MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b8b15833c5fed4b3d1393d1d6729099fca39aad8199fd6f8c7e5fb3f36d9732f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



CoinMiner


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: b8b15833c5fed4b3d1393d1d6729099fca39aad8199fd6f8c7e5fb3f36d9732f
SHA3-384 hash: 9abc10dbfb6b9f7df7dbd88552f83aa9ccc9343be1e291b0b07a3d33161028b616752a3249daf8a2d91fe3d6ced7192e
SHA1 hash: 672411fbd9cc063cfaac1ce3ff74ba0afd64c9f2
MD5 hash: c65a817f6a196ce78bac4e28b2d0cd61
humanhash: emma-bacon-cold-golf
File name:mon.sh
Download: download sample
Signature CoinMiner
File size:5'277 bytes
First seen:2025-08-24 13:55:20 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 96:l06z0cic273AUP7DTAiVjlhIAmx793jt0yjtgmu4IL1qFQ2ZV7Raa3d6z0cd:l080c9i3DzDNj3Gd935XvIL1qFhH7Rxw
TLSH T1A1B1874AF690C6B0389D81A8A99B70863A06428B4E451D1DF86EF19C7F5479871F83FF
Magika shell
Reporter abuse_ch
Tags:CoinMiner sh
URLMalware sample (SHA256 hash)SignatureTags
http://162.248.53.119:8000/mon.sh1e891ab1521b27923233e694f60fdbf0e1b840e657d8b1ffdefd8b5ef5e38964 CoinMinerCoinMiner
http://ip-api.com/json/n/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
31
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
fingerprint threat
Verdict:
Malicious
File Type:
unix shell
Detections:
HEUR:Trojan-Downloader.Shell.Agent.bc
Status:
terminated
Behavior Graph:
%3 guuid=1e3c0a2a-1900-0000-d52c-365ba60b0000 pid=2982 /usr/bin/sudo guuid=2ba2bb2d-1900-0000-d52c-365bb20b0000 pid=2994 /tmp/sample.bin guuid=1e3c0a2a-1900-0000-d52c-365ba60b0000 pid=2982->guuid=2ba2bb2d-1900-0000-d52c-365bb20b0000 pid=2994 execve guuid=90bfa42e-1900-0000-d52c-365bb40b0000 pid=2996 /usr/bin/whoami guuid=2ba2bb2d-1900-0000-d52c-365bb20b0000 pid=2994->guuid=90bfa42e-1900-0000-d52c-365bb40b0000 pid=2996 execve guuid=16f15c2f-1900-0000-d52c-365bb60b0000 pid=2998 /usr/bin/whoami guuid=2ba2bb2d-1900-0000-d52c-365bb20b0000 pid=2994->guuid=16f15c2f-1900-0000-d52c-365bb60b0000 pid=2998 execve guuid=70dbcf2f-1900-0000-d52c-365bb80b0000 pid=3000 /usr/bin/whoami guuid=2ba2bb2d-1900-0000-d52c-365bb20b0000 pid=2994->guuid=70dbcf2f-1900-0000-d52c-365bb80b0000 pid=3000 execve guuid=afa55630-1900-0000-d52c-365bba0b0000 pid=3002 /usr/bin/bash guuid=2ba2bb2d-1900-0000-d52c-365bb20b0000 pid=2994->guuid=afa55630-1900-0000-d52c-365bba0b0000 pid=3002 clone guuid=d1b79130-1900-0000-d52c-365bbc0b0000 pid=3004 /usr/bin/id guuid=2ba2bb2d-1900-0000-d52c-365bb20b0000 pid=2994->guuid=d1b79130-1900-0000-d52c-365bbc0b0000 pid=3004 execve guuid=314ec631-1900-0000-d52c-365bc00b0000 pid=3008 /usr/bin/systemctl guuid=2ba2bb2d-1900-0000-d52c-365bb20b0000 pid=2994->guuid=314ec631-1900-0000-d52c-365bc00b0000 pid=3008 execve guuid=bc995c34-1900-0000-d52c-365bc50b0000 pid=3013 /usr/bin/bash guuid=2ba2bb2d-1900-0000-d52c-365bb20b0000 pid=2994->guuid=bc995c34-1900-0000-d52c-365bc50b0000 pid=3013 clone guuid=8d6d6734-1900-0000-d52c-365bc60b0000 pid=3014 /usr/bin/grep guuid=2ba2bb2d-1900-0000-d52c-365bb20b0000 pid=2994->guuid=8d6d6734-1900-0000-d52c-365bc60b0000 pid=3014 execve guuid=6bc7d834-1900-0000-d52c-365bc70b0000 pid=3015 /usr/bin/bash guuid=2ba2bb2d-1900-0000-d52c-365bb20b0000 pid=2994->guuid=6bc7d834-1900-0000-d52c-365bc70b0000 pid=3015 clone guuid=fa63e134-1900-0000-d52c-365bc90b0000 pid=3017 /usr/bin/bash guuid=2ba2bb2d-1900-0000-d52c-365bb20b0000 pid=2994->guuid=fa63e134-1900-0000-d52c-365bc90b0000 pid=3017 clone guuid=b8b93135-1900-0000-d52c-365bcb0b0000 pid=3019 /usr/bin/ps guuid=2ba2bb2d-1900-0000-d52c-365bb20b0000 pid=2994->guuid=b8b93135-1900-0000-d52c-365bcb0b0000 pid=3019 execve guuid=7aa03b35-1900-0000-d52c-365bcc0b0000 pid=3020 /usr/bin/mawk guuid=2ba2bb2d-1900-0000-d52c-365bb20b0000 pid=2994->guuid=7aa03b35-1900-0000-d52c-365bcc0b0000 pid=3020 execve guuid=ed495c35-1900-0000-d52c-365bce0b0000 pid=3022 /usr/bin/bash guuid=2ba2bb2d-1900-0000-d52c-365bb20b0000 pid=2994->guuid=ed495c35-1900-0000-d52c-365bce0b0000 pid=3022 clone guuid=6b27203a-1900-0000-d52c-365bdc0b0000 pid=3036 /usr/bin/bash guuid=2ba2bb2d-1900-0000-d52c-365bb20b0000 pid=2994->guuid=6b27203a-1900-0000-d52c-365bdc0b0000 pid=3036 clone guuid=6c24283d-1900-0000-d52c-365beb0b0000 pid=3051 /usr/bin/bash guuid=2ba2bb2d-1900-0000-d52c-365bb20b0000 pid=2994->guuid=6c24283d-1900-0000-d52c-365beb0b0000 pid=3051 clone guuid=3371ce3d-1900-0000-d52c-365bf00b0000 pid=3056 /usr/bin/curl net send-data guuid=2ba2bb2d-1900-0000-d52c-365bb20b0000 pid=2994->guuid=3371ce3d-1900-0000-d52c-365bf00b0000 pid=3056 execve guuid=8dc5d53d-1900-0000-d52c-365bf10b0000 pid=3057 /usr/bin/grep guuid=2ba2bb2d-1900-0000-d52c-365bb20b0000 pid=2994->guuid=8dc5d53d-1900-0000-d52c-365bf10b0000 pid=3057 execve guuid=ed341353-1900-0000-d52c-365b200c0000 pid=3104 /usr/bin/wget net send-data write-file guuid=2ba2bb2d-1900-0000-d52c-365bb20b0000 pid=2994->guuid=ed341353-1900-0000-d52c-365b200c0000 pid=3104 execve guuid=e8efda63-1900-0000-d52c-365b510c0000 pid=3153 /usr/bin/chmod guuid=2ba2bb2d-1900-0000-d52c-365bb20b0000 pid=2994->guuid=e8efda63-1900-0000-d52c-365b510c0000 pid=3153 execve guuid=84c73164-1900-0000-d52c-365b530c0000 pid=3155 /home/sandbox/run.sh guuid=2ba2bb2d-1900-0000-d52c-365bb20b0000 pid=2994->guuid=84c73164-1900-0000-d52c-365b530c0000 pid=3155 execve guuid=b144a8c6-1c00-0000-d52c-365b3d150000 pid=5437 /usr/bin/rm delete-file guuid=2ba2bb2d-1900-0000-d52c-365bb20b0000 pid=2994->guuid=b144a8c6-1c00-0000-d52c-365b3d150000 pid=5437 execve guuid=28df06c7-1c00-0000-d52c-365b3e150000 pid=5438 /usr/bin/whoami guuid=2ba2bb2d-1900-0000-d52c-365bb20b0000 pid=2994->guuid=28df06c7-1c00-0000-d52c-365b3e150000 pid=5438 execve guuid=65b074c7-1c00-0000-d52c-365b3f150000 pid=5439 /usr/bin/whoami guuid=2ba2bb2d-1900-0000-d52c-365bb20b0000 pid=2994->guuid=65b074c7-1c00-0000-d52c-365b3f150000 pid=5439 execve guuid=f744d9c7-1c00-0000-d52c-365b40150000 pid=5440 /usr/bin/whoami guuid=2ba2bb2d-1900-0000-d52c-365bb20b0000 pid=2994->guuid=f744d9c7-1c00-0000-d52c-365b40150000 pid=5440 execve guuid=c4f7e634-1900-0000-d52c-365bca0b0000 pid=3018 /usr/bin/bash guuid=6bc7d834-1900-0000-d52c-365bc70b0000 