MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 857d463c693b5c80236eff885408ce3ddbfc45f94e9a5022fe67ebbc090ba151. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



PumaBot


Vendor detections: 8


Intelligence 8 IOCs YARA 8 File information Comments

SHA256 hash: 857d463c693b5c80236eff885408ce3ddbfc45f94e9a5022fe67ebbc090ba151
SHA3-384 hash: 019d140862a35a14e2c84bd9ba5c3735e02b2281a5216ede5ad20ddc2c53c72416e84978ce819713aa315d310368ad60
SHA1 hash: 08707d71625644cba93835512d1a6413e1ff3298
MD5 hash: c3f1b3e25876af35eda033d91d57dd9f
humanhash: aspen-muppet-eleven-eighteen
File name:jiedian
Download: download sample
Signature PumaBot
File size:2'618'680 bytes
First seen:2025-11-13 18:37:01 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 49152:k4Fb7UQogZfExV0s1jRITst794gVEifZp8kEz1Sb3ODCoi/WZjH:kSZow9sXIYx4axERuoi/WV
TLSH T191C53397425E4F89D38FF5AC7B2B49FA10CD96B252B0809E0C579E8E82B11FDCDA3415
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter abuse_ch
Tags:elf PumaBot

Intelligence


File Origin
# of uploads :
1
# of downloads :
38
Origin country :
DE DE
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:
Gathering data
Verdict:
Malicious
Uses P2P?:
false
Uses anti-vm?:
true
Architecture:
x86
Packer:
custom
Botnet:
unknown
Number of open files:
685
Number of processes launched:
1471
Processes remaning?
true
Remote TCP ports scanned:
not identified
Behaviour
Anti-VM
Persistence
Process Renaming
Botnet C2s
TCP botnet C2(s):
not identified
UDP botnet C2(s):
not identified
Verdict:
Clean
File Type:
elf.64.le
First seen:
2025-11-13T15:57:00Z UTC
Last seen:
2025-11-13T16:10:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=17619036-1b00-0000-513a-9d37480b0000 pid=2888 /usr/bin/sudo guuid=ee258a39-1b00-0000-513a-9d374f0b0000 pid=2895 /tmp/sample.bin mprotect-exec guuid=17619036-1b00-0000-513a-9d37480b0000 pid=2888->guuid=ee258a39-1b00-0000-513a-9d374f0b0000 pid=2895 execve guuid=ee258a39-1b00-0000-513a-9d374f0b0000 pid=2927 /tmp/sample.bin guuid=ee258a39-1b00-0000-513a-9d374f0b0000 pid=2895->guuid=ee258a39-1b00-0000-513a-9d374f0b0000 pid=2927 clone guuid=ee258a39-1b00-0000-513a-9d374f0b0000 pid=2928 /tmp/sample.bin write-config guuid=ee258a39-1b00-0000-513a-9d374f0b0000 pid=2895->guuid=ee258a39-1b00-0000-513a-9d374f0b0000 pid=2928 clone guuid=ee258a39-1b00-0000-513a-9d374f0b0000 pid=2929 /tmp/sample.bin guuid=ee258a39-1b00-0000-513a-9d374f0b0000 pid=2895->guuid=ee258a39-1b00-0000-513a-9d374f0b0000 pid=2929 clone guuid=ee258a39-1b00-0000-513a-9d374f0b0000 pid=2930 /tmp/sample.bin guuid=ee258a39-1b00-0000-513a-9d374f0b0000 pid=2895->guuid=ee258a39-1b00-0000-513a-9d374f0b0000 pid=2930 clone guuid=ee258a39-1b00-0000-513a-9d374f0b0000 pid=2931 /tmp/sample.bin guuid=ee258a39-1b00-0000-513a-9d374f0b0000 pid=2895->guuid=ee258a39-1b00-0000-513a-9d374f0b0000 pid=2931 clone guuid=6b9d095d-1b00-0000-513a-9d377b0b0000 pid=2939 /tmp/sample.bin guuid=ee258a39-1b00-0000-513a-9d374f0b0000 pid=2931->guuid=6b9d095d-1b00-0000-513a-9d377b0b0000 pid=2939 clone guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2940 /tmp/sample.bin delete-file mprotect-exec zombie guuid=ee258a39-1b00-0000-513a-9d374f0b0000 pid=2931->guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2940 execve guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2956 /tmp/sample.bin zombie guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2940->guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2956 clone guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2957 /tmp/sample.bin delete-file write-config zombie guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2940->guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2957 clone guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2958 /tmp/sample.bin guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2940->guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2958 clone guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2959 /tmp/sample.bin write-config write-file zombie guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2940->guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2959 clone guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2960 /tmp/sample.bin delete-file write-config zombie guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2940->guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2960 clone guuid=7b8bd966-1b00-0000-513a-9d37910b0000 pid=2961 /tmp/sample.bin guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2940->guuid=7b8bd966-1b00-0000-513a-9d37910b0000 pid=2961 clone guuid=4312e166-1b00-0000-513a-9d37920b0000 pid=2962 /usr/bin/mount guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2940->guuid=4312e166-1b00-0000-513a-9d37920b0000 pid=2962 execve guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=2967 /tmp/sample.bin delete-file mprotect-exec net send-data write-config guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2940->guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=2967 execve guuid=a9ecf266-1b00-0000-513a-9d37930b0000 pid=2963 /usr/bin/pgrep guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2958->guuid=a9ecf266-1b00-0000-513a-9d37930b0000 pid=2963 execve guuid=9f659377-1b00-0000-513a-9d37b50b0000 pid=2997 /usr/bin/pgrep guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2958->guuid=9f659377-1b00-0000-513a-9d37b50b0000 pid=2997 execve guuid=ebdf4d89-1b00-0000-513a-9d37cb0b0000 pid=3019 /usr/bin/pgrep guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2958->guuid=ebdf4d89-1b00-0000-513a-9d37cb0b0000 pid=3019 execve guuid=8d227093-1b00-0000-513a-9d37dc0b0000 pid=3036 /usr/bin/pgrep guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2958->guuid=8d227093-1b00-0000-513a-9d37dc0b0000 pid=3036 execve guuid=0da4d29e-1b00-0000-513a-9d37ed0b0000 pid=3053 /usr/bin/pgrep guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2958->guuid=0da4d29e-1b00-0000-513a-9d37ed0b0000 pid=3053 execve guuid=46c312a6-1b00-0000-513a-9d37070c0000 pid=3079 /usr/bin/pgrep guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2958->guuid=46c312a6-1b00-0000-513a-9d37070c0000 pid=3079 execve guuid=c5b7e1aa-1b00-0000-513a-9d371b0c0000 pid=3099 /usr/bin/pgrep guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2958->guuid=c5b7e1aa-1b00-0000-513a-9d371b0c0000 pid=3099 execve guuid=5a2813ae-1b00-0000-513a-9d37250c0000 pid=3109 /usr/bin/pgrep guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2958->guuid=5a2813ae-1b00-0000-513a-9d37250c0000 pid=3109 execve guuid=25b833b2-1b00-0000-513a-9d372f0c0000 pid=3119 /usr/bin/pgrep guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2958->guuid=25b833b2-1b00-0000-513a-9d372f0c0000 pid=3119 execve guuid=cfdbe7b7-1b00-0000-513a-9d373c0c0000 pid=3132 /usr/bin/pgrep guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2958->guuid=cfdbe7b7-1b00-0000-513a-9d373c0c0000 pid=3132 execve guuid=16b0fdbc-1b00-0000-513a-9d37580c0000 pid=3160 /usr/bin/pgrep guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2958->guuid=16b0fdbc-1b00-0000-513a-9d37580c0000 pid=3160 execve guuid=b9dd40c6-1b00-0000-513a-9d37720c0000 pid=3186 /usr/bin/pgrep guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2958->guuid=b9dd40c6-1b00-0000-513a-9d37720c0000 pid=3186 execve guuid=1874c6d5-1b00-0000-513a-9d379c0c0000 pid=3228 /usr/bin/systemctl guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2958->guuid=1874c6d5-1b00-0000-513a-9d379c0c0000 pid=3228 execve guuid=2aa07dcf-1c00-0000-513a-9d37c10e0000 pid=3777 /usr/bin/systemctl guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2958->guuid=2aa07dcf-1c00-0000-513a-9d37c10e0000 pid=3777 execve guuid=faabdcae-1d00-0000-513a-9d3745110000 pid=4421 /usr/bin/systemctl guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2958->guuid=faabdcae-1d00-0000-513a-9d3745110000 pid=4421 execve guuid=282b3f71-1e00-0000-513a-9d37a9130000 pid=5033 /usr/bin/dash guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2958->guuid=282b3f71-1e00-0000-513a-9d37a9130000 pid=5033 execve guuid=bdac1172-1e00-0000-513a-9d37ae130000 pid=5038 /usr/bin/dash guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2958->guuid=bdac1172-1e00-0000-513a-9d37ae130000 pid=5038 execve guuid=a0e52298-1e00-0000-513a-9d371c140000 pid=5148 /usr/bin/dash guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2958->guuid=a0e52298-1e00-0000-513a-9d371c140000 pid=5148 execve guuid=81aabb98-1e00-0000-513a-9d3723140000 pid=5155 /usr/bin/dash guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2958->guuid=81aabb98-1e00-0000-513a-9d3723140000 pid=5155 execve guuid=4d8efd9d-1e00-0000-513a-9d373b140000 pid=5179 /usr/bin/dash guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2958->guuid=4d8efd9d-1e00-0000-513a-9d373b140000 pid=5179 execve guuid=0e3f3ba1-1e00-0000-513a-9d3751140000 pid=5201 /usr/bin/dash guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2958->guuid=0e3f3ba1-1e00-0000-513a-9d3751140000 pid=5201 execve guuid=124056a6-1e00-0000-513a-9d376c140000 pid=5228 /usr/bin/dash guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2958->guuid=124056a6-1e00-0000-513a-9d376c140000 pid=5228 execve guuid=ab1670d1-1f00-0000-513a-9d3726150000 pid=5414 /usr/bin/pgrep guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2958->guuid=ab1670d1-1f00-0000-513a-9d3726150000 pid=5414 execve guuid=56d2f1d6-1f00-0000-513a-9d3728150000 pid=5416 /usr/bin/pgrep guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2958->guuid=56d2f1d6-1f00-0000-513a-9d3728150000 pid=5416 execve guuid=310d0adb-1f00-0000-513a-9d372a150000 pid=5418 /usr/bin/pgrep guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2958->guuid=310d0adb-1f00-0000-513a-9d372a150000 pid=5418 execve guuid=9fe33fdf-1f00-0000-513a-9d372b150000 pid=5419 /usr/bin/pgrep guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2958->guuid=9fe33fdf-1f00-0000-513a-9d372b150000 pid=5419 execve guuid=7f9f10e3-1f00-0000-513a-9d372d150000 pid=5421 /usr/bin/pgrep guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2958->guuid=7f9f10e3-1f00-0000-513a-9d372d150000 pid=5421 execve guuid=da926467-1b00-0000-513a-9d37940b0000 pid=2964 /usr/bin/systemctl guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2959->guuid=da926467-1b00-0000-513a-9d37940b0000 pid=2964 execve guuid=e4813cb0-1b00-0000-513a-9d372b0c0000 pid=3115 /usr/bin/systemctl guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2959->guuid=e4813cb0-1b00-0000-513a-9d372b0c0000 pid=3115 execve guuid=53a86ee6-1f00-0000-513a-9d372f150000 pid=5423 /usr/bin/pgrep guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2960->guuid=53a86ee6-1f00-0000-513a-9d372f150000 pid=5423 execve guuid=8fdc1bec-1f00-0000-513a-9d3732150000 pid=5426 /usr/bin/pgrep guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2960->guuid=8fdc1bec-1f00-0000-513a-9d3732150000 pid=5426 execve guuid=e1c544f0-1f00-0000-513a-9d3734150000 pid=5428 /usr/bin/pgrep guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2960->guuid=e1c544f0-1f00-0000-513a-9d3734150000 pid=5428 execve guuid=760de4f3-1f00-0000-513a-9d3736150000 pid=5430 /usr/bin/pgrep guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2960->guuid=760de4f3-1f00-0000-513a-9d3736150000 pid=5430 execve guuid=eaac3af9-1f00-0000-513a-9d3737150000 pid=5431 /usr/bin/pgrep guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2960->guuid=eaac3af9-1f00-0000-513a-9d3737150000 pid=5431 execve guuid=2566aaff-1f00-0000-513a-9d3739150000 pid=5433 /usr/bin/pgrep guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2960->guuid=2566aaff-1f00-0000-513a-9d3739150000 pid=5433 execve guuid=f56b4a04-2000-0000-513a-9d373b150000 pid=5435 /usr/bin/pgrep guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2960->guuid=f56b4a04-2000-0000-513a-9d373b150000 pid=5435 execve guuid=f0cf6209-2000-0000-513a-9d373d150000 pid=5437 /usr/bin/systemctl guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2960->guuid=f0cf6209-2000-0000-513a-9d373d150000 pid=5437 execve guuid=d30a3ae9-2000-0000-513a-9d3757150000 pid=5463 /usr/bin/systemctl guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2960->guuid=d30a3ae9-2000-0000-513a-9d3757150000 pid=5463 execve guuid=28a8e08c-2100-0000-513a-9d3776150000 