MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a927d760f2c71dd6ac8fbd11658b7edfe9315ba370b2abfa699659fba48d8fef. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



CoinMiner


Vendor detections: 6


Intelligence 6 IOCs YARA 2 File information Comments

SHA256 hash: a927d760f2c71dd6ac8fbd11658b7edfe9315ba370b2abfa699659fba48d8fef
SHA3-384 hash: 09ef803c07c7a1635249cbe0d3c5ae39b36d0e7d4e9636e0de88cdcc8df56914500f894b0ea7b51a531d41d2b85416cd
SHA1 hash: 23efceded45925142b529f4c07575c90a9847b89
MD5 hash: de4dfdb13e1a50d30773791779c17b46
humanhash: sink-saturn-princess-berlin
File name:run-CN.sh
Download: download sample
Signature CoinMiner
File size:6'837 bytes
First seen:2025-08-08 12:33:21 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 192:2I848CzDN1eEXOKDk5+rqaAxayH3MeYVZTMNZlu:hvnP9kPAZTyu
TLSH T1CBE19605F79199B425DCC168044A1D806D4B512B3D092C18FCEDB5AABF28B6C62FDBFB
Magika shell
Reporter abuse_ch
Tags:CoinMiner sh
URLMalware sample (SHA256 hash)SignatureTags
http://162.248.53.119:8000/mon.sh1e891ab1521b27923233e694f60fdbf0e1b840e657d8b1ffdefd8b5ef5e38964 CoinMinerCoinMiner
http://162.248.53.119:8000/yes.tar.gzn/an/aopendir
https://cdn.tempfile.pro/0c748b9e8bc6b5b4/proc.binn/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
33
Origin country :
DE DE
Vendor Threat Intelligence
Status:
terminated
Behavior Graph:
%3 guuid=b0f0e769-1800-0000-6737-0203070d0000 pid=3335 /usr/bin/sudo guuid=88cfb36b-1800-0000-6737-02030d0d0000 pid=3341 /tmp/sample.bin guuid=b0f0e769-1800-0000-6737-0203070d0000 pid=3335->guuid=88cfb36b-1800-0000-6737-02030d0d0000 pid=3341 execve guuid=13240a6c-1800-0000-6737-02030e0d0000 pid=3342 /usr/bin/systemctl guuid=88cfb36b-1800-0000-6737-02030d0d0000 pid=3341->guuid=13240a6c-1800-0000-6737-02030e0d0000 pid=3342 execve guuid=45f1b26d-1800-0000-6737-0203130d0000 pid=3347 /usr/bin/bash guuid=88cfb36b-1800-0000-6737-02030d0d0000 pid=3341->guuid=45f1b26d-1800-0000-6737-0203130d0000 pid=3347 clone guuid=d9715474-1800-0000-6737-0203240d0000 pid=3364 /usr/bin/bash guuid=88cfb36b-1800-0000-6737-02030d0d0000 pid=3341->guuid=d9715474-1800-0000-6737-0203240d0000 pid=3364 clone guuid=3d8cda74-1800-0000-6737-0203280d0000 pid=3368 /usr/bin/id guuid=88cfb36b-1800-0000-6737-02030d0d0000 pid=3341->guuid=3d8cda74-1800-0000-6737-0203280d0000 pid=3368 execve guuid=c52a6275-1800-0000-6737-02032b0d0000 pid=3371 /usr/bin/apt-get delete-file write-file guuid=88cfb36b-1800-0000-6737-02030d0d0000 pid=3341->guuid=c52a6275-1800-0000-6737-02032b0d0000 pid=3371 execve guuid=71764a34-1a00-0000-6737-02032f120000 pid=4655 /usr/bin/apt-get guuid=88cfb36b-1800-0000-6737-02030d0d0000 pid=3341->guuid=71764a34-1a00-0000-6737-02032f120000 pid=4655 execve guuid=cbc12c36-1a00-0000-6737-02033b120000 pid=4667 /usr/bin/mkdir guuid=88cfb36b-1800-0000-6737-02030d0d0000 pid=3341->guuid=cbc12c36-1a00-0000-6737-02033b120000 pid=4667 execve guuid=4a068b36-1a00-0000-6737-02033f120000 pid=4671 /usr/bin/wget dns net send-data write-file guuid=88cfb36b-1800-0000-6737-02030d0d0000 pid=3341->guuid=4a068b36-1a00-0000-6737-02033f120000 pid=4671 execve guuid=1c1e8a5c-1a00-0000-6737-0203d6120000 pid=4822 /usr/bin/mv guuid=88cfb36b-1800-0000-6737-02030d0d0000 pid=3341->guuid=1c1e8a5c-1a00-0000-6737-0203d6120000 pid=4822 execve guuid=9886e45c-1a00-0000-6737-0203d7120000 pid=4823 /usr/bin/rm guuid=88cfb36b-1800-0000-6737-02030d0d0000 pid=3341->guuid=9886e45c-1a00-0000-6737-0203d7120000 pid=4823 execve guuid=21d8205d-1a00-0000-6737-0203da120000 pid=4826 /usr/bin/chmod guuid=88cfb36b-1800-0000-6737-02030d0d0000 pid=3341->guuid=21d8205d-1a00-0000-6737-0203da120000 pid=4826 execve guuid=84826a5d-1a00-0000-6737-0203de120000 pid=4830 /usr/lib/dev/systemdev/systemd-mont mprotect-exec net send-data guuid=88cfb36b-1800-0000-6737-02030d0d0000 pid=3341->guuid=84826a5d-1a00-0000-6737-0203de120000 pid=4830 execve guuid=889e745d-1a00-0000-6737-0203e0120000 pid=4832 /usr/bin/sleep guuid=88cfb36b-1800-0000-6737-02030d0d0000 pid=3341->guuid=889e745d-1a00-0000-6737-0203e0120000 pid=4832 execve guuid=683fb57b-1a00-0000-6737-020356130000 pid=4950 /usr/bin/ps guuid=88cfb36b-1800-0000-6737-02030d0d0000 pid=3341->guuid=683fb57b-1a00-0000-6737-020356130000 pid=4950 execve guuid=06d9907f-1a00-0000-6737-02036a130000 pid=4970 /usr/bin/sleep guuid=88cfb36b-1800-0000-6737-02030d0d0000 pid=3341->guuid=06d9907f-1a00-0000-6737-02036a130000 pid=4970 execve guuid=87e9f28c-1b00-0000-6737-020328150000 pid=5416 /usr/bin/ps guuid=88cfb36b-1800-0000-6737-02030d0d0000 pid=3341->guuid=87e9f28c-1b00-0000-6737-020328150000 pid=5416 execve guuid=eee8b590-1b00-0000-6737-020329150000 pid=5417 /usr/bin/rm guuid=88cfb36b-1800-0000-6737-02030d0d0000 pid=3341->guuid=eee8b590-1b00-0000-6737-020329150000 pid=5417 execve guuid=a24d1191-1b00-0000-6737-02032a150000 pid=5418 /usr/bin/rm guuid=88cfb36b-1800-0000-6737-02030d0d0000 pid=3341->guuid=a24d1191-1b00-0000-6737-02032a150000 pid=5418 execve guuid=61ccc56d-1800-0000-6737-0203150d0000 pid=3349 /usr/bin/wget dns net send-data guuid=45f1b26d-1800-0000-6737-0203130d0000 pid=3347->guuid=61ccc56d-1800-0000-6737-0203150d0000 pid=3349 execve 