MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ae54f5cc038825e241d2daaa16080582ff610ab1ee8af4016b13aac3a7a4097d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



CoinMiner


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: ae54f5cc038825e241d2daaa16080582ff610ab1ee8af4016b13aac3a7a4097d
SHA3-384 hash: c549eabea5b55c24fb8af1ff029073bfe1d3905020889939caaadb0e79f2a61268133dc6a257c6b56498b6ac24215b47
SHA1 hash: 15b46556dc59fa61c9d5f89fcd43fb25ec39102d
MD5 hash: 429bd0de6b2a5b3b57c62bc1f4dcd8ab
humanhash: mobile-lion-purple-iowa
File name:4thepool_miner.sh
Download: download sample
Signature CoinMiner
File size:22'656 bytes
First seen:2025-12-21 18:13:15 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 384:hOUS1SKKJW78mIxR0Q/+c7+F68gHdVf+0+0tSJyqeW1VTed0:wUS1SxJW78RJN7+F6thqyqeW1Jee
TLSH T12EA2B722524536B5220E45B8D897A0402A76106B411C393C76DEBB48BF9CFAD73FF7B6
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:CoinMiner sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
65
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
coinminer
Verdict:
Adware
File Type:
unix shell
First seen:
2025-12-15T13:12:00Z UTC
Last seen:
2025-12-21T15:02:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=dcbc8cd0-1b00-0000-f381-f6ec700c0000 pid=3184 /usr/bin/sudo guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189 /tmp/sample.bin write-file guuid=dcbc8cd0-1b00-0000-f381-f6ec700c0000 pid=3184->guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189 execve guuid=0644efd3-1b00-0000-f381-f6ec780c0000 pid=3192 /usr/bin/clear guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=0644efd3-1b00-0000-f381-f6ec780c0000 pid=3192 execve guuid=90f992d4-1b00-0000-f381-f6ec790c0000 pid=3193 /usr/bin/id guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=90f992d4-1b00-0000-f381-f6ec790c0000 pid=3193 execve guuid=6b666bd5-1b00-0000-f381-f6ec7a0c0000 pid=3194 /usr/bin/date guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=6b666bd5-1b00-0000-f381-f6ec7a0c0000 pid=3194 execve guuid=34e9e9d5-1b00-0000-f381-f6ec7b0c0000 pid=3195 /usr/bin/sleep guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=34e9e9d5-1b00-0000-f381-f6ec7b0c0000 pid=3195 execve guuid=b005be4d-1c00-0000-f381-f6ecf70c0000 pid=3319 /usr/bin/bash guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=b005be4d-1c00-0000-f381-f6ecf70c0000 pid=3319 clone guuid=74c85e4e-1c00-0000-f381-f6ecfa0c0000 pid=3322 /usr/bin/bash guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=74c85e4e-1c00-0000-f381-f6ecfa0c0000 pid=3322 clone guuid=5657de4e-1c00-0000-f381-f6ecfc0c0000 pid=3324 /usr/bin/date guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=5657de4e-1c00-0000-f381-f6ecfc0c0000 pid=3324 execve guuid=71a4334f-1c00-0000-f381-f6ecfd0c0000 pid=3325 /usr/bin/date guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=71a4334f-1c00-0000-f381-f6ecfd0c0000 pid=3325 execve guuid=ccc7a24f-1c00-0000-f381-f6ecfe0c0000 pid=3326 /usr/bin/nproc guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=ccc7a24f-1c00-0000-f381-f6ecfe0c0000 pid=3326 execve guuid=3b80007f-1c00-0000-f381-f6ec000d0000 pid=3328 /usr/bin/bash guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=3b80007f-1c00-0000-f381-f6ec000d0000 pid=3328 clone guuid=346e0183-1c00-0000-f381-f6ec080d0000 pid=3336 /usr/bin/date guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=346e0183-1c00-0000-f381-f6ec080d0000 pid=3336 execve guuid=a08e8683-1c00-0000-f381-f6ec0a0d0000 pid=3338 /usr/bin/date guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=a08e8683-1c00-0000-f381-f6ec0a0d0000 pid=3338 execve guuid=89231084-1c00-0000-f381-f6ec0d0d0000 pid=3341 /usr/bin/date guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=89231084-1c00-0000-f381-f6ec0d0d0000 pid=3341 execve guuid=c0628584-1c00-0000-f381-f6ec0f0d0000 pid=3343 /usr/bin/date guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=c0628584-1c00-0000-f381-f6ec0f0d0000 pid=3343 execve guuid=0316eb84-1c00-0000-f381-f6ec110d0000 pid=3345 /usr/bin/systemctl guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=0316eb84-1c00-0000-f381-f6ec110d0000 pid=3345 execve guuid=b0b0fb84-1c00-0000-f381-f6ec120d0000 pid=3346 /usr/bin/grep guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=b0b0fb84-1c00-0000-f381-f6ec120d0000 pid=3346 execve guuid=4a6e0103-1d00-0000-f381-f6ec0c0e0000 pid=3596 /usr/bin/systemctl guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=4a6e0103-1d00-0000-f381-f6ec0c0e0000 