MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 788949bced00005c922e666d700a832cef7e30536a711761ae68ff82a7605d6a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



CoinMiner


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 788949bced00005c922e666d700a832cef7e30536a711761ae68ff82a7605d6a
SHA3-384 hash: cb18a0406461a44b6d83e168ea2a0a421a956e20f2ebfbcd8c469245b35d925c5efe6f4b7dc883fe0ddbd828edaa3cad
SHA1 hash: 123b0943a07e9084ccca1e6e974372838ad96a1a
MD5 hash: c0e427045cf5ea0a631808c02c2706f0
humanhash: quebec-illinois-november-football
File name:run-CN.sh
Download: download sample
Signature CoinMiner
File size:7'772 bytes
First seen:2025-08-24 13:34:24 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 192:2I848XyzHWZzzDN1eEXOKDk5aam3qarbayHDPMeYPcMNZlu:szvnvaUNjn+cyu
TLSH T1C4F1C702F7D09AB419DCC568444A1840698B911B6D092C48F8FDB5A9FF3476C71FDBEB
Magika shell
Reporter abuse_ch
Tags:CoinMiner sh
URLMalware sample (SHA256 hash)SignatureTags
http://162.248.53.119:8000/mon.sh1e891ab1521b27923233e694f60fdbf0e1b840e657d8b1ffdefd8b5ef5e38964 CoinMinerCoinMiner
http://162.248.53.119:8000/yes.tar.gzn/an/aopendir
https://github.com/rplant8/xmrig-vrl/releases/download/6.0.24-virel/xmrig-vrl-linux.tar.xzn/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
28
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
Script
Detections:
HEUR:Trojan-Downloader.Shell.Agent.bc
Status:
terminated
Behavior Graph:
%3 guuid=e044414b-1a00-0000-3654-b83364090000 pid=2404 /usr/bin/sudo guuid=d0bfe54c-1a00-0000-3654-b83366090000 pid=2406 /tmp/sample.bin guuid=e044414b-1a00-0000-3654-b83364090000 pid=2404->guuid=d0bfe54c-1a00-0000-3654-b83366090000 pid=2406 execve guuid=466adc4d-1a00-0000-3654-b83368090000 pid=2408 /usr/bin/systemctl guuid=d0bfe54c-1a00-0000-3654-b83366090000 pid=2406->guuid=466adc4d-1a00-0000-3654-b83368090000 pid=2408 execve guuid=e5fd1351-1a00-0000-3654-b8336e090000 pid=2414 /usr/bin/bash guuid=d0bfe54c-1a00-0000-3654-b83366090000 pid=2406->guuid=e5fd1351-1a00-0000-3654-b8336e090000 pid=2414 clone guuid=49f8545c-1a00-0000-3654-b83388090000 pid=2440 /usr/bin/bash guuid=d0bfe54c-1a00-0000-3654-b83366090000 pid=2406->guuid=49f8545c-1a00-0000-3654-b83388090000 pid=2440 clone guuid=d3c95a5d-1a00-0000-3654-b8338e090000 pid=2446 /usr/bin/pgrep guuid=d0bfe54c-1a00-0000-3654-b83366090000 pid=2406->guuid=d3c95a5d-1a00-0000-3654-b8338e090000 pid=2446 execve guuid=a6888060-1a00-0000-3654-b83397090000 pid=2455 /usr/bin/pgrep guuid=d0bfe54c-1a00-0000-3654-b83366090000 pid=2406->guuid=a6888060-1a00-0000-3654-b83397090000 pid=2455 execve guuid=82fa6763-1a00-0000-3654-b8339b090000 pid=2459 /usr/bin/pgrep guuid=d0bfe54c-1a00-0000-3654-b83366090000 pid=2406->guuid=82fa6763-1a00-0000-3654-b8339b090000 pid=2459 execve guuid=10b07063-1a00-0000-3654-b8339c090000 pid=2460 /usr/bin/grep guuid=d0bfe54c-1a00-0000-3654-b83366090000 pid=2406->guuid=10b07063-1a00-0000-3654-b8339c090000 pid=2460 execve guuid=e0ff7863-1a00-0000-3654-b8339e090000 pid=2462 /usr/bin/xargs guuid=d0bfe54c-1a00-0000-3654-b83366090000 pid=2406->guuid=e0ff7863-1a00-0000-3654-b8339e090000 pid=2462 execve guuid=64e42366-1a00-0000-3654-b833a6090000 pid=2470 /usr/bin/id guuid=d0bfe54c-1a00-0000-3654-b83366090000 pid=2406->guuid=64e42366-1a00-0000-3654-b833a6090000 pid=2470 execve guuid=f6abbb66-1a00-0000-3654-b833a7090000 pid=2471 /usr/bin/apt-get delete-file write-file guuid=d0bfe54c-1a00-0000-3654-b83366090000 pid=2406->guuid=f6abbb66-1a00-0000-3654-b833a7090000 pid=2471 execve guuid=d0268f38-1c00-0000-3654-b833620d0000 pid=3426 /usr/bin/apt-get guuid=d0bfe54c-1a00-0000-3654-b83366090000 pid=2406->guuid=d0268f38-1c00-0000-3654-b833620d0000 pid=3426 execve guuid=922b993a-1c00-0000-3654-b833670d0000 pid=3431 /usr/bin/mkdir guuid=d0bfe54c-1a00-0000-3654-b83366090000 pid=2406->guuid=922b993a-1c00-0000-3654-b833670d0000 pid=3431 execve guuid=3da0113b-1c00-0000-3654-b833690d0000 pid=3433 /usr/bin/wget dns net send-data write-file guuid=d0bfe54c-1a00-0000-3654-b83366090000 pid=2406->guuid=3da0113b-1c00-0000-3654-b833690d0000 pid=3433 execve guuid=0ad2e45d-1c00-0000-3654-b833af0d0000 pid=3503 /usr/bin/tar write-file guuid=d0bfe54c-1a00-0000-3654-b83366090000 pid=2406->guuid=0ad2e45d-1c00-0000-3654-b833af0d0000 pid=3503 execve guuid=bd2d2f78-1c00-0000-3654-b833010e0000 pid=3585 /usr/bin/mv guuid=d0bfe54c-1a00-0000-3654-b83366090000 pid=2406->guuid=bd2d2f78-1c00-0000-3654-b833010e0000 pid=3585 execve guuid=45a79e78-1c00-0000-3654-b833030e0000 pid=3587 /usr/bin/rm guuid=d0bfe54c-1a00-0000-3654-b83366090000 pid=2406->guuid=45a79e78-1c00-0000-3654-b833030e0000 pid=3587 execve guuid=8a4fed78-1c00-0000-3654-b833050e0000 pid=3589 /usr/bin/chmod guuid=d0bfe54c-1a00-0000-3654-b83366090000 pid=2406->guuid=8a4fed78-1c00-0000-3654-b833050e0000 pid=3589 execve guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=3591 /usr/lib/dev/systemdev/systemd-mont mprotect-exec net send-data zombie guuid=d0bfe54c-1a00-0000-3654-b83366090000 pid=2406->guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=3591 execve guuid=87715c79-1c00-0000-3654-b833080e0000 pid=3592 /usr/bin/sleep guuid=d0bfe54c-1a00-0000-3654-b83366090000 pid=2406->guuid=87715c79-1c00-0000-3654-b833080e0000 pid=3592 execve guuid=46f1c097-1c00-0000-3654-b833440e0000 pid=3652 /usr/bin/ps guuid=d0bfe54c-1a00-0000-3654-b83366090000 pid=2406->guuid=46f1c097-1c00-0000-3654-b833440e0000 pid=3652 execve guuid=ceda2e9a-1c00-0000-3654-b8334b0e0000 pid=3659 /usr/bin/sleep guuid=d0bfe54c-1a00-0000-3654-b83366090000 pid=2406->guuid=ceda2e9a-1c00-0000-3654-b8334b0e0000 pid=3659 execve guuid=2017b6a6-1d00-0000-3654-b833e6100000 pid=4326 /usr/bin/ps guuid=d0bfe54c-1a00-0000-3654-b83366090000 pid=2406->guuid=2017b6a6-1d00-0000-3654-b833e6100000 pid=4326 execve guuid=04883fa9-1d00-0000-3654-b833f0100000 pid=4336 /usr/bin/rm guuid=d0bfe54c-1a00-0000-3654-b83366090000 pid=2406->guuid=04883fa9-1d00-0000-3654-b833f0100000 pid=4336 execve guuid=eec1b3a9-1d00-0000-3654-b833f2100000 pid=4338 /usr/bin/rm guuid=d0bfe54c-1a00-0000-3654-b83366090000 pid=2406->guuid=eec1b3a9-1d00-0000-3654-b833f2100000 pid=4338 execve guuid=61082451-1a00-0000-3654-b8336f090000 pid=2415 /usr/bin/wget dns net send-data guuid=e5fd1351-1a00-0000-3654-b8336e090000 pid=2414->guuid=61082451-1a00-0000-3654-b8336f090000 pid=2415 execve 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=61082451-1a00-0000-3654-b8336f090000 pid=2415->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 72B 0690ccd5-4816-5f11-94dc-7c585f38cdea ipv4.icanhazip.com:0 guuid=61082451-1a00-0000-3654-b8336f090000 pid=2415->0690ccd5-4816-5f11-94dc-7c585f38cdea con d0ecfe49-aa79-583f-85c6-85ac97075256 ipv4.icanhazip.com:80 guuid=61082451-1a00-0000-3654-b8336f090000 pid=2415->d0ecfe49-aa79-583f-85c6-85ac97075256 send: 133B guuid=24fc655c-1a00-0000-3654-b83389090000 pid=2441 /usr/bin/bash guuid=49f8545c-1a00-0000-3654-b83388090000 pid=2440->guuid=24fc655c-1a00-0000-3654-b83389090000 pid=2441 clone guuid=605c745c-1a00-0000-3654-b8338a090000 pid=2442 /usr/bin/sed guuid=49f8545c-1a00-0000-3654-b83388090000 pid=2440->guuid=605c745c-1a00-0000-3654-b8338a090000 pid=2442 execve guuid=a0a2805c-1a00-0000-3654-b8338b090000 pid=2443 /usr/bin/cut guuid=49f8545c-1a00-0000-3654-b83388090000 pid=2440->guuid=a0a2805c-1a00-0000-3654-b8338b090000 pid=2443 execve guuid=9a0dff67-1a00-0000-3654-b833ab090000 pid=2475 /usr/bin/dpkg guuid=f6abbb66-1a00-0000-3654-b833a7090000 pid=2471->guuid=9a0dff67-1a00-0000-3654-b833ab090000 pid=2475 execve guuid=99429f68-1a00-0000-3654-b833ae090000 pid=2478 /usr/lib/apt/methods/mirror guuid=f6abbb66-1a00-0000-3654-b833a7090000 pid=2471->guuid=99429f68-1a00-0000-3654-b833ae090000 pid=2478 execve guuid=ae9db769-1a00-0000-3654-b833b3090000 pid=2483 /usr/lib/apt/methods/mirror guuid=f6abbb66-1a00-0000-3654-b833a7090000 pid=2471->guuid=ae9db769-1a00-0000-3654-b833b3090000 pid=2483 execve guuid=2584de6a-1a00-0000-3654-b833b7090000 pid=2487 /usr/lib/apt/methods/file guuid=f6abbb66-1a00-0000-3654-b833a7090000 pid=2471->guuid=2584de6a-1a00-0000-3654-b833b7090000 pid=2487 execve guuid=40a1026c-1a00-0000-3654-b833bb090000 pid=2491 /usr/lib/apt/methods/file delete-file guuid=f6abbb66-1a00-0000-3654-b833a7090000 pid=2471->guuid=40a1026c-1a00-0000-3654-b833bb090000 pid=2491 execve guuid=f8cf3a6d-1a00-0000-3654-b833bf090000 pid=2495 /usr/lib/apt/methods/http guuid=f6abbb66-1a00-0000-3654-b833a7090000 pid=2471->guuid=f8cf3a6d-1a00-0000-3654-b833bf090000 pid=2495 execve guuid=0ff6d26e-1a00-0000-3654-b833c4090000 pid=2500 /usr/lib/apt/methods/http dns net send-data write-file guuid=f6abbb66-1a00-0000-3654-b833a7090000 pid=2471->guuid=0ff6d26e-1a00-0000-3654-b833c4090000 pid=2500 execve guuid=1e51208a-1a00-0000-3654-b833f4090000 pid=2548 /usr/lib/apt/methods/gpgv guuid=f6abbb66-1a00-0000-3654-b833a7090000 pid=2471->guuid=1e51208a-1a00-0000-3654-b833f4090000 pid=2548 execve guuid=dc626e8b-1a00-0000-3654-b833f5090000 pid=2549 /usr/lib/apt/methods/gpgv guuid=f6abbb66-1a00-0000-3654-b833a7090000 pid=2471->guuid=dc626e8b-1a00-0000-3654-b833f5090000 pid=2549 execve guuid=d8e6c8b7-1a00-0000-3654-b833850a0000 pid=2693 /usr/lib/apt/methods/store guuid=f6abbb66-1a00-0000-3654-b833a7090000 pid=2471->guuid=d8e6c8b7-1a00-0000-3654-b833850a0000 pid=2693 execve guuid=034435b9-1a00-0000-3654-b8338b0a0000 pid=2699 /usr/lib/apt/methods/store write-file guuid=f6abbb66-1a00-0000-3654-b833a7090000 pid=2471->guuid=034435b9-1a00-0000-3654-b8338b0a0000 pid=2699 execve guuid=9b1bfed5-1a00-0000-3654-b833fe0a0000 pid=2814 /usr/lib/apt/methods/rred guuid=f6abbb66-1a00-0000-3654-b833a7090000 pid=2471->guuid=9b1bfed5-1a00-0000-3654-b833fe0a0000 pid=2814 execve guuid=5e2fd4dc-1a00-0000-3654-b8330f0b0000 pid=2831 /usr/lib/apt/methods/rred write-file guuid=f6abbb66-1a00-0000-3654-b833a7090000 pid=2471->guuid=5e2fd4dc-1a00-0000-3654-b8330f0b0000 pid=2831 execve guuid=4a468813-1b00-0000-3654-b833710b0000 pid=2929 /usr/bin/dpkg guuid=f6abbb66-1a00-0000-3654-b833a7090000 pid=2471->guuid=4a468813-1b00-0000-3654-b833710b0000 pid=2929 execve guuid=9f0ebd2d-1c00-0000-3654-b8334d0d0000 pid=3405 /usr/bin/dpkg guuid=f6abbb66-1a00-0000-3654-b833a7090000 pid=2471->guuid=9f0ebd2d-1c00-0000-3654-b8334d0d0000 pid=3405 execve guuid=0ff6d26e-1a00-0000-3654-b833c4090000 pid=2500->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 122B 869ebe88-8c1e-5fbb-adb0-cfe48d8d7faf debian.map.fastly.net:443 guuid=0ff6d26e-1a00-0000-3654-b833c4090000 pid=2500->869ebe88-8c1e-5fbb-adb0-cfe48d8d7faf con guuid=43099f8c-1a00-0000-3654-b833f8090000 pid=2552 /usr/lib/apt/methods/gpgv delete-file write-file guuid=dc626e8b-1a00-0000-3654-b833f5090000 pid=2549->guuid=43099f8c-1a00-0000-3654-b833f8090000 pid=2552 clone guuid=594e42a2-1a00-0000-3654-b8332d0a0000 pid=2605 /usr/lib/apt/methods/gpgv delete-file write-file guuid=dc626e8b-1a00-0000-3654-b833f5090000 pid=2549->guuid=594e42a2-1a00-0000-3654-b8332d0a0000 pid=2605 clone