c2ec0c0000 pid=3308->guuid=a8d7839a-1b00-0000-d11c-11c2ef0c0000 pid=3311 execve guuid=45ff199d-1b00-0000-d11c-11c2f30c0000 pid=3315 /usr/bin/dpkg guuid=6483c89b-1b00-0000-d11c-11c2f20c0000 pid=3314->guuid=45ff199d-1b00-0000-d11c-11c2f30c0000 pid=3315 execve guuid=acf9909e-1b00-0000-d11c-11c2fb0c0000 pid=3323 /usr/bin/dash guuid=a2ef859e-1b00-0000-d11c-11c2fa0c0000 pid=3322->guuid=acf9909e-1b00-0000-d11c-11c2fb0c0000 pid=3323 clone guuid=eeaa979e-1b00-0000-d11c-11c2fc0c0000 pid=3324 /usr/bin/sed guuid=a2ef859e-1b00-0000-d11c-11c2fa0c0000 pid=3322->guuid=eeaa979e-1b00-0000-d11c-11c2fc0c0000 pid=3324 execve guuid=db593d9f-1b00-0000-d11c-11c2ff0c0000 pid=3327 /usr/bin/dash guuid=e657329f-1b00-0000-d11c-11c2fe0c0000 pid=3326->guuid=db593d9f-1b00-0000-d11c-11c2ff0c0000 pid=3327 clone guuid=c4f5489f-1b00-0000-d11c-11c2010d0000 pid=3329 /usr/bin/sed guuid=e657329f-1b00-0000-d11c-11c2fe0c0000 pid=3326->guuid=c4f5489f-1b00-0000-d11c-11c2010d0000 pid=3329 execve guuid=e558a4a6-1b00-0000-d11c-11c2070d0000 pid=3335 /usr/bin/apt-key write-file guuid=aa6fb6a4-1b00-0000-d11c-11c2060d0000 pid=3334->guuid=e558a4a6-1b00-0000-d11c-11c2070d0000 pid=3335 execve guuid=f1840aa7-1b00-0000-d11c-11c2080d0000 pid=3336 /usr/bin/dash guuid=e558a4a6-1b00-0000-d11c-11c2070d0000 pid=3335->guuid=f1840aa7-1b00-0000-d11c-11c2080d0000 pid=3336 clone guuid=03a119a7-1b00-0000-d11c-11c2090d0000 pid=3337 /usr/bin/apt-config guuid=e558a4a6-1b00-0000-d11c-11c2070d0000 pid=3335->guuid=03a119a7-1b00-0000-d11c-11c2090d0000 pid=3337 execve guuid=dde69daa-1b00-0000-d11c-11c2110d0000 pid=3345 /usr/bin/apt-config guuid=e558a4a6-1b00-0000-d11c-11c2070d0000 pid=3335->guuid=dde69daa-1b00-0000-d11c-11c2110d0000 pid=3345 execve guuid=5be984ac-1b00-0000-d11c-11c2170d0000 pid=3351 /usr/bin/apt-config guuid=e558a4a6-1b00-0000-d11c-11c2070d0000 pid=3335->guuid=5be984ac-1b00-0000-d11c-11c2170d0000 pid=3351 execve guuid=711aacb3-1b00-0000-d11c-11c2230d0000 pid=3363 /usr/bin/apt-config guuid=e558a4a6-1b00-0000-d11c-11c2070d0000 pid=3335->guuid=711aacb3-1b00-0000-d11c-11c2230d0000 pid=3363 execve guuid=d36becb6-1b00-0000-d11c-11c2260d0000 pid=3366 /usr/bin/dash guuid=e558a4a6-1b00-0000-d11c-11c2070d0000 pid=3335->guuid=d36becb6-1b00-0000-d11c-11c2260d0000 pid=3366 clone guuid=a61734b7-1b00-0000-d11c-11c2270d0000 pid=3367 /usr/bin/apt-config guuid=e558a4a6-1b00-0000-d11c-11c2070d0000 pid=3335->guuid=a61734b7-1b00-0000-d11c-11c2270d0000 pid=3367 execve guuid=a5b0b8ba-1b00-0000-d11c-11c22d0d0000 pid=3373 /usr/bin/mktemp guuid=e558a4a6-1b00-0000-d11c-11c2070d0000 pid=3335->guuid=a5b0b8ba-1b00-0000-d11c-11c22d0d0000 pid=3373 execve guuid=b6e70cbb-1b00-0000-d11c-11c2300d0000 pid=3376 /usr/bin/chmod guuid=e558a4a6-1b00-0000-d11c-11c2070d0000 pid=3335->guuid=b6e70cbb-1b00-0000-d11c-11c2300d0000 pid=3376 