pid=3015->guuid=c4f7e634-1900-0000-d52c-365bca0b0000 pid=3018 clone guuid=d20c3e3a-1900-0000-d52c-365bde0b0000 pid=3038 /usr/bin/pgrep guuid=6b27203a-1900-0000-d52c-365bdc0b0000 pid=3036->guuid=d20c3e3a-1900-0000-d52c-365bde0b0000 pid=3038 execve guuid=9ab4453a-1900-0000-d52c-365bdf0b0000 pid=3039 /usr/bin/bash guuid=6b27203a-1900-0000-d52c-365bdc0b0000 pid=3036->guuid=9ab4453a-1900-0000-d52c-365bdf0b0000 pid=3039 clone guuid=b4f33f3d-1900-0000-d52c-365bed0b0000 pid=3053 /usr/bin/grep guuid=6c24283d-1900-0000-d52c-365beb0b0000 pid=3051->guuid=b4f33f3d-1900-0000-d52c-365bed0b0000 pid=3053 execve b60edd83-de97-543e-8c12-c815cb088ff2 ip-api.com:80 guuid=3371ce3d-1900-0000-d52c-365bf00b0000 pid=3056->b60edd83-de97-543e-8c12-c815cb088ff2 send: 79B guuid=3371ce3d-1900-0000-d52c-365bf00b0000 pid=3068 /usr/bin/curl dns net send-data guuid=3371ce3d-1900-0000-d52c-365bf00b0000 pid=3056->guuid=3371ce3d-1900-0000-d52c-365bf00b0000 pid=3068 clone 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=3371ce3d-1900-0000-d52c-365bf00b0000 pid=3068->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 28B 2f67bf0f-8453-5800-9e7b-37101ce5849f 162.248.53.119:8000 guuid=ed341353-1900-0000-d52c-365b200c0000 pid=3104->2f67bf0f-8453-5800-9e7b-37101ce5849f send: 140B guuid=98efd664-1900-0000-d52c-365b570c0000 pid=3159 /usr/bin/systemctl guuid=84c73164-1900-0000-d52c-365b530c0000 pid=3155->guuid=98efd664-1900-0000-d52c-365b570c0000 pid=3159 execve guuid=272b6f66-1900-0000-d52c-365b5c0c0000 pid=3164 /usr/bin/bash guuid=84c73164-1900-0000-d52c-365b530c0000 pid=3155->guuid=272b6f66-1900-0000-d52c-365b5c0c0000 pid=3164 clone guuid=a4d6546c-1900-0000-d52c-365b680c0000 pid=3176 /usr/bin/bash guuid=84c73164-1900-0000-d52c-365b530c0000 pid=3155->guuid=a4d6546c-1900-0000-d52c-365b680c0000 pid=3176 clone guuid=9182f16c-1900-0000-d52c-365b6e0c0000 pid=3182 /usr/bin/pgrep guuid=84c73164-1900-0000-d52c-365b530c0000 pid=3155->guuid=9182f16c-1900-0000-d52c-365b6e0c0000 pid=3182 execve guuid=1383fc70-1900-0000-d52c-365b730c0000 pid=3187 /usr/bin/pgrep guuid=84c73164-1900-0000-d52c-365b530c0000 pid=3155->guuid=1383fc70-1900-0000-d52c-365b730c0000 pid=3187 execve guuid=e8898f73-1900-0000-d52c-365b7a0c0000 pid=3194 /usr/bin/pgrep guuid=84c73164-1900-0000-d52c-365b530c0000 pid=3155->guuid=e8898f73-1900-0000-d52c-365b7a0c0000 pid=3194 execve guuid=f7a49673-1900-0000-d52c-365b7b0c0000 pid=3195 /usr/bin/grep guuid=84c73164-1900-0000-d52c-365b530c0000 pid=3155->guuid=f7a49673-1900-0000-d52c-365b7b0c0000 pid=3195 execve guuid=b8ee9d73-1900-0000-d52c-365b7d0c0000 pid=3197 /usr/bin/xargs guuid=84c73164-1900-0000-d52c-365b530c0000 pid=3155->guuid=b8ee9d73-1900-0000-d52c-365b7d0c0000 pid=3197 execve guuid=2d108376-1900-0000-d52c-365b840c0000 pid=3204 /usr/bin/id guuid=84c73164-1900-0000-d52c-365b530c0000 pid=3155->guuid=2d108376-1900-0000-d52c-365b840c0000 pid=3204 execve guuid=54700677-1900-0000-d52c-365b850c0000 pid=3205 /usr/bin/apt-get delete-file write-file guuid=84c73164-1900-0000-d52c-365b530c0000 pid=3155->guuid=54700677-1900-0000-d52c-365b850c0000 pid=3205 execve guuid=b7d8574e-1b00-0000-d52c-365b39110000 pid=4409 /usr/bin/apt-get guuid=84c73164-1900-0000-d52c-365b530c0000 pid=3155->guuid=b7d8574e-1b00-0000-d52c-365b39110000 pid=4409 execve guuid=e8c84150-1b00-0000-d52c-365b44110000 pid=4420 /usr/bin/mkdir guuid=84c73164-1900-0000-d52c-365b530c0000 pid=3155->guuid=e8c84150-1b00-0000-d52c-365b44110000 pid=4420 execve guuid=171ba450-1b00-0000-d52c-365b48110000 pid=4424 /usr/bin/wget dns net send-data write-file guuid=84c73164-1900-0000-d52c-365b530c0000 pid=3155->guuid=171ba450-1b00-0000-d52c-365b48110000 pid=4424 execve guuid=12ebd871-1b00-0000-d52c-365b85110000 pid=4485 /usr/bin/tar write-file guuid=84c73164-1900-0000-d52c-365b530c0000 pid=3155->guuid=12ebd871-1b00-0000-d52c-365b85110000 pid=4485 execve guuid=6496b08f-1b00-0000-d52c-365bfe110000 pid=4606 /usr/bin/mv guuid=84c73164-1900-0000-d52c-365b530c0000 pid=3155->guuid=6496b08f-1b00-0000-d52c-365bfe110000 pid=4606 execve guuid=1c010c90-1b00-0000-d52c-365b00120000 pid=4608 /usr/bin/rm guuid=84c73164-1900-0000-d52c-365b530c0000 pid=3155->guuid=1c010c90-1b00-0000-d52c-365b00120000 pid=4608 execve guuid=6b544a90-1b00-0000-d52c-365b02120000 pid=4610 /usr/bin/chmod guuid=84c73164-1900-0000-d52c-365b530c0000 pid=3155->guuid=6b544a90-1b00-0000-d52c-365b02120000 pid=4610 execve guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4612 /usr/lib/dev/systemdev/systemd-mont mprotect-exec net send-data guuid=84c73164-1900-0000-d52c-365b530c0000 pid=3155->guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4612 execve guuid=178c9790-1b00-0000-d52c-365b06120000 pid=4614 /usr/bin/sleep guuid=84c73164-1900-0000-d52c-365b530c0000 pid=3155->guuid=178c9790-1b00-0000-d52c-365b06120000 pid=4614 execve guuid=2b3fd2ae-1b00-0000-d52c-365b37120000 pid=4663 /usr/bin/ps guuid=84c73164-1900-0000-d52c-365b530c0000 pid=3155->guuid=2b3fd2ae-1b00-0000-d52c-365b37120000 pid=4663 execve guuid=ff9f5db3-1b00-0000-d52c-365b3c120000 pid=4668 /usr/bin/sleep guuid=84c73164-1900-0000-d52c-365b530c0000 pid=3155->guuid=ff9f5db3-1b00-0000-d52c-365b3c120000 pid=4668 execve guuid=ade316c0-1c00-0000-d52c-365b32150000 pid=5426 /usr/bin/ps guuid=84c73164-1900-0000-d52c-365b530c0000 pid=3155->guuid=ade316c0-1c00-0000-d52c-365b32150000 pid=5426 execve guuid=b59840c5-1c00-0000-d52c-365b3b150000 pid=5435 /usr/bin/rm guuid=84c73164-1900-0000-d52c-365b530c0000 pid=3155->guuid=b59840c5-1c00-0000-d52c-365b3b150000 pid=5435 execve guuid=a3b406c6-1c00-0000-d52c-365b3c150000 pid=5436 /usr/bin/rm guuid=84c73164-1900-0000-d52c-365b530c0000 pid=3155->guuid=a3b406c6-1c00-0000-d52c-365b3c150000 pid=5436 execve guuid=1d218866-1900-0000-d52c-365b5d0c0000 pid=3165 /usr/bin/wget dns net send-data guuid=272b6f66-1900-0000-d52c-365b5c0c0000 pid=3164->guuid=1d218866-1900-0000-d52c-365b5d0c0000 pid=3165 execve guuid=1d218866-1900-0000-d52c-365b5d0c0000 pid=3165->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 72B 0690ccd5-4816-5f11-94dc-7c585f38cdea ipv4.icanhazip.com:0 