guuid=cdd0aab3-1a00-0000-3654-b833770a0000 pid=2679 /usr/lib/apt/methods/gpgv delete-file write-file guuid=dc626e8b-1a00-0000-3654-b833f5090000 pid=2549->guuid=cdd0aab3-1a00-0000-3654-b833770a0000 pid=2679 clone guuid=f92f43cb-1a00-0000-3654-b833d00a0000 pid=2768 /usr/lib/apt/methods/gpgv delete-file write-file guuid=dc626e8b-1a00-0000-3654-b833f5090000 pid=2549->guuid=f92f43cb-1a00-0000-3654-b833d00a0000 pid=2768 clone guuid=0007378f-1a00-0000-3654-b833ff090000 pid=2559 /usr/bin/apt-key write-file guuid=43099f8c-1a00-0000-3654-b833f8090000 pid=2552->guuid=0007378f-1a00-0000-3654-b833ff090000 pid=2559 execve guuid=223a758f-1a00-0000-3654-b833010a0000 pid=2561 /usr/bin/dash guuid=0007378f-1a00-0000-3654-b833ff090000 pid=2559->guuid=223a758f-1a00-0000-3654-b833010a0000 pid=2561 clone guuid=8ac1978f-1a00-0000-3654-b833030a0000 pid=2563 /usr/bin/apt-config guuid=0007378f-1a00-0000-3654-b833ff090000 pid=2559->guuid=8ac1978f-1a00-0000-3654-b833030a0000 pid=2563 execve guuid=b7126f93-1a00-0000-3654-b833050a0000 pid=2565 /usr/bin/apt-config guuid=0007378f-1a00-0000-3654-b833ff090000 pid=2559->guuid=b7126f93-1a00-0000-3654-b833050a0000 pid=2565 execve guuid=44e74b95-1a00-0000-3654-b833070a0000 pid=2567 /usr/bin/apt-config guuid=0007378f-1a00-0000-3654-b833ff090000 pid=2559->guuid=44e74b95-1a00-0000-3654-b833070a0000 pid=2567 execve guuid=291a4497-1a00-0000-3654-b833090a0000 pid=2569 /usr/bin/apt-config guuid=0007378f-1a00-0000-3654-b833ff090000 pid=2559->guuid=291a4497-1a00-0000-3654-b833090a0000 pid=2569 execve guuid=f9953399-1a00-0000-3654-b8330c0a0000 pid=2572 /usr/bin/dash guuid=0007378f-1a00-0000-3654-b833ff090000 pid=2559->guuid=f9953399-1a00-0000-3654-b8330c0a0000 pid=2572 clone guuid=ca8c7199-1a00-0000-3654-b8330d0a0000 pid=2573 /usr/bin/apt-config guuid=0007378f-1a00-0000-3654-b833ff090000 pid=2559->guuid=ca8c7199-1a00-0000-3654-b8330d0a0000 pid=2573 execve guuid=e6d1489b-1a00-0000-3654-b833120a0000 pid=2578 /usr/bin/mktemp guuid=0007378f-1a00-0000-3654-b833ff090000 pid=2559->guuid=e6d1489b-1a00-0000-3654-b833120a0000 pid=2578 execve guuid=b8e29a9b-1a00-0000-3654-b833140a0000 pid=2580 /usr/bin/chmod guuid=0007378f-1a00-0000-3654-b833ff090000 pid=2559->guuid=b8e29a9b-1a00-0000-3654-b833140a0000 pid=2580 execve guuid=68a8cd9b-1a00-0000-3654-b833160a0000 pid=2582 /usr/bin/dash guuid=0007378f-1a00-0000-3654-b833ff090000 pid=2559->guuid=68a8cd9b-1a00-0000-3654-b833160a0000 pid=2582 clone guuid=3afbe69b-1a00-0000-3654-b833170a0000 pid=2583 /usr/bin/dash guuid=0007378f-1a00-0000-3654-b833ff090000 pid=2559->guuid=3afbe69b-1a00-0000-3654-b833170a0000 pid=2583 clone guuid=3db36a9c-1a00-0000-3654-b8331c0a0000 pid=2588 /usr/bin/dash guuid=0007378f-1a00-0000-3654-b833ff090000 pid=2559->guuid=3db36a9c-1a00-0000-3654-b8331c0a0000 pid=2588 clone guuid=1b01db9c-1a00-0000-3654-b833200a0000 pid=2592 /usr/bin/dash guuid=0007378f-1a00-0000-3654-b833ff090000 pid=2559->guuid=1b01db9c-1a00-0000-3654-b833200a0000 pid=2592 clone guuid=988bed9c-1a00-0000-3654-b833210a0000 pid=2593 /usr/bin/gpgv guuid=0007378f-1a00-0000-3654-b833ff090000 pid=2559->guuid=988bed9c-1a00-0000-3654-b833210a0000 pid=2593 execve guuid=ee61a89f-1a00-0000-3654-b833290a0000 pid=2601 /usr/bin/rm delete-file guuid=0007378f-1a00-0000-3654-b833ff090000 pid=2559->guuid=ee61a89f-1a00-0000-3654-b833290a0000 pid=2601 execve guuid=5423ec92-1a00-0000-3654-b833040a0000 pid=2564 /usr/bin/dpkg guuid=8ac1978f-1a00-0000-3654-b833030a0000 pid=2563->guuid=5423ec92-1a00-0000-3654-b833040a0000 pid=2564 execve guuid=f1378894-1a00-0000-3654-b833060a0000 pid=2566 /usr/bin/dpkg guuid=b7126f93-1a00-0000-3654-b833050a0000 pid=2565->guuid=f1378894-1a00-0000-3654-b833060a0000 pid=2566 execve guuid=15a89396-1a00-0000-3654-b833080a0000 pid=2568 /usr/bin/dpkg guuid=44e74b95-1a00-0000-3654-b833070a0000 pid=2567->guuid=15a89396-1a00-0000-3654-b833080a0000 pid=2568 execve guuid=3b248c98-1a00-0000-3654-b8330b0a0000 pid=2571 /usr/bin/dpkg guuid=291a4497-1a00-0000-3654-b833090a0000 pid=2569->guuid=3b248c98-1a00-0000-3654-b8330b0a0000 pid=2571 execve guuid=2acec49a-1a00-0000-3654-b833100a0000 pid=2576 /usr/bin/dpkg guuid=ca8c7199-1a00-0000-3654-b8330d0a0000 pid=2573->guuid=2acec49a-1a00-0000-3654-b833100a0000 pid=2576 execve guuid=b22bf09b-1a00-0000-3654-b833190a0000 pid=2585 /usr/bin/dash guuid=3afbe69b-1a00-0000-3654-b833170a0000 pid=2583->guuid=b22bf09b-1a00-0000-3654-b833190a0000 pid=2585 clone guuid=159ef99b-1a00-0000-3654-b8331a0a0000 pid=2586 /usr/bin/sed guuid=3afbe69b-1a00-0000-3654-b833170a0000 pid=2583->guuid=159ef99b-1a00-0000-3654-b8331a0a0000 pid=2586 execve guuid=c849779c-1a00-0000-3654-b8331d0a0000 pid=2589 /usr/bin/dash guuid=3db36a9c-1a00-0000-3654-b8331c0a0000 pid=2588->guuid=c849779c-1a00-0000-3654-b8331d0a0000 pid=2589 clone guuid=6cbb7e9c-1a00-0000-3654-b8331e0a0000 pid=2590 /usr/bin/sed guuid=3db36a9c-1a00-0000-3654-b8331c0a0000 pid=2588->guuid=6cbb7e9c-1a00-0000-3654-b8331e0a0000 pid=2590 execve guuid=4ca769a3-1a00-0000-3654-b833310a0000 pid=2609 /usr/bin/apt-key write-file guuid=594e42a2-1a00-0000-3654-b8332d0a0000 pid=2605->guuid=4ca769a3-1a00-0000-3654-b833310a0000 pid=2609 execve guuid=a74bc3a3-1a00-0000-3654-b833330a0000 pid=2611 /usr/bin/dash guuid=4ca769a3-1a00-0000-3654-b833310a0000 pid=2609->guuid=a74bc3a3-1a00-0000-3654-b833330a0000 pid=2611 clone guuid=eee7d4a3-1a00-0000-3654-b833340a0000 pid=2612 /usr/bin/apt-config guuid=4ca769a3-1a00-0000-3654-b833310a0000 pid=2609->guuid=eee7d4a3-1a00-0000-3654-b833340a0000 