pid=3596 execve guuid=4de90a03-1d00-0000-f381-f6ec0e0e0000 pid=3598 /usr/bin/grep guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=4de90a03-1d00-0000-f381-f6ec0e0e0000 pid=3598 execve guuid=21172978-1d00-0000-f381-f6ec2e0f0000 pid=3886 /usr/bin/systemctl guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=21172978-1d00-0000-f381-f6ec2e0f0000 pid=3886 execve guuid=47293178-1d00-0000-f381-f6ec2f0f0000 pid=3887 /usr/bin/grep guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=47293178-1d00-0000-f381-f6ec2f0f0000 pid=3887 execve guuid=607daddd-1d00-0000-f381-f6ec82100000 pid=4226 /usr/bin/systemctl guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=607daddd-1d00-0000-f381-f6ec82100000 pid=4226 execve guuid=2b44b7dd-1d00-0000-f381-f6ec83100000 pid=4227 /usr/bin/grep guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=2b44b7dd-1d00-0000-f381-f6ec83100000 pid=4227 execve guuid=6e46b943-1e00-0000-f381-f6ecea110000 pid=4586 /usr/bin/date guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=6e46b943-1e00-0000-f381-f6ecea110000 pid=4586 execve guuid=30247444-1e00-0000-f381-f6eceb110000 pid=4587 /usr/bin/sudo net guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=30247444-1e00-0000-f381-f6eceb110000 pid=4587 execve guuid=68eeaf47-1e00-0000-f381-f6ecf7110000 pid=4599 /usr/bin/sudo net guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=68eeaf47-1e00-0000-f381-f6ecf7110000 pid=4599 execve guuid=37ddcc50-1e00-0000-f381-f6ec12120000 pid=4626 /usr/bin/sudo net guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=37ddcc50-1e00-0000-f381-f6ec12120000 pid=4626 execve guuid=d08fdea0-1e00-0000-f381-f6ecdf120000 pid=4831 /usr/bin/sudo net guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=d08fdea0-1e00-0000-f381-f6ecdf120000 pid=4831 execve guuid=895c82a3-1e00-0000-f381-f6eceb120000 pid=4843 /usr/bin/systemctl guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=895c82a3-1e00-0000-f381-f6eceb120000 pid=4843 execve guuid=42ee87a3-1e00-0000-f381-f6ecec120000 pid=4844 /usr/bin/grep guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=42ee87a3-1e00-0000-f381-f6ecec120000 pid=4844 execve guuid=90061c0b-1f00-0000-f381-f6ec5d140000 pid=5213 /usr/bin/sudo net guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=90061c0b-1f00-0000-f381-f6ec5d140000 pid=5213 execve guuid=8241520d-1f00-0000-f381-f6ec65140000 pid=5221 /usr/bin/sudo net guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=8241520d-1f00-0000-f381-f6ec65140000 pid=5221 execve guuid=69f8b047-1f00-0000-f381-f6eccc140000 pid=5324 /usr/bin/pgrep guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=69f8b047-1f00-0000-f381-f6eccc140000 pid=5324 execve guuid=f331c64a-1f00-0000-f381-f6eccd140000 pid=5325 /usr/bin/date guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=f331c64a-1f00-0000-f381-f6eccd140000 pid=5325 execve guuid=68ff374b-1f00-0000-f381-f6ecce140000 pid=5326 /usr/bin/date guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=68ff374b-1f00-0000-f381-f6ecce140000 pid=5326 execve guuid=834c8b4b-1f00-0000-f381-f6eccf140000 pid=5327 /usr/bin/sleep guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=834c8b4b-1f00-0000-f381-f6eccf140000 pid=5327 execve guuid=491dff75-2000-0000-f381-f6ecd7140000 pid=5335 /usr/bin/mkdir guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=491dff75-2000-0000-f381-f6ecd7140000 pid=5335 execve guuid=3b9f7e77-2000-0000-f381-f6ecd8140000 pid=5336 /usr/bin/date guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=3b9f7e77-2000-0000-f381-f6ecd8140000 pid=5336 execve guuid=cdb27278-2000-0000-f381-f6ecd9140000 pid=5337 /usr/bin/date guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=cdb27278-2000-0000-f381-f6ecd9140000 pid=5337 execve guuid=91261d79-2000-0000-f381-f6ecda140000 pid=5338 /usr/bin/curl net send-data write-file guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=91261d79-2000-0000-f381-f6ecda140000 pid=5338 execve guuid=44f5c1aa-2000-0000-f381-f6ecdb140000 pid=5339 /usr/bin/date guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=44f5c1aa-2000-0000-f381-f6ecdb140000 pid=5339 execve guuid=c04f4cab-2000-0000-f381-f6ecdc140000 pid=5340 /usr/bin/date guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=c04f4cab-2000-0000-f381-f6ecdc140000 pid=5340 execve guuid=7e2120ac-2000-0000-f381-f6ecdd140000 pid=5341 /usr/bin/tar write-file guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=7e2120ac-2000-0000-f381-f6ecdd140000 pid=5341 execve guuid=d0e76eb8-2000-0000-f381-f6ecdf140000 pid=5343 /usr/bin/rm delete-file guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=d0e76eb8-2000-0000-f381-f6ecdf140000 pid=5343 execve guuid=956208be-2000-0000-f381-f6ece0140000 pid=5344 /usr/bin/mv guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=956208be-2000-0000-f381-f6ece0140000 pid=5344 execve guuid=b36593c2-2000-0000-f381-f6ece1140000 pid=5345 /usr/bin/chmod guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=b36593c2-2000-0000-f381-f6ece1140000 pid=5345 execve guuid=f254f7c2-2000-0000-f381-f6ece2140000 pid=5346 /usr/bin/date guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=f254f7c2-2000-0000-f381-f6ece2140000 pid=5346 execve guuid=42a929c8-2000-0000-f381-f6ece3140000 pid=5347 /usr/bin/bash guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=42a929c8-2000-0000-f381-f6ece3140000 pid=5347 clone guuid=561b89cf-2000-0000-f381-f6ece6140000 pid=5350 /usr/bin/date guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=561b89cf-2000-0000-f381-f6ece6140000 pid=5350 execve guuid=4fee40d0-2000-0000-f381-f6ece7140000 pid=5351 /usr/bin/bash guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=4fee40d0-2000-0000-f381-f6ece7140000 pid=5351 clone guuid=796061d0-2000-0000-f381-f6ece8140000 pid=5352 /usr/bin/date guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=796061d0-2000-0000-f381-f6ece8140000 pid=5352 execve guuid=c1e2bcd0-2000-0000-f381-f6ece9140000 pid=5353 /usr/bin/cp guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=c1e2bcd0-2000-0000-f381-f6ece9140000 pid=5353 execve guuid=c7ef51d1-2000-0000-f381-f6ecea140000 pid=5354 /usr/bin/sed write-file guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=c7ef51d1-2000-0000-f381-f6ecea140000 pid=5354 execve guuid=f43a21d2-2000-0000-f381-f6eceb140000 pid=5355 /usr/bin/sed write-file guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=f43a21d2-2000-0000-f381-f6eceb140000 pid=5355 execve guuid=66e39bd2-2000-0000-f381-f6ecec140000 pid=5356 /usr/bin/sed write-file guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=66e39bd2-2000-0000-f381-f6ecec140000 pid=5356 execve guuid=001d49d3-2000-0000-f381-f6eced140000 pid=5357 /usr/bin/sed write-file guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=001d49d3-2000-0000-f381-f6eced140000 pid=5357 execve guuid=8e9fc5d3-2000-0000-f381-f6ecee140000 pid=5358 /usr/bin/sed write-file guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=8e9fc5d3-2000-0000-f381-f6ecee140000 pid=5358 execve guuid=4f3a3ed4-2000-0000-f381-f6ecef140000 pid=5359 /usr/bin/sed write-file guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=4f3a3ed4-2000-0000-f381-f6ecef140000 pid=5359 execve guuid=cbde02d5-2000-0000-f381-f6ecf0140000 pid=5360 /usr/bin/sed write-file guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=cbde02d5-2000-0000-f381-f6ecf0140000 pid=5360 execve guuid=17753dd8-2000-0000-f381-f6ecf1140000 pid=5361 /usr/bin/date guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=17753dd8-2000-0000-f381-f6ecf1140000 pid=5361 execve guuid=4328dad8-2000-0000-f381-f6ecf2140000 pid=5362 /usr/bin/date guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=4328dad8-2000-0000-f381-f6ecf2140000 pid=5362 execve guuid=3b5e36d9-2000-0000-f381-f6ecf3140000 pid=5363 /usr/bin/sudo net guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=3b5e36d9-2000-0000-f381-f6ecf3140000 pid=5363 execve guuid=a06874db-2000-0000-f381-f6ecf5140000 pid=5365 /usr/bin/date guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=a06874db-2000-0000-f381-f6ecf5140000 pid=5365 execve guuid=3d1fd0db-2000-0000-f381-f6ecf6140000 pid=5366 /usr/bin/cat guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=3d1fd0db-2000-0000-f381-f6ecf6140000 pid=5366 execve guuid=162dd6db-2000-0000-f381-f6ecf7140000 pid=5367 /usr/bin/sudo net guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=162dd6db-2000-0000-f381-f6ecf7140000 pid=5367 execve guuid=bc6037e3-2000-0000-f381-f6ecfa140000 pid=5370 /usr/bin/sudo net guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=bc6037e3-2000-0000-f381-f6ecfa140000 pid=5370 execve guuid=34a9651c-2100-0000-f381-f6ec10150000 pid=5392 /usr/bin/sudo net guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=34a9651c-2100-0000-f381-f6ec10150000 pid=5392 execve guuid=a02beb46-2100-0000-f381-f6ec2e150000 pid=5422 /usr/bin/sudo net guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=a02beb46-2100-0000-f381-f6ec2e150000 pid=5422 execve guuid=e054504c-2100-0000-f381-f6ec34150000 pid=5428 /usr/bin/date guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=e054504c-2100-0000-f381-f6ec34150000 pid=5428 execve guuid=caa6994c-2100-0000-f381-f6ec35150000 pid=5429 /usr/bin/date guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=caa6994c-2100-0000-f381-f6ec35150000 pid=5429 execve guuid=4376e74c-2100-0000-f381-f6ec36150000 pid=5430 /usr/bin/date guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=4376e74c-2100-0000-f381-f6ec36150000 pid=5430 execve guuid=3ecd324d-2100-0000-f381-f6ec37150000 pid=5431 /usr/bin/date guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=3ecd324d-2100-0000-f381-f6ec37150000 pid=5431 execve guuid=d3967e4d-2100-0000-f381-f6ec39150000 pid=5433 /usr/bin/sudo net guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=d3967e4d-2100-0000-f381-f6ec39150000 pid=5433 execve guuid=a237b451-2100-0000-f381-f6ec3b150000 pid=5435 /usr/bin/date guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=a237b451-2100-0000-f381-f6ec3b150000 pid=5435 execve guuid=47c0d652-2100-0000-f381-f6ec3c150000 pid=5436 /usr/bin/date guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=47c0d652-2100-0000-f381-f6ec3c150000 pid=5436 execve guuid=7abdd453-2100-0000-f381-f6ec3d150000 pid=5437 /usr/bin/curl net send-data write-file guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=7abdd453-2100-0000-f381-f6ec3d150000 pid=5437 execve guuid=5267726d-2100-0000-f381-f6ec49150000 pid=5449 /usr/bin/date guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=5267726d-2100-0000-f381-f6ec49150000 pid=5449 execve guuid=88650e6f-2100-0000-f381-f6ec4c150000 pid=5452 /usr/bin/chmod guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=88650e6f-2100-0000-f381-f6ec4c150000 pid=5452 execve guuid=062eb370-2100-0000-f381-f6ec4f150000 pid=5455 /usr/bin/sudo net guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=062eb370-2100-0000-f381-f6ec4f150000 pid=5455 execve guuid=19b75477-2100-0000-f381-f6ec59150000 pid=5465 /usr/bin/sudo net guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=19b75477-2100-0000-f381-f6ec59150000 pid=5465 execve guuid=5a210e7e-2100-0000-f381-f6ec62150000 pid=5474 /usr/bin/sudo net guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=5a210e7e-2100-0000-f381-f6ec62150000 pid=5474 execve guuid=d5146584-2100-0000-f381-f6ec66150000 pid=5478 /usr/bin/date guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=d5146584-2100-0000-f381-f6ec66150000 pid=5478 execve guuid=8802ba85-2100-0000-f381-f6ec67150000 pid=5479 /usr/local/bin/watcher guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=8802ba85-2100-0000-f381-f6ec67150000 pid=5479 execve guuid=9862b986-2100-0000-f381-f6ec6a150000 pid=5482 /usr/bin/date guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=9862b986-2100-0000-f381-f6ec6a150000 pid=5482 execve guuid=be93a190-2100-0000-f381-f6ec6c150000 pid=5484 /usr/bin/date guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=be93a190-2100-0000-f381-f6ec6c150000 pid=5484 execve guuid=36d55891-2100-0000-f381-f6ec6d150000 pid=5485 /usr/bin/sudo net guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=36d55891-2100-0000-f381-f6ec6d150000 pid=5485 execve guuid=aed96a93-2100-0000-f381-f6ec6f150000 pid=5487 /usr/bin/date guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=aed96a93-2100-0000-f381-f6ec6f150000 pid=5487 execve guuid=34131294-2100-0000-f381-f6ec70150000 pid=5488 /usr/bin/cat guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=34131294-2100-0000-f381-f6ec70150000 pid=5488 execve guuid=67ba1b94-2100-0000-f381-f6ec71150000 pid=5489 /usr/bin/sudo net guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=67ba1b94-2100-0000-f381-f6ec71150000 pid=5489 execve guuid=524a4998-2100-0000-f381-f6ec75150000 pid=5493 /usr/bin/sudo net guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=524a4998-2100-0000-f381-f6ec75150000 pid=5493 execve guuid=c644d1c1-2100-0000-f381-f6ec9c150000 pid=5532 /usr/bin/sudo net guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=c644d1c1-2100-0000-f381-f6ec9c150000 pid=5532 execve guuid=1f0e30e9-2100-0000-f381-f6ecb2150000 pid=5554 /usr/bin/sudo net guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=1f0e30e9-2100-0000-f381-f6ecb2150000 pid=5554 execve guuid=176a7eee-2100-0000-f381-f6ecb7150000 