execve guuid=b85154bb-1b00-0000-d11c-11c2330d0000 pid=3379 /usr/bin/dash guuid=e558a4a6-1b00-0000-d11c-11c2070d0000 pid=3335->guuid=b85154bb-1b00-0000-d11c-11c2330d0000 pid=3379 clone guuid=49e36ebb-1b00-0000-d11c-11c2340d0000 pid=3380 /usr/bin/dash guuid=e558a4a6-1b00-0000-d11c-11c2070d0000 pid=3335->guuid=49e36ebb-1b00-0000-d11c-11c2340d0000 pid=3380 clone guuid=a15107bc-1b00-0000-d11c-11c23b0d0000 pid=3387 /usr/bin/dash guuid=e558a4a6-1b00-0000-d11c-11c2070d0000 pid=3335->guuid=a15107bc-1b00-0000-d11c-11c23b0d0000 pid=3387 clone guuid=f6daa5bc-1b00-0000-d11c-11c2410d0000 pid=3393 /usr/bin/dash guuid=e558a4a6-1b00-0000-d11c-11c2070d0000 pid=3335->guuid=f6daa5bc-1b00-0000-d11c-11c2410d0000 pid=3393 clone guuid=5aa3babc-1b00-0000-d11c-11c2420d0000 pid=3394 /usr/bin/gpgv guuid=e558a4a6-1b00-0000-d11c-11c2070d0000 pid=3335->guuid=5aa3babc-1b00-0000-d11c-11c2420d0000 pid=3394 execve guuid=36676bbf-1b00-0000-d11c-11c2490d0000 pid=3401 /usr/bin/rm delete-file guuid=e558a4a6-1b00-0000-d11c-11c2070d0000 pid=3335->guuid=36676bbf-1b00-0000-d11c-11c2490d0000 pid=3401 execve guuid=43f09ca9-1b00-0000-d11c-11c20d0d0000 pid=3341 /usr/bin/dpkg guuid=03a119a7-1b00-0000-d11c-11c2090d0000 pid=3337->guuid=43f09ca9-1b00-0000-d11c-11c20d0d0000 pid=3341 execve guuid=5a3ff5ab-1b00-0000-d11c-11c2150d0000 pid=3349 /usr/bin/dpkg guuid=dde69daa-1b00-0000-d11c-11c2110d0000 pid=3345->guuid=5a3ff5ab-1b00-0000-d11c-11c2150d0000 pid=3349 execve guuid=f2d7d9ad-1b00-0000-d11c-11c21c0d0000 pid=3356 /usr/bin/dpkg guuid=5be984ac-1b00-0000-d11c-11c2170d0000 pid=3351->guuid=f2d7d9ad-1b00-0000-d11c-11c21c0d0000 pid=3356 execve guuid=b6873ab5-1b00-0000-d11c-11c2250d0000 pid=3365 /usr/bin/dpkg guuid=711aacb3-1b00-0000-d11c-11c2230d0000 pid=3363->guuid=b6873ab5-1b00-0000-d11c-11c2250d0000 pid=3365 execve guuid=2591fab9-1b00-0000-d11c-11c22a0d0000 pid=3370 /usr/bin/dpkg guuid=a61734b7-1b00-0000-d11c-11c2270d0000 pid=3367->guuid=2591fab9-1b00-0000-d11c-11c22a0d0000 pid=3370 execve guuid=4a967abb-1b00-0000-d11c-11c2360d0000 pid=3382 /usr/bin/dash guuid=49e36ebb-1b00-0000-d11c-11c2340d0000 pid=3380->guuid=4a967abb-1b00-0000-d11c-11c2360d0000 pid=3382 clone guuid=d17f81bb-1b00-0000-d11c-11c2370d0000 pid=3383 /usr/bin/sed guuid=49e36ebb-1b00-0000-d11c-11c2340d0000 pid=3380->guuid=d17f81bb-1b00-0000-d11c-11c2370d0000 pid=3383 execve guuid=99ab12bc-1b00-0000-d11c-11c23c0d0000 pid=3388 /usr/bin/dash guuid=a15107bc-1b00-0000-d11c-11c23b0d0000 pid=3387->guuid=99ab12bc-1b00-0000-d11c-11c23c0d0000 pid=3388 clone guuid=ff3519bc-1b00-0000-d11c-11c23d0d0000 pid=3389 /usr/bin/sed guuid=a15107bc-1b00-0000-d11c-11c23b0d0000 pid=3387->guuid=ff3519bc-1b00-0000-d11c-11c23d0d0000 pid=3389 execve guuid=a47006c4-1b00-0000-d11c-11c24b0d0000 pid=3403 /usr/bin/apt-key write-file