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=61ccc56d-1800-0000-6737-0203150d0000 pid=3349->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 72B 0690ccd5-4816-5f11-94dc-7c585f38cdea ipv4.icanhazip.com:0 guuid=61ccc56d-1800-0000-6737-0203150d0000 pid=3349->0690ccd5-4816-5f11-94dc-7c585f38cdea con d0ecfe49-aa79-583f-85c6-85ac97075256 ipv4.icanhazip.com:80 guuid=61ccc56d-1800-0000-6737-0203150d0000 pid=3349->d0ecfe49-aa79-583f-85c6-85ac97075256 send: 133B guuid=77a75f74-1800-0000-6737-0203250d0000 pid=3365 /usr/bin/bash guuid=d9715474-1800-0000-6737-0203240d0000 pid=3364->guuid=77a75f74-1800-0000-6737-0203250d0000 pid=3365 clone guuid=dfac6774-1800-0000-6737-0203260d0000 pid=3366 /usr/bin/sed guuid=d9715474-1800-0000-6737-0203240d0000 pid=3364->guuid=dfac6774-1800-0000-6737-0203260d0000 pid=3366 execve guuid=6a9d6d74-1800-0000-6737-0203270d0000 pid=3367 /usr/bin/cut guuid=d9715474-1800-0000-6737-0203240d0000 pid=3364->guuid=6a9d6d74-1800-0000-6737-0203270d0000 pid=3367 execve guuid=5f63b176-1800-0000-6737-0203310d0000 pid=3377 /usr/bin/dpkg guuid=c52a6275-1800-0000-6737-02032b0d0000 pid=3371->guuid=5f63b176-1800-0000-6737-0203310d0000 pid=3377 execve guuid=9db85077-1800-0000-6737-0203330d0000 pid=3379 /usr/lib/apt/methods/mirror guuid=c52a6275-1800-0000-6737-02032b0d0000 pid=3371->guuid=9db85077-1800-0000-6737-0203330d0000 pid=3379 execve guuid=4b9f7e78-1800-0000-6737-0203350d0000 pid=3381 /usr/lib/apt/methods/mirror guuid=c52a6275-1800-0000-6737-02032b0d0000 pid=3371->guuid=4b9f7e78-1800-0000-6737-0203350d0000 pid=3381 execve guuid=e20abd79-1800-0000-6737-0203370d0000 pid=3383 /usr/lib/apt/methods/file guuid=c52a6275-1800-0000-6737-02032b0d0000 pid=3371->guuid=e20abd79-1800-0000-6737-0203370d0000 pid=3383 execve guuid=afb6607b-1800-0000-6737-02033b0d0000 pid=3387 /usr/lib/apt/methods/file delete-file guuid=c52a6275-1800-0000-6737-02032b0d0000 pid=3371->guuid=afb6607b-1800-0000-6737-02033b0d0000 pid=3387 execve guuid=8b5ad97c-1800-0000-6737-0203400d0000 pid=3392 /usr/lib/apt/methods/http guuid=c52a6275-1800-0000-6737-02032b0d0000 pid=3371->guuid=8b5ad97c-1800-0000-6737-0203400d0000 pid=3392 execve guuid=52180b80-1800-0000-6737-0203490d0000 pid=3401 /usr/lib/apt/methods/http dns net send-data write-file guuid=c52a6275-1800-0000-6737-02032b0d0000 pid=3371->guuid=52180b80-1800-0000-6737-0203490d0000 pid=3401 execve guuid=06308196-1800-0000-6737-0203700d0000 pid=3440 /usr/lib/apt/methods/gpgv guuid=c52a6275-1800-0000-6737-02032b0d0000 pid=3371->guuid=06308196-1800-0000-6737-0203700d0000 pid=3440 execve guuid=c10a5a98-1800-0000-6737-0203750d0000 pid=3445 /usr/lib/apt/methods/gpgv guuid=c52a6275-1800-0000-6737-02032b0d0000 pid=3371->guuid=c10a5a98-1800-0000-6737-0203750d0000 pid=3445 execve guuid=7f20edc3-1800-0000-6737-02030f0e0000 pid=3599 /usr/lib/apt/methods/rred guuid=c52a6275-1800-0000-6737-02032b0d0000 pid=3371->guuid=7f20edc3-1800-0000-6737-02030f0e0000 pid=3599 execve guuid=c14e7ad8-1800-0000-6737-0203260e0000 pid=3622 /usr/lib/apt/methods/rred write-file guuid=c52a6275-1800-0000-6737-02032b0d0000 pid=3371->guuid=c14e7ad8-1800-0000-6737-0203260e0000 pid=3622 execve guuid=e77e14db-1800-0000-6737-0203290e0000 pid=3625 /usr/lib/apt/methods/rred write-file guuid=c52a6275-1800-0000-6737-02032b0d0000 pid=3371->guuid=e77e14db-1800-0000-6737-0203290e0000 pid=3625 execve guuid=3c1be7e4-1800-0000-6737-02034b0e0000 pid=3659 /usr/lib/apt/methods/store guuid=c52a6275-1800-0000-6737-02032b0d0000 pid=3371->guuid=3c1be7e4-1800-0000-6737-02034b0e0000 pid=3659 execve guuid=3de653e6-1800-0000-6737-0203520e0000 pid=3666 /usr/lib/apt/methods/store write-file guuid=c52a6275-1800-0000-6737-02032b0d0000 pid=3371->guuid=3de653e6-1800-0000-6737-0203520e0000 pid=3666 execve guuid=c5aed025-1900-0000-6737-0203d20e0000 pid=3794 /usr/bin/dpkg guuid=c52a6275-1800-0000-6737-02032b0d0000 pid=3371->guuid=c5aed025-1900-0000-6737-0203d20e0000 pid=3794 execve guuid=ea733a30-1a00-0000-6737-020320120000 pid=4640 /usr/bin/dpkg guuid=c52a6275-1800-0000-6737-02032b0d0000 pid=3371->guuid=ea733a30-1a00-0000-6737-020320120000 pid=4640 execve guuid=52180b80-1800-0000-6737-0203490d0000 pid=3401->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 122B 869ebe88-8c1e-5fbb-adb0-cfe48d8d7faf debian.map.fastly.net:443 guuid=52180b80-1800-0000-6737-0203490d0000 pid=3401->869ebe88-8c1e-5fbb-adb0-cfe48d8d7faf con guuid=34c4a299-1800-0000-6737-02037a0d0000 pid=3450 /usr/lib/apt/methods/gpgv delete-file write-file guuid=c10a5a98-1800-0000-6737-0203750d0000 pid=3445->guuid=34c4a299-1800-0000-6737-02037a0d0000 pid=3450 clone guuid=355e98af-1800-0000-6737-0203cb0d0000 pid=3531 /usr/lib/apt/methods/gpgv delete-file write-file guuid=c10a5a98-1800-0000-6737-0203750d0000 pid=3445->guuid=355e98af-1800-0000-6737-0203cb0d0000 pid=3531 clone guuid=3892a6be-1800-0000-6737-0203000e0000 pid=3584 /usr/lib/apt/methods/gpgv delete-file write-file guuid=c10a5a98-1800-0000-6737-0203750d0000 pid=3445->guuid=3892a6be-1800-0000-6737-0203000e0000 pid=3584 clone guuid=902741dd-1800-0000-6737-02032f0e0000 pid=3631 /usr/lib/apt/methods/gpgv delete-file write-file guuid=c10a5a98-1800-0000-6737-0203750d0000 