pid=5559 /usr/bin/sleep guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=176a7eee-2100-0000-f381-f6ecb7150000 pid=5559 execve guuid=dec20366-2200-0000-f381-f6ecb8150000 pid=5560 /usr/bin/sudo net guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=dec20366-2200-0000-f381-f6ecb8150000 pid=5560 execve guuid=1a89dc69-2200-0000-f381-f6ecba150000 pid=5562 /usr/bin/date guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=1a89dc69-2200-0000-f381-f6ecba150000 pid=5562 execve guuid=4799346a-2200-0000-f381-f6ecbb150000 pid=5563 /usr/bin/sudo net guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=4799346a-2200-0000-f381-f6ecbb150000 pid=5563 execve guuid=760abc6d-2200-0000-f381-f6ecbd150000 pid=5565 /usr/bin/date guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=760abc6d-2200-0000-f381-f6ecbd150000 pid=5565 execve guuid=1eed0f6e-2200-0000-f381-f6ecbe150000 pid=5566 /usr/local/bin/watcher guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=1eed0f6e-2200-0000-f381-f6ecbe150000 pid=5566 execve guuid=8ce1256e-2200-0000-f381-f6ecbf150000 pid=5567 /usr/bin/bash guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=8ce1256e-2200-0000-f381-f6ecbf150000 pid=5567 clone guuid=5ef3896e-2200-0000-f381-f6ecc2150000 pid=5570 /usr/bin/date guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=5ef3896e-2200-0000-f381-f6ecc2150000 pid=5570 execve guuid=95bdd96e-2200-0000-f381-f6ecc4150000 pid=5572 /usr/bin/date guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=95bdd96e-2200-0000-f381-f6ecc4150000 pid=5572 execve guuid=ce9e2b6f-2200-0000-f381-f6ecc5150000 pid=5573 /usr/bin/date guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=ce9e2b6f-2200-0000-f381-f6ecc5150000 pid=5573 execve guuid=06a37b6f-2200-0000-f381-f6ecc6150000 pid=5574 /usr/bin/date guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=06a37b6f-2200-0000-f381-f6ecc6150000 pid=5574 execve guuid=1e6acf6f-2200-0000-f381-f6ecc7150000 pid=5575 /usr/bin/date guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=1e6acf6f-2200-0000-f381-f6ecc7150000 pid=5575 execve guuid=7d4b2270-2200-0000-f381-f6ecc8150000 pid=5576 /usr/bin/date guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=7d4b2270-2200-0000-f381-f6ecc8150000 pid=5576 execve guuid=76758870-2200-0000-f381-f6ecc9150000 pid=5577 /usr/bin/date guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=76758870-2200-0000-f381-f6ecc9150000 pid=5577 execve guuid=ee1fdd70-2200-0000-f381-f6ecca150000 pid=5578 /usr/bin/date guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=ee1fdd70-2200-0000-f381-f6ecca150000 pid=5578 execve guuid=079d3f71-2200-0000-f381-f6eccb150000 pid=5579 /usr/bin/date guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=079d3f71-2200-0000-f381-f6eccb150000 pid=5579 execve guuid=16429971-2200-0000-f381-f6eccc150000 pid=5580 /usr/bin/date guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=16429971-2200-0000-f381-f6eccc150000 pid=5580 execve guuid=88bcf871-2200-0000-f381-f6eccd150000 pid=5581 /usr/bin/date guuid=636f26d3-1b00-0000-f381-f6ec750c0000 pid=3189->guuid=88bcf871-2200-0000-f381-f6eccd150000 pid=5581 execve guuid=d40bd24d-1c00-0000-f381-f6ecf80c0000 pid=3320 /usr/bin/bash guuid=b005be4d-1c00-0000-f381-f6ecf70c0000 pid=3319->guuid=d40bd24d-1c00-0000-f381-f6ecf80c0000 pid=3320 clone guuid=f097d84d-1c00-0000-f381-f6ecf90c0000 pid=3321 /usr/bin/cut guuid=b005be4d-1c00-0000-f381-f6ecf70c0000 pid=3319->guuid=f097d84d-1c00-0000-f381-f6ecf90c0000 pid=3321 execve guuid=bd64704e-1c00-0000-f381-f6ecfb0c0000 pid=3323 /usr/bin/uname guuid=74c85e4e-1c00-0000-f381-f6ecfa0c0000 pid=3322->guuid=bd64704e-1c00-0000-f381-f6ecfb0c0000 pid=3323 execve guuid=5dc1147f-1c00-0000-f381-f6ec010d0000 pid=3329 /usr/bin/free guuid=3b80007f-1c00-0000-f381-f6ec000d0000 pid=3328->guuid=5dc1147f-1c00-0000-f381-f6ec010d0000 pid=3329 execve guuid=9ddb217f-1c00-0000-f381-f6ec020d0000 pid=3330 /usr/bin/mawk guuid=3b80007f-1c00-0000-f381-f6ec000d0000 pid=3328->guuid=9ddb217f-1c00-0000-f381-f6ec020d0000 pid=3330 execve 0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 10.0.2.15:0 guuid=30247444-1e00-0000-f381-f6eceb110000 pid=4587->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con 558177e1-1f18-5f39-990b-d68b1c194e8a fec0::5054:ff:fe12:3456:0 guuid=30247444-1e00-0000-f381-f6eceb110000 pid=4587->558177e1-1f18-5f39-990b-d68b1c194e8a con cbc59886-1795-52e1-b014-449ae22fd09b fe80::5054:ff:fe12:3456:0 guuid=30247444-1e00-0000-f381-f6eceb110000 pid=4587->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=2a589f46-1e00-0000-f381-f6ecf5110000 pid=4597 /usr/bin/true guuid=30247444-1e00-0000-f381-f6eceb110000 pid=4587->guuid=2a589f46-1e00-0000-f381-f6ecf5110000 pid=4597 execve guuid=68eeaf47-1e00-0000-f381-f6ecf7110000 pid=4599->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con guuid=68eeaf47-1e00-0000-f381-f6ecf7110000 pid=4599->558177e1-1f18-5f39-990b-d68b1c194e8a con guuid=68eeaf47-1e00-0000-f381-f6ecf7110000 pid=4599->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=3a523d4b-1e00-0000-f381-f6ec00120000 pid=4608 /usr/bin/systemctl guuid=68eeaf47-1e00-0000-f381-f6ecf7110000 pid=4599->guuid=3a523d4b-1e00-0000-f381-f6ec00120000 pid=4608 execve guuid=37ddcc50-1e00-0000-f381-f6ec12120000 pid=4626->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con guuid=37ddcc50-1e00-0000-f381-f6ec12120000 pid=4626->558177e1-1f18-5f39-990b-d68b1c194e8a con guuid=37ddcc50-1e00-0000-f381-f6ec12120000 pid=4626->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=253c7852-1e00-0000-f381-f6ec1a120000 pid=4634 /usr/bin/systemctl guuid=37ddcc50-1e00-0000-f381-f6ec12120000 pid=4626->guuid=253c7852-1e00-0000-f381-f6ec1a120000 pid=4634 execve guuid=d08fdea0-1e00-0000-f381-f6ecdf120000 pid=4831->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con guuid=d08fdea0-1e00-0000-f381-f6ecdf120000 pid=4831->558177e1-1f18-5f39-990b-d68b1c194e8a con guuid=d08fdea0-1e00-0000-f381-f6ecdf120000 pid=4831->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=ac7a22a3-1e00-0000-f381-f6ece9120000 pid=4841 /usr/bin/rm guuid=d08fdea0-1e00-0000-f381-f6ecdf120000 pid=4831->guuid=ac7a22a3-1e00-0000-f381-f6ece9120000 pid=4841 execve guuid=90061c0b-1f00-0000-f381-f6ec5d140000 pid=5213->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con guuid=90061c0b-1f00-0000-f381-f6ec5d140000 pid=5213->558177e1-1f18-5f39-990b-d68b1c194e8a con guuid=90061c0b-1f00-0000-f381-f6ec5d140000 pid=5213->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=a4ead10c-1f00-0000-f381-f6ec62140000 pid=5218 /usr/bin/true guuid=90061c0b-1f00-0000-f381-f6ec5d140000 pid=5213->guuid=a4ead10c-1f00-0000-f381-f6ec62140000 pid=5218 execve guuid=8241520d-1f00-0000-f381-f6ec65140000 pid=5221->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con guuid=8241520d-1f00-0000-f381-f6ec65140000 pid=5221->558177e1-1f18-5f39-990b-d68b1c194e8a con guuid=8241520d-1f00-0000-f381-f6ec65140000 pid=5221->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=9d3b410f-1f00-0000-f381-f6ec6d140000 pid=5229 /usr/bin/systemctl guuid=8241520d-1f00-0000-f381-f6ec65140000 pid=5221->guuid=9d3b410f-1f00-0000-f381-f6ec6d140000 pid=5229 execve f6e5790d-96c2-5381-8e14-4935a19ea2d0 31.57.109.131:80 guuid=91261d79-2000-0000-f381-f6ecda140000 pid=5338->f6e5790d-96c2-5381-8e14-4935a19ea2d0 send: 97B guuid=1f7c1cad-2000-0000-f381-f6ecde140000 pid=5342 /usr/bin/gzip guuid=7e2120ac-2000-0000-f381-f6ecdd140000 pid=5341->guuid=1f7c1cad-2000-0000-f381-f6ecde140000 pid=5342 execve guuid=1eeaa3c9-2000-0000-f381-f6ece4140000 pid=5348 /usr/bin/hostname guuid=42a929c8-2000-0000-f381-f6ece3140000 pid=5347->guuid=1eeaa3c9-2000-0000-f381-f6ece4140000 pid=5348 execve guuid=73a5b0c9-2000-0000-f381-f6ece5140000 pid=5349 /usr/bin/sed guuid=42a929c8-2000-0000-f381-f6ece3140000 pid=5347->guuid=73a5b0c9-2000-0000-f381-f6ece5140000 pid=5349 execve guuid=3b5e36d9-2000-0000-f381-f6ecf3140000 pid=5363->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con guuid=3b5e36d9-2000-0000-f381-f6ecf3140000 pid=5363->558177e1-1f18-5f39-990b-d68b1c194e8a con guuid=3b5e36d9-2000-0000-f381-f6ecf3140000 pid=5363->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=0b8afcda-2000-0000-f381-f6ecf4140000 pid=5364 /usr/bin/true guuid=3b5e36d9-2000-0000-f381-f6ecf3140000 pid=5363->guuid=0b8afcda-2000-0000-f381-f6ecf4140000 pid=5364 execve guuid=5f49f2db-2000-0000-f381-f6ecf8140000 pid=5368 /usr/bin/whoami guuid=3d1fd0db-2000-0000-f381-f6ecf6140000 pid=5366->guuid=5f49f2db-2000-0000-f381-f6ecf8140000 pid=5368 execve guuid=162dd6db-2000-0000-f381-f6ecf7140000 pid=5367->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con guuid=162dd6db-2000-0000-f381-f6ecf7140000 pid=5367->558177e1-1f18-5f39-990b-d68b1c194e8a con guuid=162dd6db-2000-0000-f381-f6ecf7140000 pid=5367->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=215817df-2000-0000-f381-f6ecf9140000 pid=5369 /usr/bin/tee write-config guuid=162dd6db-2000-0000-f381-f6ecf7140000 pid=5367->guuid=215817df-2000-0000-f381-f6ecf9140000 pid=5369 execve guuid=bc6037e3-2000-0000-f381-f6ecfa140000 pid=5370->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con guuid=bc6037e3-2000-0000-f381-f6ecfa140000 pid=5370->558177e1-1f18-5f39-990b-d68b1c194e8a con guuid=bc6037e3-2000-0000-f381-f6ecfa140000 pid=5370->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=72210ae6-2000-0000-f381-f6ecfb140000 pid=5371 /usr/bin/systemctl guuid=bc6037e3-2000-0000-f381-f6ecfa140000 pid=5370->guuid=72210ae6-2000-0000-f381-f6ecfb140000 pid=5371 execve guuid=34a9651c-2100-0000-f381-f6ec10150000 pid=5392->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con guuid=34a9651c-2100-0000-f381-f6ec10150000 pid=5392->558177e1-1f18-5f39-990b-d68b1c194e8a con guuid=34a9651c-2100-0000-f381-f6ec10150000 pid=5392->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=e206531e-2100-0000-f381-f6ec12150000 pid=5394 /usr/bin/systemctl guuid=34a9651c-2100-0000-f381-f6ec10150000 pid=5392->guuid=e206531e-2100-0000-f381-f6ec12150000 pid=5394 execve guuid=a02beb46-2100-0000-f381-f6ec2e150000 pid=5422->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con guuid=a02beb46-2100-0000-f381-f6ec2e150000 pid=5422->558177e1-1f18-5f39-990b-d68b1c194e8a con guuid=a02beb46-2100-0000-f381-f6ec2e150000 pid=5422->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=6d6e2c48-2100-0000-f381-f6ec30150000 pid=5424 /usr/bin/systemctl guuid=a02beb46-2100-0000-f381-f6ec2e150000 pid=5422->guuid=6d6e2c48-2100-0000-f381-f6ec30150000 pid=5424 execve guuid=d3967e4d-2100-0000-f381-f6ec39150000 pid=5433->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con guuid=d3967e4d-2100-0000-f381-f6ec39150000 pid=5433->558177e1-1f18-5f39-990b-d68b1c194e8a con guuid=d3967e4d-2100-0000-f381-f6ec39150000 pid=5433->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=5a4cb94f-2100-0000-f381-f6ec3a150000 pid=5434 /usr/bin/true guuid=d3967e4d-2100-0000-f381-f6ec39150000 pid=5433->guuid=5a4cb94f-2100-0000-f381-f6ec3a150000 pid=5434 execve guuid=7abdd453-2100-0000-f381-f6ec3d150000 pid=5437->f6e5790d-96c2-5381-8e14-4935a19ea2d0 send: 92B guuid=062eb370-2100-0000-f381-f6ec4f150000 pid=5455->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con guuid=062eb370-2100-0000-f381-f6ec4f150000 pid=5455->558177e1-1f18-5f39-990b-d68b1c194e8a con guuid=062eb370-2100-0000-f381-f6ec4f150000 pid=5455->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=65377575-2100-0000-f381-f6ec57150000 pid=5463 /usr/bin/true guuid=062eb370-2100-0000-f381-f6ec4f150000 pid=5455->guuid=65377575-2100-0000-f381-f6ec57150000 pid=5463 execve guuid=19b75477-2100-0000-f381-f6ec59150000 pid=5465->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con guuid=19b75477-2100-0000-f381-f6ec59150000 pid=5465->558177e1-1f18-5f39-990b-d68b1c194e8a con guuid=19b75477-2100-0000-f381-f6ec59150000 pid=5465->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=f051067b-2100-0000-f381-f6ec5c150000 pid=5468 /usr/bin/mv guuid=19b75477-2100-0000-f381-f6ec59150000 pid=5465->guuid=f051067b-2100-0000-f381-f6ec5c150000 pid=5468 execve guuid=5a210e7e-2100-0000-f381-f6ec62150000 pid=5474->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con guuid=5a210e7e-2100-0000-f381-f6ec62150000 pid=5474->558177e1-1f18-5f39-990b-d68b1c194e8a con guuid=5a210e7e-2100-0000-f381-f6ec62150000 pid=5474->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=a3e14782-2100-0000-f381-f6ec65150000 pid=5477 /usr/bin/chmod guuid=5a210e7e-2100-0000-f381-f6ec62150000 pid=5474->guuid=a3e14782-2100-0000-f381-f6ec65150000 pid=5477 execve guuid=dba34f86-2100-0000-f381-f6ec68150000 pid=5480 /usr/local/bin/watcher zombie guuid=8802ba85-2100-0000-f381-f6ec67150000 pid=5479->guuid=dba34f86-2100-0000-f381-f6ec68150000 pid=5480 clone guuid=d6426b86-2100-0000-f381-f6ec69150000 pid=5481 /usr/local/bin/watcher guuid=dba34f86-2100-0000-f381-f6ec68150000 pid=5480->guuid=d6426b86-2100-0000-f381-f6ec69150000 pid=5481 clone guuid=36d55891-2100-0000-f381-f6ec6d150000 pid=5485->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con guuid=36d55891-2100-0000-f381-f6ec6d150000 pid=5485->558177e1-1f18-5f39-990b-d68b1c194e8a con guuid=36d55891-2100-0000-f381-f6ec6d150000 pid=5485->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=fe16f092-2100-0000-f381-f6ec6e150000 pid=5486 /usr/bin/true guuid=36d55891-2100-0000-f381-f6ec6d150000 pid=5485->guuid=fe16f092-2100-0000-f381-f6ec6e150000 pid=5486 execve guuid=a5bd3f94-2100-0000-f381-f6ec72150000 pid=5490 /usr/bin/whoami guuid=34131294-2100-0000-f381-f6ec70150000 pid=5488->guuid=a5bd3f94-2100-0000-f381-f6ec72150000 pid=5490 execve guuid=67ba1b94-2100-0000-f381-f6ec71150000 pid=5489->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con guuid=67ba1b94-2100-0000-f381-f6ec71150000 pid=5489->558177e1-1f18-5f39-990b-d68b1c194e8a con guuid=67ba1b94-2100-0000-f381-f6ec71150000 pid=5489->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=43e8d097-2100-0000-f381-f6ec74150000 pid=5492 /usr/bin/tee write-config guuid=67ba1b94-2100-0000-f381-f6ec71150000 pid=5489->guuid=43e8d097-2100-0000-f381-f6ec74150000 pid=5492 execve guuid=524a4998-2100-0000-f381-f6ec75150000 pid=5493->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con guuid=524a4998-2100-0000-f381-f6ec75150000 pid=5493->558177e1-1f18-5f39-990b-d68b1c194e8a con guuid=524a4998-2100-0000-f381-f6ec75150000 pid=5493->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=6ccba699-2100-0000-f381-f6ec76150000 pid=5494 /usr/bin/systemctl guuid=524a4998-2100-0000-f381-f6ec75150000 pid=5493->guuid=6ccba699-2100-0000-f381-f6ec76150000 pid=5494 execve guuid=c644d1c1-2100-0000-f381-f6ec9c150000 pid=5532->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con guuid=c644d1c1-2100-0000-f381-f6ec9c150000 pid=5532->558177e1-1f18-5f39-990b-d68b1c194e8a con guuid=c644d1c1-2100-0000-f381-f6ec9c150000 pid=5532->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=e12f54c3-2100-0000-f381-f6ec9d150000 pid=5533 /usr/bin/systemctl guuid=c644d1c1-2100-0000-f381-f6ec9c150000 pid=5532->guuid=e12f54c3-2100-0000-f381-f6ec9d150000 pid=5533 execve guuid=1f0e30e9-2100-0000-f381-f6ecb2150000 pid=5554->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con guuid=1f0e30e9-2100-0000-f381-f6ecb2150000 pid=5554->558177e1-1f18-5f39-990b-d68b1c194e8a con guuid=1f0e30e9-2100-0000-f381-f6ecb2150000 pid=5554->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=aece92ea-2100-0000-f381-f6ecb3150000 pid=5555 /usr/bin/systemctl guuid=1f0e30e9-2100-0000-f381-f6ecb2150000 pid=5554->guuid=aece92ea-2100-0000-f381-f6ecb3150000 pid=5555 execve guuid=dec20366-2200-0000-f381-f6ecb8150000 pid=5560->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con guuid=dec20366-2200-0000-f381-f6ecb8150000 pid=5560->558177e1-1f18-5f39-990b-d68b1c194e8a con guuid=dec20366-2200-0000-f381-f6ecb8150000 pid=5560->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=af5c6567-2200-0000-f381-f6ecb9150000 pid=5561 /usr/bin/systemctl guuid=dec20366-2200-0000-f381-f6ecb8150000 pid=5560->guuid=af5c6567-2200-0000-f381-f6ecb9150000 pid=5561 execve guuid=4799346a-2200-0000-f381-f6ecbb150000 pid=5563->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con guuid=4799346a-2200-0000-f381-f6ecbb150000 pid=5563->558177e1-1f18-5f39-990b-d68b1c194e8a con guuid=4799346a-2200-0000-f381-f6ecbb150000 pid=5563->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=4d2bd66b-2200-0000-f381-f6ecbc150000 pid=5564 /usr/bin/systemctl guuid=4799346a-2200-0000-f381-f6ecbb150000 pid=5563->guuid=4d2bd66b-2200-0000-f381-f6ecbc150000 pid=5564 execve guuid=76a2836e-2200-0000-f381-f6ecc1150000 pid=5569 /usr/local/bin/watcher zombie guuid=1eed0f6e-2200-0000-f381-f6ecbe150000 pid=5566->guuid=76a2836e-2200-0000-f381-f6ecc1150000 pid=5569 clone guuid=8041396e-2200-0000-f381-f6ecc0150000 pid=5568 /usr/bin/cat guuid=8ce1256e-2200-0000-f381-f6ecbf150000 pid=5567->guuid=8041396e-2200-0000-f381-f6ecc0150000 pid=5568 execve guuid=02238c6e-2200-0000-f381-f6ecc3150000 pid=5571 /usr/local/bin/watcher guuid=76a2836e-2200-0000-f381-f6ecc1150000 pid=5569->guuid=02238c6e-2200-0000-f381-f6ecc3150000 pid=5571 clone
Result
Malware family:
xmrig_linux
Score:
  10/10
Tags:
family:xmrig_linux antivm defense_evasion discovery linux miner persistence privilege_escalation upx
Behaviour
Enumerates kernel/hardware configuration
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
Reads CPU attributes
UPX packed file
Abuse Elevation Control Mechanism: Sudo and Sudo Caching
Enumerates running processes
Modifies systemd
File and Directory Permissions Modification
Executes dropped EXE
Xmrig_linux family
xmrig
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

CoinMiner

sh ae54f5cc038825e241d2daaa16080582ff610ab1ee8af4016b13aac3a7a4097d

(this sample)

  
Delivery method
Distributed via web download

Comments