pid=2612 execve guuid=87efeba5-1a00-0000-3654-b8333c0a0000 pid=2620 /usr/bin/apt-config guuid=4ca769a3-1a00-0000-3654-b833310a0000 pid=2609->guuid=87efeba5-1a00-0000-3654-b8333c0a0000 pid=2620 execve guuid=ae9eaea7-1a00-0000-3654-b833420a0000 pid=2626 /usr/bin/apt-config guuid=4ca769a3-1a00-0000-3654-b833310a0000 pid=2609->guuid=ae9eaea7-1a00-0000-3654-b833420a0000 pid=2626 execve guuid=17e2baa9-1a00-0000-3654-b8334a0a0000 pid=2634 /usr/bin/apt-config guuid=4ca769a3-1a00-0000-3654-b833310a0000 pid=2609->guuid=17e2baa9-1a00-0000-3654-b8334a0a0000 pid=2634 execve guuid=6886e8ac-1a00-0000-3654-b833530a0000 pid=2643 /usr/bin/dash guuid=4ca769a3-1a00-0000-3654-b833310a0000 pid=2609->guuid=6886e8ac-1a00-0000-3654-b833530a0000 pid=2643 clone guuid=bbca0aad-1a00-0000-3654-b833550a0000 pid=2645 /usr/bin/apt-config guuid=4ca769a3-1a00-0000-3654-b833310a0000 pid=2609->guuid=bbca0aad-1a00-0000-3654-b833550a0000 pid=2645 execve guuid=d66c5baf-1a00-0000-3654-b8335e0a0000 pid=2654 /usr/bin/mktemp guuid=4ca769a3-1a00-0000-3654-b833310a0000 pid=2609->guuid=d66c5baf-1a00-0000-3654-b8335e0a0000 pid=2654 execve guuid=4acca8af-1a00-0000-3654-b833610a0000 pid=2657 /usr/bin/chmod guuid=4ca769a3-1a00-0000-3654-b833310a0000 pid=2609->guuid=4acca8af-1a00-0000-3654-b833610a0000 pid=2657 execve guuid=f7aee2af-1a00-0000-3654-b833630a0000 pid=2659 /usr/bin/dash guuid=4ca769a3-1a00-0000-3654-b833310a0000 pid=2609->guuid=f7aee2af-1a00-0000-3654-b833630a0000 pid=2659 clone guuid=5f7bf3af-1a00-0000-3654-b833640a0000 pid=2660 /usr/bin/dash guuid=4ca769a3-1a00-0000-3654-b833310a0000 pid=2609->guuid=5f7bf3af-1a00-0000-3654-b833640a0000 pid=2660 clone guuid=b0ef5cb0-1a00-0000-3654-b833680a0000 pid=2664 /usr/bin/dash guuid=4ca769a3-1a00-0000-3654-b833310a0000 pid=2609->guuid=b0ef5cb0-1a00-0000-3654-b833680a0000 pid=2664 clone guuid=7d80cab0-1a00-0000-3654-b8336c0a0000 pid=2668 /usr/bin/dash guuid=4ca769a3-1a00-0000-3654-b833310a0000 pid=2609->guuid=7d80cab0-1a00-0000-3654-b8336c0a0000 pid=2668 clone guuid=406de1b0-1a00-0000-3654-b8336e0a0000 pid=2670 /usr/bin/gpgv guuid=4ca769a3-1a00-0000-3654-b833310a0000 pid=2609->guuid=406de1b0-1a00-0000-3654-b8336e0a0000 pid=2670 execve guuid=c142a3b2-1a00-0000-3654-b833740a0000 pid=2676 /usr/bin/rm delete-file guuid=4ca769a3-1a00-0000-3654-b833310a0000 pid=2609->guuid=c142a3b2-1a00-0000-3654-b833740a0000 pid=2676 execve guuid=f6ed63a5-1a00-0000-3654-b833390a0000 pid=2617 /usr/bin/dpkg guuid=eee7d4a3-1a00-0000-3654-b833340a0000 pid=2612->guuid=f6ed63a5-1a00-0000-3654-b833390a0000 pid=2617 execve guuid=3a68f8a6-1a00-0000-3654-b833400a0000 pid=2624 /usr/bin/dpkg guuid=87efeba5-1a00-0000-3654-b8333c0a0000 pid=2620->guuid=3a68f8a6-1a00-0000-3654-b833400a0000 pid=2624 execve guuid=17fb12a9-1a00-0000-3654-b833470a0000 pid=2631 /usr/bin/dpkg guuid=ae9eaea7-1a00-0000-3654-b833420a0000 pid=2626->guuid=17fb12a9-1a00-0000-3654-b833470a0000 pid=2631 execve guuid=412526ac-1a00-0000-3654-b833510a0000 pid=2641 /usr/bin/dpkg guuid=17e2baa9-1a00-0000-3654-b8334a0a0000 pid=2634->guuid=412526ac-1a00-0000-3654-b833510a0000 pid=2641 execve guuid=df1df2ae-1a00-0000-3654-b8335c0a0000 pid=2652 /usr/bin/dpkg guuid=bbca0aad-1a00-0000-3654-b833550a0000 pid=2645->guuid=df1df2ae-1a00-0000-3654-b8335c0a0000 pid=2652 execve guuid=2a5efcaf-1a00-0000-3654-b833650a0000 pid=2661 /usr/bin/dash guuid=5f7bf3af-1a00-0000-3654-b833640a0000 pid=2660->guuid=2a5efcaf-1a00-0000-3654-b833650a0000 pid=2661 clone guuid=da4602b0-1a00-0000-3654-b833660a0000 pid=2662 /usr/bin/sed guuid=5f7bf3af-1a00-0000-3654-b833640a0000 pid=2660->guuid=da4602b0-1a00-0000-3654-b833660a0000 pid=2662 execve guuid=51846db0-1a00-0000-3654-b833690a0000 pid=2665 /usr/bin/dash guuid=b0ef5cb0-1a00-0000-3654-b833680a0000 pid=2664->guuid=51846db0-1a00-0000-3654-b833690a0000 pid=2665 clone guuid=3d9d74b0-1a00-0000-3654-b8336a0a0000 pid=2666 /usr/bin/sed guuid=b0ef5cb0-1a00-0000-3654-b833680a0000 pid=2664->guuid=3d9d74b0-1a00-0000-3654-b8336a0a0000 pid=2666 execve guuid=6117a1b4-1a00-0000-3654-b8337b0a0000 pid=2683 /usr/bin/apt-key write-file guuid=cdd0aab3-1a00-0000-3654-b833770a0000 pid=2679->guuid=6117a1b4-1a00-0000-3654-b8337b0a0000 pid=2683 execve guuid=93b3d9b4-1a00-0000-3654-b8337d0a0000 pid=2685 /usr/bin/dash guuid=6117a1b4-1a00-0000-3654-b8337b0a0000 pid=2683->guuid=93b3d9b4-1a00-0000-3654-b8337d0a0000 pid=2685 clone guuid=59cbf3b4-1a00-0000-3654-b8337e0a0000 pid=2686 /usr/bin/apt-config guuid=6117a1b4-1a00-0000-3654-b8337b0a0000 pid=2683->guuid=59cbf3b4-1a00-0000-3654-b8337e0a0000 pid=2686 execve guuid=416a92b8-1a00-0000-3654-b833880a0000 pid=2696 /usr/bin/apt-config guuid=6117a1b4-1a00-0000-3654-b8337b0a0000 pid=2683->guuid=416a92b8-1a00-0000-3654-b833880a0000 pid=2696 execve guuid=e50ce9ba-1a00-0000-3654-b833910a0000 pid=2705 /usr/bin/apt-config guuid=6117a1b4-1a00-0000-3654-b8337b0a0000 pid=2683->guuid=e50ce9ba-1a00-0000-3654-b833910a0000 pid=2705 execve guuid=d589dec0-1a00-0000-3654-b8339f0a0000 pid=2719 /usr/bin/apt-config guuid=6117a1b4-1a00-0000-3654-b8337b0a0000 pid=2683->guuid=d589dec0-1a00-0000-3654-b8339f0a0000 pid=2719 execve guuid=601094c2-1a00-0000-3654-b833a50a0000 pid=2725 /usr/bin/dash guuid=6117a1b4-1a00-0000-3654-b8337b0a0000 pid=2683->guuid=601094c2-1a00-0000-3654-b833a50a0000 pid=2725 clone guuid=1918dec2-1a00-0000-3654-b833a70a0000 pid=2727 /usr/bin/apt-config guuid=6117a1b4-1a00-0000-3654-b8337b0a0000 pid=2683->guuid=1918dec2-1a00-0000-3654-b833a70a0000 pid=2727 execve