guuid=cfce34c1-1b00-0000-d11c-11c24a0d0000 pid=3402->guuid=a47006c4-1b00-0000-d11c-11c24b0d0000 pid=3403 execve guuid=2d8eb5c4-1b00-0000-d11c-11c24c0d0000 pid=3404 /usr/bin/dash guuid=a47006c4-1b00-0000-d11c-11c24b0d0000 pid=3403->guuid=2d8eb5c4-1b00-0000-d11c-11c24c0d0000 pid=3404 clone guuid=4014c4c4-1b00-0000-d11c-11c24d0d0000 pid=3405 /usr/bin/apt-config guuid=a47006c4-1b00-0000-d11c-11c24b0d0000 pid=3403->guuid=4014c4c4-1b00-0000-d11c-11c24d0d0000 pid=3405 execve guuid=44c14cc6-1b00-0000-d11c-11c24f0d0000 pid=3407 /usr/bin/apt-config guuid=a47006c4-1b00-0000-d11c-11c24b0d0000 pid=3403->guuid=44c14cc6-1b00-0000-d11c-11c24f0d0000 pid=3407 execve guuid=dba9d7c7-1b00-0000-d11c-11c2510d0000 pid=3409 /usr/bin/apt-config guuid=a47006c4-1b00-0000-d11c-11c24b0d0000 pid=3403->guuid=dba9d7c7-1b00-0000-d11c-11c2510d0000 pid=3409 execve guuid=798760c9-1b00-0000-d11c-11c2530d0000 pid=3411 /usr/bin/apt-config guuid=a47006c4-1b00-0000-d11c-11c24b0d0000 pid=3403->guuid=798760c9-1b00-0000-d11c-11c2530d0000 pid=3411 execve guuid=ac94f9ca-1b00-0000-d11c-11c2550d0000 pid=3413 /usr/bin/dash guuid=a47006c4-1b00-0000-d11c-11c24b0d0000 pid=3403->guuid=ac94f9ca-1b00-0000-d11c-11c2550d0000 pid=3413 clone guuid=e13727cb-1b00-0000-d11c-11c2560d0000 pid=3414 /usr/bin/apt-config guuid=a47006c4-1b00-0000-d11c-11c24b0d0000 pid=3403->guuid=e13727cb-1b00-0000-d11c-11c2560d0000 pid=3414 execve guuid=2aa2d9cc-1b00-0000-d11c-11c2580d0000 pid=3416 /usr/bin/mktemp guuid=a47006c4-1b00-0000-d11c-11c24b0d0000 pid=3403->guuid=2aa2d9cc-1b00-0000-d11c-11c2580d0000 pid=3416 execve guuid=5f1218cd-1b00-0000-d11c-11c2590d0000 pid=3417 /usr/bin/chmod guuid=a47006c4-1b00-0000-d11c-11c24b0d0000 pid=3403->guuid=5f1218cd-1b00-0000-d11c-11c2590d0000 pid=3417 execve guuid=6b614ecd-1b00-0000-d11c-11c25a0d0000 pid=3418 /usr/bin/dash guuid=a47006c4-1b00-0000-d11c-11c24b0d0000 pid=3403->guuid=6b614ecd-1b00-0000-d11c-11c25a0d0000 pid=3418 clone guuid=a3e862cd-1b00-0000-d11c-11c25b0d0000 pid=3419 /usr/bin/dash guuid=a47006c4-1b00-0000-d11c-11c24b0d0000 pid=3403->guuid=a3e862cd-1b00-0000-d11c-11c25b0d0000 pid=3419 clone guuid=ce26d6cd-1b00-0000-d11c-11c25e0d0000 pid=3422 /usr/bin/dash guuid=a47006c4-1b00-0000-d11c-11c24b0d0000 pid=3403->guuid=ce26d6cd-1b00-0000-d11c-11c25e0d0000 pid=3422 clone guuid=19b636ce-1b00-0000-d11c-11c2610d0000 pid=3425 /usr/bin/dash guuid=a47006c4-1b00-0000-d11c-11c24b0d0000 pid=3403->guuid=19b636ce-1b00-0000-d11c-11c2610d0000 pid=3425 clone guuid=00b843ce-1b00-0000-d11c-11c2620d0000 pid=3426 /usr/bin/gpgv guuid=a47006c4-1b00-0000-d11c-11c24b0d0000 pid=3403->guuid=00b843ce-1b00-0000-d11c-11c2620d0000 pid=3426 execve guuid=ee6101d0-1b00-0000-d11c-11c2630d0000 pid=3427 /usr/bin/rm delete-file guuid=a47006c4-1b00-0000-d11c-11c24b0d0000 pid=3403->guuid=ee6101d0-1b00-0000-d11c-11c2630d0000 