guuid=1d218866-1900-0000-d52c-365b5d0c0000 pid=3165->0690ccd5-4816-5f11-94dc-7c585f38cdea con d0ecfe49-aa79-583f-85c6-85ac97075256 ipv4.icanhazip.com:80 guuid=1d218866-1900-0000-d52c-365b5d0c0000 pid=3165->d0ecfe49-aa79-583f-85c6-85ac97075256 send: 133B guuid=55cd666c-1900-0000-d52c-365b690c0000 pid=3177 /usr/bin/bash guuid=a4d6546c-1900-0000-d52c-365b680c0000 pid=3176->guuid=55cd666c-1900-0000-d52c-365b690c0000 pid=3177 clone guuid=402a706c-1900-0000-d52c-365b6a0c0000 pid=3178 /usr/bin/sed guuid=a4d6546c-1900-0000-d52c-365b680c0000 pid=3176->guuid=402a706c-1900-0000-d52c-365b6a0c0000 pid=3178 execve guuid=ceb8756c-1900-0000-d52c-365b6b0c0000 pid=3179 /usr/bin/cut guuid=a4d6546c-1900-0000-d52c-365b680c0000 pid=3176->guuid=ceb8756c-1900-0000-d52c-365b6b0c0000 pid=3179 execve guuid=4a816978-1900-0000-d52c-365b8a0c0000 pid=3210 /usr/bin/dpkg guuid=54700677-1900-0000-d52c-365b850c0000 pid=3205->guuid=4a816978-1900-0000-d52c-365b8a0c0000 pid=3210 execve guuid=62ded47e-1900-0000-d52c-365b8d0c0000 pid=3213 /usr/lib/apt/methods/mirror guuid=54700677-1900-0000-d52c-365b850c0000 pid=3205->guuid=62ded47e-1900-0000-d52c-365b8d0c0000 pid=3213 execve guuid=f7cb1a80-1900-0000-d52c-365b8e0c0000 pid=3214 /usr/lib/apt/methods/mirror guuid=54700677-1900-0000-d52c-365b850c0000 pid=3205->guuid=f7cb1a80-1900-0000-d52c-365b8e0c0000 pid=3214 execve guuid=0b05bc81-1900-0000-d52c-365b8f0c0000 pid=3215 /usr/lib/apt/methods/file guuid=54700677-1900-0000-d52c-365b850c0000 pid=3205->guuid=0b05bc81-1900-0000-d52c-365b8f0c0000 pid=3215 execve guuid=c928a484-1900-0000-d52c-365b900c0000 pid=3216 /usr/lib/apt/methods/file delete-file guuid=54700677-1900-0000-d52c-365b850c0000 pid=3205->guuid=c928a484-1900-0000-d52c-365b900c0000 pid=3216 execve guuid=c4ef9b86-1900-0000-d52c-365b910c0000 pid=3217 /usr/lib/apt/methods/http guuid=54700677-1900-0000-d52c-365b850c0000 pid=3205->guuid=c4ef9b86-1900-0000-d52c-365b910c0000 pid=3217 execve guuid=af950e8b-1900-0000-d52c-365b940c0000 pid=3220 /usr/lib/apt/methods/http dns net send-data write-file guuid=54700677-1900-0000-d52c-365b850c0000 pid=3205->guuid=af950e8b-1900-0000-d52c-365b940c0000 pid=3220 execve guuid=816843a7-1900-0000-d52c-365bb70c0000 pid=3255 /usr/lib/apt/methods/gpgv guuid=54700677-1900-0000-d52c-365b850c0000 pid=3205->guuid=816843a7-1900-0000-d52c-365bb70c0000 pid=3255 execve guuid=94871eaa-1900-0000-d52c-365bb80c0000 pid=3256 /usr/lib/apt/methods/gpgv guuid=54700677-1900-0000-d52c-365b850c0000 pid=3205->guuid=94871eaa-1900-0000-d52c-365bb80c0000 pid=3256 execve guuid=6958f5e2-1900-0000-d52c-365b3b0d0000 pid=3387 /usr/lib/apt/methods/store guuid=54700677-1900-0000-d52c-365b850c0000 pid=3205->guuid=6958f5e2-1900-0000-d52c-365b3b0d0000 pid=3387 execve guuid=7e79cae3-1900-0000-d52c-365b400d0000 pid=3392 /usr/lib/apt/methods/store write-file guuid=54700677-1900-0000-d52c-365b850c0000 pid=3205->guuid=7e79cae3-1900-0000-d52c-365b400d0000 pid=3392 execve guuid=dfaa65ff-1900-0000-d52c-365b840d0000 pid=3460 /usr/lib/apt/methods/rred guuid=54700677-1900-0000-d52c-365b850c0000 pid=3205->guuid=dfaa65ff-1900-0000-d52c-365b840d0000 pid=3460 execve guuid=d5af680d-1a00-0000-d52c-365b950d0000 pid=3477 /usr/lib/apt/methods/rred write-file guuid=54700677-1900-0000-d52c-365b850c0000 pid=3205->guuid=d5af680d-1a00-0000-d52c-365b950d0000 pid=3477 execve guuid=99333646-1a00-0000-d52c-365bfe0d0000 pid=3582 /usr/bin/dpkg guuid=54700677-1900-0000-d52c-365b850c0000 pid=3205->guuid=99333646-1a00-0000-d52c-365bfe0d0000 pid=3582 execve guuid=b2b9f548-1b00-0000-d52c-365b25110000 pid=4389 /usr/bin/dpkg guuid=54700677-1900-0000-d52c-365b850c0000 pid=3205->guuid=b2b9f548-1b00-0000-d52c-365b25110000 pid=4389 execve guuid=af950e8b-1900-0000-d52c-365b940c0000 pid=3220->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 122B 869ebe88-8c1e-5fbb-adb0-cfe48d8d7faf debian.map.fastly.net:443 guuid=af950e8b-1900-0000-d52c-365b940c0000 pid=3220->869ebe88-8c1e-5fbb-adb0-cfe48d8d7faf send: 5667B guuid=dce2d6ab-1900-0000-d52c-365bb90c0000 pid=3257 /usr/lib/apt/methods/gpgv delete-file write-file guuid=94871eaa-1900-0000-d52c-365bb80c0000 pid=3256->guuid=dce2d6ab-1900-0000-d52c-365bb90c0000 pid=3257 clone guuid=e3b5d6ce-1900-0000-d52c-365bf70c0000 pid=3319 /usr/lib/apt/methods/gpgv delete-file write-file guuid=94871eaa-1900-0000-d52c-365bb80c0000 pid=3256->guuid=e3b5d6ce-1900-0000-d52c-365bf70c0000 pid=3319 clone guuid=a2e537df-1900-0000-d52c-365b2b0d0000 pid=3371 /usr/lib/apt/methods/gpgv delete-file write-file guuid=94871eaa-1900-0000-d52c-365bb80c0000 pid=3256->guuid=a2e537df-1900-0000-d52c-365b2b0d0000 pid=3371 clone guuid=5f3ed9ef-1900-0000-d52c-365b710d0000 pid=3441 /usr/lib/apt/methods/gpgv delete-file write-file guuid=94871eaa-1900-0000-d52c-365bb80c0000 pid=3256->guuid=5f3ed9ef-1900-0000-d52c-365b710d0000 pid=3441 clone guuid=b8492daf-1900-0000-d52c-365bbc0c0000 pid=3260 /usr/bin/apt-key write-file guuid=dce2d6ab-1900-0000-d52c-365bb90c0000 pid=3257->guuid=b8492daf-1900-0000-d52c-365bbc0c0000 pid=3260 execve guuid=dc3e89af-1900-0000-d52c-365bbe0c0000 pid=3262 /usr/bin/dash guuid=b8492daf-1900-0000-d52c-365bbc0c0000 pid=3260->guuid=dc3e89af-1900-0000-d52c-365bbe0c0000 pid=3262 clone guuid=2571a2af-1900-0000-d52c-365bbf0c0000 pid=3263 /usr/bin/apt-config guuid=b8492daf-1900-0000-d52c-365bbc0c0000 pid=3260->guuid=2571a2af-1900-0000-d52c-365bbf0c0000 pid=3263 execve guuid=85382eb3-1900-0000-d52c-365bc50c0000 pid=3269 /usr/bin/apt-config guuid=b8492daf-1900-0000-d52c-365bbc0c0000 pid=3260->guuid=85382eb3-1900-0000-d52c-365bc50c0000 pid=3269 execve guuid=731727bb-1900-0000-d52c-365bc70c0000 pid=3271 /usr/bin/apt-config guuid=b8492daf-1900-0000-d52c-365bbc0c0000 pid=3260->guuid=731727bb-1900-0000-d52c-365bc70c0000 pid=3271 execve guuid=ba0be4c3-1900-0000-d52c-365bd20c0000 pid=3282 /usr/bin/apt-config guuid=b8492daf-1900-0000-d52c-365bbc0c0000 pid=3260->guuid=ba0be4c3-1900-0000-d52c-365bd20c0000 pid=3282 execve guuid=891962c5-1900-0000-d52c-365bd90c0000 pid=3289 /usr/bin/dash guuid=b8492daf-1900-0000-d52c-365bbc0c0000 pid=3260->guuid=891962c5-1900-0000-d52c-365bd90c0000 pid=3289 clone