pid=3445->guuid=902741dd-1800-0000-6737-02032f0e0000 pid=3631 clone guuid=e1ccde9b-1800-0000-6737-0203800d0000 pid=3456 /usr/bin/apt-key write-file guuid=34c4a299-1800-0000-6737-02037a0d0000 pid=3450->guuid=e1ccde9b-1800-0000-6737-0203800d0000 pid=3456 execve guuid=9e4a1c9c-1800-0000-6737-0203820d0000 pid=3458 /usr/bin/dash guuid=e1ccde9b-1800-0000-6737-0203800d0000 pid=3456->guuid=9e4a1c9c-1800-0000-6737-0203820d0000 pid=3458 clone guuid=d4524f9c-1800-0000-6737-0203830d0000 pid=3459 /usr/bin/apt-config guuid=e1ccde9b-1800-0000-6737-0203800d0000 pid=3456->guuid=d4524f9c-1800-0000-6737-0203830d0000 pid=3459 execve guuid=355d61a3-1800-0000-6737-0203970d0000 pid=3479 /usr/bin/apt-config guuid=e1ccde9b-1800-0000-6737-0203800d0000 pid=3456->guuid=355d61a3-1800-0000-6737-0203970d0000 pid=3479 execve guuid=5c24f7a5-1800-0000-6737-0203a10d0000 pid=3489 /usr/bin/apt-config guuid=e1ccde9b-1800-0000-6737-0203800d0000 pid=3456->guuid=5c24f7a5-1800-0000-6737-0203a10d0000 pid=3489 execve guuid=5ab0d0a7-1800-0000-6737-0203a80d0000 pid=3496 /usr/bin/apt-config guuid=e1ccde9b-1800-0000-6737-0203800d0000 pid=3456->guuid=5ab0d0a7-1800-0000-6737-0203a80d0000 pid=3496 execve guuid=542409aa-1800-0000-6737-0203b30d0000 pid=3507 /usr/bin/dash guuid=e1ccde9b-1800-0000-6737-0203800d0000 pid=3456->guuid=542409aa-1800-0000-6737-0203b30d0000 pid=3507 clone guuid=57d528aa-1800-0000-6737-0203b40d0000 pid=3508 /usr/bin/apt-config guuid=e1ccde9b-1800-0000-6737-0203800d0000 pid=3456->guuid=57d528aa-1800-0000-6737-0203b40d0000 pid=3508 execve guuid=3d5cbfab-1800-0000-6737-0203bc0d0000 pid=3516 /usr/bin/mktemp guuid=e1ccde9b-1800-0000-6737-0203800d0000 pid=3456->guuid=3d5cbfab-1800-0000-6737-0203bc0d0000 pid=3516 execve guuid=ac6ef1ab-1800-0000-6737-0203c00d0000 pid=3520 /usr/bin/chmod guuid=e1ccde9b-1800-0000-6737-0203800d0000 pid=3456->guuid=ac6ef1ab-1800-0000-6737-0203c00d0000 pid=3520 execve guuid=c9fa1dac-1800-0000-6737-0203c10d0000 pid=3521 /usr/bin/dash guuid=e1ccde9b-1800-0000-6737-0203800d0000 pid=3456->guuid=c9fa1dac-1800-0000-6737-0203c10d0000 pid=3521 clone guuid=3b5d2aac-1800-0000-6737-0203c20d0000 pid=3522 /usr/bin/dash guuid=e1ccde9b-1800-0000-6737-0203800d0000 pid=3456->guuid=3b5d2aac-1800-0000-6737-0203c20d0000 pid=3522 clone guuid=2b8385ac-1800-0000-6737-0203c50d0000 pid=3525 /usr/bin/dash guuid=e1ccde9b-1800-0000-6737-0203800d0000 pid=3456->guuid=2b8385ac-1800-0000-6737-0203c50d0000 pid=3525 clone guuid=7a32e1ac-1800-0000-6737-0203c80d0000 pid=3528 /usr/bin/dash guuid=e1ccde9b-1800-0000-6737-0203800d0000 pid=3456->guuid=7a32e1ac-1800-0000-6737-0203c80d0000 pid=3528 clone guuid=8202f3ac-1800-0000-6737-0203c90d0000 pid=3529 /usr/bin/gpgv guuid=e1ccde9b-1800-0000-6737-0203800d0000 pid=3456->guuid=8202f3ac-1800-0000-6737-0203c90d0000 pid=3529 execve guuid=8158c7ae-1800-0000-6737-0203ca0d0000 pid=3530 /usr/bin/rm delete-file guuid=e1ccde9b-1800-0000-6737-0203800d0000 pid=3456->guuid=8158c7ae-1800-0000-6737-0203ca0d0000 pid=3530 execve guuid=b786ae9e-1800-0000-6737-02038a0d0000 pid=3466 /usr/bin/dpkg guuid=d4524f9c-1800-0000-6737-0203830d0000 pid=3459->guuid=b786ae9e-1800-0000-6737-02038a0d0000 pid=3466 execve guuid=f2c07ca5-1800-0000-6737-02039f0d0000 pid=3487 /usr/bin/dpkg guuid=355d61a3-1800-0000-6737-0203970d0000 pid=3479->guuid=f2c07ca5-1800-0000-6737-02039f0d0000 pid=3487 execve guuid=185f6da7-1800-0000-6737-0203a60d0000 pid=3494 /usr/bin/dpkg guuid=5c24f7a5-1800-0000-6737-0203a10d0000 pid=3489->guuid=185f6da7-1800-0000-6737-0203a60d0000 pid=3494 execve guuid=93d49ea9-1800-0000-6737-0203b00d0000 pid=3504 /usr/bin/dpkg guuid=5ab0d0a7-1800-0000-6737-0203a80d0000 pid=3496->guuid=93d49ea9-1800-0000-6737-0203b00d0000 pid=3504 execve guuid=25f209ab-1800-0000-6737-0203b80d0000 pid=3512 /usr/bin/dpkg guuid=57d528aa-1800-0000-6737-0203b40d0000 pid=3508->guuid=25f209ab-1800-0000-6737-0203b80d0000 pid=3512 execve guuid=0d8b32ac-1800-0000-6737-0203c30d0000 pid=3523 /usr/bin/dash guuid=3b5d2aac-1800-0000-6737-0203c20d0000 pid=3522->guuid=0d8b32ac-1800-0000-6737-0203c30d0000 pid=3523 clone guuid=c9a937ac-1800-0000-6737-0203c40d0000 pid=3524 /usr/bin/sed guuid=3b5d2aac-1800-0000-6737-0203c20d0000 pid=3522->guuid=c9a937ac-1800-0000-6737-0203c40d0000 pid=3524 execve guuid=c2688bac-1800-0000-6737-0203c60d0000 pid=3526 /usr/bin/dash guuid=2b8385ac-1800-0000-6737-0203c50d0000 pid=3525->guuid=c2688bac-1800-0000-6737-0203c60d0000 pid=3526 clone guuid=549c8fac-1800-0000-6737-0203c70d0000 pid=3527 /usr/bin/sed guuid=2b8385ac-1800-0000-6737-0203c50d0000 pid=3525->guuid=549c8fac-1800-0000-6737-0203c70d0000 pid=3527 execve guuid=1b6e38b0-1800-0000-6737-0203cc0d0000 pid=3532 /usr/bin/apt-key write-file guuid=355e98af-1800-0000-6737-0203cb0d0000 pid=3531->guuid=1b6e38b0-1800-0000-6737-0203cc0d0000 pid=3532 execve guuid=fcca6bb0-1800-0000-6737-0203cd0d0000 pid=3533 /usr/bin/dash guuid=1b6e38b0-1800-0000-6737-0203cc0d0000 pid=3532->guuid=fcca6bb0-1800-0000-6737-0203cd0d0000 pid=3533 clone guuid=7e3081b0-1800-0000-6737-0203ce0d0000 pid=3534 /usr/bin/apt-config guuid=1b6e38b0-1800-0000-6737-0203cc0d0000 pid=3532->guuid=7e3081b0-1800-0000-6737-0203ce0d0000 pid=3534 execve