pid=3427 execve guuid=1a35cdc5-1b00-0000-d11c-11c24e0d0000 pid=3406 /usr/bin/dpkg guuid=4014c4c4-1b00-0000-d11c-11c24d0d0000 pid=3405->guuid=1a35cdc5-1b00-0000-d11c-11c24e0d0000 pid=3406 execve guuid=8da368c7-1b00-0000-d11c-11c2500d0000 pid=3408 /usr/bin/dpkg guuid=44c14cc6-1b00-0000-d11c-11c24f0d0000 pid=3407->guuid=8da368c7-1b00-0000-d11c-11c2500d0000 pid=3408 execve guuid=b1c4eec8-1b00-0000-d11c-11c2520d0000 pid=3410 /usr/bin/dpkg guuid=dba9d7c7-1b00-0000-d11c-11c2510d0000 pid=3409->guuid=b1c4eec8-1b00-0000-d11c-11c2520d0000 pid=3410 execve guuid=3a6e63ca-1b00-0000-d11c-11c2540d0000 pid=3412 /usr/bin/dpkg guuid=798760c9-1b00-0000-d11c-11c2530d0000 pid=3411->guuid=3a6e63ca-1b00-0000-d11c-11c2540d0000 pid=3412 execve guuid=4c9154cc-1b00-0000-d11c-11c2570d0000 pid=3415 /usr/bin/dpkg guuid=e13727cb-1b00-0000-d11c-11c2560d0000 pid=3414->guuid=4c9154cc-1b00-0000-d11c-11c2570d0000 pid=3415 execve guuid=74db6dcd-1b00-0000-d11c-11c25c0d0000 pid=3420 /usr/bin/dash guuid=a3e862cd-1b00-0000-d11c-11c25b0d0000 pid=3419->guuid=74db6dcd-1b00-0000-d11c-11c25c0d0000 pid=3420 clone guuid=97f273cd-1b00-0000-d11c-11c25d0d0000 pid=3421 /usr/bin/sed guuid=a3e862cd-1b00-0000-d11c-11c25b0d0000 pid=3419->guuid=97f273cd-1b00-0000-d11c-11c25d0d0000 pid=3421 execve guuid=ecb6ddcd-1b00-0000-d11c-11c25f0d0000 pid=3423 /usr/bin/dash guuid=ce26d6cd-1b00-0000-d11c-11c25e0d0000 pid=3422->guuid=ecb6ddcd-1b00-0000-d11c-11c25f0d0000 pid=3423 clone guuid=89f6e3cd-1b00-0000-d11c-11c2600d0000 pid=3424 /usr/bin/sed guuid=ce26d6cd-1b00-0000-d11c-11c25e0d0000 pid=3422->guuid=89f6e3cd-1b00-0000-d11c-11c2600d0000 pid=3424 execve guuid=f6809c08-1f00-0000-d11c-11c20a150000 pid=5386 /usr/bin/dpkg guuid=b2cc9c07-1f00-0000-d11c-11c209150000 pid=5385->guuid=f6809c08-1f00-0000-d11c-11c20a150000 pid=5386 execve
Threat name:
Linux.Trojan.Generic
Status:
Suspicious
First seen:
2017-06-15 21:03:26 UTC
File Type:
Text (Shell)
AV detection:
24 of 36 (66.67%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  9/10
Tags:
antivm credential_access defense_evasion discovery execution linux persistence privilege_escalation
Behaviour
Software Deployment Tools
Enumerates kernel/hardware configuration
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Deobfuscate/Decode Files or Information
Changes its process name
Checks CPU configuration
Reads CPU attributes
Reads system network configuration
Deletes log files
Enumerates running processes
Write file to user bin folder
File and Directory Permissions Modification
Creates Raw socket
Executes dropped EXE
Modifies hosts file
OS Credential Dumping
Writes DNS configuration
Adds new SSH keys
Contacts a large (100019) amount of remote hosts
Creates a large amount of network flows
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Other

Comments