pid=5494 /usr/bin/systemctl guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2960->guuid=28a8e08c-2100-0000-513a-9d3776150000 pid=5494 execve guuid=139d8f25-2200-0000-513a-9d3782150000 pid=5506 /usr/bin/dash guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2960->guuid=139d8f25-2200-0000-513a-9d3782150000 pid=5506 execve guuid=41840426-2200-0000-513a-9d3784150000 pid=5508 /usr/bin/dash guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2960->guuid=41840426-2200-0000-513a-9d3784150000 pid=5508 execve guuid=91a8fc28-2200-0000-513a-9d378d150000 pid=5517 /usr/bin/dash guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2960->guuid=91a8fc28-2200-0000-513a-9d378d150000 pid=5517 execve guuid=50718a29-2200-0000-513a-9d3790150000 pid=5520 /usr/bin/dash guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2960->guuid=50718a29-2200-0000-513a-9d3790150000 pid=5520 execve guuid=1cd4c12b-2200-0000-513a-9d379c150000 pid=5532 /usr/bin/dash guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2960->guuid=1cd4c12b-2200-0000-513a-9d379c150000 pid=5532 execve guuid=80be9d2e-2200-0000-513a-9d37a3150000 pid=5539 /usr/bin/dash guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2960->guuid=80be9d2e-2200-0000-513a-9d37a3150000 pid=5539 execve guuid=cb26a830-2200-0000-513a-9d37ae150000 pid=5550 /usr/bin/dash guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2960->guuid=cb26a830-2200-0000-513a-9d37ae150000 pid=5550 execve guuid=568c035c-2300-0000-513a-9d37bc150000 pid=5564 /usr/bin/pgrep guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2960->guuid=568c035c-2300-0000-513a-9d37bc150000 pid=5564 execve guuid=d142e75f-2300-0000-513a-9d37be150000 pid=5566 /usr/bin/pgrep guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2960->guuid=d142e75f-2300-0000-513a-9d37be150000 pid=5566 execve guuid=246a5c63-2300-0000-513a-9d37c0150000 pid=5568 /usr/bin/pgrep guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2960->guuid=246a5c63-2300-0000-513a-9d37c0150000 pid=5568 execve guuid=8bd36765-2300-0000-513a-9d37c2150000 pid=5570 /usr/bin/pgrep guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2960->guuid=8bd36765-2300-0000-513a-9d37c2150000 pid=5570 execve guuid=d1d48367-2300-0000-513a-9d37c4150000 pid=5572 /usr/bin/pgrep guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2960->guuid=d1d48367-2300-0000-513a-9d37c4150000 pid=5572 execve guuid=5dfb7069-2300-0000-513a-9d37c6150000 pid=5574 /usr/bin/pgrep guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2960->guuid=5dfb7069-2300-0000-513a-9d37c6150000 pid=5574 execve guuid=b2fb7d6b-2300-0000-513a-9d37c8150000 pid=5576 /usr/bin/pgrep guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2960->guuid=b2fb7d6b-2300-0000-513a-9d37c8150000 pid=5576 execve guuid=30577a6d-2300-0000-513a-9d37ca150000 pid=5578 /usr/bin/pgrep guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2960->guuid=30577a6d-2300-0000-513a-9d37ca150000 pid=5578 execve guuid=56eb786f-2300-0000-513a-9d37cc150000 pid=5580 /usr/bin/pgrep guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2960->guuid=56eb786f-2300-0000-513a-9d37cc150000 pid=5580 execve guuid=0aee7d71-2300-0000-513a-9d37ce150000 pid=5582 /usr/bin/pgrep guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2960->guuid=0aee7d71-2300-0000-513a-9d37ce150000 pid=5582 execve guuid=9abd9e73-2300-0000-513a-9d37d0150000 pid=5584 /usr/bin/pgrep guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2960->guuid=9abd9e73-2300-0000-513a-9d37d0150000 pid=5584 execve guuid=cab6aa75-2300-0000-513a-9d37d2150000 pid=5586 /usr/bin/pgrep guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2960->guuid=cab6aa75-2300-0000-513a-9d37d2150000 pid=5586 execve guuid=f39ba177-2300-0000-513a-9d37d4150000 pid=5588 /usr/bin/systemctl guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2960->guuid=f39ba177-2300-0000-513a-9d37d4150000 pid=5588 execve guuid=cb6f380f-2400-0000-513a-9d37e0150000 pid=5600 /usr/bin/systemctl guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2960->guuid=cb6f380f-2400-0000-513a-9d37e0150000 pid=5600 execve guuid=55a082ab-2400-0000-513a-9d37ec150000 pid=5612 /usr/bin/systemctl guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2960->guuid=55a082ab-2400-0000-513a-9d37ec150000 pid=5612 execve guuid=009ee043-2500-0000-513a-9d37f8150000 pid=5624 /usr/bin/dash guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2960->guuid=009ee043-2500-0000-513a-9d37f8150000 pid=5624 execve guuid=f9477a44-2500-0000-513a-9d37fa150000 pid=5626 /usr/bin/dash guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2960->guuid=f9477a44-2500-0000-513a-9d37fa150000 pid=5626 execve guuid=f7ecc447-2500-0000-513a-9d3703160000 pid=5635 /usr/bin/dash guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2960->guuid=f7ecc447-2500-0000-513a-9d3703160000 pid=5635 execve guuid=b2c16e48-2500-0000-513a-9d3705160000 pid=5637 /usr/bin/dash guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2960->guuid=b2c16e48-2500-0000-513a-9d3705160000 pid=5637 execve guuid=d36d0e4b-2500-0000-513a-9d3712160000 pid=5650 /usr/bin/dash guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2960->guuid=d36d0e4b-2500-0000-513a-9d3712160000 pid=5650 execve guuid=6ee6ac4d-2500-0000-513a-9d3719160000 pid=5657 /usr/bin/dash guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2960->guuid=6ee6ac4d-2500-0000-513a-9d3719160000 pid=5657 execve guuid=10f4634f-2500-0000-513a-9d3724160000 pid=5668 /usr/bin/dash guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2960->guuid=10f4634f-2500-0000-513a-9d3724160000 pid=5668 execve guuid=2ed2c87a-2600-0000-513a-9d3732160000 pid=5682 /usr/bin/pgrep guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2960->guuid=2ed2c87a-2600-0000-513a-9d3732160000 pid=5682 execve guuid=4af1377d-2600-0000-513a-9d3734160000 pid=5684 /usr/bin/pgrep guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2960->guuid=4af1377d-2600-0000-513a-9d3734160000 pid=5684 execve guuid=46f3567f-2600-0000-513a-9d3736160000 pid=5686 /usr/bin/pgrep guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2960->guuid=46f3567f-2600-0000-513a-9d3736160000 pid=5686 execve guuid=3424c681-2600-0000-513a-9d3738160000 pid=5688 /usr/bin/pgrep guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2960->guuid=3424c681-2600-0000-513a-9d3738160000 pid=5688 execve guuid=3d9cf983-2600-0000-513a-9d373a160000 pid=5690 /usr/bin/pgrep guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2960->guuid=3d9cf983-2600-0000-513a-9d373a160000 pid=5690 execve guuid=c581fb85-2600-0000-513a-9d373c160000 pid=5692 /usr/bin/pgrep guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2960->guuid=c581fb85-2600-0000-513a-9d373c160000 pid=5692 execve guuid=c4cf8788-2600-0000-513a-9d373f160000 pid=5695 /usr/bin/pgrep guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2960->guuid=c4cf8788-2600-0000-513a-9d373f160000 pid=5695 execve guuid=7657848a-2600-0000-513a-9d3741160000 pid=5697 /usr/bin/pgrep guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2960->guuid=7657848a-2600-0000-513a-9d3741160000 pid=5697 execve guuid=0a786f8c-2600-0000-513a-9d3743160000 pid=5699 /usr/bin/pgrep guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2960->guuid=0a786f8c-2600-0000-513a-9d3743160000 pid=5699 execve guuid=858d668e-2600-0000-513a-9d3744160000 pid=5700 /usr/bin/pgrep guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2960->guuid=858d668e-2600-0000-513a-9d3744160000 pid=5700 execve guuid=f9385a90-2600-0000-513a-9d3746160000 pid=5702 /usr/bin/pgrep guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2960->guuid=f9385a90-2600-0000-513a-9d3746160000 pid=5702 execve guuid=f3bc4f92-2600-0000-513a-9d3748160000 pid=5704 /usr/bin/pgrep guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2960->guuid=f3bc4f92-2600-0000-513a-9d3748160000 pid=5704 execve guuid=35eb4894-2600-0000-513a-9d374a160000 pid=5706 /usr/bin/systemctl guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2960->guuid=35eb4894-2600-0000-513a-9d374a160000 pid=5706 execve guuid=c12bd430-2700-0000-513a-9d3756160000 pid=5718 /usr/bin/systemctl guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2960->guuid=c12bd430-2700-0000-513a-9d3756160000 pid=5718 execve guuid=f9ada4ce-2700-0000-513a-9d3762160000 pid=5730 /usr/bin/systemctl guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2960->guuid=f9ada4ce-2700-0000-513a-9d3762160000 pid=5730 execve guuid=06d73e6a-2800-0000-513a-9d376e160000 pid=5742 /usr/bin/dash guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2960->guuid=06d73e6a-2800-0000-513a-9d376e160000 pid=5742 execve guuid=c9bdd06a-2800-0000-513a-9d3770160000 pid=5744 /usr/bin/dash guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2960->guuid=c9bdd06a-2800-0000-513a-9d3770160000 pid=5744 execve guuid=17a0426d-2800-0000-513a-9d3779160000 pid=5753 /usr/bin/dash guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2960->guuid=17a0426d-2800-0000-513a-9d3779160000 pid=5753 execve guuid=8f45c96d-2800-0000-513a-9d377b160000 pid=5755 /usr/bin/dash guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2960->guuid=8f45c96d-2800-0000-513a-9d377b160000 pid=5755 execve guuid=3e1cd86f-2800-0000-513a-9d3788160000 pid=5768 /usr/bin/dash guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2960->guuid=3e1cd86f-2800-0000-513a-9d3788160000 pid=5768 execve guuid=1cb26b72-2800-0000-513a-9d378f160000 pid=5775 /usr/bin/dash guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2960->guuid=1cb26b72-2800-0000-513a-9d378f160000 pid=5775 execve guuid=3eae1874-2800-0000-513a-9d3797160000 pid=5783 /usr/bin/dash guuid=469f135d-1b00-0000-513a-9d377c0b0000 pid=2960->guuid=3eae1874-2800-0000-513a-9d3797160000 pid=5783 execve 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=2967->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 44B guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3024 /tmp/sample.bin guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=2967->guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3024 clone guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3025 /tmp/sample.bin delete-file dns net write-config write-file guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=2967->guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3025 clone guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3026 /tmp/sample.bin net send-data guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=2967->guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3026 clone guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3027 /tmp/sample.bin delete-file write-config guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=2967->guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3027 clone guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3038 /tmp/sample.bin delete-file write-config write-file guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=2967->guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3038 clone guuid=e4dfde99-1b00-0000-513a-9d37e40b0000 pid=3044 /usr/bin/mount guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=2967->guuid=e4dfde99-1b00-0000-513a-9d37e40b0000 pid=3044 execve guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3048 /tmp/sample.bin guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=2967->guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3048 clone guuid=c01f3427-2200-0000-513a-9d3789150000 pid=5513 /usr/bin/dash guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=2967->guuid=c01f3427-2200-0000-513a-9d3789150000 pid=5513 execve guuid=741cbb29-2200-0000-513a-9d3793150000 pid=5523 /usr/bin/dash guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=2967->guuid=741cbb29-2200-0000-513a-9d3793150000 pid=5523 execve guuid=9ab95c2a-2200-0000-513a-9d3797150000 pid=5527 /usr/bin/dash guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=2967->guuid=9ab95c2a-2200-0000-513a-9d3797150000 pid=5527 execve guuid=91b6922c-2200-0000-513a-9d379f150000 pid=5535 /usr/bin/dash guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=2967->guuid=91b6922c-2200-0000-513a-9d379f150000 pid=5535 execve guuid=1f061c2f-2200-0000-513a-9d37a9150000 pid=5545 /usr/bin/dash guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=2967->guuid=1f061c2f-2200-0000-513a-9d37a9150000 pid=5545 execve guuid=a5513031-2200-0000-513a-9d37b5150000 pid=5557 /usr/bin/dash guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=2967->guuid=a5513031-2200-0000-513a-9d37b5150000 pid=5557 execve guuid=5f72605c-2300-0000-513a-9d37bd150000 pid=5565 /usr/bin/pgrep guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=2967->guuid=5f72605c-2300-0000-513a-9d37bd150000 pid=5565 execve guuid=f256a560-2300-0000-513a-9d37bf150000 pid=5567 /usr/bin/pgrep guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=2967->guuid=f256a560-2300-0000-513a-9d37bf150000 pid=5567 execve f0b285bb-1a84-5e59-8bd2-9c64ab8fa677 www.dwf1579.vip:55550 guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3025->f0b285bb-1a84-5e59-8bd2-9c64ab8fa677 con guuid=58300570-1e00-0000-513a-9d379e130000 pid=5022 /usr/bin/dash guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3025->guuid=58300570-1e00-0000-513a-9d379e130000 pid=5022 execve guuid=4f178370-1e00-0000-513a-9d37a3130000 pid=5027 /usr/bin/dash guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3025->guuid=4f178370-1e00-0000-513a-9d37a3130000 pid=5027 execve guuid=08e82398-1e00-0000-513a-9d371d140000 pid=5149 /usr/bin/dash guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3025->guuid=08e82398-1e00-0000-513a-9d371d140000 pid=5149 execve guuid=fb525899-1e00-0000-513a-9d3727140000 pid=5159 /usr/bin/dash guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3025->guuid=fb525899-1e00-0000-513a-9d3727140000 pid=5159 execve guuid=842bde9e-1e00-0000-513a-9d373f140000 pid=5183 /usr/bin/dash guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3025->guuid=842bde9e-1e00-0000-513a-9d373f140000 pid=5183 execve guuid=8eafbb63-2300-0000-513a-9d37c1150000 pid=5569 /usr/bin/pgrep guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3025->guuid=8eafbb63-2300-0000-513a-9d37c1150000 pid=5569 execve guuid=fbc2e965-2300-0000-513a-9d37c3150000 pid=5571 /usr/bin/pgrep guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3025->guuid=fbc2e965-2300-0000-513a-9d37c3150000 pid=5571 execve guuid=f2014f68-2300-0000-513a-9d37c5150000 pid=5573 /usr/bin/pgrep guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3025->guuid=f2014f68-2300-0000-513a-9d37c5150000 pid=5573 execve guuid=44fb4b6a-2300-0000-513a-9d37c7150000 pid=5575 /usr/bin/pgrep guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3025->guuid=44fb4b6a-2300-0000-513a-9d37c7150000 pid=5575 execve guuid=fbac506c-2300-0000-513a-9d37c9150000 pid=5577 /usr/bin/pgrep guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3025->guuid=fbac506c-2300-0000-513a-9d37c9150000 pid=5577 execve guuid=a893506e-2300-0000-513a-9d37cb150000 pid=5579 /usr/bin/pgrep guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3025->guuid=a893506e-2300-0000-513a-9d37cb150000 pid=5579 execve guuid=cf425670-2300-0000-513a-9d37cd150000 pid=5581 /usr/bin/pgrep guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3025->guuid=cf425670-2300-0000-513a-9d37cd150000 pid=5581 execve guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3026->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 44B guuid=22031f93-1b00-0000-513a-9d37d90b0000 pid=3033 /tmp/sample.bin guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3027->guuid=22031f93-1b00-0000-513a-9d37d90b0000 pid=3033 clone guuid=be2af093-1b00-0000-513a-9d37df0b0000 pid=3039 /usr/bin/pgrep guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3027->guuid=be2af093-1b00-0000-513a-9d37df0b0000 pid=3039 execve guuid=524a449e-1b00-0000-513a-9d37ea0b0000 pid=3050 /usr/bin/pgrep guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3038->guuid=524a449e-1b00-0000-513a-9d37ea0b0000 pid=3050 execve guuid=cac036a1-1b00-0000-513a-9d37f40b0000 pid=3060 /usr/bin/pgrep guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3038->guuid=cac036a1-1b00-0000-513a-9d37f40b0000 pid=3060 execve guuid=ff4da9a4-1b00-0000-513a-9d37020c0000 pid=3074 /usr/bin/pgrep guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3038->guuid=ff4da9a4-1b00-0000-513a-9d37020c0000 pid=3074 execve guuid=0bf802a9-1b00-0000-513a-9d37130c0000 pid=3091 /usr/bin/pgrep guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3038->guuid=0bf802a9-1b00-0000-513a-9d37130c0000 pid=3091 execve guuid=3a0c6bb2-1b00-0000-513a-9d37310c0000 pid=3121 /usr/bin/pgrep guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3038->guuid=3a0c6bb2-1b00-0000-513a-9d37310c0000 pid=3121 execve guuid=fa6c4db9-1b00-0000-513a-9d37410c0000 pid=3137 /usr/bin/pgrep guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3038->guuid=fa6c4db9-1b00-0000-513a-9d37410c0000 pid=3137 execve guuid=0c40b1c5-1b00-0000-513a-9d37710c0000 pid=3185 /usr/bin/pgrep guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3038->guuid=0c40b1c5-1b00-0000-513a-9d37710c0000 pid=3185 execve guuid=e4cb73cf-1b00-0000-513a-9d37870c0000 pid=3207 /usr/bin/pgrep guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3038->guuid=e4cb73cf-1b00-0000-513a-9d37870c0000 pid=3207 execve guuid=af37ffd8-1b00-0000-513a-9d37a60c0000 pid=3238 /usr/bin/pgrep guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3038->guuid=af37ffd8-1b00-0000-513a-9d37a60c0000 pid=3238 execve guuid=2f1bdcdc-1b00-0000-513a-9d37b40c0000 pid=3252 /usr/bin/pgrep guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3038->guuid=2f1bdcdc-1b00-0000-513a-9d37b40c0000 pid=3252 execve guuid=878a67e1-1b00-0000-513a-9d37be0c0000 pid=3262 /usr/bin/pgrep guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3038->guuid=878a67e1-1b00-0000-513a-9d37be0c0000 pid=3262 execve guuid=7f1506e8-1b00-0000-513a-9d37c70c0000 pid=3271 /usr/bin/systemctl guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3038->guuid=7f1506e8-1b00-0000-513a-9d37c70c0000 pid=3271 execve guuid=916cb5ce-1c00-0000-513a-9d37b90e0000 pid=3769 /usr/bin/systemctl guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3038->guuid=916cb5ce-1c00-0000-513a-9d37b90e0000 pid=3769 execve guuid=a7f663ad-1d00-0000-513a-9d373c110000 pid=4412 /usr/bin/systemctl guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3038->guuid=a7f663ad-1d00-0000-513a-9d373c110000 pid=4412 execve guuid=078d96a2-1e00-0000-513a-9d375f140000 pid=5215 /usr/bin/dash guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3038->guuid=078d96a2-1e00-0000-513a-9d375f140000 pid=5215 execve guuid=92dc94a7-1e00-0000-513a-9d377a140000 pid=5242 /usr/bin/dash guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3038->guuid=92dc94a7-1e00-0000-513a-9d377a140000 pid=5242 execve guuid=b4160dd3-1f00-0000-513a-9d3727150000 pid=5415 /usr/bin/pgrep guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3038->guuid=b4160dd3-1f00-0000-513a-9d3727150000 pid=5415 execve guuid=cdc911d9-1f00-0000-513a-9d3729150000 pid=5417 /usr/bin/pgrep guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3038->guuid=cdc911d9-1f00-0000-513a-9d3729150000 pid=5417 execve guuid=afc043df-1f00-0000-513a-9d372c150000 pid=5420 /usr/bin/pgrep guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3038->guuid=afc043df-1f00-0000-513a-9d372c150000 pid=5420 execve guuid=561211e5-1f00-0000-513a-9d372e150000 pid=5422 /usr/bin/pgrep guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3038->guuid=561211e5-1f00-0000-513a-9d372e150000 pid=5422 execve guuid=82a345e8-1f00-0000-513a-9d3730150000 pid=5424 /usr/bin/pgrep guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3038->guuid=82a345e8-1f00-0000-513a-9d3730150000 pid=5424 execve guuid=b9a408ec-1f00-0000-513a-9d3731150000 pid=5425 /usr/bin/pgrep guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3038->guuid=b9a408ec-1f00-0000-513a-9d3731150000 pid=5425 execve guuid=606898ef-1f00-0000-513a-9d3733150000 pid=5427 /usr/bin/pgrep guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3038->guuid=606898ef-1f00-0000-513a-9d3733150000 pid=5427 execve guuid=33cea2f3-1f00-0000-513a-9d3735150000 pid=5429 /usr/bin/pgrep guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3038->guuid=33cea2f3-1f00-0000-513a-9d3735150000 pid=5429 execve guuid=c4474cf9-1f00-0000-513a-9d3738150000 pid=5432 /usr/bin/pgrep guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3038->guuid=c4474cf9-1f00-0000-513a-9d3738150000 pid=5432 execve guuid=ab9bc701-2000-0000-513a-9d373a150000 pid=5434 /usr/bin/pgrep guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3038->guuid=ab9bc701-2000-0000-513a-9d373a150000 pid=5434 execve guuid=bce04907-2000-0000-513a-9d373c150000 pid=5436 /usr/bin/pgrep guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3038->guuid=bce04907-2000-0000-513a-9d373c150000 pid=5436 execve guuid=b4b02b0c-2000-0000-513a-9d3743150000 pid=5443 /usr/bin/pgrep guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3038->guuid=b4b02b0c-2000-0000-513a-9d3743150000 pid=5443 execve guuid=ac132e13-2000-0000-513a-9d3744150000 pid=5444 /usr/bin/systemctl guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3038->guuid=ac132e13-2000-0000-513a-9d3744150000 pid=5444 execve guuid=240a0aeb-2000-0000-513a-9d375d150000 pid=5469 /usr/bin/systemctl guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3038->guuid=240a0aeb-2000-0000-513a-9d375d150000 pid=5469 execve guuid=c81c808d-2100-0000-513a-9d3779150000 pid=5497 /usr/bin/systemctl guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3038->guuid=c81c808d-2100-0000-513a-9d3779150000 pid=5497 execve guuid=d21a8d26-2200-0000-513a-9d3787150000 pid=5511 /usr/bin/dash guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3038->guuid=d21a8d26-2200-0000-513a-9d3787150000 pid=5511 execve guuid=e0046c72-2300-0000-513a-9d37cf150000 pid=5583 /usr/bin/pgrep guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3048->guuid=e0046c72-2300-0000-513a-9d37cf150000 pid=5583 execve guuid=c3fe9e74-2300-0000-513a-9d37d1150000 pid=5585 /usr/bin/pgrep guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3048->guuid=c3fe9e74-2300-0000-513a-9d37d1150000 pid=5585 execve guuid=bd15a676-2300-0000-513a-9d37d3150000 pid=5587 /usr/bin/pgrep guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3048->guuid=bd15a676-2300-0000-513a-9d37d3150000 pid=5587 execve guuid=c234b978-2300-0000-513a-9d37da150000 pid=5594 /usr/bin/systemctl guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3048->guuid=c234b978-2300-0000-513a-9d37da150000 pid=5594 execve guuid=85912d10-2400-0000-513a-9d37e6150000 pid=5606 /usr/bin/systemctl guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3048->guuid=85912d10-2400-0000-513a-9d37e6150000 pid=5606 execve guuid=68f0f0ac-2400-0000-513a-9d37f2150000 pid=5618 /usr/bin/systemctl guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3048->guuid=68f0f0ac-2400-0000-513a-9d37f2150000 pid=5618 execve guuid=d8ae9c45-2500-0000-513a-9d37fd150000 pid=5629 /usr/bin/dash guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3048->guuid=d8ae9c45-2500-0000-513a-9d37fd150000 pid=5629 execve guuid=203d0846-2500-0000-513a-9d37ff150000 pid=5631 /usr/bin/dash guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3048->guuid=203d0846-2500-0000-513a-9d37ff150000 pid=5631 execve guuid=3a58c449-2500-0000-513a-9d370b160000 pid=5643 /usr/bin/dash guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3048->guuid=3a58c449-2500-0000-513a-9d370b160000 pid=5643 execve guuid=3783434a-2500-0000-513a-9d370d160000 pid=5645 /usr/bin/dash guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3048->guuid=3783434a-2500-0000-513a-9d370d160000 pid=5645 execve guuid=a57b534c-2500-0000-513a-9d3715160000 pid=5653 /usr/bin/dash guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3048->guuid=a57b534c-2500-0000-513a-9d3715160000 pid=5653 execve guuid=5a37c34e-2500-0000-513a-9d371f160000 pid=5663 /usr/bin/dash guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3048->guuid=5a37c34e-2500-0000-513a-9d371f160000 pid=5663 execve guuid=066a8f50-2500-0000-513a-9d372b160000 pid=5675 /usr/bin/dash guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3048->guuid=066a8f50-2500-0000-513a-9d372b160000 pid=5675 execve guuid=93855d7b-2600-0000-513a-9d3733160000 pid=5683 /usr/bin/pgrep guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3048->guuid=93855d7b-2600-0000-513a-9d3733160000 