guuid=eb88cab2-1800-0000-6737-0203d60d0000 pid=3542 /usr/bin/apt-config guuid=1b6e38b0-1800-0000-6737-0203cc0d0000 pid=3532->guuid=eb88cab2-1800-0000-6737-0203d60d0000 pid=3542 execve guuid=26c526b4-1800-0000-6737-0203dd0d0000 pid=3549 /usr/bin/apt-config guuid=1b6e38b0-1800-0000-6737-0203cc0d0000 pid=3532->guuid=26c526b4-1800-0000-6737-0203dd0d0000 pid=3549 execve guuid=cc210eb7-1800-0000-6737-0203e20d0000 pid=3554 /usr/bin/apt-config guuid=1b6e38b0-1800-0000-6737-0203cc0d0000 pid=3532->guuid=cc210eb7-1800-0000-6737-0203e20d0000 pid=3554 execve guuid=deb343b8-1800-0000-6737-0203e70d0000 pid=3559 /usr/bin/dash guuid=1b6e38b0-1800-0000-6737-0203cc0d0000 pid=3532->guuid=deb343b8-1800-0000-6737-0203e70d0000 pid=3559 clone guuid=5eed65b8-1800-0000-6737-0203e80d0000 pid=3560 /usr/bin/apt-config guuid=1b6e38b0-1800-0000-6737-0203cc0d0000 pid=3532->guuid=5eed65b8-1800-0000-6737-0203e80d0000 pid=3560 execve guuid=fab8d7ba-1800-0000-6737-0203ee0d0000 pid=3566 /usr/bin/mktemp guuid=1b6e38b0-1800-0000-6737-0203cc0d0000 pid=3532->guuid=fab8d7ba-1800-0000-6737-0203ee0d0000 pid=3566 execve guuid=167d18bb-1800-0000-6737-0203ef0d0000 pid=3567 /usr/bin/chmod guuid=1b6e38b0-1800-0000-6737-0203cc0d0000 pid=3532->guuid=167d18bb-1800-0000-6737-0203ef0d0000 pid=3567 execve guuid=6ca658bb-1800-0000-6737-0203f00d0000 pid=3568 /usr/bin/dash guuid=1b6e38b0-1800-0000-6737-0203cc0d0000 pid=3532->guuid=6ca658bb-1800-0000-6737-0203f00d0000 pid=3568 clone guuid=041f83bb-1800-0000-6737-0203f10d0000 pid=3569 /usr/bin/dash guuid=1b6e38b0-1800-0000-6737-0203cc0d0000 pid=3532->guuid=041f83bb-1800-0000-6737-0203f10d0000 pid=3569 clone guuid=ea55febb-1800-0000-6737-0203f40d0000 pid=3572 /usr/bin/dash guuid=1b6e38b0-1800-0000-6737-0203cc0d0000 pid=3532->guuid=ea55febb-1800-0000-6737-0203f40d0000 pid=3572 clone guuid=a8d770bc-1800-0000-6737-0203f70d0000 pid=3575 /usr/bin/dash guuid=1b6e38b0-1800-0000-6737-0203cc0d0000 pid=3532->guuid=a8d770bc-1800-0000-6737-0203f70d0000 pid=3575 clone guuid=1f4f7fbc-1800-0000-6737-0203f90d0000 pid=3577 /usr/bin/gpgv guuid=1b6e38b0-1800-0000-6737-0203cc0d0000 pid=3532->guuid=1f4f7fbc-1800-0000-6737-0203f90d0000 pid=3577 execve guuid=14dfd6bd-1800-0000-6737-0203fd0d0000 pid=3581 /usr/bin/rm delete-file guuid=1b6e38b0-1800-0000-6737-0203cc0d0000 pid=3532->guuid=14dfd6bd-1800-0000-6737-0203fd0d0000 pid=3581 execve guuid=e3a654b2-1800-0000-6737-0203d40d0000 pid=3540 /usr/bin/dpkg guuid=7e3081b0-1800-0000-6737-0203ce0d0000 pid=3534->guuid=e3a654b2-1800-0000-6737-0203d40d0000 pid=3540 execve guuid=c1dcbab3-1800-0000-6737-0203db0d0000 pid=3547 /usr/bin/dpkg guuid=eb88cab2-1800-0000-6737-0203d60d0000 pid=3542->guuid=c1dcbab3-1800-0000-6737-0203db0d0000 pid=3547 execve guuid=bf947db6-1800-0000-6737-0203e00d0000 pid=3552 /usr/bin/dpkg guuid=26c526b4-1800-0000-6737-0203dd0d0000 pid=3549->guuid=bf947db6-1800-0000-6737-0203e00d0000 pid=3552 execve guuid=82e3e6b7-1800-0000-6737-0203e50d0000 pid=3557 /usr/bin/dpkg guuid=cc210eb7-1800-0000-6737-0203e20d0000 pid=3554->guuid=82e3e6b7-1800-0000-6737-0203e50d0000 pid=3557 execve guuid=41673cb9-1800-0000-6737-0203ec0d0000 pid=3564 /usr/bin/dpkg guuid=5eed65b8-1800-0000-6737-0203e80d0000 pid=3560->guuid=41673cb9-1800-0000-6737-0203ec0d0000 pid=3564 execve guuid=656c90bb-1800-0000-6737-0203f20d0000 pid=3570 /usr/bin/dash guuid=041f83bb-1800-0000-6737-0203f10d0000 pid=3569->guuid=656c90bb-1800-0000-6737-0203f20d0000 pid=3570 clone guuid=39d596bb-1800-0000-6737-0203f30d0000 pid=3571 /usr/bin/sed guuid=041f83bb-1800-0000-6737-0203f10d0000 pid=3569->guuid=39d596bb-1800-0000-6737-0203f30d0000 pid=3571 execve guuid=bd430bbc-1800-0000-6737-0203f50d0000 pid=3573 /usr/bin/dash guuid=ea55febb-1800-0000-6737-0203f40d0000 pid=3572->guuid=bd430bbc-1800-0000-6737-0203f50d0000 pid=3573 clone guuid=e1c611bc-1800-0000-6737-0203f60d0000 pid=3574 /usr/bin/sed guuid=ea55febb-1800-0000-6737-0203f40d0000 pid=3572->guuid=e1c611bc-1800-0000-6737-0203f60d0000 pid=3574 execve guuid=5a1753bf-1800-0000-6737-0203040e0000 pid=3588 /usr/bin/apt-key write-file guuid=3892a6be-1800-0000-6737-0203000e0000 pid=3584->guuid=5a1753bf-1800-0000-6737-0203040e0000 pid=3588 execve guuid=215ab9bf-1800-0000-6737-0203060e0000 pid=3590 /usr/bin/dash guuid=5a1753bf-1800-0000-6737-0203040e0000 pid=3588->guuid=215ab9bf-1800-0000-6737-0203060e0000 pid=3590 clone guuid=c09e50c0-1800-0000-6737-0203090e0000 pid=3593 /usr/bin/apt-config guuid=5a1753bf-1800-0000-6737-0203040e0000 pid=3588->guuid=c09e50c0-1800-0000-6737-0203090e0000 pid=3593 execve guuid=500345c6-1800-0000-6737-0203100e0000 pid=3600 /usr/bin/apt-config guuid=5a1753bf-1800-0000-6737-0203040e0000 pid=3588->guuid=500345c6-1800-0000-6737-0203100e0000 pid=3600 execve guuid=c9eddec7-1800-0000-6737-0203120e0000 pid=3602 /usr/bin/apt-config guuid=5a1753bf-1800-0000-6737-0203040e0000 pid=3588->guuid=c9eddec7-1800-0000-6737-0203120e0000 pid=3602 execve guuid=d19394c9-1800-0000-6737-0203140e0000 pid=3604 /usr/bin/apt-config guuid=5a1753bf-1800-0000-6737-0203040e0000 pid=3588->guuid=d19394c9-1800-0000-6737-0203140e0000 pid=3604 execve guuid=29d8f5ca-1800-0000-6737-0203160e0000 pid=3606 /usr/bin/dash