guuid=9ae783c5-1a00-0000-3654-b833b20a0000 pid=2738 /usr/bin/mktemp guuid=6117a1b4-1a00-0000-3654-b8337b0a0000 pid=2683->guuid=9ae783c5-1a00-0000-3654-b833b20a0000 pid=2738 execve guuid=d382b4c5-1a00-0000-3654-b833b30a0000 pid=2739 /usr/bin/chmod guuid=6117a1b4-1a00-0000-3654-b8337b0a0000 pid=2683->guuid=d382b4c5-1a00-0000-3654-b833b30a0000 pid=2739 execve guuid=bae103c6-1a00-0000-3654-b833b60a0000 pid=2742 /usr/bin/dash guuid=6117a1b4-1a00-0000-3654-b8337b0a0000 pid=2683->guuid=bae103c6-1a00-0000-3654-b833b60a0000 pid=2742 clone guuid=7f9d20c6-1a00-0000-3654-b833b70a0000 pid=2743 /usr/bin/dash guuid=6117a1b4-1a00-0000-3654-b8337b0a0000 pid=2683->guuid=7f9d20c6-1a00-0000-3654-b833b70a0000 pid=2743 clone guuid=363983c6-1a00-0000-3654-b833bb0a0000 pid=2747 /usr/bin/dash guuid=6117a1b4-1a00-0000-3654-b8337b0a0000 pid=2683->guuid=363983c6-1a00-0000-3654-b833bb0a0000 pid=2747 clone guuid=989de8c6-1a00-0000-3654-b833be0a0000 pid=2750 /usr/bin/dash guuid=6117a1b4-1a00-0000-3654-b8337b0a0000 pid=2683->guuid=989de8c6-1a00-0000-3654-b833be0a0000 pid=2750 clone guuid=fb1ffdc6-1a00-0000-3654-b833c00a0000 pid=2752 /usr/bin/gpgv guuid=6117a1b4-1a00-0000-3654-b8337b0a0000 pid=2683->guuid=fb1ffdc6-1a00-0000-3654-b833c00a0000 pid=2752 execve guuid=e5f5b3c9-1a00-0000-3654-b833cb0a0000 pid=2763 /usr/bin/rm delete-file guuid=6117a1b4-1a00-0000-3654-b8337b0a0000 pid=2683->guuid=e5f5b3c9-1a00-0000-3654-b833cb0a0000 pid=2763 execve guuid=31e6e2b7-1a00-0000-3654-b833860a0000 pid=2694 /usr/bin/dpkg guuid=59cbf3b4-1a00-0000-3654-b8337e0a0000 pid=2686->guuid=31e6e2b7-1a00-0000-3654-b833860a0000 pid=2694 execve guuid=12f563ba-1a00-0000-3654-b833900a0000 pid=2704 /usr/bin/dpkg guuid=416a92b8-1a00-0000-3654-b833880a0000 pid=2696->guuid=12f563ba-1a00-0000-3654-b833900a0000 pid=2704 execve guuid=640614bc-1a00-0000-3654-b833940a0000 pid=2708 /usr/bin/dpkg guuid=e50ce9ba-1a00-0000-3654-b833910a0000 pid=2705->guuid=640614bc-1a00-0000-3654-b833940a0000 pid=2708 execve guuid=d728d9c1-1a00-0000-3654-b833a20a0000 pid=2722 /usr/bin/dpkg guuid=d589dec0-1a00-0000-3654-b8339f0a0000 pid=2719->guuid=d728d9c1-1a00-0000-3654-b833a20a0000 pid=2722 execve guuid=7a6903c5-1a00-0000-3654-b833af0a0000 pid=2735 /usr/bin/dpkg guuid=1918dec2-1a00-0000-3654-b833a70a0000 pid=2727->guuid=7a6903c5-1a00-0000-3654-b833af0a0000 pid=2735 execve guuid=4b3f2dc6-1a00-0000-3654-b833b80a0000 pid=2744 /usr/bin/dash guuid=7f9d20c6-1a00-0000-3654-b833b70a0000 pid=2743->guuid=4b3f2dc6-1a00-0000-3654-b833b80a0000 pid=2744 clone guuid=68d134c6-1a00-0000-3654-b833b90a0000 pid=2745 /usr/bin/sed guuid=7f9d20c6-1a00-0000-3654-b833b70a0000 pid=2743->guuid=68d134c6-1a00-0000-3654-b833b90a0000 pid=2745 execve guuid=5ba58cc6-1a00-0000-3654-b833bc0a0000 pid=2748 /usr/bin/dash guuid=363983c6-1a00-0000-3654-b833bb0a0000 pid=2747->guuid=5ba58cc6-1a00-0000-3654-b833bc0a0000 pid=2748 clone guuid=fe2893c6-1a00-0000-3654-b833bd0a0000 pid=2749 /usr/bin/sed guuid=363983c6-1a00-0000-3654-b833bb0a0000 pid=2747->guuid=fe2893c6-1a00-0000-3654-b833bd0a0000 pid=2749 execve guuid=e8cae3cb-1a00-0000-3654-b833d30a0000 pid=2771 /usr/bin/apt-key write-file guuid=f92f43cb-1a00-0000-3654-b833d00a0000 pid=2768->guuid=e8cae3cb-1a00-0000-3654-b833d30a0000 pid=2771 execve guuid=62de1dcc-1a00-0000-3654-b833d50a0000 pid=2773 /usr/bin/dash guuid=e8cae3cb-1a00-0000-3654-b833d30a0000 pid=2771->guuid=62de1dcc-1a00-0000-3654-b833d50a0000 pid=2773 clone guuid=56c835cc-1a00-0000-3654-b833d60a0000 pid=2774 /usr/bin/apt-config guuid=e8cae3cb-1a00-0000-3654-b833d30a0000 pid=2771->guuid=56c835cc-1a00-0000-3654-b833d60a0000 pid=2774 execve guuid=177e6cce-1a00-0000-3654-b833dd0a0000 pid=2781 /usr/bin/apt-config guuid=e8cae3cb-1a00-0000-3654-b833d30a0000 pid=2771->guuid=177e6cce-1a00-0000-3654-b833dd0a0000 pid=2781 execve guuid=b0d7d4d0-1a00-0000-3654-b833e80a0000 pid=2792 /usr/bin/apt-config guuid=e8cae3cb-1a00-0000-3654-b833d30a0000 pid=2771->guuid=b0d7d4d0-1a00-0000-3654-b833e80a0000 pid=2792 execve guuid=1076cfd2-1a00-0000-3654-b833f10a0000 pid=2801 /usr/bin/apt-config guuid=e8cae3cb-1a00-0000-3654-b833d30a0000 pid=2771->guuid=1076cfd2-1a00-0000-3654-b833f10a0000 pid=2801 execve guuid=b3e747d4-1a00-0000-3654-b833f70a0000 pid=2807 /usr/bin/dash guuid=e8cae3cb-1a00-0000-3654-b833d30a0000 pid=2771->guuid=b3e747d4-1a00-0000-3654-b833f70a0000 pid=2807 clone guuid=b90568d4-1a00-0000-3654-b833f90a0000 pid=2809 /usr/bin/apt-config guuid=e8cae3cb-1a00-0000-3654-b833d30a0000 pid=2771->guuid=b90568d4-1a00-0000-3654-b833f90a0000 pid=2809 execve guuid=d17420dc-1a00-0000-3654-b8330d0b0000 pid=2829 /usr/bin/mktemp guuid=e8cae3cb-1a00-0000-3654-b833d30a0000 pid=2771->guuid=d17420dc-1a00-0000-3654-b8330d0b0000 pid=2829 execve guuid=d2b5f1dc-1a00-0000-3654-b833110b0000 pid=2833 /usr/bin/chmod guuid=e8cae3cb-1a00-0000-3654-b833d30a0000 pid=2771->guuid=d2b5f1dc-1a00-0000-3654-b833110b0000 pid=2833 execve guuid=0afe21dd-1a00-0000-3654-b833120b0000 pid=2834 /usr/bin/dash guuid=e8cae3cb-1a00-0000-3654-b833d30a0000 pid=2771->guuid=0afe21dd-1a00-0000-3654-b833120b0000 pid=2834 clone guuid=ab2785dd-1a00-0000-3654-b833150b0000 pid=2837 /usr/bin/dash guuid=e8cae3cb-1a00-0000-3654-b833d30a0000 pid=2771->guuid=ab2785dd-1a00-0000-3654-b833150b0000 pid=2837 clone guuid=63458dde-1a00-0000-3654-b8331a0b0000 pid=2842 /usr/bin/dash guuid=e8cae3cb-1a00-0000-3654-b833d30a0000 pid=2771->guuid=63458dde-1a00-0000-3654-b8331a0b0000 pid=2842 clone guuid=77155cdf-1a00-0000-3654-b8331f0b0000 pid=2847 /usr/bin/dash