pid=5683 execve guuid=78e2607e-2600-0000-513a-9d3735160000 pid=5685 /usr/bin/pgrep guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3048->guuid=78e2607e-2600-0000-513a-9d3735160000 pid=5685 execve guuid=39f76680-2600-0000-513a-9d3737160000 pid=5687 /usr/bin/pgrep guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3048->guuid=39f76680-2600-0000-513a-9d3737160000 pid=5687 execve guuid=16917382-2600-0000-513a-9d3739160000 pid=5689 /usr/bin/pgrep guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3048->guuid=16917382-2600-0000-513a-9d3739160000 pid=5689 execve guuid=023a6884-2600-0000-513a-9d373b160000 pid=5691 /usr/bin/pgrep guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3048->guuid=023a6884-2600-0000-513a-9d373b160000 pid=5691 execve guuid=19575986-2600-0000-513a-9d373d160000 pid=5693 /usr/bin/pgrep guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3048->guuid=19575986-2600-0000-513a-9d373d160000 pid=5693 execve guuid=9fb86e88-2600-0000-513a-9d373e160000 pid=5694 /usr/bin/pgrep guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3048->guuid=9fb86e88-2600-0000-513a-9d373e160000 pid=5694 execve guuid=2c376f8a-2600-0000-513a-9d3740160000 pid=5696 /usr/bin/pgrep guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3048->guuid=2c376f8a-2600-0000-513a-9d3740160000 pid=5696 execve guuid=62875f8c-2600-0000-513a-9d3742160000 pid=5698 /usr/bin/pgrep guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3048->guuid=62875f8c-2600-0000-513a-9d3742160000 pid=5698 execve guuid=fd9f778e-2600-0000-513a-9d3745160000 pid=5701 /usr/bin/pgrep guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3048->guuid=fd9f778e-2600-0000-513a-9d3745160000 pid=5701 execve guuid=f9497f90-2600-0000-513a-9d3747160000 pid=5703 /usr/bin/pgrep guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3048->guuid=f9497f90-2600-0000-513a-9d3747160000 pid=5703 execve guuid=655f8692-2600-0000-513a-9d3749160000 pid=5705 /usr/bin/pgrep guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3048->guuid=655f8692-2600-0000-513a-9d3749160000 pid=5705 execve guuid=fbcea494-2600-0000-513a-9d374c160000 pid=5708 /usr/bin/systemctl guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3048->guuid=fbcea494-2600-0000-513a-9d374c160000 pid=5708 execve guuid=a248b331-2700-0000-513a-9d3759160000 pid=5721 /usr/bin/systemctl guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3048->guuid=a248b331-2700-0000-513a-9d3759160000 pid=5721 execve guuid=b29543d0-2700-0000-513a-9d3765160000 pid=5733 /usr/bin/systemctl guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3048->guuid=b29543d0-2700-0000-513a-9d3765160000 pid=5733 execve guuid=aaaa716b-2800-0000-513a-9d3773160000 pid=5747 /usr/bin/dash guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3048->guuid=aaaa716b-2800-0000-513a-9d3773160000 pid=5747 execve guuid=280adc6b-2800-0000-513a-9d3775160000 pid=5749 /usr/bin/dash guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3048->guuid=280adc6b-2800-0000-513a-9d3775160000 pid=5749 execve guuid=d636616e-2800-0000-513a-9d3781160000 pid=5761 /usr/bin/dash guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3048->guuid=d636616e-2800-0000-513a-9d3781160000 pid=5761 execve guuid=6b2b056f-2800-0000-513a-9d3783160000 pid=5763 /usr/bin/dash guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3048->guuid=6b2b056f-2800-0000-513a-9d3783160000 pid=5763 execve guuid=21951971-2800-0000-513a-9d378b160000 pid=5771 /usr/bin/dash guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3048->guuid=21951971-2800-0000-513a-9d378b160000 pid=5771 execve guuid=edc99473-2800-0000-513a-9d3795160000 pid=5781 /usr/bin/dash guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3048->guuid=edc99473-2800-0000-513a-9d3795160000 pid=5781 execve guuid=01d7e775-2800-0000-513a-9d37a1160000 pid=5793 /usr/bin/dash guuid=304a6d69-1b00-0000-513a-9d37970b0000 pid=3048->guuid=01d7e775-2800-0000-513a-9d37a1160000 pid=5793 execve guuid=8883acd7-1b00-0000-513a-9d37a10c0000 pid=3233 /usr/bin/basename guuid=1874c6d5-1b00-0000-513a-9d379c0c0000 pid=3228->guuid=8883acd7-1b00-0000-513a-9d37a10c0000 pid=3233 execve guuid=3dbbfcd7-1b00-0000-513a-9d37a20c0000 pid=3234 /usr/bin/basename guuid=1874c6d5-1b00-0000-513a-9d379c0c0000 pid=3228->guuid=3dbbfcd7-1b00-0000-513a-9d37a20c0000 pid=3234 execve guuid=5df882da-1b00-0000-513a-9d37ac0c0000 pid=3244 /usr/bin/dash guuid=1874c6d5-1b00-0000-513a-9d379c0c0000 pid=3228->guuid=5df882da-1b00-0000-513a-9d37ac0c0000 pid=3244 clone guuid=f748e5da-1b00-0000-513a-9d37ae0c0000 pid=3246 /usr/bin/systemctl guuid=5df882da-1b00-0000-513a-9d37ac0c0000 pid=3244->guuid=f748e5da-1b00-0000-513a-9d37ae0c0000 pid=3246 execve guuid=3507eada-1b00-0000-513a-9d37af0c0000 pid=3247 /usr/bin/sed guuid=5df882da-1b00-0000-513a-9d37ac0c0000 pid=3244->guuid=3507eada-1b00-0000-513a-9d37af0c0000 pid=3247 execve guuid=344393e9-1b00-0000-513a-9d37c90c0000 pid=3273 /usr/bin/basename guuid=7f1506e8-1b00-0000-513a-9d37c70c0000 pid=3271->guuid=344393e9-1b00-0000-513a-9d37c90c0000 pid=3273 execve guuid=0a21d0ea-1b00-0000-513a-9d37cc0c0000 pid=3276 /usr/bin/basename guuid=7f1506e8-1b00-0000-513a-9d37c70c0000 pid=3271->guuid=0a21d0ea-1b00-0000-513a-9d37cc0c0000 pid=3276 execve guuid=585156eb-1b00-0000-513a-9d37cd0c0000 pid=3277 /usr/bin/dash guuid=7f1506e8-1b00-0000-513a-9d37c70c0000 pid=3271->guuid=585156eb-1b00-0000-513a-9d37cd0c0000 pid=3277 clone guuid=ab2b5eeb-1b00-0000-513a-9d37ce0c0000 pid=3278 /usr/bin/systemctl guuid=585156eb-1b00-0000-513a-9d37cd0c0000 pid=3277->guuid=ab2b5eeb-1b00-0000-513a-9d37ce0c0000 pid=3278 execve guuid=a98566eb-1b00-0000-513a-9d37cf0c0000 pid=3279 /usr/bin/sed guuid=585156eb-1b00-0000-513a-9d37cd0c0000 pid=3277->guuid=a98566eb-1b00-0000-513a-9d37cf0c0000 pid=3279 execve guuid=66cee2ce-1c00-0000-513a-9d37bb0e0000 pid=3771 /usr/bin/basename guuid=916cb5ce-1c00-0000-513a-9d37b90e0000 pid=3769->guuid=66cee2ce-1c00-0000-513a-9d37bb0e0000 pid=3771 execve guuid=a96a1fcf-1c00-0000-513a-9d37bc0e0000 pid=3772 /usr/bin/basename guuid=916cb5ce-1c00-0000-513a-9d37b90e0000 pid=3769->guuid=a96a1fcf-1c00-0000-513a-9d37bc0e0000 pid=3772 execve guuid=65db5fcf-1c00-0000-513a-9d37be0e0000 pid=3774 /usr/bin/dash guuid=916cb5ce-1c00-0000-513a-9d37b90e0000 pid=3769->guuid=65db5fcf-1c00-0000-513a-9d37be0e0000 pid=3774 clone guuid=c3aa75cf-1c00-0000-513a-9d37c00e0000 pid=3776 /usr/bin/systemctl guuid=65db5fcf-1c00-0000-513a-9d37be0e0000 pid=3774->guuid=c3aa75cf-1c00-0000-513a-9d37c00e0000 pid=3776 execve guuid=78fba8cf-1c00-0000-513a-9d37c30e0000 pid=3779 /usr/bin/sed guuid=65db5fcf-1c00-0000-513a-9d37be0e0000 pid=3774->guuid=78fba8cf-1c00-0000-513a-9d37c30e0000 pid=3779 execve guuid=e78fa7cf-1c00-0000-513a-9d37c20e0000 pid=3778 /usr/bin/basename guuid=2aa07dcf-1c00-0000-513a-9d37c10e0000 pid=3777->guuid=e78fa7cf-1c00-0000-513a-9d37c20e0000 pid=3778 execve guuid=e754ffcf-1c00-0000-513a-9d37c40e0000 pid=3780 /usr/bin/basename guuid=2aa07dcf-1c00-0000-513a-9d37c10e0000 pid=3777->guuid=e754ffcf-1c00-0000-513a-9d37c40e0000 pid=3780 execve guuid=1badead1-1c00-0000-513a-9d37cb0e0000 pid=3787 /usr/bin/dash guuid=2aa07dcf-1c00-0000-513a-9d37c10e0000 pid=3777->guuid=1badead1-1c00-0000-513a-9d37cb0e0000 pid=3787 clone guuid=bce509d2-1c00-0000-513a-9d37cc0e0000 pid=3788 /usr/bin/systemctl guuid=1badead1-1c00-0000-513a-9d37cb0e0000 pid=3787->guuid=bce509d2-1c00-0000-513a-9d37cc0e0000 pid=3788 execve guuid=6e1316d2-1c00-0000-513a-9d37cd0e0000 pid=3789 /usr/bin/sed guuid=1badead1-1c00-0000-513a-9d37cb0e0000 pid=3787->guuid=6e1316d2-1c00-0000-513a-9d37cd0e0000 pid=3789 execve guuid=e02a03ae-1d00-0000-513a-9d3740110000 pid=4416 /usr/bin/basename guuid=a7f663ad-1d00-0000-513a-9d373c110000 pid=4412->guuid=e02a03ae-1d00-0000-513a-9d3740110000 pid=4416 execve guuid=de1f61ae-1d00-0000-513a-9d3741110000 pid=4417 /usr/bin/basename guuid=a7f663ad-1d00-0000-513a-9d373c110000 pid=4412->guuid=de1f61ae-1d00-0000-513a-9d3741110000 pid=4417 execve guuid=b027d3ae-1d00-0000-513a-9d3744110000 pid=4420 /usr/bin/dash guuid=a7f663ad-1d00-0000-513a-9d373c110000 pid=4412->guuid=b027d3ae-1d00-0000-513a-9d3744110000 pid=4420 clone guuid=91a2dcae-1d00-0000-513a-9d3746110000 pid=4422 /usr/bin/systemctl guuid=b027d3ae-1d00-0000-513a-9d3744110000 pid=4420->guuid=91a2dcae-1d00-0000-513a-9d3746110000 pid=4422 execve guuid=4902e4ae-1d00-0000-513a-9d3748110000 pid=4424 /usr/bin/sed guuid=b027d3ae-1d00-0000-513a-9d3744110000 pid=4420->guuid=4902e4ae-1d00-0000-513a-9d3748110000 pid=4424 execve guuid=88c6b3af-1d00-0000-513a-9d374b110000 pid=4427 /usr/bin/basename guuid=faabdcae-1d00-0000-513a-9d3745110000 pid=4421->guuid=88c6b3af-1d00-0000-513a-9d374b110000 pid=4427 execve guuid=e3a502b0-1d00-0000-513a-9d374e110000 pid=4430 /usr/bin/basename guuid=faabdcae-1d00-0000-513a-9d3745110000 pid=4421->guuid=e3a502b0-1d00-0000-513a-9d374e110000 pid=4430 execve guuid=e75d5cb0-1d00-0000-513a-9d3750110000 pid=4432 /usr/bin/dash guuid=faabdcae-1d00-0000-513a-9d3745110000 pid=4421->guuid=e75d5cb0-1d00-0000-513a-9d3750110000 pid=4432 clone guuid=f4ce65b0-1d00-0000-513a-9d3751110000 pid=4433 /usr/bin/systemctl guuid=e75d5cb0-1d00-0000-513a-9d3750110000 pid=4432->guuid=f4ce65b0-1d00-0000-513a-9d3751110000 pid=4433 execve guuid=897c6bb0-1d00-0000-513a-9d3752110000 pid=4434 /usr/bin/sed guuid=e75d5cb0-1d00-0000-513a-9d3750110000 pid=4432->guuid=897c6bb0-1d00-0000-513a-9d3752110000 pid=4434 execve guuid=cfe74770-1e00-0000-513a-9d37a1130000 pid=5025 /usr/bin/rm guuid=58300570-1e00-0000-513a-9d379e130000 pid=5022->guuid=cfe74770-1e00-0000-513a-9d37a1130000 pid=5025 execve guuid=bb23a670-1e00-0000-513a-9d37a4130000 pid=5028 /usr/bin/pgrep guuid=4f178370-1e00-0000-513a-9d37a3130000 pid=5027->guuid=bb23a670-1e00-0000-513a-9d37a4130000 pid=5028 execve guuid=b7f4ab70-1e00-0000-513a-9d37a6130000 pid=5030 /usr/bin/xargs guuid=4f178370-1e00-0000-513a-9d37a3130000 pid=5027->guuid=b7f4ab70-1e00-0000-513a-9d37a6130000 pid=5030 execve guuid=3140bd97-1e00-0000-513a-9d371b140000 pid=5147 /usr/bin/kill zombie guuid=b7f4ab70-1e00-0000-513a-9d37a6130000 pid=5030->guuid=3140bd97-1e00-0000-513a-9d371b140000 pid=5147 execve guuid=a6458e71-1e00-0000-513a-9d37ab130000 pid=5035 /usr/bin/rm guuid=282b3f71-1e00-0000-513a-9d37a9130000 pid=5033->guuid=a6458e71-1e00-0000-513a-9d37ab130000 pid=5035 execve guuid=94764f72-1e00-0000-513a-9d37b0130000 pid=5040 /usr/bin/pgrep guuid=bdac1172-1e00-0000-513a-9d37ae130000 pid=5038->guuid=94764f72-1e00-0000-513a-9d37b0130000 pid=5040 execve guuid=a2575472-1e00-0000-513a-9d37b1130000 pid=5041 /usr/bin/xargs guuid=bdac1172-1e00-0000-513a-9d37ae130000 pid=5038->guuid=a2575472-1e00-0000-513a-9d37b1130000 pid=5041 execve guuid=8da7b197-1e00-0000-513a-9d371a140000 pid=5146 /usr/bin/kill zombie guuid=a2575472-1e00-0000-513a-9d37b1130000 pid=5041->guuid=8da7b197-1e00-0000-513a-9d371a140000 pid=5146 execve guuid=b79c5598-1e00-0000-513a-9d371e140000 pid=5150 /usr/bin/find guuid=a0e52298-1e00-0000-513a-9d371c140000 pid=5148->guuid=b79c5598-1e00-0000-513a-9d371e140000 pid=5150 execve guuid=27f29598-1e00-0000-513a-9d3721140000 pid=5153 /usr/bin/find guuid=08e82398-1e00-0000-513a-9d371d140000 pid=5149->guuid=27f29598-1e00-0000-513a-9d3721140000 pid=5153 execve guuid=d0585999-1e00-0000-513a-9d3728140000 pid=5160 /usr/bin/ps guuid=81aabb98-1e00-0000-513a-9d3723140000 pid=5155->guuid=d0585999-1e00-0000-513a-9d3728140000 pid=5160 execve guuid=19d08f99-1e00-0000-513a-9d372c140000 pid=5164 /usr/bin/grep guuid=81aabb98-1e00-0000-513a-9d3723140000 pid=5155->guuid=19d08f99-1e00-0000-513a-9d372c140000 pid=5164 execve guuid=f7aedf99-1e00-0000-513a-9d3731140000 pid=5169 /usr/bin/mawk guuid=81aabb98-1e00-0000-513a-9d3723140000 pid=5155->guuid=f7aedf99-1e00-0000-513a-9d3731140000 pid=5169 execve guuid=d1130e9a-1e00-0000-513a-9d3735140000 pid=5173 /usr/bin/xargs guuid=81aabb98-1e00-0000-513a-9d3723140000 pid=5155->guuid=d1130e9a-1e00-0000-513a-9d3735140000 pid=5173 execve guuid=2f61a499-1e00-0000-513a-9d372d140000 pid=5165 /usr/bin/ps guuid=fb525899-1e00-0000-513a-9d3727140000 pid=5159->guuid=2f61a499-1e00-0000-513a-9d372d140000 pid=5165 execve guuid=80cdaa99-1e00-0000-513a-9d372e140000 pid=5166 /usr/bin/grep guuid=fb525899-1e00-0000-513a-9d3727140000 