guuid=60cc94c5-1900-0000-d52c-365bda0c0000 pid=3290 /usr/bin/apt-config guuid=b8492daf-1900-0000-d52c-365bbc0c0000 pid=3260->guuid=60cc94c5-1900-0000-d52c-365bda0c0000 pid=3290 execve guuid=95a9ccc7-1900-0000-d52c-365bdd0c0000 pid=3293 /usr/bin/mktemp guuid=b8492daf-1900-0000-d52c-365bbc0c0000 pid=3260->guuid=95a9ccc7-1900-0000-d52c-365bdd0c0000 pid=3293 execve guuid=51f502c8-1900-0000-d52c-365bde0c0000 pid=3294 /usr/bin/chmod guuid=b8492daf-1900-0000-d52c-365bbc0c0000 pid=3260->guuid=51f502c8-1900-0000-d52c-365bde0c0000 pid=3294 execve guuid=7c8c36c8-1900-0000-d52c-365bdf0c0000 pid=3295 /usr/bin/dash guuid=b8492daf-1900-0000-d52c-365bbc0c0000 pid=3260->guuid=7c8c36c8-1900-0000-d52c-365bdf0c0000 pid=3295 clone guuid=85f94dc8-1900-0000-d52c-365be00c0000 pid=3296 /usr/bin/dash guuid=b8492daf-1900-0000-d52c-365bbc0c0000 pid=3260->guuid=85f94dc8-1900-0000-d52c-365be00c0000 pid=3296 clone guuid=2719c4c8-1900-0000-d52c-365be40c0000 pid=3300 /usr/bin/dash guuid=b8492daf-1900-0000-d52c-365bbc0c0000 pid=3260->guuid=2719c4c8-1900-0000-d52c-365be40c0000 pid=3300 clone guuid=77c576c9-1900-0000-d52c-365be90c0000 pid=3305 /usr/bin/dash guuid=b8492daf-1900-0000-d52c-365bbc0c0000 pid=3260->guuid=77c576c9-1900-0000-d52c-365be90c0000 pid=3305 clone guuid=62ce87c9-1900-0000-d52c-365bea0c0000 pid=3306 /usr/bin/gpgv guuid=b8492daf-1900-0000-d52c-365bbc0c0000 pid=3260->guuid=62ce87c9-1900-0000-d52c-365bea0c0000 pid=3306 execve guuid=1655c3cb-1900-0000-d52c-365bef0c0000 pid=3311 /usr/bin/rm delete-file guuid=b8492daf-1900-0000-d52c-365bbc0c0000 pid=3260->guuid=1655c3cb-1900-0000-d52c-365bef0c0000 pid=3311 execve guuid=3b3e29b2-1900-0000-d52c-365bc40c0000 pid=3268 /usr/bin/dpkg guuid=2571a2af-1900-0000-d52c-365bbf0c0000 pid=3263->guuid=3b3e29b2-1900-0000-d52c-365bc40c0000 pid=3268 execve guuid=5f93f3b5-1900-0000-d52c-365bc60c0000 pid=3270 /usr/bin/dpkg guuid=85382eb3-1900-0000-d52c-365bc50c0000 pid=3269->guuid=5f93f3b5-1900-0000-d52c-365bc60c0000 pid=3270 execve guuid=82dd9abc-1900-0000-d52c-365bc80c0000 pid=3272 /usr/bin/dpkg guuid=731727bb-1900-0000-d52c-365bc70c0000 pid=3271->guuid=82dd9abc-1900-0000-d52c-365bc80c0000 pid=3272 execve guuid=e59cc6c4-1900-0000-d52c-365bd60c0000 pid=3286 /usr/bin/dpkg guuid=ba0be4c3-1900-0000-d52c-365bd20c0000 pid=3282->guuid=e59cc6c4-1900-0000-d52c-365bd60c0000 pid=3286 execve guuid=0c4821c7-1900-0000-d52c-365bdb0c0000 pid=3291 /usr/bin/dpkg guuid=60cc94c5-1900-0000-d52c-365bda0c0000 pid=3290->guuid=0c4821c7-1900-0000-d52c-365bdb0c0000 pid=3291 execve guuid=6d9d58c8-1900-0000-d52c-365be10c0000 pid=3297 /usr/bin/dash guuid=85f94dc8-1900-0000-d52c-365be00c0000 pid=3296->guuid=6d9d58c8-1900-0000-d52c-365be10c0000 pid=3297 clone guuid=2e0f5ec8-1900-0000-d52c-365be20c0000 pid=3298 /usr/bin/sed guuid=85f94dc8-1900-0000-d52c-365be00c0000 pid=3296->guuid=2e0f5ec8-1900-0000-d52c-365be20c0000 pid=3298 execve guuid=eb37cfc8-1900-0000-d52c-365be50c0000 pid=3301 /usr/bin/dash guuid=2719c4c8-1900-0000-d52c-365be40c0000 pid=3300->guuid=eb37cfc8-1900-0000-d52c-365be50c0000 pid=3301 clone guuid=ad8ad4c8-1900-0000-d52c-365be60c0000 pid=3302 /usr/bin/sed guuid=2719c4c8-1900-0000-d52c-365be40c0000 pid=3300->guuid=ad8ad4c8-1900-0000-d52c-365be60c0000 pid=3302 execve guuid=20e6bacf-1900-0000-d52c-365bf90c0000 pid=3321 /usr/bin/apt-key write-file guuid=e3b5d6ce-1900-0000-d52c-365bf70c0000 pid=3319->guuid=20e6bacf-1900-0000-d52c-365bf90c0000 pid=3321 execve guuid=aaae07d0-1900-0000-d52c-365bfa0c0000 pid=3322 /usr/bin/dash guuid=20e6bacf-1900-0000-d52c-365bf90c0000 pid=3321->guuid=aaae07d0-1900-0000-d52c-365bfa0c0000 pid=3322 clone guuid=974618d0-1900-0000-d52c-365bfc0c0000 pid=3324 /usr/bin/apt-config guuid=20e6bacf-1900-0000-d52c-365bf90c0000 pid=3321->guuid=974618d0-1900-0000-d52c-365bfc0c0000 pid=3324 execve guuid=fbeee2d3-1900-0000-d52c-365b020d0000 pid=3330 /usr/bin/apt-config guuid=20e6bacf-1900-0000-d52c-365bf90c0000 pid=3321->guuid=fbeee2d3-1900-0000-d52c-365b020d0000 pid=3330 execve guuid=04fb07d6-1900-0000-d52c-365b040d0000 pid=3332 /usr/bin/apt-config guuid=20e6bacf-1900-0000-d52c-365bf90c0000 pid=3321->guuid=04fb07d6-1900-0000-d52c-365b040d0000 pid=3332 execve guuid=70c406d8-1900-0000-d52c-365b070d0000 pid=3335 /usr/bin/apt-config guuid=20e6bacf-1900-0000-d52c-365bf90c0000 pid=3321->guuid=70c406d8-1900-0000-d52c-365b070d0000 pid=3335 execve guuid=0de8aed9-1900-0000-d52c-365b0e0d0000 pid=3342 /usr/bin/dash guuid=20e6bacf-1900-0000-d52c-365bf90c0000 pid=3321->guuid=0de8aed9-1900-0000-d52c-365b0e0d0000 pid=3342 clone guuid=46e2d9d9-1900-0000-d52c-365b100d0000 pid=3344 /usr/bin/apt-config guuid=20e6bacf-1900-0000-d52c-365bf90c0000 pid=3321->guuid=46e2d9d9-1900-0000-d52c-365b100d0000 pid=3344 execve guuid=671853db-1900-0000-d52c-365b160d0000 pid=3350 /usr/bin/mktemp guuid=20e6bacf-1900-0000-d52c-365bf90c0000 pid=3321->guuid=671853db-1900-0000-d52c-365b160d0000 pid=3350 execve guuid=0ef08bdb-1900-0000-d52c-365b180d0000 pid=3352 /usr/bin/chmod guuid=20e6bacf-1900-0000-d52c-365bf90c0000 pid=3321->guuid=0ef08bdb-1900-0000-d52c-365b180d0000 pid=3352 execve guuid=34e5bddb-1900-0000-d52c-365b1a0d0000 pid=3354 /usr/bin/dash guuid=20e6bacf-1900-0000-d52c-365bf90c0000 pid=3321->guuid=34e5bddb-1900-0000-d52c-365b1a0d0000 pid=3354 clone guuid=afe3d4db-1900-0000-d52c-365b1b0d0000 pid=3355 /usr/bin/dash guuid=20e6bacf-1900-0000-d52c-365bf90c0000 pid=3321->guuid=afe3d4db-1900-0000-d52c-365b1b0d0000 pid=3355 clone guuid=44e04edc-1900-0000-d52c-365b200d0000 pid=3360 /usr/bin/dash guuid=20e6bacf-1900-0000-d52c-365bf90c0000 pid=3321->guuid=44e04edc-1900-0000-d52c-365b200d0000 pid=3360 clone guuid=4d7caadc-1900-0000-d52c-365b240d0000 pid=3364 /usr/bin/dash guuid=20e6bacf-1900-0000-d52c-365bf90c0000 pid=3321->guuid=4d7caadc-1900-0000-d52c-365b240d0000 pid=3364 clone guuid=ba9fbfdc-1900-0000-d52c-365b260d0000 pid=3366 /usr/bin/gpgv guuid=20e6bacf-1900-0000-d52c-365bf90c0000 pid=3321->guuid=ba9fbfdc-1900-0000-d52c-365b260d0000 pid=3366 execve guuid=2e1d12de-1900-0000-d52c-365b290d0000 pid=3369 /usr/bin/rm delete-file guuid=20e6bacf-1900-0000-d52c-365bf90c0000 pid=3321->guuid=2e1d12de-1900-0000-d52c-365b290d0000 