guuid=e8cae3cb-1a00-0000-3654-b833d30a0000 pid=2771->guuid=77155cdf-1a00-0000-3654-b8331f0b0000 pid=2847 clone guuid=ff7969df-1a00-0000-3654-b833200b0000 pid=2848 /usr/bin/gpgv guuid=e8cae3cb-1a00-0000-3654-b833d30a0000 pid=2771->guuid=ff7969df-1a00-0000-3654-b833200b0000 pid=2848 execve guuid=5e2a97e1-1a00-0000-3654-b833250b0000 pid=2853 /usr/bin/rm delete-file guuid=e8cae3cb-1a00-0000-3654-b833d30a0000 pid=2771->guuid=5e2a97e1-1a00-0000-3654-b833250b0000 pid=2853 execve guuid=3196bacd-1a00-0000-3654-b833db0a0000 pid=2779 /usr/bin/dpkg guuid=56c835cc-1a00-0000-3654-b833d60a0000 pid=2774->guuid=3196bacd-1a00-0000-3654-b833db0a0000 pid=2779 execve guuid=dfd527d0-1a00-0000-3654-b833e40a0000 pid=2788 /usr/bin/dpkg guuid=177e6cce-1a00-0000-3654-b833dd0a0000 pid=2781->guuid=dfd527d0-1a00-0000-3654-b833e40a0000 pid=2788 execve guuid=ace66ad2-1a00-0000-3654-b833ef0a0000 pid=2799 /usr/bin/dpkg guuid=b0d7d4d0-1a00-0000-3654-b833e80a0000 pid=2792->guuid=ace66ad2-1a00-0000-3654-b833ef0a0000 pid=2799 execve guuid=1fdbc8d3-1a00-0000-3654-b833f50a0000 pid=2805 /usr/bin/dpkg guuid=1076cfd2-1a00-0000-3654-b833f10a0000 pid=2801->guuid=1fdbc8d3-1a00-0000-3654-b833f50a0000 pid=2805 execve guuid=f690fdd5-1a00-0000-3654-b833fd0a0000 pid=2813 /usr/bin/dpkg guuid=b90568d4-1a00-0000-3654-b833f90a0000 pid=2809->guuid=f690fdd5-1a00-0000-3654-b833fd0a0000 pid=2813 execve guuid=10388ddd-1a00-0000-3654-b833160b0000 pid=2838 /usr/bin/dash guuid=ab2785dd-1a00-0000-3654-b833150b0000 pid=2837->guuid=10388ddd-1a00-0000-3654-b833160b0000 pid=2838 clone guuid=947091dd-1a00-0000-3654-b833170b0000 pid=2839 /usr/bin/sed guuid=ab2785dd-1a00-0000-3654-b833150b0000 pid=2837->guuid=947091dd-1a00-0000-3654-b833170b0000 pid=2839 execve guuid=ab8596de-1a00-0000-3654-b8331b0b0000 pid=2843 /usr/bin/dash guuid=63458dde-1a00-0000-3654-b8331a0b0000 pid=2842->guuid=ab8596de-1a00-0000-3654-b8331b0b0000 pid=2843 clone guuid=c7f49bde-1a00-0000-3654-b8331c0b0000 pid=2844 /usr/bin/sed guuid=63458dde-1a00-0000-3654-b8331a0b0000 pid=2842->guuid=c7f49bde-1a00-0000-3654-b8331c0b0000 pid=2844 execve guuid=f7d9f539-1c00-0000-3654-b833640d0000 pid=3428 /usr/bin/dpkg guuid=d0268f38-1c00-0000-3654-b833620d0000 pid=3426->guuid=f7d9f539-1c00-0000-3654-b833640d0000 pid=3428 execve guuid=3da0113b-1c00-0000-3654-b833690d0000 pid=3433->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 164B 75aab096-419b-50ef-be46-7d76b6a90e4c github.com:443 guuid=3da0113b-1c00-0000-3654-b833690d0000 pid=3433->75aab096-419b-50ef-be46-7d76b6a90e4c send: 799B f8c5e44f-328d-5324-8bbd-da50752b9120 release-assets.githubusercontent.com:0 guuid=3da0113b-1c00-0000-3654-b833690d0000 pid=3433->f8c5e44f-328d-5324-8bbd-da50752b9120 con f0eebea5-e97d-507c-a771-59cac353877c release-assets.githubusercontent.com:443 guuid=3da0113b-1c00-0000-3654-b833690d0000 pid=3433->f0eebea5-e97d-507c-a771-59cac353877c send: 1634B guuid=7a91385e-1c00-0000-3654-b833b10d0000 pid=3505 /usr/bin/xz guuid=0ad2e45d-1c00-0000-3654-b833af0d0000 pid=3503->guuid=7a91385e-1c00-0000-3654-b833b10d0000 pid=3505 execve 2f50a59f-2358-5b5c-aa0a-c8fc64202aee hosts-to-ignore.ignorelist.com:1443 guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=3591->2f50a59f-2358-5b5c-aa0a-c8fc64202aee send: 859B guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=3603 /usr/lib/dev/systemdev/systemd-mont write-file zombie guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=3591->guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=3603 clone guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=3604 /usr/lib/dev/systemdev/systemd-mont dns net send-data zombie guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=3591->guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=3604 clone guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=3605 /usr/lib/dev/systemdev/systemd-mont guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=3591->guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=3605 clone guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=3606 /usr/lib/dev/systemdev/systemd-mont guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=3591->guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=3606 clone guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=3607 /usr/lib/dev/systemdev/systemd-mont guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=3591->guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=3607 clone guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5211 /usr/lib/dev/systemdev/systemd-mont zombie guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=3591->guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5211 clone guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5212 /usr/lib/dev/systemdev/systemd-mont zombie guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=3591->guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5212 clone guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5213 /usr/lib/dev/systemdev/systemd-mont zombie guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=3591->guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5213 clone guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5214 /usr/lib/dev/systemdev/systemd-mont zombie guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=3591->guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5214 clone guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5221 /usr/lib/dev/systemdev/systemd-mont zombie guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=3591->guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5221 clone guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5222 /usr/lib/dev/systemdev/systemd-mont zombie guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=3591->guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5222 clone guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5223 /usr/lib/dev/systemdev/systemd-mont zombie guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=3591->guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5223 clone guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5224 /usr/lib/dev/systemdev/systemd-mont zombie guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=3591->guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5224 clone guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5243 /usr/lib/dev/systemdev/systemd-mont zombie guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=3591->guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5243 clone guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5244 /usr/lib/dev/systemdev/systemd-mont zombie guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=3591->guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5244 clone guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5246 /usr/lib/dev/systemdev/systemd-mont zombie guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=3591->guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5246 clone guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5247 /usr/lib/dev/systemdev/systemd-mont zombie guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=3591->guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5247 clone guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5269 /usr/lib/dev/systemdev/systemd-mont zombie guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=3591->guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5269 clone guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5270 /usr/lib/dev/systemdev/systemd-mont zombie guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=3591->guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5270 clone guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5271 /usr/lib/dev/systemdev/systemd-mont zombie guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=3591->guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5271 clone guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5272 /usr/lib/dev/systemdev/systemd-mont zombie guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=3591->guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5272 clone guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5292 /usr/lib/dev/systemdev/systemd-mont zombie guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=3591->guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5292 clone guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5293 /usr/lib/dev/systemdev/systemd-mont zombie guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=3591->guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5293 clone guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5294 /usr/lib/dev/systemdev/systemd-mont zombie guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=3591->guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5294 clone guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5295 /usr/lib/dev/systemdev/systemd-mont zombie guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=3591->guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5295 clone guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5315 /usr/lib/dev/systemdev/systemd-mont zombie guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=3591->guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5315 clone guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5316 /usr/lib/dev/systemdev/systemd-mont zombie guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=3591->guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5316 clone guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5317 /usr/lib/dev/systemdev/systemd-mont zombie guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=3591->guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5317 clone guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5318 /usr/lib/dev/systemdev/systemd-mont zombie guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=3591->guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5318 clone guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5343 /usr/lib/dev/systemdev/systemd-mont zombie guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=3591->guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5343 clone guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5344 /usr/lib/dev/systemdev/systemd-mont zombie guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=3591->guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5344 clone guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5345 /usr/lib/dev/systemdev/systemd-mont zombie guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=3591->guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5345 clone guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5346 /usr/lib/dev/systemdev/systemd-mont zombie guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=3591->guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5346 clone guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5368 /usr/lib/dev/systemdev/systemd-mont zombie guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=3591->guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5368 clone guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5369 /usr/lib/dev/systemdev/systemd-mont zombie guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=3591->guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5369 clone guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5370 /usr/lib/dev/systemdev/systemd-mont zombie guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=3591->guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5370 clone guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5371 /usr/lib/dev/systemdev/systemd-mont zombie guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=3591->guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5371 clone guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5398 /usr/lib/dev/systemdev/systemd-mont zombie guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=3591->guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5398 clone guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5400 /usr/lib/dev/systemdev/systemd-mont zombie guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=3591->guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5400 clone guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5401 /usr/lib/dev/systemdev/systemd-mont zombie guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=3591->guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5401 clone guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5402 /usr/lib/dev/systemdev/systemd-mont zombie guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=3591->guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5402 clone guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5403 /usr/lib/dev/systemdev/systemd-mont zombie guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=3591->guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5403 clone guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5404 /usr/lib/dev/systemdev/systemd-mont zombie guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=3591->guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5404 clone guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5405 /usr/lib/dev/systemdev/systemd-mont zombie guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=3591->guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5405 clone guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5406 /usr/lib/dev/systemdev/systemd-mont zombie guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=3591->guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5406 clone guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5409 /usr/lib/dev/systemdev/systemd-mont zombie guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=3591->guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5409 clone guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5410 /usr/lib/dev/systemdev/systemd-mont zombie guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=3591->guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5410 clone guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5411 /usr/lib/dev/systemdev/systemd-mont zombie guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=3591->guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5411 clone guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5412 /usr/lib/dev/systemdev/systemd-mont zombie guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=3591->guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5412 clone guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5422 /usr/lib/dev/systemdev/systemd-mont zombie guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=3591->guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5422 clone guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5423 /usr/lib/dev/systemdev/systemd-mont zombie guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=3591->guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5423 clone guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5424 /usr/lib/dev/systemdev/systemd-mont zombie guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=3591->guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5424 clone guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5425 /usr/lib/dev/systemdev/systemd-mont zombie guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=3591->guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=5425 clone guuid=f00e4f79-1c00-0000-3654-b833070e0000 pid=3604->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 240B
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2025-08-24 13:35:53 UTC
File Type:
Text (Shell)
AV detection:
9 of 24 (37.50%)
Threat level:
  5/5
Result
Malware family:
xmrig_linux
Score:
  10/10
Tags:
family:xmrig family:xmrig_linux antivm defense_evasion discovery linux miner
Behaviour
Enumerates kernel/hardware configuration
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads CPU attributes
Checks hardware identifiers (DMI)
Enumerates running processes
Reads hardware information
File and Directory Permissions Modification
Executes dropped EXE
XMRig Miner payload
Xmrig family
Xmrig_linux family
xmrig
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Distributed via web download

Comments