guuid=5a1753bf-1800-0000-6737-0203040e0000 pid=3588->guuid=29d8f5ca-1800-0000-6737-0203160e0000 pid=3606 clone guuid=262f1fcb-1800-0000-6737-0203170e0000 pid=3607 /usr/bin/apt-config guuid=5a1753bf-1800-0000-6737-0203040e0000 pid=3588->guuid=262f1fcb-1800-0000-6737-0203170e0000 pid=3607 execve guuid=31f410ce-1800-0000-6737-0203190e0000 pid=3609 /usr/bin/mktemp guuid=5a1753bf-1800-0000-6737-0203040e0000 pid=3588->guuid=31f410ce-1800-0000-6737-0203190e0000 pid=3609 execve guuid=c89934d1-1800-0000-6737-02031a0e0000 pid=3610 /usr/bin/chmod guuid=5a1753bf-1800-0000-6737-0203040e0000 pid=3588->guuid=c89934d1-1800-0000-6737-02031a0e0000 pid=3610 execve guuid=871d8ed1-1800-0000-6737-02031b0e0000 pid=3611 /usr/bin/dash guuid=5a1753bf-1800-0000-6737-0203040e0000 pid=3588->guuid=871d8ed1-1800-0000-6737-02031b0e0000 pid=3611 clone guuid=9696b1d1-1800-0000-6737-02031c0e0000 pid=3612 /usr/bin/dash guuid=5a1753bf-1800-0000-6737-0203040e0000 pid=3588->guuid=9696b1d1-1800-0000-6737-02031c0e0000 pid=3612 clone guuid=71ff6cd2-1800-0000-6737-02031f0e0000 pid=3615 /usr/bin/dash guuid=5a1753bf-1800-0000-6737-0203040e0000 pid=3588->guuid=71ff6cd2-1800-0000-6737-02031f0e0000 pid=3615 clone guuid=d9562bd3-1800-0000-6737-0203220e0000 pid=3618 /usr/bin/dash guuid=5a1753bf-1800-0000-6737-0203040e0000 pid=3588->guuid=d9562bd3-1800-0000-6737-0203220e0000 pid=3618 clone guuid=175543d3-1800-0000-6737-0203230e0000 pid=3619 /usr/bin/gpgv guuid=5a1753bf-1800-0000-6737-0203040e0000 pid=3588->guuid=175543d3-1800-0000-6737-0203230e0000 pid=3619 execve guuid=95669dd5-1800-0000-6737-0203240e0000 pid=3620 /usr/bin/rm delete-file guuid=5a1753bf-1800-0000-6737-0203040e0000 pid=3588->guuid=95669dd5-1800-0000-6737-0203240e0000 pid=3620 execve guuid=00aed7c1-1800-0000-6737-02030e0e0000 pid=3598 /usr/bin/dpkg guuid=c09e50c0-1800-0000-6737-0203090e0000 pid=3593->guuid=00aed7c1-1800-0000-6737-02030e0e0000 pid=3598 execve guuid=ee9943c7-1800-0000-6737-0203110e0000 pid=3601 /usr/bin/dpkg guuid=500345c6-1800-0000-6737-0203100e0000 pid=3600->guuid=ee9943c7-1800-0000-6737-0203110e0000 pid=3601 execve guuid=cce9dfc8-1800-0000-6737-0203130e0000 pid=3603 /usr/bin/dpkg guuid=c9eddec7-1800-0000-6737-0203120e0000 pid=3602->guuid=cce9dfc8-1800-0000-6737-0203130e0000 pid=3603 execve guuid=b1e891ca-1800-0000-6737-0203150e0000 pid=3605 /usr/bin/dpkg guuid=d19394c9-1800-0000-6737-0203140e0000 pid=3604->guuid=b1e891ca-1800-0000-6737-0203150e0000 pid=3605 execve guuid=8d0634cd-1800-0000-6737-0203180e0000 pid=3608 /usr/bin/dpkg guuid=262f1fcb-1800-0000-6737-0203170e0000 pid=3607->guuid=8d0634cd-1800-0000-6737-0203180e0000 pid=3608 execve guuid=6abdbfd1-1800-0000-6737-02031d0e0000 pid=3613 /usr/bin/dash guuid=9696b1d1-1800-0000-6737-02031c0e0000 pid=3612->guuid=6abdbfd1-1800-0000-6737-02031d0e0000 pid=3613 clone guuid=63d4c9d1-1800-0000-6737-02031e0e0000 pid=3614 /usr/bin/sed guuid=9696b1d1-1800-0000-6737-02031c0e0000 pid=3612->guuid=63d4c9d1-1800-0000-6737-02031e0e0000 pid=3614 execve guuid=e55e7cd2-1800-0000-6737-0203200e0000 pid=3616 /usr/bin/dash guuid=71ff6cd2-1800-0000-6737-02031f0e0000 pid=3615->guuid=e55e7cd2-1800-0000-6737-0203200e0000 pid=3616 clone guuid=c88184d2-1800-0000-6737-0203210e0000 pid=3617 /usr/bin/sed guuid=71ff6cd2-1800-0000-6737-02031f0e0000 pid=3615->guuid=c88184d2-1800-0000-6737-0203210e0000 pid=3617 execve guuid=eff9fddd-1800-0000-6737-0203320e0000 pid=3634 /usr/bin/apt-key write-file guuid=902741dd-1800-0000-6737-02032f0e0000 pid=3631->guuid=eff9fddd-1800-0000-6737-0203320e0000 pid=3634 execve guuid=1e714ade-1800-0000-6737-0203330e0000 pid=3635 /usr/bin/dash guuid=eff9fddd-1800-0000-6737-0203320e0000 pid=3634->guuid=1e714ade-1800-0000-6737-0203330e0000 pid=3635 clone guuid=33415dde-1800-0000-6737-0203340e0000 pid=3636 /usr/bin/apt-config guuid=eff9fddd-1800-0000-6737-0203320e0000 pid=3634->guuid=33415dde-1800-0000-6737-0203340e0000 pid=3636 execve guuid=577e94e0-1800-0000-6737-02033c0e0000 pid=3644 /usr/bin/apt-config guuid=eff9fddd-1800-0000-6737-0203320e0000 pid=3634->guuid=577e94e0-1800-0000-6737-02033c0e0000 pid=3644 execve guuid=074750e6-1800-0000-6737-0203510e0000 pid=3665 /usr/bin/apt-config guuid=eff9fddd-1800-0000-6737-0203320e0000 pid=3634->guuid=074750e6-1800-0000-6737-0203510e0000 pid=3665 execve guuid=b9a7d5e7-1800-0000-6737-0203540e0000 pid=3668 /usr/bin/apt-config guuid=eff9fddd-1800-0000-6737-0203320e0000 pid=3634->guuid=b9a7d5e7-1800-0000-6737-0203540e0000 pid=3668 execve guuid=69e041ea-1800-0000-6737-0203570e0000 pid=3671 /usr/bin/dash guuid=eff9fddd-1800-0000-6737-0203320e0000 pid=3634->guuid=69e041ea-1800-0000-6737-0203570e0000 pid=3671 clone guuid=c11c8aeb-1800-0000-6737-02035b0e0000 pid=3675 /usr/bin/apt-config guuid=eff9fddd-1800-0000-6737-0203320e0000 pid=3634->guuid=c11c8aeb-1800-0000-6737-02035b0e0000 pid=3675 execve guuid=4406abee-1800-0000-6737-0203620e0000 pid=3682 /usr/bin/mktemp guuid=eff9fddd-1800-0000-6737-0203320e0000 pid=3634->guuid=4406abee-1800-0000-6737-0203620e0000 pid=3682 execve guuid=7e205cef-1800-0000-6737-0203630e0000 pid=3683 /usr/bin/chmod guuid=eff9fddd-1800-0000-6737-0203320e0000 pid=3634->guuid=7e205cef-1800-0000-6737-0203630e0000 pid=3683 execve guuid=f49294ef-1800-0000-6737-0203640e0000 pid=3684 /usr/bin/dash guuid=eff9fddd-1800-0000-6737-0203320e0000 pid=3634->guuid=f49294ef-1800-0000-6737-0203640e0000 pid=3684 clone guuid=52a2a8ef-1800-0000-6737-0203650e0000 pid=3685 /usr/bin/dash guuid=eff9fddd-1800-0000-6737-0203320e0000 pid=3634->guuid=52a2a8ef-1800-0000-6737-0203650e0000 pid=3685 clone guuid=a01417f0-1800-0000-6737-0203680e0000 pid=3688 /usr/bin/dash guuid=eff9fddd-1800-0000-6737-0203320e0000 pid=3634->guuid=a01417f0-1800-0000-6737-0203680e0000 pid=3688 clone guuid=08a194f0-1800-0000-6737-02036d0e0000 pid=3693 /usr/bin/dash guuid=eff9fddd-1800-0000-6737-0203320e0000 pid=3634->guuid=08a194f0-1800-0000-6737-02036d0e0000 pid=3693 clone guuid=37cca4f0-1800-0000-6737-02036e0e0000 pid=3694 /usr/bin/gpgv guuid=eff9fddd-1800-0000-6737-0203320e0000 pid=3634->guuid=37cca4f0-1800-0000-6737-02036e0e0000 pid=3694 execve guuid=8f215af2-1800-0000-6737-0203710e0000 pid=3697 /usr/bin/rm delete-file guuid=eff9fddd-1800-0000-6737-0203320e0000 pid=3634->guuid=8f215af2-1800-0000-6737-0203710e0000 pid=3697 execve guuid=2020e1df-1800-0000-6737-0203390e0000 pid=3641 /usr/bin/dpkg guuid=33415dde-1800-0000-6737-0203340e0000 pid=3636->guuid=2020e1df-1800-0000-6737-0203390e0000 pid=3641 execve guuid=1f48b1e1-1800-0000-6737-0203420e0000 pid=3650 /usr/bin/dpkg guuid=577e94e0-1800-0000-6737-02033c0e0000 pid=3644->guuid=1f48b1e1-1800-0000-6737-0203420e0000 pid=3650 execve guuid=07a43fe7-1800-0000-6737-0203530e0000 pid=3667 /usr/bin/dpkg guuid=074750e6-1800-0000-6737-0203510e0000 pid=3665->guuid=07a43fe7-1800-0000-6737-0203530e0000 pid=3667 execve guuid=f08d26e9-1800-0000-6737-0203550e0000 pid=3669 /usr/bin/dpkg guuid=b9a7d5e7-1800-0000-6737-0203540e0000 pid=3668->guuid=f08d26e9-1800-0000-6737-0203550e0000 pid=3669 execve guuid=c13ec8ed-1800-0000-6737-0203610e0000 pid=3681 /usr/bin/dpkg guuid=c11c8aeb-1800-0000-6737-02035b0e0000 pid=3675->guuid=c13ec8ed-1800-0000-6737-0203610e0000 pid=3681 execve guuid=e1c6b7ef-1800-0000-6737-0203660e0000 pid=3686 /usr/bin/dash guuid=52a2a8ef-1800-0000-6737-0203650e0000 pid=3685->guuid=e1c6b7ef-1800-0000-6737-0203660e0000 pid=3686 clone guuid=44e0beef-1800-0000-6737-0203670e0000 pid=3687 /usr/bin/sed guuid=52a2a8ef-1800-0000-6737-0203650e0000 pid=3685->guuid=44e0beef-1800-0000-6737-0203670e0000 pid=3687 execve guuid=899820f0-1800-0000-6737-0203690e0000 pid=3689 /usr/bin/dash guuid=a01417f0-1800-0000-6737-0203680e0000 pid=3688->guuid=899820f0-1800-0000-6737-0203690e0000 pid=3689 clone guuid=109030f0-1800-0000-6737-02036b0e0000 pid=3691 /usr/bin/sed guuid=a01417f0-1800-0000-6737-0203680e0000 pid=3688->guuid=109030f0-1800-0000-6737-02036b0e0000 pid=3691 execve guuid=f9df4b35-1a00-0000-6737-020335120000 pid=4661 /usr/bin/dpkg guuid=71764a34-1a00-0000-6737-02032f120000 pid=4655->guuid=f9df4b35-1a00-0000-6737-020335120000 pid=4661 execve guuid=4a068b36-1a00-0000-6737-02033f120000 pid=4671->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 68B b4e27614-81b3-59ca-8787-716d0d292a6d cdn.tempfile.pro:0 guuid=4a068b36-1a00-0000-6737-02033f120000 pid=4671->b4e27614-81b3-59ca-8787-716d0d292a6d con e0beffae-5a5b-5021-9f66-3b7bd68d1c4e cdn.tempfile.pro:443 guuid=4a068b36-1a00-0000-6737-02033f120000 pid=4671->e0beffae-5a5b-5021-9f66-3b7bd68d1c4e send: 775B 1bb9f4ee-b940-5756-8449-f219f2617353 162.248.53.119:9443 guuid=84826a5d-1a00-0000-6737-0203de120000 pid=4830->1bb9f4ee-b940-5756-8449-f219f2617353 send: 960B guuid=84826a5d-1a00-0000-6737-0203de120000 pid=4845 /usr/lib/dev/systemdev/systemd-mont write-file zombie guuid=84826a5d-1a00-0000-6737-0203de120000 pid=4830->guuid=84826a5d-1a00-0000-6737-0203de120000 pid=4845 clone guuid=84826a5d-1a00-0000-6737-0203de120000 pid=4849 /usr/lib/dev/systemdev/systemd-mont guuid=84826a5d-1a00-0000-6737-0203de120000 pid=4830->guuid=84826a5d-1a00-0000-6737-0203de120000 pid=4849 clone guuid=84826a5d-1a00-0000-6737-0203de120000 pid=4850 /usr/lib/dev/systemdev/systemd-mont guuid=84826a5d-1a00-0000-6737-0203de120000 pid=4830->guuid=84826a5d-1a00-0000-6737-0203de120000 pid=4850 clone guuid=84826a5d-1a00-0000-6737-0203de120000 pid=4851 /usr/lib/dev/systemdev/systemd-mont guuid=84826a5d-1a00-0000-6737-0203de120000 pid=4830->guuid=84826a5d-1a00-0000-6737-0203de120000 pid=4851 clone guuid=84826a5d-1a00-0000-6737-0203de120000 pid=4852 /usr/lib/dev/systemdev/systemd-mont guuid=84826a5d-1a00-0000-6737-0203de120000 pid=4830->guuid=84826a5d-1a00-0000-6737-0203de120000 pid=4852 clone guuid=84826a5d-1a00-0000-6737-0203de120000 pid=4925 /usr/lib/dev/systemdev/systemd-mont guuid=84826a5d-1a00-0000-6737-0203de120000 pid=4830->guuid=84826a5d-1a00-0000-6737-0203de120000 pid=4925 clone guuid=84826a5d-1a00-0000-6737-0203de120000 pid=4926 /usr/lib/dev/systemdev/systemd-mont guuid=84826a5d-1a00-0000-6737-0203de120000 pid=4830->guuid=84826a5d-1a00-0000-6737-0203de120000 pid=4926 clone guuid=84826a5d-1a00-0000-6737-0203de120000 pid=4927 /usr/lib/dev/systemdev/systemd-mont guuid=84826a5d-1a00-0000-6737-0203de120000 pid=4830->guuid=84826a5d-1a00-0000-6737-0203de120000 pid=4927 clone guuid=84826a5d-1a00-0000-6737-0203de120000 pid=4928 /usr/lib/dev/systemdev/systemd-mont guuid=84826a5d-1a00-0000-6737-0203de120000 pid=4830->guuid=84826a5d-1a00-0000-6737-0203de120000 pid=4928 clone guuid=84826a5d-1a00-0000-6737-0203de120000 pid=4951 /usr/lib/dev/systemdev/systemd-mont guuid=84826a5d-1a00-0000-6737-0203de120000 pid=4830->guuid=84826a5d-1a00-0000-6737-0203de120000 pid=4951 clone guuid=84826a5d-1a00-0000-6737-0203de120000 pid=4952 /usr/lib/dev/systemdev/systemd-mont guuid=84826a5d-1a00-0000-6737-0203de120000 pid=4830->guuid=84826a5d-1a00-0000-6737-0203de120000 pid=4952 clone guuid=84826a5d-1a00-0000-6737-0203de120000 pid=4953 /usr/lib/dev/systemdev/systemd-mont guuid=84826a5d-1a00-0000-6737-0203de120000 pid=4830->guuid=84826a5d-1a00-0000-6737-0203de120000 pid=4953 clone guuid=84826a5d-1a00-0000-6737-0203de120000 pid=4954 /usr/lib/dev/systemdev/systemd-mont guuid=84826a5d-1a00-0000-6737-0203de120000 pid=4830->guuid=84826a5d-1a00-0000-6737-0203de120000 pid=4954 clone guuid=84826a5d-1a00-0000-6737-0203de120000 pid=4980 /usr/lib/dev/systemdev/systemd-mont guuid=84826a5d-1a00-0000-6737-0203de120000 pid=4830->guuid=84826a5d-1a00-0000-6737-0203de120000 pid=4980 clone guuid=84826a5d-1a00-0000-6737-0203de120000 pid=4981 /usr/lib/dev/systemdev/systemd-mont guuid=84826a5d-1a00-0000-6737-0203de120000 pid=4830->guuid=84826a5d-1a00-0000-6737-0203de120000 pid=4981 clone guuid=84826a5d-1a00-0000-6737-0203de120000 pid=4982 /usr/lib/dev/systemdev/systemd-mont guuid=84826a5d-1a00-0000-6737-0203de120000 pid=4830->guuid=84826a5d-1a00-0000-6737-0203de120000 pid=4982 clone guuid=84826a5d-1a00-0000-6737-0203de120000 pid=4983 /usr/lib/dev/systemdev/systemd-mont guuid=84826a5d-1a00-0000-6737-0203de120000 pid=4830->guuid=84826a5d-1a00-0000-6737-0203de120000 pid=4983 clone guuid=84826a5d-1a00-0000-6737-0203de120000 pid=5014 /usr/lib/dev/systemdev/systemd-mont guuid=84826a5d-1a00-0000-6737-0203de120000 pid=4830->guuid=84826a5d-1a00-0000-6737-0203de120000 pid=5014 clone guuid=84826a5d-1a00-0000-6737-0203de120000 pid=5015 /usr/lib/dev/systemdev/systemd-mont guuid=84826a5d-1a00-0000-6737-0203de120000 pid=4830->guuid=84826a5d-1a00-0000-6737-0203de120000 pid=5015 clone guuid=84826a5d-1a00-0000-6737-0203de120000 pid=5016 /usr/lib/dev/systemdev/systemd-mont guuid=84826a5d-1a00-0000-6737-0203de120000 pid=4830->guuid=84826a5d-1a00-0000-6737-0203de120000 pid=5016 clone guuid=84826a5d-1a00-0000-6737-0203de120000 pid=5017 /usr/lib/dev/systemdev/systemd-mont guuid=84826a5d-1a00-0000-6737-0203de120000 pid=4830->guuid=84826a5d-1a00-0000-6737-0203de120000 pid=5017 clone guuid=84826a5d-1a00-0000-6737-0203de120000 pid=5042 /usr/lib/dev/systemdev/systemd-mont guuid=84826a5d-1a00-0000-6737-0203de120000 pid=4830->guuid=84826a5d-1a00-0000-6737-0203de120000 pid=5042 clone guuid=84826a5d-1a00-0000-6737-0203de120000 pid=5043 /usr/lib/dev/systemdev/systemd-mont guuid=84826a5d-1a00-0000-6737-0203de120000 pid=4830->guuid=84826a5d-1a00-0000-6737-0203de120000 pid=5043 clone guuid=84826a5d-1a00-0000-6737-0203de120000 pid=5044 /usr/lib/dev/systemdev/systemd-mont guuid=84826a5d-1a00-0000-6737-0203de120000 pid=4830->guuid=84826a5d-1a00-0000-6737-0203de120000 pid=5044 clone guuid=84826a5d-1a00-0000-6737-0203de120000 pid=5045 /usr/lib/dev/systemdev/systemd-mont guuid=84826a5d-1a00-0000-6737-0203de120000 pid=4830->guuid=84826a5d-1a00-0000-6737-0203de120000 pid=5045 clone guuid=84826a5d-1a00-0000-6737-0203de120000 pid=5071 /usr/lib/dev/systemdev/systemd-mont guuid=84826a5d-1a00-0000-6737-0203de120000 pid=4830->guuid=84826a5d-1a00-0000-6737-0203de120000 pid=5071 clone guuid=84826a5d-1a00-0000-6737-0203de120000 pid=5072 /usr/lib/dev/systemdev/systemd-mont guuid=84826a5d-1a00-0000-6737-0203de120000 pid=4830->guuid=84826a5d-1a00-0000-6737-0203de120000 pid=5072 clone guuid=84826a5d-1a00-0000-6737-0203de120000 pid=5073 /usr/lib/dev/systemdev/systemd-mont guuid=84826a5d-1a00-0000-6737-0203de120000 pid=4830->guuid=84826a5d-1a00-0000-6737-0203de120000 pid=5073 clone guuid=84826a5d-1a00-0000-6737-0203de120000 pid=5074 /usr/lib/dev/systemdev/systemd-mont guuid=84826a5d-1a00-0000-6737-0203de120000 pid=4830->guuid=84826a5d-1a00-0000-6737-0203de120000 pid=5074 clone guuid=84826a5d-1a00-0000-6737-0203de120000 pid=5101 /usr/lib/dev/systemdev/systemd-mont guuid=84826a5d-1a00-0000-6737-0203de120000 pid=4830->guuid=84826a5d-1a00-0000-6737-0203de120000 pid=5101 clone guuid=84826a5d-1a00-0000-6737-0203de120000 pid=5102 /usr/lib/dev/systemdev/systemd-mont guuid=84826a5d-1a00-0000-6737-0203de120000 pid=4830->guuid=84826a5d-1a00-0000-6737-0203de120000 pid=5102 clone guuid=84826a5d-1a00-0000-6737-0203de120000 pid=5104 /usr/lib/dev/systemdev/systemd-mont guuid=84826a5d-1a00-0000-6737-0203de120000 pid=4830->guuid=84826a5d-1a00-0000-6737-0203de120000 pid=5104 clone guuid=84826a5d-1a00-0000-6737-0203de120000 pid=5105 /usr/lib/dev/systemdev/systemd-mont guuid=84826a5d-1a00-0000-6737-0203de120000 pid=4830->guuid=84826a5d-1a00-0000-6737-0203de120000 pid=5105 clone guuid=84826a5d-1a00-0000-6737-0203de120000 pid=5136 /usr/lib/dev/systemdev/systemd-mont guuid=84826a5d-1a00-0000-6737-0203de120000 pid=4830->guuid=84826a5d-1a00-0000-6737-0203de120000 pid=5136 clone guuid=84826a5d-1a00-0000-6737-0203de120000 pid=5137 /usr/lib/dev/systemdev/systemd-mont guuid=84826a5d-1a00-0000-6737-0203de120000 pid=4830->guuid=84826a5d-1a00-0000-6737-0203de120000 pid=5137 clone guuid=84826a5d-1a00-0000-6737-0203de120000 pid=5138 /usr/lib/dev/systemdev/systemd-mont guuid=84826a5d-1a00-0000-6737-0203de120000 pid=4830->guuid=84826a5d-1a00-0000-6737-0203de120000 pid=5138 clone guuid=84826a5d-1a00-0000-6737-0203de120000 pid=5139 /usr/lib/dev/systemdev/systemd-mont guuid=84826a5d-1a00-0000-6737-0203de120000 pid=4830->guuid=84826a5d-1a00-0000-6737-0203de120000 pid=5139 clone guuid=84826a5d-1a00-0000-6737-0203de120000 pid=5170 /usr/lib/dev/systemdev/systemd-mont guuid=84826a5d-1a00-0000-6737-0203de120000 pid=4830->guuid=84826a5d-1a00-0000-6737-0203de120000 pid=5170 clone guuid=84826a5d-1a00-0000-6737-0203de120000 pid=5172 /usr/lib/dev/systemdev/systemd-mont guuid=84826a5d-1a00-0000-6737-0203de120000 pid=4830->guuid=84826a5d-1a00-0000-6737-0203de120000 pid=5172 clone guuid=84826a5d-1a00-0000-6737-0203de120000 pid=5173 /usr/lib/dev/systemdev/systemd-mont guuid=84826a5d-1a00-0000-6737-0203de120000 pid=4830->guuid=84826a5d-1a00-0000-6737-0203de120000 pid=5173 clone guuid=84826a5d-1a00-0000-6737-0203de120000 pid=5174 /usr/lib/dev/systemdev/systemd-mont guuid=84826a5d-1a00-0000-6737-0203de120000 pid=4830->guuid=84826a5d-1a00-0000-6737-0203de120000 pid=5174 clone guuid=84826a5d-1a00-0000-6737-0203de120000 pid=5193 /usr/lib/dev/systemdev/systemd-mont guuid=84826a5d-1a00-0000-6737-0203de120000 pid=4830->guuid=84826a5d-1a00-0000-6737-0203de120000 pid=5193 clone guuid=84826a5d-1a00-0000-6737-0203de120000 pid=5194 /usr/lib/dev/systemdev/systemd-mont guuid=84826a5d-1a00-0000-6737-0203de120000 pid=4830->guuid=84826a5d-1a00-0000-6737-0203de120000 pid=5194 clone guuid=84826a5d-1a00-0000-6737-0203de120000 pid=5195 /usr/lib/dev/systemdev/systemd-mont guuid=84826a5d-1a00-0000-6737-0203de120000 pid=4830->guuid=84826a5d-1a00-0000-6737-0203de120000 pid=5195 clone guuid=84826a5d-1a00-0000-6737-0203de120000 pid=5196 /usr/lib/dev/systemdev/systemd-mont guuid=84826a5d-1a00-0000-6737-0203de120000 pid=4830->guuid=84826a5d-1a00-0000-6737-0203de120000 pid=5196 clone guuid=84826a5d-1a00-0000-6737-0203de120000 pid=5230 /usr/lib/dev/systemdev/systemd-mont guuid=84826a5d-1a00-0000-6737-0203de120000 pid=4830->guuid=84826a5d-1a00-0000-6737-0203de120000 pid=5230 clone guuid=84826a5d-1a00-0000-6737-0203de120000 pid=5232 /usr/lib/dev/systemdev/systemd-mont guuid=84826a5d-1a00-0000-6737-0203de120000 pid=4830->guuid=84826a5d-1a00-0000-6737-0203de120000 pid=5232 clone guuid=84826a5d-1a00-0000-6737-0203de120000 pid=5234 /usr/lib/dev/systemdev/systemd-mont guuid=84826a5d-1a00-0000-6737-0203de120000 pid=4830->guuid=84826a5d-1a00-0000-6737-0203de120000 pid=5234 clone guuid=84826a5d-1a00-0000-6737-0203de120000 pid=5235 /usr/lib/dev/systemdev/systemd-mont guuid=84826a5d-1a00-0000-6737-0203de120000 pid=4830->guuid=84826a5d-1a00-0000-6737-0203de120000 pid=5235 clone guuid=84826a5d-1a00-0000-6737-0203de120000 pid=5261 /usr/lib/dev/systemdev/systemd-mont guuid=84826a5d-1a00-0000-6737-0203de120000 pid=4830->guuid=84826a5d-1a00-0000-6737-0203de120000 pid=5261 clone guuid=84826a5d-1a00-0000-6737-0203de120000 pid=5263 /usr/lib/dev/systemdev/systemd-mont guuid=84826a5d-1a00-0000-6737-0203de120000 pid=4830->guuid=84826a5d-1a00-0000-6737-0203de120000 pid=5263 clone guuid=84826a5d-1a00-0000-6737-0203de120000 pid=5264 /usr/lib/dev/systemdev/systemd-mont guuid=84826a5d-1a00-0000-6737-0203de120000 pid=4830->guuid=84826a5d-1a00-0000-6737-0203de120000 pid=5264 clone guuid=84826a5d-1a00-0000-6737-0203de120000 pid=5265 /usr/lib/dev/systemdev/systemd-mont guuid=84826a5d-1a00-0000-6737-0203de120000 pid=4830->guuid=84826a5d-1a00-0000-6737-0203de120000 pid=5265 clone
Verdict:
Malicious
Threat:
HEUR:Downloader.Shell.Miner
Threat name:
Linux.Trojan.Generic
Status:
Suspicious
First seen:
2025-08-08 12:34:33 UTC
File Type:
Text (Shell)
AV detection:
7 of 22 (31.82%)
Threat level:
  5/5
Result
Malware family:
xmrig_linux
Score:
  10/10
Tags:
family:xmrig family:xmrig_linux antivm defense_evasion discovery linux miner upx
Behaviour
Enumerates kernel/hardware configuration
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads CPU attributes
UPX packed file
Checks hardware identifiers (DMI)
Enumerates running processes
Reads hardware information
File and Directory Permissions Modification
Executes dropped EXE
XMRig Miner payload
Xmrig family
Xmrig_linux family
xmrig
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:SUSP_LNX_SH_CryptoMiner_Indicators_Dec20_1
Author:Florian Roth (Nextron Systems)
Description:Detects helper script used in a crypto miner campaign
Reference:https://www.intezer.com/blog/research/new-golang-worm-drops-xmrig-miner-on-servers/
Rule name:SUSP_LNX_SH_CryptoMiner_Indicators_Dec20_1_RID364E
Author:Florian Roth
Description:Detects helper script used in a crypto miner campaign
Reference:https://www.intezer.com/blog/research/new-golang-worm-drops-xmrig-miner-on-servers/

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Distributed via web download

Comments