pid=3369 execve guuid=10874dd3-1900-0000-d52c-365b010d0000 pid=3329 /usr/bin/dpkg guuid=974618d0-1900-0000-d52c-365bfc0c0000 pid=3324->guuid=10874dd3-1900-0000-d52c-365b010d0000 pid=3329 execve guuid=ccd21ed5-1900-0000-d52c-365b030d0000 pid=3331 /usr/bin/dpkg guuid=fbeee2d3-1900-0000-d52c-365b020d0000 pid=3330->guuid=ccd21ed5-1900-0000-d52c-365b030d0000 pid=3331 execve guuid=a13228d7-1900-0000-d52c-365b060d0000 pid=3334 /usr/bin/dpkg guuid=04fb07d6-1900-0000-d52c-365b040d0000 pid=3332->guuid=a13228d7-1900-0000-d52c-365b060d0000 pid=3334 execve guuid=351f1ad9-1900-0000-d52c-365b0b0d0000 pid=3339 /usr/bin/dpkg guuid=70c406d8-1900-0000-d52c-365b070d0000 pid=3335->guuid=351f1ad9-1900-0000-d52c-365b0b0d0000 pid=3339 execve guuid=a72dcfda-1900-0000-d52c-365b130d0000 pid=3347 /usr/bin/dpkg guuid=46e2d9d9-1900-0000-d52c-365b100d0000 pid=3344->guuid=a72dcfda-1900-0000-d52c-365b130d0000 pid=3347 execve guuid=12c8dddb-1900-0000-d52c-365b1c0d0000 pid=3356 /usr/bin/dash guuid=afe3d4db-1900-0000-d52c-365b1b0d0000 pid=3355->guuid=12c8dddb-1900-0000-d52c-365b1c0d0000 pid=3356 clone guuid=756be3db-1900-0000-d52c-365b1d0d0000 pid=3357 /usr/bin/sed guuid=afe3d4db-1900-0000-d52c-365b1b0d0000 pid=3355->guuid=756be3db-1900-0000-d52c-365b1d0d0000 pid=3357 execve guuid=6c9f57dc-1900-0000-d52c-365b210d0000 pid=3361 /usr/bin/dash guuid=44e04edc-1900-0000-d52c-365b200d0000 pid=3360->guuid=6c9f57dc-1900-0000-d52c-365b210d0000 pid=3361 clone guuid=7c085ddc-1900-0000-d52c-365b220d0000 pid=3362 /usr/bin/sed guuid=44e04edc-1900-0000-d52c-365b200d0000 pid=3360->guuid=7c085ddc-1900-0000-d52c-365b220d0000 pid=3362 execve guuid=12e5fbdf-1900-0000-d52c-365b2d0d0000 pid=3373 /usr/bin/apt-key write-file guuid=a2e537df-1900-0000-d52c-365b2b0d0000 pid=3371->guuid=12e5fbdf-1900-0000-d52c-365b2d0d0000 pid=3373 execve guuid=74fb43e0-1900-0000-d52c-365b2f0d0000 pid=3375 /usr/bin/dash guuid=12e5fbdf-1900-0000-d52c-365b2d0d0000 pid=3373->guuid=74fb43e0-1900-0000-d52c-365b2f0d0000 pid=3375 clone guuid=75224ee0-1900-0000-d52c-365b300d0000 pid=3376 /usr/bin/apt-config guuid=12e5fbdf-1900-0000-d52c-365b2d0d0000 pid=3373->guuid=75224ee0-1900-0000-d52c-365b300d0000 pid=3376 execve guuid=8acd29e2-1900-0000-d52c-365b370d0000 pid=3383 /usr/bin/apt-config guuid=12e5fbdf-1900-0000-d52c-365b2d0d0000 pid=3373->guuid=8acd29e2-1900-0000-d52c-365b370d0000 pid=3383 execve guuid=8a6c30e4-1900-0000-d52c-365b420d0000 pid=3394 /usr/bin/apt-config guuid=12e5fbdf-1900-0000-d52c-365b2d0d0000 pid=3373->guuid=8a6c30e4-1900-0000-d52c-365b420d0000 pid=3394 execve guuid=d6c985e5-1900-0000-d52c-365b480d0000 pid=3400 /usr/bin/apt-config guuid=12e5fbdf-1900-0000-d52c-365b2d0d0000 pid=3373->guuid=d6c985e5-1900-0000-d52c-365b480d0000 pid=3400 execve guuid=9fc894e8-1900-0000-d52c-365b4f0d0000 pid=3407 /usr/bin/dash guuid=12e5fbdf-1900-0000-d52c-365b2d0d0000 pid=3373->guuid=9fc894e8-1900-0000-d52c-365b4f0d0000 pid=3407 clone guuid=f1c7c9e8-1900-0000-d52c-365b500d0000 pid=3408 /usr/bin/apt-config guuid=12e5fbdf-1900-0000-d52c-365b2d0d0000 pid=3373->guuid=f1c7c9e8-1900-0000-d52c-365b500d0000 pid=3408 execve guuid=bbda86ec-1900-0000-d52c-365b570d0000 pid=3415 /usr/bin/mktemp guuid=12e5fbdf-1900-0000-d52c-365b2d0d0000 pid=3373->guuid=bbda86ec-1900-0000-d52c-365b570d0000 pid=3415 execve guuid=4b4fbeec-1900-0000-d52c-365b590d0000 pid=3417 /usr/bin/chmod guuid=12e5fbdf-1900-0000-d52c-365b2d0d0000 pid=3373->guuid=4b4fbeec-1900-0000-d52c-365b590d0000 pid=3417 execve guuid=8adceaec-1900-0000-d52c-365b5b0d0000 pid=3419 /usr/bin/dash guuid=12e5fbdf-1900-0000-d52c-365b2d0d0000 pid=3373->guuid=8adceaec-1900-0000-d52c-365b5b0d0000 pid=3419 clone guuid=7b9bfbec-1900-0000-d52c-365b5c0d0000 pid=3420 /usr/bin/dash guuid=12e5fbdf-1900-0000-d52c-365b2d0d0000 pid=3373->guuid=7b9bfbec-1900-0000-d52c-365b5c0d0000 pid=3420 clone guuid=9b2d5eed-1900-0000-d52c-365b600d0000 pid=3424 /usr/bin/dash guuid=12e5fbdf-1900-0000-d52c-365b2d0d0000 pid=3373->guuid=9b2d5eed-1900-0000-d52c-365b600d0000 pid=3424 clone guuid=1e3cc0ed-1900-0000-d52c-365b650d0000 pid=3429 /usr/bin/dash guuid=12e5fbdf-1900-0000-d52c-365b2d0d0000 pid=3373->guuid=1e3cc0ed-1900-0000-d52c-365b650d0000 pid=3429 clone guuid=29b1cfed-1900-0000-d52c-365b660d0000 pid=3430 /usr/bin/gpgv guuid=12e5fbdf-1900-0000-d52c-365b2d0d0000 pid=3373->guuid=29b1cfed-1900-0000-d52c-365b660d0000 pid=3430 execve guuid=7f2f23ef-1900-0000-d52c-365b6d0d0000 pid=3437 /usr/bin/rm delete-file guuid=12e5fbdf-1900-0000-d52c-365b2d0d0000 pid=3373->guuid=7f2f23ef-1900-0000-d52c-365b6d0d0000 pid=3437 execve guuid=e003c0e1-1900-0000-d52c-365b350d0000 pid=3381 /usr/bin/dpkg guuid=75224ee0-1900-0000-d52c-365b300d0000 pid=3376->guuid=e003c0e1-1900-0000-d52c-365b350d0000 pid=3381 execve guuid=9bd084e3-1900-0000-d52c-365b3e0d0000 pid=3390 /usr/bin/dpkg guuid=8acd29e2-1900-0000-d52c-365b370d0000 pid=3383->guuid=9bd084e3-1900-0000-d52c-365b3e0d0000 pid=3390 execve guuid=606e0ce5-1900-0000-d52c-365b460d0000 pid=3398 /usr/bin/dpkg guuid=8a6c30e4-1900-0000-d52c-365b420d0000 pid=3394->guuid=606e0ce5-1900-0000-d52c-365b460d0000 pid=3398 execve guuid=9ef915e8-1900-0000-d52c-365b4c0d0000 pid=3404 /usr/bin/dpkg guuid=d6c985e5-1900-0000-d52c-365b480d0000 pid=3400->guuid=9ef915e8-1900-0000-d52c-365b4c0d0000 pid=3404 execve guuid=16f0faeb-1900-0000-d52c-365b540d0000 pid=3412 /usr/bin/dpkg guuid=f1c7c9e8-1900-0000-d52c-365b500d0000 pid=3408->guuid=16f0faeb-1900-0000-d52c-365b540d0000 pid=3412 execve guuid=06f704ed-1900-0000-d52c-365b5d0d0000 pid=3421 /usr/bin/dash guuid=7b9bfbec-1900-0000-d52c-365b5c0d0000 pid=3420->guuid=06f704ed-1900-0000-d52c-365b5d0d0000 pid=3421 clone guuid=fb270aed-1900-0000-d52c-365b5e0d0000 pid=3422 /usr/bin/sed guuid=7b9bfbec-1900-0000-d52c-365b5c0d0000 pid=3420->guuid=fb270aed-1900-0000-d52c-365b5e0d0000 pid=3422 execve guuid=a05464ed-1900-0000-d52c-365b610d0000 pid=3425 /usr/bin/dash guuid=9b2d5eed-1900-0000-d52c-365b600d0000 pid=3424->guuid=a05464ed-1900-0000-d52c-365b610d0000 pid=3425 clone guuid=30d269ed-1900-0000-d52c-365b630d0000 pid=3427 /usr/bin/sed guuid=9b2d5eed-1900-0000-d52c-365b600d0000 