pid=5159->guuid=80cdaa99-1e00-0000-513a-9d372e140000 pid=5166 execve guuid=c576b299-1e00-0000-513a-9d372f140000 pid=5167 /usr/bin/mawk guuid=fb525899-1e00-0000-513a-9d3727140000 pid=5159->guuid=c576b299-1e00-0000-513a-9d372f140000 pid=5167 execve guuid=3154b899-1e00-0000-513a-9d3730140000 pid=5168 /usr/bin/xargs guuid=fb525899-1e00-0000-513a-9d3727140000 pid=5159->guuid=3154b899-1e00-0000-513a-9d3730140000 pid=5168 execve guuid=7c9f4f9e-1e00-0000-513a-9d373c140000 pid=5180 /usr/bin/pgrep guuid=4d8efd9d-1e00-0000-513a-9d373b140000 pid=5179->guuid=7c9f4f9e-1e00-0000-513a-9d373c140000 pid=5180 execve guuid=9024559e-1e00-0000-513a-9d373d140000 pid=5181 /usr/bin/xargs guuid=4d8efd9d-1e00-0000-513a-9d373b140000 pid=5179->guuid=9024559e-1e00-0000-513a-9d373d140000 pid=5181 execve guuid=9d1af3a0-1e00-0000-513a-9d374d140000 pid=5197 /usr/bin/kill guuid=9024559e-1e00-0000-513a-9d373d140000 pid=5181->guuid=9d1af3a0-1e00-0000-513a-9d374d140000 pid=5197 execve guuid=36a5a59f-1e00-0000-513a-9d3746140000 pid=5190 /usr/bin/pgrep guuid=842bde9e-1e00-0000-513a-9d373f140000 pid=5183->guuid=36a5a59f-1e00-0000-513a-9d3746140000 pid=5190 execve guuid=7b26aa9f-1e00-0000-513a-9d3747140000 pid=5191 /usr/bin/xargs guuid=842bde9e-1e00-0000-513a-9d373f140000 pid=5183->guuid=7b26aa9f-1e00-0000-513a-9d3747140000 pid=5191 execve guuid=32f525a2-1e00-0000-513a-9d3758140000 pid=5208 /usr/bin/kill guuid=7b26aa9f-1e00-0000-513a-9d3747140000 pid=5191->guuid=32f525a2-1e00-0000-513a-9d3758140000 pid=5208 execve guuid=643df7a1-1e00-0000-513a-9d3757140000 pid=5207 /usr/bin/nproc guuid=0e3f3ba1-1e00-0000-513a-9d3751140000 pid=5201->guuid=643df7a1-1e00-0000-513a-9d3757140000 pid=5207 execve guuid=0f8869a2-1e00-0000-513a-9d375c140000 pid=5212 /usr/bin/ps guuid=0e3f3ba1-1e00-0000-513a-9d3751140000 pid=5201->guuid=0f8869a2-1e00-0000-513a-9d375c140000 pid=5212 execve guuid=475b6da2-1e00-0000-513a-9d375d140000 pid=5213 /usr/bin/mawk guuid=0e3f3ba1-1e00-0000-513a-9d3751140000 pid=5201->guuid=475b6da2-1e00-0000-513a-9d375d140000 pid=5213 execve guuid=2b7472a2-1e00-0000-513a-9d375e140000 pid=5214 /usr/bin/xargs guuid=0e3f3ba1-1e00-0000-513a-9d3751140000 pid=5201->guuid=2b7472a2-1e00-0000-513a-9d375e140000 pid=5214 execve guuid=d167ada3-1e00-0000-513a-9d3764140000 pid=5220 /usr/bin/nproc guuid=078d96a2-1e00-0000-513a-9d375f140000 pid=5215->guuid=d167ada3-1e00-0000-513a-9d3764140000 pid=5220 execve guuid=fd943aa4-1e00-0000-513a-9d3766140000 pid=5222 /usr/bin/ps guuid=078d96a2-1e00-0000-513a-9d375f140000 pid=5215->guuid=fd943aa4-1e00-0000-513a-9d3766140000 pid=5222 execve guuid=cf0f3fa4-1e00-0000-513a-9d3767140000 pid=5223 /usr/bin/mawk guuid=078d96a2-1e00-0000-513a-9d375f140000 pid=5215->guuid=cf0f3fa4-1e00-0000-513a-9d3767140000 pid=5223 execve guuid=5cad46a4-1e00-0000-513a-9d3769140000 pid=5225 /usr/bin/xargs guuid=078d96a2-1e00-0000-513a-9d375f140000 pid=5215->guuid=5cad46a4-1e00-0000-513a-9d3769140000 pid=5225 execve guuid=a8cf89a6-1e00-0000-513a-9d376d140000 pid=5229 /usr/bin/dash guuid=124056a6-1e00-0000-513a-9d376c140000 pid=5228->guuid=a8cf89a6-1e00-0000-513a-9d376d140000 pid=5229 clone guuid=0f6e8ea6-1e00-0000-513a-9d376e140000 pid=5230 /usr/bin/mawk guuid=124056a6-1e00-0000-513a-9d376c140000 pid=5228->guuid=0f6e8ea6-1e00-0000-513a-9d376e140000 pid=5230 execve guuid=f8ca95a6-1e00-0000-513a-9d3770140000 pid=5232 /usr/bin/sort guuid=124056a6-1e00-0000-513a-9d376c140000 pid=5228->guuid=f8ca95a6-1e00-0000-513a-9d3770140000 pid=5232 execve guuid=98379ea6-1e00-0000-513a-9d3772140000 pid=5234 /usr/bin/uniq guuid=124056a6-1e00-0000-513a-9d376c140000 pid=5228->guuid=98379ea6-1e00-0000-513a-9d3772140000 pid=5234 execve guuid=f555a1a6-1e00-0000-513a-9d3773140000 pid=5235 /usr/bin/mawk guuid=124056a6-1e00-0000-513a-9d376c140000 pid=5228->guuid=f555a1a6-1e00-0000-513a-9d3773140000 pid=5235 execve guuid=bb7ea5a6-1e00-0000-513a-9d3775140000 pid=5237 /usr/bin/xargs guuid=124056a6-1e00-0000-513a-9d376c140000 pid=5228->guuid=bb7ea5a6-1e00-0000-513a-9d3775140000 pid=5237 execve guuid=a600c0a7-1e00-0000-513a-9d377c140000 pid=5244 /usr/bin/dash guuid=92dc94a7-1e00-0000-513a-9d377a140000 pid=5242->guuid=a600c0a7-1e00-0000-513a-9d377c140000 pid=5244 clone guuid=638dc4a7-1e00-0000-513a-9d377d140000 pid=5245 /usr/bin/mawk guuid=92dc94a7-1e00-0000-513a-9d377a140000 pid=5242->guuid=638dc4a7-1e00-0000-513a-9d377d140000 pid=5245 execve guuid=691ec9a7-1e00-0000-513a-9d377e140000 pid=5246 /usr/bin/sort guuid=92dc94a7-1e00-0000-513a-9d377a140000 pid=5242->guuid=691ec9a7-1e00-0000-513a-9d377e140000 pid=5246 execve guuid=d7cdd2a7-1e00-0000-513a-9d377f140000 pid=5247 /usr/bin/uniq guuid=92dc94a7-1e00-0000-513a-9d377a140000 pid=5242->guuid=d7cdd2a7-1e00-0000-513a-9d377f140000 pid=5247 execve guuid=13c7d6a7-1e00-0000-513a-9d3780140000 pid=5248 /usr/bin/mawk guuid=92dc94a7-1e00-0000-513a-9d377a140000 pid=5242->guuid=13c7d6a7-1e00-0000-513a-9d3780140000 pid=5248 execve guuid=0e46daa7-1e00-0000-513a-9d3781140000 pid=5249 /usr/bin/xargs guuid=92dc94a7-1e00-0000-513a-9d377a140000 pid=5242->guuid=0e46daa7-1e00-0000-513a-9d3781140000 pid=5249 execve guuid=3a84d80a-2000-0000-513a-9d373e150000 pid=5438 /usr/bin/basename guuid=f0cf6209-2000-0000-513a-9d373d150000 pid=5437->guuid=3a84d80a-2000-0000-513a-9d373e150000 pid=5438 execve guuid=b0e4ae0b-2000-0000-513a-9d373f150000 pid=5439 /usr/bin/basename guuid=f0cf6209-2000-0000-513a-9d373d150000 pid=5437->guuid=b0e4ae0b-2000-0000-513a-9d373f150000 pid=5439 execve guuid=b0df0e0c-2000-0000-513a-9d3740150000 pid=5440 /usr/bin/dash guuid=f0cf6209-2000-0000-513a-9d373d150000 pid=5437->guuid=b0df0e0c-2000-0000-513a-9d3740150000 pid=5440 clone guuid=e1261d0c-2000-0000-513a-9d3741150000 pid=5441 /usr/bin/systemctl guuid=b0df0e0c-2000-0000-513a-9d3740150000 pid=5440->guuid=e1261d0c-2000-0000-513a-9d3741150000 pid=5441 execve guuid=9e25270c-2000-0000-513a-9d3742150000 pid=5442 /usr/bin/sed guuid=b0df0e0c-2000-0000-513a-9d3740150000 pid=5440->guuid=9e25270c-2000-0000-513a-9d3742150000 pid=5442 execve guuid=8d701114-2000-0000-513a-9d3745150000 pid=5445 /usr/bin/basename guuid=ac132e13-2000-0000-513a-9d3744150000 pid=5444->guuid=8d701114-2000-0000-513a-9d3745150000 pid=5445 execve guuid=88456414-2000-0000-513a-9d3746150000 pid=5446 /usr/bin/basename guuid=ac132e13-2000-0000-513a-9d3744150000 pid=5444->guuid=88456414-2000-0000-513a-9d3746150000 pid=5446 execve guuid=df5ed214-2000-0000-513a-9d3747150000 pid=5447 /usr/bin/dash guuid=ac132e13-2000-0000-513a-9d3744150000 pid=5444->guuid=df5ed214-2000-0000-513a-9d3747150000 pid=5447 clone guuid=6ff1db14-2000-0000-513a-9d3748150000 pid=5448 /usr/bin/systemctl guuid=df5ed214-2000-0000-513a-9d3747150000 pid=5447->guuid=6ff1db14-2000-0000-513a-9d3748150000 pid=5448 execve guuid=40d1e314-2000-0000-513a-9d3749150000 pid=5449 /usr/bin/sed guuid=df5ed214-2000-0000-513a-9d3747150000 pid=5447->guuid=40d1e314-2000-0000-513a-9d3749150000 pid=5449 execve guuid=ea8d68e9-2000-0000-513a-9d3758150000 pid=5464 /usr/bin/basename guuid=d30a3ae9-2000-0000-513a-9d3757150000 pid=5463->guuid=ea8d68e9-2000-0000-513a-9d3758150000 pid=5464 execve guuid=4d87dfe9-2000-0000-513a-9d3759150000 pid=5465 /usr/bin/basename guuid=d30a3ae9-2000-0000-513a-9d3757150000 pid=5463->guuid=4d87dfe9-2000-0000-513a-9d3759150000 pid=5465 execve guuid=229528ea-2000-0000-513a-9d375a150000 pid=5466 /usr/bin/dash guuid=d30a3ae9-2000-0000-513a-9d3757150000 pid=5463->guuid=229528ea-2000-0000-513a-9d375a150000 pid=5466 clone guuid=923c35ea-2000-0000-513a-9d375b150000 pid=5467 /usr/bin/systemctl guuid=229528ea-2000-0000-513a-9d375a150000 pid=5466->guuid=923c35ea-2000-0000-513a-9d375b150000 pid=5467 execve guuid=9aa339ea-2000-0000-513a-9d375c150000 pid=5468 /usr/bin/sed guuid=229528ea-2000-0000-513a-9d375a150000 pid=5466->guuid=9aa339ea-2000-0000-513a-9d375c150000 pid=5468 execve guuid=3de85feb-2000-0000-513a-9d375e150000 pid=5470 /usr/bin/basename guuid=240a0aeb-2000-0000-513a-9d375d150000 pid=5469->guuid=3de85feb-2000-0000-513a-9d375e150000 pid=5470 execve guuid=37cb10ec-2000-0000-513a-9d3760150000 pid=5472 /usr/bin/basename guuid=240a0aeb-2000-0000-513a-9d375d150000 pid=5469->guuid=37cb10ec-2000-0000-513a-9d3760150000 pid=5472 execve guuid=69466cec-2000-0000-513a-9d3761150000 pid=5473 /usr/bin/dash guuid=240a0aeb-2000-0000-513a-9d375d150000 pid=5469->guuid=69466cec-2000-0000-513a-9d3761150000 pid=5473 clone guuid=97657aec-2000-0000-513a-9d3762150000 pid=5474 /usr/bin/systemctl guuid=69466cec-2000-0000-513a-9d3761150000 pid=5473->guuid=97657aec-2000-0000-513a-9d3762150000 pid=5474 execve guuid=2fd182ec-2000-0000-513a-9d3763150000 pid=5475 /usr/bin/sed guuid=69466cec-2000-0000-513a-9d3761150000 pid=5473->guuid=2fd182ec-2000-0000-513a-9d3763150000 pid=5475 execve guuid=412f0c8d-2100-0000-513a-9d3777150000 pid=5495 /usr/bin/basename guuid=28a8e08c-2100-0000-513a-9d3776150000 pid=5494->guuid=412f0c8d-2100-0000-513a-9d3777150000 pid=5495 execve guuid=7002488d-2100-0000-513a-9d3778150000 pid=5496 /usr/bin/basename guuid=28a8e08c-2100-0000-513a-9d3776150000 pid=5494->guuid=7002488d-2100-0000-513a-9d3778150000 pid=5496 execve guuid=79e8878d-2100-0000-513a-9d377a150000 pid=5498 /usr/bin/dash guuid=28a8e08c-2100-0000-513a-9d3776150000 pid=5494->guuid=79e8878d-2100-0000-513a-9d377a150000 pid=5498 clone guuid=0f36b88d-2100-0000-513a-9d377d150000 pid=5501 /usr/bin/basename guuid=c81c808d-2100-0000-513a-9d3779150000 pid=5497->guuid=0f36b88d-2100-0000-513a-9d377d150000 pid=5501 execve guuid=c7fbf88d-2100-0000-513a-9d377e150000 pid=5502 /usr/bin/basename guuid=c81c808d-2100-0000-513a-9d3779150000 pid=5497->guuid=c7fbf88d-2100-0000-513a-9d377e150000 pid=5502 execve guuid=e83c3d8e-2100-0000-513a-9d377f150000 pid=5503 /usr/bin/dash guuid=c81c808d-2100-0000-513a-9d3779150000 pid=5497->guuid=e83c3d8e-2100-0000-513a-9d377f150000 pid=5503 clone guuid=58059b8d-2100-0000-513a-9d377b150000 pid=5499 /usr/bin/systemctl guuid=79e8878d-2100-0000-513a-9d377a150000 pid=5498->guuid=58059b8d-2100-0000-513a-9d377b150000 pid=5499 execve guuid=fdc2a58d-2100-0000-513a-9d377c150000 pid=5500 /usr/bin/sed guuid=79e8878d-2100-0000-513a-9d377a150000 pid=5498->guuid=fdc2a58d-2100-0000-513a-9d377c150000 pid=5500 execve guuid=151f508e-2100-0000-513a-9d3780150000 pid=5504 /usr/bin/systemctl guuid=e83c3d8e-2100-0000-513a-9d377f150000 pid=5503->guuid=151f508e-2100-0000-513a-9d3780150000 pid=5504 execve guuid=d2025b8e-2100-0000-513a-9d3781150000 pid=5505 /usr/bin/sed guuid=e83c3d8e-2100-0000-513a-9d377f150000 pid=5503->guuid=d2025b8e-2100-0000-513a-9d3781150000 pid=5505 execve guuid=d0d2be25-2200-0000-513a-9d3783150000 pid=5507 /usr/bin/rm guuid=139d8f25-2200-0000-513a-9d3782150000 pid=5506->guuid=d0d2be25-2200-0000-513a-9d3783150000 pid=5507 execve guuid=45ac3b26-2200-0000-513a-9d3785150000 pid=5509 /usr/bin/pgrep guuid=41840426-2200-0000-513a-9d3784150000 pid=5508->guuid=45ac3b26-2200-0000-513a-9d3785150000 pid=5509 execve guuid=d4a84026-2200-0000-513a-9d3786150000 pid=5510 /usr/bin/xargs zombie guuid=41840426-2200-0000-513a-9d3784150000 pid=5508->guuid=d4a84026-2200-0000-513a-9d3786150000 pid=5510 execve guuid=c3cfbd28-2200-0000-513a-9d378c150000 pid=5516 /usr/bin/kill guuid=d4a84026-2200-0000-513a-9d3786150000 pid=5510->guuid=c3cfbd28-2200-0000-513a-9d378c150000 pid=5516 execve guuid=663cc626-2200-0000-513a-9d3788150000 pid=5512 /usr/bin/rm guuid=d21a8d26-2200-0000-513a-9d3787150000 pid=5511->guuid=663cc626-2200-0000-513a-9d3788150000 pid=5512 execve guuid=bd346c27-2200-0000-513a-9d378a150000 pid=5514 /usr/bin/pgrep guuid=c01f3427-2200-0000-513a-9d3789150000 pid=5513->guuid=bd346c27-2200-0000-513a-9d378a150000 pid=5514 execve guuid=6fb07127-2200-0000-513a-9d378b150000 pid=5515 /usr/bin/xargs guuid=c01f3427-2200-0000-513a-9d3789150000 pid=5513->guuid=6fb07127-2200-0000-513a-9d378b150000 pid=5515 execve guuid=2acc7629-2200-0000-513a-9d378f150000 pid=5519 /usr/bin/kill guuid=6fb07127-2200-0000-513a-9d378b150000 pid=5515->guuid=2acc7629-2200-0000-513a-9d378f150000 pid=5519 execve guuid=a53f2629-2200-0000-513a-9d378e150000 pid=5518 /usr/bin/find guuid=91a8fc28-2200-0000-513a-9d378d150000 pid=5517->guuid=a53f2629-2200-0000-513a-9d378e150000 pid=5518 execve guuid=6117b529-2200-0000-513a-9d3791150000 pid=5521 /usr/bin/ps guuid=50718a29-2200-0000-513a-9d3790150000 pid=5520->guuid=6117b529-2200-0000-513a-9d3791150000 pid=5521 execve guuid=93ebb829-2200-0000-513a-9d3792150000 pid=5522 /usr/bin/grep guuid=50718a29-2200-0000-513a-9d3790150000 pid=5520->guuid=93ebb829-2200-0000-513a-9d3792150000 pid=5522 execve guuid=4beabc29-2200-0000-513a-9d3794150000 pid=5524 /usr/bin/mawk guuid=50718a29-2200-0000-513a-9d3790150000 pid=5520->guuid=4beabc29-2200-0000-513a-9d3794150000 pid=5524 execve guuid=1b63c029-2200-0000-513a-9d3795150000 pid=5525 /usr/bin/xargs guuid=50718a29-2200-0000-513a-9d3790150000 pid=5520->guuid=1b63c029-2200-0000-513a-9d3795150000 pid=5525 execve guuid=17d5dd29-2200-0000-513a-9d3796150000 pid=5526 /usr/bin/find guuid=741cbb29-2200-0000-513a-9d3793150000 pid=5523->guuid=17d5dd29-2200-0000-513a-9d3796150000 pid=5526 execve guuid=1981842a-2200-0000-513a-9d3798150000 pid=5528 /usr/bin/ps guuid=9ab95c2a-2200-0000-513a-9d3797150000 pid=5527->guuid=1981842a-2200-0000-513a-9d3798150000 pid=5528 execve guuid=7a22892a-2200-0000-513a-9d3799150000 pid=5529 /usr/bin/grep guuid=9ab95c2a-2200-0000-513a-9d3797150000 pid=5527->guuid=7a22892a-2200-0000-513a-9d3799150000 pid=5529 execve guuid=39918e2a-2200-0000-513a-9d379a150000 pid=5530 /usr/bin/mawk guuid=9ab95c2a-2200-0000-513a-9d3797150000 pid=5527->guuid=39918e2a-2200-0000-513a-9d379a150000 pid=5530 execve guuid=8b07952a-2200-0000-513a-9d379b150000 pid=5531 /usr/bin/xargs guuid=9ab95c2a-2200-0000-513a-9d3797150000 pid=5527->guuid=8b07952a-2200-0000-513a-9d379b150000 pid=5531 execve guuid=84e0ea2b-2200-0000-513a-9d379d150000 pid=5533 /usr/bin/pgrep guuid=1cd4c12b-2200-0000-513a-9d379c150000 pid=5532->guuid=84e0ea2b-2200-0000-513a-9d379d150000 pid=5533 execve guuid=ce68f02b-2200-0000-513a-9d379e150000 pid=5534 /usr/bin/xargs guuid=1cd4c12b-2200-0000-513a-9d379c150000 pid=5532->guuid=ce68f02b-2200-0000-513a-9d379e150000 pid=5534 execve guuid=b5b8472e-2200-0000-513a-9d37a2150000 pid=5538 /usr/bin/kill guuid=ce68f02b-2200-0000-513a-9d379e150000 pid=5534->guuid=b5b8472e-2200-0000-513a-9d37a2150000 pid=5538 execve guuid=4d12c72c-2200-0000-513a-9d37a0150000 pid=5536 /usr/bin/pgrep guuid=91b6922c-2200-0000-513a-9d379f150000 pid=5535->guuid=4d12c72c-2200-0000-513a-9d37a0150000 pid=5536 execve guuid=1f49cb2c-2200-0000-513a-9d37a1150000 pid=5537 /usr/bin/xargs guuid=91b6922c-2200-0000-513a-9d379f150000 pid=5535->guuid=1f49cb2c-2200-0000-513a-9d37a1150000 pid=5537 execve guuid=55d7cd2e-2200-0000-513a-9d37a5150000 pid=5541 /usr/bin/kill guuid=1f49cb2c-2200-0000-513a-9d37a1150000 pid=5537->guuid=55d7cd2e-2200-0000-513a-9d37a5150000 pid=5541 execve guuid=83a1c62e-2200-0000-513a-9d37a4150000 pid=5540 /usr/bin/nproc guuid=80be9d2e-2200-0000-513a-9d37a3150000 pid=5539->guuid=83a1c62e-2200-0000-513a-9d37a4150000 pid=5540 execve guuid=0cf4102f-2200-0000-513a-9d37a6150000 pid=5542 /usr/bin/ps guuid=80be9d2e-2200-0000-513a-9d37a3150000 pid=5539->guuid=0cf4102f-2200-0000-513a-9d37a6150000 pid=5542 execve guuid=beaf152f-2200-0000-513a-9d37a7150000 pid=5543 /usr/bin/mawk guuid=80be9d2e-2200-0000-513a-9d37a3150000 pid=5539->guuid=beaf152f-2200-0000-513a-9d37a7150000 pid=5543 execve guuid=ac951a2f-2200-0000-513a-9d37a8150000 pid=5544 /usr/bin/xargs guuid=80be9d2e-2200-0000-513a-9d37a3150000 pid=5539->guuid=ac951a2f-2200-0000-513a-9d37a8150000 pid=5544 execve guuid=f3036d2f-2200-0000-513a-9d37aa150000 pid=5546 /usr/bin/nproc guuid=1f061c2f-2200-0000-513a-9d37a9150000 pid=5545->guuid=f3036d2f-2200-0000-513a-9d37aa150000 pid=5546 execve guuid=e298a52f-2200-0000-513a-9d37ab150000 pid=5547 /usr/bin/ps guuid=1f061c2f-2200-0000-513a-9d37a9150000 pid=5545->guuid=e298a52f-2200-0000-513a-9d37ab150000 pid=5547 execve guuid=c425a92f-2200-0000-513a-9d37ac150000 pid=5548 /usr/bin/mawk guuid=1f061c2f-2200-0000-513a-9d37a9150000 pid=5545->guuid=c425a92f-2200-0000-513a-9d37ac150000 pid=5548 execve guuid=3baaac2f-2200-0000-513a-9d37ad150000 pid=5549 /usr/bin/xargs guuid=1f061c2f-2200-0000-513a-9d37a9150000 pid=5545->guuid=3baaac2f-2200-0000-513a-9d37ad150000 pid=5549 execve guuid=29b6cd30-2200-0000-513a-9d37af150000 pid=5551 /usr/bin/dash guuid=cb26a830-2200-0000-513a-9d37ae150000 pid=5550->guuid=29b6cd30-2200-0000-513a-9d37af150000 pid=5551 clone guuid=44ccd430-2200-0000-513a-9d37b0150000 pid=5552 /usr/bin/mawk guuid=cb26a830-2200-0000-513a-9d37ae150000 pid=5550->guuid=44ccd430-2200-0000-513a-9d37b0150000 pid=5552 execve guuid=6081d830-2200-0000-513a-9d37b1150000 pid=5553 /usr/bin/sort guuid=cb26a830-2200-0000-513a-9d37ae150000 pid=5550->guuid=6081d830-2200-0000-513a-9d37b1150000 pid=5553 execve guuid=c624dc30-2200-0000-513a-9d37b2150000 pid=5554 /usr/bin/uniq guuid=cb26a830-2200-0000-513a-9d37ae150000 pid=5550->guuid=c624dc30-2200-0000-513a-9d37b2150000 pid=5554 execve guuid=904fdf30-2200-0000-513a-9d37b3150000 pid=5555 /usr/bin/mawk guuid=cb26a830-2200-0000-513a-9d37ae150000 pid=5550->guuid=904fdf30-2200-0000-513a-9d37b3150000 pid=5555 execve guuid=af4fe330-2200-0000-513a-9d37b4150000 pid=5556 /usr/bin/xargs guuid=cb26a830-2200-0000-513a-9d37ae150000 pid=5550->guuid=af4fe330-2200-0000-513a-9d37b4150000 pid=5556 execve guuid=25195731-2200-0000-513a-9d37b6150000 pid=5558 /usr/bin/dash guuid=a5513031-2200-0000-513a-9d37b5150000 pid=5557->guuid=25195731-2200-0000-513a-9d37b6150000 pid=5558 clone guuid=9af35b31-2200-0000-513a-9d37b7150000 pid=5559 /usr/bin/mawk guuid=a5513031-2200-0000-513a-9d37b5150000 pid=5557->guuid=9af35b31-2200-0000-513a-9d37b7150000 pid=5559 execve guuid=91815f31-2200-0000-513a-9d37b8150000 pid=5560 /usr/bin/sort guuid=a5513031-2200-0000-513a-9d37b5150000 pid=5557->guuid=91815f31-2200-0000-513a-9d37b8150000 pid=5560 execve guuid=cd116331-2200-0000-513a-9d37b9150000 pid=5561 /usr/bin/uniq guuid=a5513031-2200-0000-513a-9d37b5150000 pid=5557->guuid=cd116331-2200-0000-513a-9d37b9150000 pid=5561 execve guuid=75316631-2200-0000-513a-9d37ba150000 pid=5562 /usr/bin/mawk guuid=a5513031-2200-0000-513a-9d37b5150000 pid=5557->guuid=75316631-2200-0000-513a-9d37ba150000 pid=5562 execve guuid=91ee6a31-2200-0000-513a-9d37bb150000 pid=5563 /usr/bin/xargs guuid=a5513031-2200-0000-513a-9d37b5150000 pid=5557->guuid=91ee6a31-2200-0000-513a-9d37bb150000 pid=5563 execve guuid=139cc977-2300-0000-513a-9d37d5150000 pid=5589 /usr/bin/basename guuid=f39ba177-2300-0000-513a-9d37d4150000 pid=5588->guuid=139cc977-2300-0000-513a-9d37d5150000 pid=5589 execve guuid=28f80578-2300-0000-513a-9d37d6150000 pid=5590 /usr/bin/basename guuid=f39ba177-2300-0000-513a-9d37d4150000 pid=5588->guuid=28f80578-2300-0000-513a-9d37d6150000 pid=5590 execve guuid=3b174978-2300-0000-513a-9d37d7150000 pid=5591 /usr/bin/dash guuid=f39ba177-2300-0000-513a-9d37d4150000 pid=5588->guuid=3b174978-2300-0000-513a-9d37d7150000 pid=5591 clone guuid=861e4f78-2300-0000-513a-9d37d8150000 pid=5592 /usr/bin/systemctl guuid=3b174978-2300-0000-513a-9d37d7150000 pid=5591->guuid=861e4f78-2300-0000-513a-9d37d8150000 pid=5592 execve guuid=35835478-2300-0000-513a-9d37d9150000 pid=5593 /usr/bin/sed guuid=3b174978-2300-0000-513a-9d37d7150000 pid=5591->guuid=35835478-2300-0000-513a-9d37d9150000 pid=5593 execve guuid=04a4e578-2300-0000-513a-9d37db150000 pid=5595 /usr/bin/basename guuid=c234b978-2300-0000-513a-9d37da150000 pid=5594->guuid=04a4e578-2300-0000-513a-9d37db150000 pid=5595 execve guuid=d1c51979-2300-0000-513a-9d37dc150000 pid=5596 /usr/bin/basename guuid=c234b978-2300-0000-513a-9d37da150000 pid=5594->guuid=d1c51979-2300-0000-513a-9d37dc150000 pid=5596 execve guuid=53df5a79-2300-0000-513a-9d37dd150000 pid=5597 /usr/bin/dash guuid=c234b978-2300-0000-513a-9d37da150000 pid=5594->guuid=53df5a79-2300-0000-513a-9d37dd150000 pid=5597 clone guuid=41bb6579-2300-0000-513a-9d37de150000 pid=5598 /usr/bin/systemctl guuid=53df5a79-2300-0000-513a-9d37dd150000 pid=5597->guuid=41bb6579-2300-0000-513a-9d37de150000 pid=5598 execve guuid=328d6c79-2300-0000-513a-9d37df150000 pid=5599 /usr/bin/sed guuid=53df5a79-2300-0000-513a-9d37dd150000 pid=5597->guuid=328d6c79-2300-0000-513a-9d37df150000 pid=5599 execve guuid=16df660f-2400-0000-513a-9d37e1150000 pid=5601 /usr/bin/basename guuid=cb6f380f-2400-0000-513a-9d37e0150000 pid=5600->guuid=16df660f-2400-0000-513a-9d37e1150000 pid=5601 execve guuid=7690d20f-2400-0000-513a-9d37e2150000 pid=5602 /usr/bin/basename guuid=cb6f380f-2400-0000-513a-9d37e0150000 pid=5600->guuid=7690d20f-2400-0000-513a-9d37e2150000 pid=5602 execve guuid=bbd91610-2400-0000-513a-9d37e3150000 pid=5603 /usr/bin/dash guuid=cb6f380f-2400-0000-513a-9d37e0150000 pid=5600->guuid=bbd91610-2400-0000-513a-9d37e3150000 pid=5603 clone guuid=ba522210-2400-0000-513a-9d37e4150000 pid=5604 /usr/bin/systemctl guuid=bbd91610-2400-0000-513a-9d37e3150000 pid=5603->guuid=ba522210-2400-0000-513a-9d37e4150000 pid=5604 execve guuid=30a22a10-2400-0000-513a-9d37e5150000 pid=5605 /usr/bin/sed guuid=bbd91610-2400-0000-513a-9d37e3150000 pid=5603->guuid=30a22a10-2400-0000-513a-9d37e5150000 pid=5605 execve guuid=53c96e10-2400-0000-513a-9d37e7150000 pid=5607 /usr/bin/basename guuid=85912d10-2400-0000-513a-9d37e6150000 pid=5606->guuid=53c96e10-2400-0000-513a-9d37e7150000 pid=5607 execve guuid=f638d910-2400-0000-513a-9d37e8150000 pid=5608 /usr/bin/basename guuid=85912d10-2400-0000-513a-9d37e6150000 pid=5606->guuid=f638d910-2400-0000-513a-9d37e8150000 pid=5608 execve guuid=84982311-2400-0000-513a-9d37e9150000 pid=5609 /usr/bin/dash guuid=85912d10-2400-0000-513a-9d37e6150000 pid=5606->guuid=84982311-2400-0000-513a-9d37e9150000 pid=5609 clone guuid=790a2e11-2400-0000-513a-9d37ea150000 pid=5610 /usr/bin/systemctl guuid=84982311-2400-0000-513a-9d37e9150000 pid=5609->guuid=790a2e11-2400-0000-513a-9d37ea150000 pid=5610 execve guuid=258f3411-2400-0000-513a-9d37eb150000 pid=5611 /usr/bin/sed guuid=84982311-2400-0000-513a-9d37e9150000 pid=5609->guuid=258f3411-2400-0000-513a-9d37eb150000 pid=5611 execve guuid=7e07c8ab-2400-0000-513a-9d37ed150000 pid=5613 /usr/bin/basename guuid=55a082ab-2400-0000-513a-9d37ec150000 pid=5612->guuid=7e07c8ab-2400-0000-513a-9d37ed150000 pid=5613 execve guuid=f82021ac-2400-0000-513a-9d37ee150000 pid=5614 /usr/bin/basename guuid=55a082ab-2400-0000-513a-9d37ec150000 pid=5612->guuid=f82021ac-2400-0000-513a-9d37ee150000 pid=5614 execve guuid=caec90ac-2400-0000-513a-9d37ef150000 pid=5615 /usr/bin/dash guuid=55a082ab-2400-0000-513a-9d37ec150000 pid=5612->guuid=caec90ac-2400-0000-513a-9d37ef150000 pid=5615 clone guuid=77649aac-2400-0000-513a-9d37f0150000 pid=5616 /usr/bin/systemctl guuid=caec90ac-2400-0000-513a-9d37ef150000 pid=5615->guuid=77649aac-2400-0000-513a-9d37f0150000 pid=5616 execve guuid=0fb6a0ac-2400-0000-513a-9d37f1150000 pid=5617 /usr/bin/sed guuid=caec90ac-2400-0000-513a-9d37ef150000 pid=5615->guuid=0fb6a0ac-2400-0000-513a-9d37f1150000 pid=5617 execve guuid=816d34ad-2400-0000-513a-9d37f3150000 pid=5619 /usr/bin/basename guuid=68f0f0ac-2400-0000-513a-9d37f2150000 pid=5618->guuid=816d34ad-2400-0000-513a-9d37f3150000 pid=5619 execve guuid=044188ad-2400-0000-513a-9d37f4150000 pid=5620 /usr/bin/basename guuid=68f0f0ac-2400-0000-513a-9d37f2150000 pid=5618->guuid=044188ad-2400-0000-513a-9d37f4150000 pid=5620 execve guuid=7b89d0ad-2400-0000-513a-9d37f5150000 pid=5621 /usr/bin/dash guuid=68f0f0ac-2400-0000-513a-9d37f2150000 pid=5618->guuid=7b89d0ad-2400-0000-513a-9d37f5150000 pid=5621 clone guuid=b699d6ad-2400-0000-513a-9d37f6150000 pid=5622 /usr/bin/systemctl guuid=7b89d0ad-2400-0000-513a-9d37f5150000 pid=5621->guuid=b699d6ad-2400-0000-513a-9d37f6150000 pid=5622 execve guuid=93dfddad-2400-0000-513a-9d37f7150000 pid=5623 /usr/bin/sed guuid=7b89d0ad-2400-0000-513a-9d37f5150000 pid=5621->guuid=93dfddad-2400-0000-513a-9d37f7150000 pid=5623 execve guuid=bcaa0744-2500-0000-513a-9d37f9150000 pid=5625 /usr/bin/rm guuid=009ee043-2500-0000-513a-9d37f8150000 pid=5624->guuid=bcaa0744-2500-0000-513a-9d37f9150000 pid=5625 execve guuid=df35d844-2500-0000-513a-9d37fb150000 pid=5627 /usr/bin/pgrep guuid=f9477a44-2500-0000-513a-9d37fa150000 pid=5626->guuid=df35d844-2500-0000-513a-9d37fb150000 pid=5627 execve guuid=1e18e544-2500-0000-513a-9d37fc150000 pid=5628 /usr/bin/xargs zombie guuid=f9477a44-2500-0000-513a-9d37fa150000 pid=5626->guuid=1e18e544-2500-0000-513a-9d37fc150000 pid=5628 execve guuid=eba84c47-2500-0000-513a-9d3702160000 pid=5634 /usr/bin/kill guuid=1e18e544-2500-0000-513a-9d37fc150000 pid=5628->guuid=eba84c47-2500-0000-513a-9d3702160000 pid=5634 execve guuid=18d7c545-2500-0000-513a-9d37fe150000 pid=5630 /usr/bin/rm guuid=d8ae9c45-2500-0000-513a-9d37fd150000 pid=5629->guuid=18d7c545-2500-0000-513a-9d37fe150000 pid=5630 execve guuid=62293046-2500-0000-513a-9d3700160000 pid=5632 /usr/bin/pgrep guuid=203d0846-2500-0000-513a-9d37ff150000 pid=5631->guuid=62293046-2500-0000-513a-9d3700160000 pid=5632 execve guuid=9cbb3646-2500-0000-513a-9d3701160000 pid=5633 /usr/bin/xargs zombie guuid=203d0846-2500-0000-513a-9d37ff150000 pid=5631->guuid=9cbb3646-2500-0000-513a-9d3701160000 pid=5633 execve guuid=75f17b49-2500-0000-513a-9d370a160000 pid=5642 /usr/bin/kill guuid=9cbb3646-2500-0000-513a-9d3701160000 pid=5633->guuid=75f17b49-2500-0000-513a-9d370a160000 pid=5642 execve guuid=0729fc47-2500-0000-513a-9d3704160000 pid=5636 /usr/bin/find guuid=f7ecc447-2500-0000-513a-9d3703160000 pid=5635->guuid=0729fc47-2500-0000-513a-9d3704160000 pid=5636 execve guuid=ca3d9548-2500-0000-513a-9d3706160000 pid=5638 /usr/bin/ps guuid=b2c16e48-2500-0000-513a-9d3705160000 pid=5637->guuid=ca3d9548-2500-0000-513a-9d3706160000 pid=5638 execve guuid=8ac49948-2500-0000-513a-9d3707160000 pid=5639 /usr/bin/grep guuid=b2c16e48-2500-0000-513a-9d3705160000 pid=5637->guuid=8ac49948-2500-0000-513a-9d3707160000 pid=5639 execve guuid=f725a048-2500-0000-513a-9d3708160000 pid=5640 /usr/bin/mawk guuid=b2c16e48-2500-0000-513a-9d3705160000 pid=5637->guuid=f725a048-2500-0000-513a-9d3708160000 pid=5640 execve guuid=3cbba948-2500-0000-513a-9d3709160000 pid=5641 /usr/bin/xargs guuid=b2c16e48-2500-0000-513a-9d3705160000 pid=5637->guuid=3cbba948-2500-0000-513a-9d3709160000 pid=5641 execve guuid=93d1ea49-2500-0000-513a-9d370c160000 pid=5644 /usr/bin/find guuid=3a58c449-2500-0000-513a-9d370b160000 pid=5643->guuid=93d1ea49-2500-0000-513a-9d370c160000 pid=5644 execve guuid=30a96a4a-2500-0000-513a-9d370e160000 pid=5646 /usr/bin/ps guuid=3783434a-2500-0000-513a-9d370d160000 pid=5645->guuid=30a96a4a-2500-0000-513a-9d370e160000 pid=5646 execve guuid=d2646f4a-2500-0000-513a-9d370f160000 pid=5647 /usr/bin/grep guuid=3783434a-2500-0000-513a-9d370d160000 pid=5645->guuid=d2646f4a-2500-0000-513a-9d370f160000 pid=5647 execve guuid=f2ad734a-2500-0000-513a-9d3710160000 pid=5648 /usr/bin/mawk guuid=3783434a-2500-0000-513a-9d370d160000 pid=5645->guuid=f2ad734a-2500-0000-513a-9d3710160000 pid=5648 execve guuid=751c774a-2500-0000-513a-9d3711160000 pid=5649 /usr/bin/xargs guuid=3783434a-2500-0000-513a-9d370d160000 pid=5645->guuid=751c774a-2500-0000-513a-9d3711160000 pid=5649 execve guuid=dc8d344b-2500-0000-513a-9d3713160000 pid=5651 /usr/bin/pgrep guuid=d36d0e4b-2500-0000-513a-9d3712160000 pid=5650->guuid=dc8d344b-2500-0000-513a-9d3713160000 pid=5651 execve guuid=c6cb384b-2500-0000-513a-9d3714160000 pid=5652 /usr/bin/xargs guuid=d36d0e4b-2500-0000-513a-9d3712160000 pid=5650->guuid=c6cb384b-2500-0000-513a-9d3714160000 pid=5652 execve guuid=baf2554d-2500-0000-513a-9d3718160000 pid=5656 /usr/bin/kill guuid=c6cb384b-2500-0000-513a-9d3714160000 pid=5652->guuid=baf2554d-2500-0000-513a-9d3718160000 pid=5656 execve guuid=a1717c4c-2500-0000-513a-9d3716160000 pid=5654 /usr/bin/pgrep guuid=a57b534c-2500-0000-513a-9d3715160000 pid=5653->guuid=a1717c4c-2500-0000-513a-9d3716160000 pid=5654 execve guuid=7d66814c-2500-0000-513a-9d3717160000 pid=5655 /usr/bin/xargs guuid=a57b534c-2500-0000-513a-9d3715160000 pid=5653->guuid=7d66814c-2500-0000-513a-9d3717160000 pid=5655 execve guuid=9ba8704e-2500-0000-513a-9d371e160000 pid=5662 /usr/bin/kill guuid=7d66814c-2500-0000-513a-9d3717160000 pid=5655->guuid=9ba8704e-2500-0000-513a-9d371e160000 pid=5662 execve guuid=c6f4d54d-2500-0000-513a-9d371a160000 pid=5658 /usr/bin/nproc guuid=6ee6ac4d-2500-0000-513a-9d3719160000 pid=5657->guuid=c6f4d54d-2500-0000-513a-9d371a160000 pid=5658 execve guuid=a462164e-2500-0000-513a-9d371b160000 pid=5659 /usr/bin/ps guuid=6ee6ac4d-2500-0000-513a-9d3719160000 pid=5657->guuid=a462164e-2500-0000-513a-9d371b160000 pid=5659 execve guuid=e4eb1c4e-2500-0000-513a-9d371c160000 pid=5660 /usr/bin/mawk guuid=6ee6ac4d-2500-0000-513a-9d3719160000 pid=5657->guuid=e4eb1c4e-2500-0000-513a-9d371c160000 pid=5660 execve guuid=0d3a224e-2500-0000-513a-9d371d160000 pid=5661 /usr/bin/xargs guuid=6ee6ac4d-2500-0000-513a-9d3719160000 pid=5657->guuid=0d3a224e-2500-0000-513a-9d371d160000 pid=5661 execve guuid=264eee4e-2500-0000-513a-9d3720160000 pid=5664 /usr/bin/nproc guuid=5a37c34e-2500-0000-513a-9d371f160000 pid=5663->guuid=264eee4e-2500-0000-513a-9d3720160000 pid=5664 execve guuid=6330284f-2500-0000-513a-9d3721160000 pid=5665 /usr/bin/ps guuid=5a37c34e-2500-0000-513a-9d371f160000 pid=5663->guuid=6330284f-2500-0000-513a-9d3721160000 pid=5665 execve guuid=4ef42c4f-2500-0000-513a-9d3722160000 pid=5666 /usr/bin/mawk guuid=5a37c34e-2500-0000-513a-9d371f160000 pid=5663->guuid=4ef42c4f-2500-0000-513a-9d3722160000 pid=5666 execve guuid=b8d9304f-2500-0000-513a-9d3723160000 pid=5667 /usr/bin/xargs guuid=5a37c34e-2500-0000-513a-9d371f160000 pid=5663->guuid=b8d9304f-2500-0000-513a-9d3723160000 pid=5667 execve guuid=70e5854f-2500-0000-513a-9d3725160000 pid=5669 /usr/bin/dash guuid=10f4634f-2500-0000-513a-9d3724160000 pid=5668->guuid=70e5854f-2500-0000-513a-9d3725160000 pid=5669 clone guuid=64db8f4f-2500-0000-513a-9d3726160000 pid=5670 /usr/bin/mawk guuid=10f4634f-2500-0000-513a-9d3724160000 pid=5668->guuid=64db8f4f-2500-0000-513a-9d3726160000 pid=5670 execve guuid=00a4944f-2500-0000-513a-9d3727160000 pid=5671 /usr/bin/sort guuid=10f4634f-2500-0000-513a-9d3724160000 pid=5668->guuid=00a4944f-2500-0000-513a-9d3727160000 pid=5671 execve guuid=9d05994f-2500-0000-513a-9d3728160000 pid=5672 /usr/bin/uniq guuid=10f4634f-2500-0000-513a-9d3724160000 pid=5668->guuid=9d05994f-2500-0000-513a-9d3728160000 pid=5672 execve guuid=4d7d9f4f-2500-0000-513a-9d3729160000 pid=5673 /usr/bin/mawk guuid=10f4634f-2500-0000-513a-9d3724160000 pid=5668->guuid=4d7d9f4f-2500-0000-513a-9d3729160000 pid=5673 execve guuid=9d10a34f-2500-0000-513a-9d372a160000 pid=5674 /usr/bin/xargs guuid=10f4634f-2500-0000-513a-9d3724160000 pid=5668->guuid=9d10a34f-2500-0000-513a-9d372a160000 pid=5674 execve guuid=9b64b750-2500-0000-513a-9d372c160000 pid=5676 /usr/bin/dash guuid=066a8f50-2500-0000-513a-9d372b160000 pid=5675->guuid=9b64b750-2500-0000-513a-9d372c160000 pid=5676 clone guuid=0f1bbf50-2500-0000-513a-9d372d160000 pid=5677 /usr/bin/mawk guuid=066a8f50-2500-0000-513a-9d372b160000 pid=5675->guuid=0f1bbf50-2500-0000-513a-9d372d160000 pid=5677 execve guuid=49e5c350-2500-0000-513a-9d372e160000 pid=5678 /usr/bin/sort guuid=066a8f50-2500-0000-513a-9d372b160000 pid=5675->guuid=49e5c350-2500-0000-513a-9d372e160000 pid=5678 execve guuid=c768c950-2500-0000-513a-9d372f160000 pid=5679 /usr/bin/uniq guuid=066a8f50-2500-0000-513a-9d372b160000 pid=5675->guuid=c768c950-2500-0000-513a-9d372f160000 pid=5679 execve guuid=5adacc50-2500-0000-513a-9d3730160000 pid=5680 /usr/bin/mawk guuid=066a8f50-2500-0000-513a-9d372b160000 pid=5675->guuid=5adacc50-2500-0000-513a-9d3730160000 pid=5680 execve guuid=922cd450-2500-0000-513a-9d3731160000 pid=5681 /usr/bin/xargs guuid=066a8f50-2500-0000-513a-9d372b160000 pid=5675->guuid=922cd450-2500-0000-513a-9d3731160000 pid=5681 execve guuid=29a47494-2600-0000-513a-9d374b160000 pid=5707 /usr/bin/basename guuid=35eb4894-2600-0000-513a-9d374a160000 pid=5706->guuid=29a47494-2600-0000-513a-9d374b160000 pid=5707 execve guuid=86ceb194-2600-0000-513a-9d374d160000 pid=5709 /usr/bin/basename guuid=35eb4894-2600-0000-513a-9d374a160000 pid=5706->guuid=86ceb194-2600-0000-513a-9d374d160000 pid=5709 execve guuid=bbaff494-2600-0000-513a-9d374f160000 pid=5711 /usr/bin/dash guuid=35eb4894-2600-0000-513a-9d374a160000 pid=5706->guuid=bbaff494-2600-0000-513a-9d374f160000 pid=5711 clone guuid=fc0bd094-2600-0000-513a-9d374e160000 pid=5710 /usr/bin/basename guuid=fbcea494-2600-0000-513a-9d374c160000 pid=5708->guuid=fc0bd094-2600-0000-513a-9d374e160000 pid=5710 execve guuid=413e1095-2600-0000-513a-9d3752160000 pid=5714 /usr/bin/basename guuid=fbcea494-2600-0000-513a-9d374c160000 pid=5708->guuid=413e1095-2600-0000-513a-9d3752160000 pid=5714 execve guuid=5c055295-2600-0000-513a-9d3753160000 pid=5715 /usr/bin/dash guuid=fbcea494-2600-0000-513a-9d374c160000 pid=5708->guuid=5c055295-2600-0000-513a-9d3753160000 pid=5715 clone guuid=4377fd94-2600-0000-513a-9d3750160000 pid=5712 /usr/bin/systemctl guuid=bbaff494-2600-0000-513a-9d374f160000 pid=5711->guuid=4377fd94-2600-0000-513a-9d3750160000 pid=5712 execve guuid=ccf80295-2600-0000-513a-9d3751160000 pid=5713 /usr/bin/sed guuid=bbaff494-2600-0000-513a-9d374f160000 pid=5711->guuid=ccf80295-2600-0000-513a-9d3751160000 pid=5713 execve guuid=2f5b5995-2600-0000-513a-9d3754160000 pid=5716 /usr/bin/systemctl guuid=5c055295-2600-0000-513a-9d3753160000 pid=5715->guuid=2f5b5995-2600-0000-513a-9d3754160000 pid=5716 execve guuid=e8265d95-2600-0000-513a-9d3755160000 pid=5717 /usr/bin/sed guuid=5c055295-2600-0000-513a-9d3753160000 pid=5715->guuid=e8265d95-2600-0000-513a-9d3755160000 pid=5717 execve guuid=5bb91d31-2700-0000-513a-9d3757160000 pid=5719 /usr/bin/basename guuid=c12bd430-2700-0000-513a-9d3756160000 pid=5718->guuid=5bb91d31-2700-0000-513a-9d3757160000 pid=5719 execve guuid=5c1d7731-2700-0000-513a-9d3758160000 pid=5720 /usr/bin/basename guuid=c12bd430-2700-0000-513a-9d3756160000 pid=5718->guuid=5c1d7731-2700-0000-513a-9d3758160000 pid=5720 execve guuid=3a26d631-2700-0000-513a-9d375a160000 pid=5722 /usr/bin/dash guuid=c12bd430-2700-0000-513a-9d3756160000 pid=5718->guuid=3a26d631-2700-0000-513a-9d375a160000 pid=5722 clone guuid=c3a4e831-2700-0000-513a-9d375b160000 pid=5723 /usr/bin/basename guuid=a248b331-2700-0000-513a-9d3759160000 pid=5721->guuid=c3a4e831-2700-0000-513a-9d375b160000 pid=5723 execve guuid=06ca4a32-2700-0000-513a-9d375e160000 pid=5726 /usr/bin/basename guuid=a248b331-2700-0000-513a-9d3759160000 pid=5721->guuid=06ca4a32-2700-0000-513a-9d375e160000 pid=5726 execve guuid=00ecab32-2700-0000-513a-9d375f160000 pid=5727 /usr/bin/dash guuid=a248b331-2700-0000-513a-9d3759160000 pid=5721->guuid=00ecab32-2700-0000-513a-9d375f160000 pid=5727 clone guuid=0aecee31-2700-0000-513a-9d375c160000 pid=5724 /usr/bin/systemctl guuid=3a26d631-2700-0000-513a-9d375a160000 pid=5722->guuid=0aecee31-2700-0000-513a-9d375c160000 pid=5724 execve guuid=f187f831-2700-0000-513a-9d375d160000 pid=5725 /usr/bin/sed guuid=3a26d631-2700-0000-513a-9d375a160000 pid=5722->guuid=f187f831-2700-0000-513a-9d375d160000 pid=5725 execve guuid=9fadb532-2700-0000-513a-9d3760160000 pid=5728 /usr/bin/systemctl guuid=00ecab32-2700-0000-513a-9d375f160000 pid=5727->guuid=9fadb532-2700-0000-513a-9d3760160000 pid=5728 execve guuid=8532ba32-2700-0000-513a-9d3761160000 pid=5729 /usr/bin/sed guuid=00ecab32-2700-0000-513a-9d375f160000 pid=5727->guuid=8532ba32-2700-0000-513a-9d3761160000 pid=5729 execve guuid=e2dc49cf-2700-0000-513a-9d3763160000 pid=5731 /usr/bin/basename guuid=f9ada4ce-2700-0000-513a-9d3762160000 pid=5730->guuid=e2dc49cf-2700-0000-513a-9d3763160000 pid=5731 execve guuid=ff9207d0-2700-0000-513a-9d3764160000 pid=5732 /usr/bin/basename guuid=f9ada4ce-2700-0000-513a-9d3762160000 pid=5730->guuid=ff9207d0-2700-0000-513a-9d3764160000 pid=5732 execve guuid=155bc3d0-2700-0000-513a-9d3768160000 pid=5736 /usr/bin/dash guuid=f9ada4ce-2700-0000-513a-9d3762160000 pid=5730->guuid=155bc3d0-2700-0000-513a-9d3768160000 pid=5736 clone guuid=6d306ed0-2700-0000-513a-9d3766160000 pid=5734 /usr/bin/basename guuid=b29543d0-2700-0000-513a-9d3765160000 pid=5733->guuid=6d306ed0-2700-0000-513a-9d3766160000 pid=5734 execve guuid=f5e9a9d0-2700-0000-513a-9d3767160000 pid=5735 /usr/bin/basename guuid=b29543d0-2700-0000-513a-9d3765160000 pid=5733->guuid=f5e9a9d0-2700-0000-513a-9d3767160000 pid=5735 execve guuid=01b1ecd0-2700-0000-513a-9d376a160000 pid=5738 /usr/bin/dash guuid=b29543d0-2700-0000-513a-9d3765160000 pid=5733->guuid=01b1ecd0-2700-0000-513a-9d376a160000 pid=5738 clone guuid=3d82d7d0-2700-0000-513a-9d3769160000 pid=5737 /usr/bin/systemctl guuid=155bc3d0-2700-0000-513a-9d3768160000 pid=5736->guuid=3d82d7d0-2700-0000-513a-9d3769160000 pid=5737 execve guuid=fc43f4d0-2700-0000-513a-9d376c160000 pid=5740 /usr/bin/sed guuid=155bc3d0-2700-0000-513a-9d3768160000 pid=5736->guuid=fc43f4d0-2700-0000-513a-9d376c160000 pid=5740 execve guuid=fef7f2d0-2700-0000-513a-9d376b160000 pid=5739 /usr/bin/systemctl guuid=01b1ecd0-2700-0000-513a-9d376a160000 pid=5738->guuid=fef7f2d0-2700-0000-513a-9d376b160000 pid=5739 execve guuid=a0c2f6d0-2700-0000-513a-9d376d160000 pid=5741 /usr/bin/sed guuid=01b1ecd0-2700-0000-513a-9d376a160000 pid=5738->guuid=a0c2f6d0-2700-0000-513a-9d376d160000 pid=5741 execve guuid=db1d7a6a-2800-0000-513a-9d376f160000 pid=5743 /usr/bin/rm guuid=06d73e6a-2800-0000-513a-9d376e160000 pid=5742->guuid=db1d7a6a-2800-0000-513a-9d376f160000 pid=5743 execve guuid=d7ea0a6b-2800-0000-513a-9d3771160000 pid=5745 /usr/bin/pgrep guuid=c9bdd06a-2800-0000-513a-9d3770160000 pid=5744->guuid=d7ea0a6b-2800-0000-513a-9d3771160000 pid=5745 execve guuid=5910136b-2800-0000-513a-9d3772160000 pid=5746 /usr/bin/xargs guuid=c9bdd06a-2800-0000-513a-9d3770160000 pid=5744->guuid=5910136b-2800-0000-513a-9d3772160000 pid=5746 execve guuid=7b56066d-2800-0000-513a-9d3778160000 pid=5752 /usr/bin/kill guuid=5910136b-2800-0000-513a-9d3772160000 pid=5746->guuid=7b56066d-2800-0000-513a-9d3778160000 pid=5752 execve guuid=e9eb9c6b-2800-0000-513a-9d3774160000 pid=5748 /usr/bin/rm guuid=aaaa716b-2800-0000-513a-9d3773160000 pid=5747->guuid=e9eb9c6b-2800-0000-513a-9d3774160000 pid=5748 execve guuid=9e43026c-2800-0000-513a-9d3776160000 pid=5750 /usr/bin/pgrep guuid=280adc6b-2800-0000-513a-9d3775160000 pid=5749->guuid=9e43026c-2800-0000-513a-9d3776160000 pid=5750 execve guuid=4e0b086c-2800-0000-513a-9d3777160000 pid=5751 /usr/bin/xargs zombie guuid=280adc6b-2800-0000-513a-9d3775160000 pid=5749->guuid=4e0b086c-2800-0000-513a-9d3777160000 pid=5751 execve guuid=0fae1c6e-2800-0000-513a-9d3780160000 pid=5760 /usr/bin/kill guuid=4e0b086c-2800-0000-513a-9d3777160000 pid=5751->guuid=0fae1c6e-2800-0000-513a-9d3780160000 pid=5760 execve guuid=e65a706d-2800-0000-513a-9d377a160000 pid=5754 /usr/bin/find guuid=17a0426d-2800-0000-513a-9d3779160000 pid=5753->guuid=e65a706d-2800-0000-513a-9d377a160000 pid=5754 execve guuid=8a19f06d-2800-0000-513a-9d377c160000 pid=5756 /usr/bin/ps guuid=8f45c96d-2800-0000-513a-9d377b160000 pid=5755->guuid=8a19f06d-2800-0000-513a-9d377c160000 pid=5756 execve guuid=653df56d-2800-0000-513a-9d377d160000 pid=5757 /usr/bin/grep guuid=8f45c96d-2800-0000-513a-9d377b160000 pid=5755->guuid=653df56d-2800-0000-513a-9d377d160000 pid=5757 execve guuid=5afcf86d-2800-0000-513a-9d377e160000 pid=5758 /usr/bin/mawk guuid=8f45c96d-2800-0000-513a-9d377b160000 pid=5755->guuid=5afcf86d-2800-0000-513a-9d377e160000 pid=5758 execve guuid=16f9046e-2800-0000-513a-9d377f160000 pid=5759 /usr/bin/xargs guuid=8f45c96d-2800-0000-513a-9d377b160000 pid=5755->guuid=16f9046e-2800-0000-513a-9d377f160000 pid=5759 execve guuid=ab8ea86e-2800-0000-513a-9d3782160000 pid=5762 /usr/bin/find guuid=d636616e-2800-0000-513a-9d3781160000 pid=5761->guuid=ab8ea86e-2800-0000-513a-9d3782160000 pid=5762 execve guuid=e54c326f-2800-0000-513a-9d3784160000 pid=5764 /usr/bin/ps guuid=6b2b056f-2800-0000-513a-9d3783160000 pid=5763->guuid=e54c326f-2800-0000-513a-9d3784160000 pid=5764 execve guuid=f75e376f-2800-0000-513a-9d3785160000 pid=5765 /usr/bin/grep guuid=6b2b056f-2800-0000-513a-9d3783160000 pid=5763->guuid=f75e376f-2800-0000-513a-9d3785160000 pid=5765 execve guuid=fdfa3b6f-2800-0000-513a-9d3786160000 pid=5766 /usr/bin/mawk guuid=6b2b056f-2800-0000-513a-9d3783160000 pid=5763->guuid=fdfa3b6f-2800-0000-513a-9d3786160000 pid=5766 execve guuid=55c0406f-2800-0000-513a-9d3787160000 pid=5767 /usr/bin/xargs guuid=6b2b056f-2800-0000-513a-9d3783160000 pid=5763->guuid=55c0406f-2800-0000-513a-9d3787160000 pid=5767 execve guuid=f20fff6f-2800-0000-513a-9d3789160000 pid=5769 /usr/bin/pgrep guuid=3e1cd86f-2800-0000-513a-9d3788160000 pid=5768->guuid=f20fff6f-2800-0000-513a-9d3789160000 pid=5769 execve guuid=5b7b0470-2800-0000-513a-9d378a160000 pid=5770 /usr/bin/xargs guuid=3e1cd86f-2800-0000-513a-9d3788160000 pid=5768->guuid=5b7b0470-2800-0000-513a-9d378a160000 pid=5770 execve guuid=affc1572-2800-0000-513a-9d378e160000 pid=5774 /usr/bin/kill guuid=5b7b0470-2800-0000-513a-9d378a160000 pid=5770->guuid=affc1572-2800-0000-513a-9d378e160000 pid=5774 execve guuid=b0544271-2800-0000-513a-9d378c160000 pid=5772 /usr/bin/pgrep guuid=21951971-2800-0000-513a-9d378b160000 pid=5771->guuid=b0544271-2800-0000-513a-9d378c160000 pid=5772 execve guuid=4c5e4871-2800-0000-513a-9d378d160000 pid=5773 /usr/bin/xargs guuid=21951971-2800-0000-513a-9d378b160000 pid=5771->guuid=4c5e4871-2800-0000-513a-9d378d160000 pid=5773 execve guuid=5cd44d73-2800-0000-513a-9d3794160000 pid=5780 /usr/bin/kill guuid=4c5e4871-2800-0000-513a-9d378d160000 pid=5773->guuid=5cd44d73-2800-0000-513a-9d3794160000 pid=5780 execve guuid=02fa9972-2800-0000-513a-9d3790160000 pid=5776 /usr/bin/nproc guuid=1cb26b72-2800-0000-513a-9d378f160000 pid=5775->guuid=02fa9972-2800-0000-513a-9d3790160000 pid=5776 execve guuid=0a2dd772-2800-0000-513a-9d3791160000 pid=5777 /usr/bin/ps guuid=1cb26b72-2800-0000-513a-9d378f160000 pid=5775->guuid=0a2dd772-2800-0000-513a-9d3791160000 pid=5777 execve guuid=3842db72-2800-0000-513a-9d3792160000 pid=5778 /usr/bin/mawk guuid=1cb26b72-2800-0000-513a-9d378f160000 pid=5775->guuid=3842db72-2800-0000-513a-9d3792160000 pid=5778 execve guuid=2957e072-2800-0000-513a-9d3793160000 pid=5779 /usr/bin/xargs guuid=1cb26b72-2800-0000-513a-9d378f160000 pid=5775->guuid=2957e072-2800-0000-513a-9d3793160000 pid=5779 execve guuid=332abe73-2800-0000-513a-9d3796160000 pid=5782 /usr/bin/nproc guuid=edc99473-2800-0000-513a-9d3795160000 pid=5781->guuid=332abe73-2800-0000-513a-9d3796160000 pid=5782 execve guuid=aae94874-2800-0000-513a-9d379b160000 pid=5787 /usr/bin/ps guuid=edc99473-2800-0000-513a-9d3795160000 pid=5781->guuid=aae94874-2800-0000-513a-9d379b160000 pid=5787 execve guuid=606a4c74-2800-0000-513a-9d379d160000 pid=5789 /usr/bin/mawk guuid=edc99473-2800-0000-513a-9d3795160000 pid=5781->guuid=606a4c74-2800-0000-513a-9d379d160000 pid=5789 execve guuid=a2b15074-2800-0000-513a-9d379f160000 pid=5791 /usr/bin/xargs guuid=edc99473-2800-0000-513a-9d3795160000 pid=5781->guuid=a2b15074-2800-0000-513a-9d379f160000 pid=5791 execve guuid=8ea73f74-2800-0000-513a-9d3798160000 pid=5784 /usr/bin/dash guuid=3eae1874-2800-0000-513a-9d3797160000 pid=5783->guuid=8ea73f74-2800-0000-513a-9d3798160000 pid=5784 clone guuid=2a764374-2800-0000-513a-9d3799160000 pid=5785 /usr/bin/mawk guuid=3eae1874-2800-0000-513a-9d3797160000 pid=5783->guuid=2a764374-2800-0000-513a-9d3799160000 pid=5785 execve guuid=b0a64774-2800-0000-513a-9d379a160000 pid=5786 /usr/bin/sort guuid=3eae1874-2800-0000-513a-9d3797160000 pid=5783->guuid=b0a64774-2800-0000-513a-9d379a160000 pid=5786 execve guuid=27604b74-2800-0000-513a-9d379c160000 pid=5788 /usr/bin/uniq guuid=3eae1874-2800-0000-513a-9d3797160000 pid=5783->guuid=27604b74-2800-0000-513a-9d379c160000 pid=5788 execve guuid=46774f74-2800-0000-513a-9d379e160000 pid=5790 /usr/bin/mawk guuid=3eae1874-2800-0000-513a-9d3797160000 pid=5783->guuid=46774f74-2800-0000-513a-9d379e160000 pid=5790 execve guuid=97e25274-2800-0000-513a-9d37a0160000 pid=5792 /usr/bin/xargs guuid=3eae1874-2800-0000-513a-9d3797160000 pid=5783->guuid=97e25274-2800-0000-513a-9d37a0160000 pid=5792 execve guuid=53191776-2800-0000-513a-9d37a2160000 pid=5794 /usr/bin/dash guuid=01d7e775-2800-0000-513a-9d37a1160000 pid=5793->guuid=53191776-2800-0000-513a-9d37a2160000 pid=5794 clone guuid=e8601f76-2800-0000-513a-9d37a3160000 pid=5795 /usr/bin/mawk guuid=01d7e775-2800-0000-513a-9d37a1160000 pid=5793->guuid=e8601f76-2800-0000-513a-9d37a3160000 pid=5795 execve guuid=28072576-2800-0000-513a-9d37a4160000 pid=5796 /usr/bin/sort guuid=01d7e775-2800-0000-513a-9d37a1160000 pid=5793->guuid=28072576-2800-0000-513a-9d37a4160000 pid=5796 execve guuid=007a2c76-2800-0000-513a-9d37a5160000 pid=5797 /usr/bin/uniq guuid=01d7e775-2800-0000-513a-9d37a1160000 pid=5793->guuid=007a2c76-2800-0000-513a-9d37a5160000 pid=5797 execve guuid=ad813076-2800-0000-513a-9d37a6160000 pid=5798 /usr/bin/mawk guuid=01d7e775-2800-0000-513a-9d37a1160000 pid=5793->guuid=ad813076-2800-0000-513a-9d37a6160000 pid=5798 execve guuid=65f93376-2800-0000-513a-9d37a7160000 pid=5799 /usr/bin/xargs guuid=01d7e775-2800-0000-513a-9d37a1160000 pid=5793->guuid=65f93376-2800-0000-513a-9d37a7160000 pid=5799 execve
Result
Threat name:
n/a
Detection:
malicious
Classification:
n/a
Score:
52 / 100
Signature
Multi AV Scanner detection for submitted file
Writes identical ELF files to multiple locations
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1813601 Sample: jiedian.elf Startdate: 13/11/2025 Architecture: LINUX Score: 52 97 www.dwf1579.vip 156.234.207.194, 55550 XIAOZHIYUN1-AS-APICIDCNETWORKUS Seychelles 2->97 99 Multi AV Scanner detection for submitted file 2->99 11 jiedian.elf 2->11         started        13 sshd sshd 2->13         started        15 sshd sshd 2->15         started        17 5 other processes 2->17 signatures3 process4 process5 19 jiedian.elf jiedian.elf 11->19         started        22 jiedian.elf pkill 11->22         started        24 jiedian.elf 11->24         started        26 sshd 13->26         started        28 sshd 15->28         started        signatures6 101 Writes identical ELF files to multiple locations 19->101 30 jiedian.elf jiedian.elf 19->30         started        33 jiedian.elf sh 19->33         started        35 jiedian.elf service systemctl 19->35         started        37 27 other processes 19->37 process7 file8 91 /usr/share/awk/mysqI.service, ELF 30->91 dropped 93 /usr/share/awk/mysqI, ELF 30->93 dropped 95 /etc/mysqI, ELF 30->95 dropped 39 jiedian.elf sh 30->39         started        41 jiedian.elf service systemctl 30->41         started        43 jiedian.elf service systemctl 30->43         started        49 25 other processes 30->49 51 6 other processes 33->51 45 service 35->45         started        53 3 other processes 35->53 47 service 37->47         started        55 21 other processes 37->55 process9 process10 61 6 other processes 39->61 57 service 41->57         started        63 3 other processes 41->63 59 service 43->59         started        65 3 other processes 43->65 67 2 other processes 45->67 69 2 other processes 47->69 71 18 other processes 49->71 73 4 other processes 55->73 process11 75 service systemctl 57->75         started        77 service sed 57->77         started        79 service systemctl 59->79         started        81 service sed 59->81         started        83 service systemctl 71->83         started        85 service sed 71->85         started        87 xargs kill 71->87         started        89 xargs kill 71->89         started       
Threat name:
Linux.Trojan.Multiverze
Status:
Malicious
First seen:
2025-11-13 18:37:53 UTC
File Type:
ELF64 Little (Exe)
AV detection:
14 of 38 (36.84%)
Threat level:
  5/5
Result
Malware family:
pumabot
Score:
  10/10
Tags:
family:pumabot botnet defense_evasion discovery linux persistence privilege_escalation upx
Behaviour
Enumerates kernel/hardware configuration
Process Discovery
Reads runtime system information
Reads CPU attributes
Security Software Discovery
UPX packed file
Disables SELinux
Enumerates running processes
Modifies systemd
Detects PumaBot systemd service
PumaBot
Pumabot family
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:GoBinTest
Rule name:golang_binary_string
Description:Golang strings present
Rule name:ProgramLanguage_Golang
Author:albertzsigovits
Description:Application written in Golang programming language
Rule name:RIPEMD160_Constants
Author:phoul (@phoul)
Description:Look for RIPEMD-160 constants
Rule name:SHA1_Constants
Author:phoul (@phoul)
Description:Look for SHA1 constants
Rule name:SHA512_Constants
Author:phoul (@phoul)
Description:Look for SHA384/SHA512 constants
Rule name:upx_antiunpack_elf64
Author:JPCERT/CC Incident Response Group
Description:UPX Anti-Unpacking technique to magic renamed for ELF64

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

PumaBot

elf 857d463c693b5c80236eff885408ce3ddbfc45f94e9a5022fe67ebbc090ba151

(this sample)

  
Delivery method
Distributed via web download

Comments