pid=3424->guuid=30d269ed-1900-0000-d52c-365b630d0000 pid=3427 execve guuid=96e517f1-1900-0000-d52c-365b750d0000 pid=3445 /usr/bin/apt-key write-file guuid=5f3ed9ef-1900-0000-d52c-365b710d0000 pid=3441->guuid=96e517f1-1900-0000-d52c-365b750d0000 pid=3445 execve guuid=198dd2f1-1900-0000-d52c-365b760d0000 pid=3446 /usr/bin/dash guuid=96e517f1-1900-0000-d52c-365b750d0000 pid=3445->guuid=198dd2f1-1900-0000-d52c-365b760d0000 pid=3446 clone guuid=b10fe8f1-1900-0000-d52c-365b770d0000 pid=3447 /usr/bin/apt-config guuid=96e517f1-1900-0000-d52c-365b750d0000 pid=3445->guuid=b10fe8f1-1900-0000-d52c-365b770d0000 pid=3447 execve guuid=1b64c3f3-1900-0000-d52c-365b7e0d0000 pid=3454 /usr/bin/apt-config guuid=96e517f1-1900-0000-d52c-365b750d0000 pid=3445->guuid=1b64c3f3-1900-0000-d52c-365b7e0d0000 pid=3454 execve guuid=027d6af5-1900-0000-d52c-365b810d0000 pid=3457 /usr/bin/apt-config guuid=96e517f1-1900-0000-d52c-365b750d0000 pid=3445->guuid=027d6af5-1900-0000-d52c-365b810d0000 pid=3457 execve guuid=ec9732fc-1900-0000-d52c-365b830d0000 pid=3459 /usr/bin/apt-config guuid=96e517f1-1900-0000-d52c-365b750d0000 pid=3445->guuid=ec9732fc-1900-0000-d52c-365b830d0000 pid=3459 execve guuid=a550ab00-1a00-0000-d52c-365b860d0000 pid=3462 /usr/bin/dash guuid=96e517f1-1900-0000-d52c-365b750d0000 pid=3445->guuid=a550ab00-1a00-0000-d52c-365b860d0000 pid=3462 clone guuid=57dd0001-1a00-0000-d52c-365b870d0000 pid=3463 /usr/bin/apt-config guuid=96e517f1-1900-0000-d52c-365b750d0000 pid=3445->guuid=57dd0001-1a00-0000-d52c-365b870d0000 pid=3463 execve guuid=4e451d03-1a00-0000-d52c-365b890d0000 pid=3465 /usr/bin/mktemp guuid=96e517f1-1900-0000-d52c-365b750d0000 pid=3445->guuid=4e451d03-1a00-0000-d52c-365b890d0000 pid=3465 execve guuid=bfb86803-1a00-0000-d52c-365b8a0d0000 pid=3466 /usr/bin/chmod guuid=96e517f1-1900-0000-d52c-365b750d0000 pid=3445->guuid=bfb86803-1a00-0000-d52c-365b8a0d0000 pid=3466 execve guuid=8342ab03-1a00-0000-d52c-365b8b0d0000 pid=3467 /usr/bin/dash guuid=96e517f1-1900-0000-d52c-365b750d0000 pid=3445->guuid=8342ab03-1a00-0000-d52c-365b8b0d0000 pid=3467 clone guuid=b60fc703-1a00-0000-d52c-365b8c0d0000 pid=3468 /usr/bin/dash guuid=96e517f1-1900-0000-d52c-365b750d0000 pid=3445->guuid=b60fc703-1a00-0000-d52c-365b8c0d0000 pid=3468 clone guuid=d6df5004-1a00-0000-d52c-365b8f0d0000 pid=3471 /usr/bin/dash guuid=96e517f1-1900-0000-d52c-365b750d0000 pid=3445->guuid=d6df5004-1a00-0000-d52c-365b8f0d0000 pid=3471 clone guuid=c1abc604-1a00-0000-d52c-365b920d0000 pid=3474 /usr/bin/dash guuid=96e517f1-1900-0000-d52c-365b750d0000 pid=3445->guuid=c1abc604-1a00-0000-d52c-365b920d0000 pid=3474 clone guuid=8b71e204-1a00-0000-d52c-365b930d0000 pid=3475 /usr/bin/gpgv guuid=96e517f1-1900-0000-d52c-365b750d0000 pid=3445->guuid=8b71e204-1a00-0000-d52c-365b930d0000 pid=3475 execve guuid=0f2f0307-1a00-0000-d52c-365b940d0000 pid=3476 /usr/bin/rm delete-file guuid=96e517f1-1900-0000-d52c-365b750d0000 pid=3445->guuid=0f2f0307-1a00-0000-d52c-365b940d0000 pid=3476 execve guuid=da070bf3-1900-0000-d52c-365b7b0d0000 pid=3451 /usr/bin/dpkg guuid=b10fe8f1-1900-0000-d52c-365b770d0000 pid=3447->guuid=da070bf3-1900-0000-d52c-365b7b0d0000 pid=3451 execve guuid=e2d6daf4-1900-0000-d52c-365b800d0000 pid=3456 /usr/bin/dpkg guuid=1b64c3f3-1900-0000-d52c-365b7e0d0000 pid=3454->guuid=e2d6daf4-1900-0000-d52c-365b800d0000 pid=3456 execve guuid=811c76f9-1900-0000-d52c-365b820d0000 pid=3458 /usr/bin/dpkg guuid=027d6af5-1900-0000-d52c-365b810d0000 pid=3457->guuid=811c76f9-1900-0000-d52c-365b820d0000 pid=3458 execve guuid=a8a27aff-1900-0000-d52c-365b850d0000 pid=3461 /usr/bin/dpkg guuid=ec9732fc-1900-0000-d52c-365b830d0000 pid=3459->guuid=a8a27aff-1900-0000-d52c-365b850d0000 pid=3461 execve guuid=35e74102-1a00-0000-d52c-365b880d0000 pid=3464 /usr/bin/dpkg guuid=57dd0001-1a00-0000-d52c-365b870d0000 pid=3463->guuid=35e74102-1a00-0000-d52c-365b880d0000 pid=3464 execve guuid=63fcd603-1a00-0000-d52c-365b8d0d0000 pid=3469 /usr/bin/dash guuid=b60fc703-1a00-0000-d52c-365b8c0d0000 pid=3468->guuid=63fcd603-1a00-0000-d52c-365b8d0d0000 pid=3469 clone guuid=5935e303-1a00-0000-d52c-365b8e0d0000 pid=3470 /usr/bin/sed guuid=b60fc703-1a00-0000-d52c-365b8c0d0000 pid=3468->guuid=5935e303-1a00-0000-d52c-365b8e0d0000 pid=3470 execve guuid=15cf5904-1a00-0000-d52c-365b900d0000 pid=3472 /usr/bin/dash guuid=d6df5004-1a00-0000-d52c-365b8f0d0000 pid=3471->guuid=15cf5904-1a00-0000-d52c-365b900d0000 pid=3472 clone guuid=26ef5f04-1a00-0000-d52c-365b910d0000 pid=3473 /usr/bin/sed guuid=d6df5004-1a00-0000-d52c-365b8f0d0000 pid=3471->guuid=26ef5f04-1a00-0000-d52c-365b910d0000 pid=3473 execve guuid=7df2984f-1b00-0000-d52c-365b3f110000 pid=4415 /usr/bin/dpkg guuid=b7d8574e-1b00-0000-d52c-365b39110000 pid=4409->guuid=7df2984f-1b00-0000-d52c-365b3f110000 pid=4415 execve guuid=171ba450-1b00-0000-d52c-365b48110000 pid=4424->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 164B 75aab096-419b-50ef-be46-7d76b6a90e4c github.com:443 guuid=171ba450-1b00-0000-d52c-365b48110000 pid=4424->75aab096-419b-50ef-be46-7d76b6a90e4c send: 799B f8c5e44f-328d-5324-8bbd-da50752b9120 release-assets.githubusercontent.com:0 guuid=171ba450-1b00-0000-d52c-365b48110000 pid=4424->f8c5e44f-328d-5324-8bbd-da50752b9120 con f0eebea5-e97d-507c-a771-59cac353877c release-assets.githubusercontent.com:443 guuid=171ba450-1b00-0000-d52c-365b48110000 pid=4424->f0eebea5-e97d-507c-a771-59cac353877c send: 1636B guuid=e68c3072-1b00-0000-d52c-365b89110000 pid=4489 /usr/bin/xz guuid=12ebd871-1b00-0000-d52c-365b85110000 pid=4485->guuid=e68c3072-1b00-0000-d52c-365b89110000 pid=4489 execve 2f50a59f-2358-5b5c-aa0a-c8fc64202aee hosts-to-ignore.ignorelist.com:1443 guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4612->2f50a59f-2358-5b5c-aa0a-c8fc64202aee send: 859B guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4628 /usr/lib/dev/systemdev/systemd-mont write-file zombie guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4612->guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4628 clone guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4629 /usr/lib/dev/systemdev/systemd-mont dns net send-data guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4612->guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4629 clone guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4630 /usr/lib/dev/systemdev/systemd-mont guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4612->guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4630 clone guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4631 /usr/lib/dev/systemdev/systemd-mont guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4612->guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4631 clone guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4632 /usr/lib/dev/systemdev/systemd-mont guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4612->guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4632 clone guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4659 /usr/lib/dev/systemdev/systemd-mont guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4612->guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4659 clone guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4660 /usr/lib/dev/systemdev/systemd-mont guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4612->guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4660 clone guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4661 /usr/lib/dev/systemdev/systemd-mont guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4612->guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4661 clone guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4662 /usr/lib/dev/systemdev/systemd-mont guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4612->guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4662 clone guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4664 /usr/lib/dev/systemdev/systemd-mont guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4612->guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4664 clone guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4665 /usr/lib/dev/systemdev/systemd-mont guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4612->guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4665 clone guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4666 /usr/lib/dev/systemdev/systemd-mont guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4612->guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4666 clone guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4667 /usr/lib/dev/systemdev/systemd-mont guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4612->guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4667 clone guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4669 /usr/lib/dev/systemdev/systemd-mont guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4612->guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4669 clone guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4670 /usr/lib/dev/systemdev/systemd-mont guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4612->guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4670 clone guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4671 /usr/lib/dev/systemdev/systemd-mont guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4612->guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4671 clone guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4672 /usr/lib/dev/systemdev/systemd-mont guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4612->guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4672 clone guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4684 /usr/lib/dev/systemdev/systemd-mont guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4612->guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4684 clone guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4685 /usr/lib/dev/systemdev/systemd-mont guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4612->guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4685 clone guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4686 /usr/lib/dev/systemdev/systemd-mont guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4612->guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4686 clone guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4687 /usr/lib/dev/systemdev/systemd-mont guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4612->guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4687 clone guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4705 /usr/lib/dev/systemdev/systemd-mont guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4612->guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4705 clone guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4706 /usr/lib/dev/systemdev/systemd-mont guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4612->guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4706 clone guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4707 /usr/lib/dev/systemdev/systemd-mont guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4612->guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4707 clone guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4708 /usr/lib/dev/systemdev/systemd-mont guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4612->guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4708 clone guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4741 /usr/lib/dev/systemdev/systemd-mont guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4612->guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4741 clone guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4742 /usr/lib/dev/systemdev/systemd-mont guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4612->guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4742 clone guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4743 /usr/lib/dev/systemdev/systemd-mont guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4612->guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4743 clone guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4744 /usr/lib/dev/systemdev/systemd-mont guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4612->guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4744 clone guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4782 /usr/lib/dev/systemdev/systemd-mont guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4612->guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4782 clone guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4783 /usr/lib/dev/systemdev/systemd-mont guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4612->guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4783 clone guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4784 /usr/lib/dev/systemdev/systemd-mont guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4612->guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4784 clone guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4785 /usr/lib/dev/systemdev/systemd-mont guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4612->guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4785 clone guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4812 /usr/lib/dev/systemdev/systemd-mont guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4612->guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4812 clone guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4813 /usr/lib/dev/systemdev/systemd-mont guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4612->guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4813 clone guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4814 /usr/lib/dev/systemdev/systemd-mont guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4612->guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4814 clone guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4815 /usr/lib/dev/systemdev/systemd-mont guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4612->guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4815 clone guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4833 /usr/lib/dev/systemdev/systemd-mont guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4612->guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4833 clone guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4834 /usr/lib/dev/systemdev/systemd-mont guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4612->guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4834 clone guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4835 /usr/lib/dev/systemdev/systemd-mont guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4612->guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4835 clone guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4836 /usr/lib/dev/systemdev/systemd-mont guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4612->guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4836 clone guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4858 /usr/lib/dev/systemdev/systemd-mont guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4612->guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4858 clone guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4859 /usr/lib/dev/systemdev/systemd-mont guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4612->guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4859 clone guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4860 /usr/lib/dev/systemdev/systemd-mont guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4612->guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4860 clone guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4861 /usr/lib/dev/systemdev/systemd-mont guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4612->guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4861 clone guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4885 /usr/lib/dev/systemdev/systemd-mont guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4612->guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4885 clone guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4886 /usr/lib/dev/systemdev/systemd-mont guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4612->guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4886 clone guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4887 /usr/lib/dev/systemdev/systemd-mont guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4612->guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4887 clone guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4888 /usr/lib/dev/systemdev/systemd-mont guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4612->guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4888 clone guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4907 /usr/lib/dev/systemdev/systemd-mont guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4612->guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4907 clone guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4908 /usr/lib/dev/systemdev/systemd-mont guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4612->guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4908 clone guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4909 /usr/lib/dev/systemdev/systemd-mont guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4612->guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4909 clone guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4910 /usr/lib/dev/systemdev/systemd-mont guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4612->guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4910 clone guuid=5e438c90-1b00-0000-d52c-365b04120000 pid=4629->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 96B
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2025-08-24 13:55:52 UTC
File Type:
Text (Shell)
AV detection:
10 of 24 (41.67%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  6/10
Tags:
antivm discovery execution linux persistence privilege_escalation
Behaviour
Enumerates kernel/hardware configuration
Reads runtime system information
Checks CPU configuration
Reads CPU attributes
Creates/modifies Cron job
Enumerates running processes
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments