MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e3b35476ea7d4de4b689a952ab25ed5ad1063149a03c0f342cfba9ad26bd614a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



CoinMiner


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: e3b35476ea7d4de4b689a952ab25ed5ad1063149a03c0f342cfba9ad26bd614a
SHA3-384 hash: 9ba7b677ec9822896835959bbcb024fed71c79a944936c237abf3e7a2455e5a7e4ac0c15ed82d7149ff3b20eac36d6f8
SHA1 hash: 3315d6d57e02c244d568529ae832025d98ac3414
MD5 hash: 36fa15d891dfbf58013db21dfa473ac2
humanhash: four-yellow-arizona-india
File name:run.sh
Download: download sample
Signature CoinMiner
File size:7'722 bytes
First seen:2025-08-27 13:53:04 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 192:F8XyzHWZzzDN19xDkIam3qarbayHDPMTMvlgYm:MzvLzaUNjm+gR
TLSH T1B0F1C706F6D0DAB42988C568844A1840794F922B5D092C48F8FDB56DFF2476C71FDBEB
Magika shell
Reporter abuse_ch
Tags:CoinMiner sh
URLMalware sample (SHA256 hash)SignatureTags
http://162.248.53.119:8000/yes.tar.gzn/an/aopendir
http://162.248.53.119:8000/mon.sh1e891ab1521b27923233e694f60fdbf0e1b840e657d8b1ffdefd8b5ef5e38964 CoinMinerCoinMiner
https://github.com/el3ctr0wqw1/xmrig-vrl2/releases/download/main/xmrig-vrln/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
38
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
unix shell
Detections:
HEUR:Trojan-Downloader.Shell.Agent.bc
Status:
terminated
Behavior Graph:
%3 guuid=ebb5f514-1900-0000-3042-a44084120000 pid=4740 /usr/bin/sudo guuid=d1bbe816-1900-0000-3042-a4408f120000 pid=4751 /tmp/sample.bin guuid=ebb5f514-1900-0000-3042-a44084120000 pid=4740->guuid=d1bbe816-1900-0000-3042-a4408f120000 pid=4751 execve guuid=e26bfe17-1900-0000-3042-a44094120000 pid=4756 /usr/bin/systemctl guuid=d1bbe816-1900-0000-3042-a4408f120000 pid=4751->guuid=e26bfe17-1900-0000-3042-a44094120000 pid=4756 execve guuid=e89c5b1a-1900-0000-3042-a4409a120000 pid=4762 /usr/bin/bash guuid=d1bbe816-1900-0000-3042-a4408f120000 pid=4751->guuid=e89c5b1a-1900-0000-3042-a4409a120000 pid=4762 clone guuid=a07ce321-1900-0000-3042-a440b9120000 pid=4793 /usr/bin/bash guuid=d1bbe816-1900-0000-3042-a4408f120000 pid=4751->guuid=a07ce321-1900-0000-3042-a440b9120000 pid=4793 clone guuid=edd77722-1900-0000-3042-a440c0120000 pid=4800 /usr/bin/pgrep guuid=d1bbe816-1900-0000-3042-a4408f120000 pid=4751->guuid=edd77722-1900-0000-3042-a440c0120000 pid=4800 execve guuid=d25b0825-1900-0000-3042-a440cd120000 pid=4813 /usr/bin/pgrep guuid=d1bbe816-1900-0000-3042-a4408f120000 pid=4751->guuid=d25b0825-1900-0000-3042-a440cd120000 pid=4813 execve guuid=af9f6428-1900-0000-3042-a440dc120000 pid=4828 /usr/bin/pgrep guuid=d1bbe816-1900-0000-3042-a4408f120000 pid=4751->guuid=af9f6428-1900-0000-3042-a440dc120000 pid=4828 execve guuid=e8177428-1900-0000-3042-a440dd120000 pid=4829 /usr/bin/grep guuid=d1bbe816-1900-0000-3042-a4408f120000 pid=4751->guuid=e8177428-1900-0000-3042-a440dd120000 pid=4829 execve guuid=474e7d28-1900-0000-3042-a440de120000 pid=4830 /usr/bin/xargs guuid=d1bbe816-1900-0000-3042-a4408f120000 pid=4751->guuid=474e7d28-1900-0000-3042-a440de120000 pid=4830 execve guuid=20a9dd2a-1900-0000-3042-a440e5120000 pid=4837 /usr/bin/id guuid=d1bbe816-1900-0000-3042-a4408f120000 pid=4751->guuid=20a9dd2a-1900-0000-3042-a440e5120000 pid=4837 execve guuid=dfff672b-1900-0000-3042-a440e7120000 pid=4839 /usr/bin/apt-get delete-file write-file guuid=d1bbe816-1900-0000-3042-a4408f120000 pid=4751->guuid=dfff672b-1900-0000-3042-a440e7120000 pid=4839 execve guuid=2bd90c03-1b00-0000-3042-a440f0140000 pid=5360 /usr/bin/apt-get guuid=d1bbe816-1900-0000-3042-a4408f120000 pid=4751->guuid=2bd90c03-1b00-0000-3042-a440f0140000 pid=5360 execve guuid=0ce5d51c-1b00-0000-3042-a440f2140000 pid=5362 /usr/bin/mkdir guuid=d1bbe816-1900-0000-3042-a4408f120000 pid=4751->guuid=0ce5d51c-1b00-0000-3042-a440f2140000 pid=5362 execve guuid=16f0a21d-1b00-0000-3042-a440f3140000 pid=5363 /usr/bin/wget dns net send-data write-file guuid=d1bbe816-1900-0000-3042-a4408f120000 pid=4751->guuid=16f0a21d-1b00-0000-3042-a440f3140000 pid=5363 execve guuid=23cf5a4e-1b00-0000-3042-a440f5140000 pid=5365 /usr/bin/mv guuid=d1bbe816-1900-0000-3042-a4408f120000 pid=4751->guuid=23cf5a4e-1b00-0000-3042-a440f5140000 pid=5365 execve guuid=f804b64e-1b00-0000-3042-a440f6140000 pid=5366 /usr/bin/rm guuid=d1bbe816-1900-0000-3042-a4408f120000 pid=4751->guuid=f804b64e-1b00-0000-3042-a440f6140000 pid=5366 execve guuid=e4b1ef4e-1b00-0000-3042-a440f7140000 pid=5367 /usr/bin/chmod guuid=d1bbe816-1900-0000-3042-a4408f120000 pid=4751->guuid=e4b1ef4e-1b00-0000-3042-a440f7140000 pid=5367 execve guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5368 /usr/lib/dev/systemdev/dns-filter mprotect-exec net send-data guuid=d1bbe816-1900-0000-3042-a4408f120000 pid=4751->guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5368 execve guuid=9cbf384f-1b00-0000-3042-a440f9140000 pid=5369 /usr/bin/sleep guuid=d1bbe816-1900-0000-3042-a4408f120000 pid=4751->guuid=9cbf384f-1b00-0000-3042-a440f9140000 pid=5369 execve guuid=c92a966d-1b00-0000-3042-a44004150000 pid=5380 /usr/bin/ps guuid=d1bbe816-1900-0000-3042-a4408f120000 pid=4751->guuid=c92a966d-1b00-0000-3042-a44004150000 pid=5380 execve guuid=1d2dc47d-1b00-0000-3042-a44009150000 pid=5385 /usr/bin/sleep guuid=d1bbe816-1900-0000-3042-a4408f120000 pid=4751->guuid=1d2dc47d-1b00-0000-3042-a44009150000 pid=5385 execve guuid=94d6a78a-1c00-0000-3042-a44050150000 pid=5456 /usr/bin/ps guuid=d1bbe816-1900-0000-3042-a4408f120000 pid=4751->guuid=94d6a78a-1c00-0000-3042-a44050150000 pid=5456 execve guuid=029c5d8d-1c00-0000-3042-a44051150000 pid=5457 /usr/bin/bash guuid=d1bbe816-1900-0000-3042-a4408f120000 pid=4751->guuid=029c5d8d-1c00-0000-3042-a44051150000 pid=5457 clone guuid=c068808d-1c00-0000-3042-a44052150000 pid=5458 /usr/bin/grep guuid=d1bbe816-1900-0000-3042-a4408f120000 pid=4751->guuid=c068808d-1c00-0000-3042-a44052150000 pid=5458 execve guuid=9c70418e-1c00-0000-3042-a44053150000 pid=5459 /usr/bin/bash guuid=d1bbe816-1900-0000-3042-a4408f120000 pid=4751->guuid=9c70418e-1c00-0000-3042-a44053150000 pid=5459 clone guuid=8f34588e-1c00-0000-3042-a44054150000 pid=5460 /usr/bin/bash guuid=d1bbe816-1900-0000-3042-a4408f120000 pid=4751->guuid=8f34588e-1c00-0000-3042-a44054150000 pid=5460 clone guuid=0c80ad8e-1c00-0000-3042-a44056150000 pid=5462 /usr/bin/rm guuid=d1bbe816-1900-0000-3042-a4408f120000 pid=4751->guuid=0c80ad8e-1c00-0000-3042-a44056150000 pid=5462 execve guuid=a37f478f-1c00-0000-3042-a44057150000 pid=5463 /usr/bin/rm guuid=d1bbe816-1900-0000-3042-a4408f120000 pid=4751->guuid=a37f478f-1c00-0000-3042-a44057150000 pid=5463 execve guuid=5360671a-1900-0000-3042-a4409b120000 pid=4763 /usr/bin/wget dns net send-data guuid=e89c5b1a-1900-0000-3042-a4409a120000 pid=4762->guuid=5360671a-1900-0000-3042-a4409b120000 pid=4763 execve 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=5360671a-1900-0000-3042-a4409b120000 pid=4763->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 72B 0690ccd5-4816-5f11-94dc-7c585f38cdea ipv4.icanhazip.com:0 guuid=5360671a-1900-0000-3042-a4409b120000 pid=4763->0690ccd5-4816-5f11-94dc-7c585f38cdea con d0ecfe49-aa79-583f-85c6-85ac97075256 ipv4.icanhazip.com:80 guuid=5360671a-1900-0000-3042-a4409b120000 pid=4763->d0ecfe49-aa79-583f-85c6-85ac97075256 send: 133B guuid=4ec4ee21-1900-0000-3042-a440ba120000 pid=4794 /usr/bin/bash guuid=a07ce321-1900-0000-3042-a440b9120000 pid=4793->guuid=4ec4ee21-1900-0000-3042-a440ba120000 pid=4794 clone guuid=6aadf421-1900-0000-3042-a440bb120000 pid=4795 /usr/bin/sed guuid=a07ce321-1900-0000-3042-a440b9120000 pid=4793->guuid=6aadf421-1900-0000-3042-a440bb120000 pid=4795 execve guuid=8f4dfc21-1900-0000-3042-a440bc120000 pid=4796 /usr/bin/cut guuid=a07ce321-1900-0000-3042-a440b9120000 pid=4793->guuid=8f4dfc21-1900-0000-3042-a440bc120000 pid=4796 execve guuid=c8bfaf2c-1900-0000-3042-a440ec120000 pid=4844 /usr/bin/dpkg guuid=dfff672b-1900-0000-3042-a440e7120000 pid=4839->guuid=c8bfaf2c-1900-0000-3042-a440ec120000 pid=4844 execve guuid=daa06f2d-1900-0000-3042-a440ef120000 pid=4847 /usr/lib/apt/methods/mirror guuid=dfff672b-1900-0000-3042-a440e7120000 pid=4839->guuid=daa06f2d-1900-0000-3042-a440ef120000 pid=4847 execve guuid=8912e72e-1900-0000-3042-a440f5120000 pid=4853 /usr/lib/apt/methods/mirror guuid=dfff672b-1900-0000-3042-a440e7120000 pid=4839->guuid=8912e72e-1900-0000-3042-a440f5120000 pid=4853 execve guuid=eab7f22f-1900-0000-3042-a440fa120000 pid=4858 /usr/lib/apt/methods/file guuid=dfff672b-1900-0000-3042-a440e7120000 pid=4839->guuid=eab7f22f-1900-0000-3042-a440fa120000 pid=4858 execve guuid=4bf59831-1900-0000-3042-a44001130000 pid=4865 /usr/lib/apt/methods/file delete-file guuid=dfff672b-1900-0000-3042-a440e7120000 pid=4839->guuid=4bf59831-1900-0000-3042-a44001130000 pid=4865 execve guuid=f24ba432-1900-0000-3042-a44007130000 pid=4871 /usr/lib/apt/methods/http guuid=dfff672b-1900-0000-3042-a440e7120000 pid=4839->guuid=f24ba432-1900-0000-3042-a44007130000 pid=4871 execve guuid=3c046a35-1900-0000-3042-a44013130000 pid=4883 /usr/lib/apt/methods/http dns net send-data write-file guuid=dfff672b-1900-0000-3042-a440e7120000 pid=4839->guuid=3c046a35-1900-0000-3042-a44013130000 pid=4883 execve guuid=ca6b464d-1900-0000-3042-a44055130000 pid=4949 /usr/lib/apt/methods/gpgv guuid=dfff672b-1900-0000-3042-a440e7120000 pid=4839->guuid=ca6b464d-1900-0000-3042-a44055130000 pid=4949 execve guuid=f62d1b4f-1900-0000-3042-a4405b130000 pid=4955 /usr/lib/apt/methods/gpgv guuid=dfff672b-1900-0000-3042-a440e7120000 pid=4839->guuid=f62d1b4f-1900-0000-3042-a4405b130000 pid=4955 execve guuid=fe506878-1900-0000-3042-a44025140000 pid=5157 /usr/lib/apt/methods/store guuid=dfff672b-1900-0000-3042-a440e7120000 pid=4839->guuid=fe506878-1900-0000-3042-a44025140000 pid=5157 execve guuid=32d37879-1900-0000-3042-a4402a140000 pid=5162 /usr/lib/apt/methods/store write-file guuid=dfff672b-1900-0000-3042-a440e7120000 pid=4839->guuid=32d37879-1900-0000-3042-a4402a140000 pid=5162 execve guuid=70f31e94-1900-0000-3042-a4408e140000 pid=5262 /usr/lib/apt/methods/rred guuid=dfff672b-1900-0000-3042-a440e7120000 pid=4839->guuid=70f31e94-1900-0000-3042-a4408e140000 pid=5262 execve guuid=825fc1a1-1900-0000-3042-a4409f140000 pid=5279 /usr/lib/apt/methods/rred write-file guuid=dfff672b-1900-0000-3042-a440e7120000 pid=4839->guuid=825fc1a1-1900-0000-3042-a4409f140000 pid=5279 execve guuid=d5663ad9-1900-0000-3042-a440e3140000 pid=5347 /usr/bin/dpkg guuid=dfff672b-1900-0000-3042-a440e7120000 pid=4839->guuid=d5663ad9-1900-0000-3042-a440e3140000 pid=5347 execve guuid=6e85e0f5-1a00-0000-3042-a440ef140000 pid=5359 /usr/bin/dpkg guuid=dfff672b-1900-0000-3042-a440e7120000 pid=4839->guuid=6e85e0f5-1a00-0000-3042-a440ef140000 pid=5359 execve guuid=3c046a35-1900-0000-3042-a44013130000 pid=4883->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 122B 869ebe88-8c1e-5fbb-adb0-cfe48d8d7faf debian.map.fastly.net:443 guuid=3c046a35-1900-0000-3042-a44013130000 pid=4883->869ebe88-8c1e-5fbb-adb0-cfe48d8d7faf con guuid=faa98150-1900-0000-3042-a44060130000 pid=4960 /usr/lib/apt/methods/gpgv delete-file write-file guuid=f62d1b4f-1900-0000-3042-a4405b130000 pid=4955->guuid=faa98150-1900-0000-3042-a44060130000 pid=4960 clone guuid=06a0f167-1900-0000-3042-a440bd130000 pid=5053 /usr/lib/apt/methods/gpgv delete-file write-file guuid=f62d1b4f-1900-0000-3042-a4405b130000 pid=4955->guuid=06a0f167-1900-0000-3042-a440bd130000 pid=5053 clone guuid=2d4fd774-1900-0000-3042-a4400a140000 pid=5130 /usr/lib/apt/methods/gpgv delete-file write-file guuid=f62d1b4f-1900-0000-3042-a4405b130000 pid=4955->guuid=2d4fd774-1900-0000-3042-a4400a140000 pid=5130 clone guuid=9bb9f886-1900-0000-3042-a4406a140000 pid=5226 /usr/lib/apt/methods/gpgv delete-file write-file guuid=f62d1b4f-1900-0000-3042-a4405b130000 pid=4955->guuid=9bb9f886-1900-0000-3042-a4406a140000 pid=5226 clone guuid=b6110c53-1900-0000-3042-a44068130000 pid=4968 /usr/bin/apt-key write-file guuid=faa98150-1900-0000-3042-a44060130000 pid=4960->guuid=b6110c53-1900-0000-3042-a44068130000 pid=4968 execve guuid=c3426553-1900-0000-3042-a4406a130000 pid=4970 /usr/bin/dash guuid=b6110c53-1900-0000-3042-a44068130000 pid=4968->guuid=c3426553-1900-0000-3042-a4406a130000 pid=4970 clone guuid=e3307753-1900-0000-3042-a4406b130000 pid=4971 /usr/bin/apt-config guuid=b6110c53-1900-0000-3042-a44068130000 pid=4968->guuid=e3307753-1900-0000-3042-a4406b130000 pid=4971 execve guuid=dffbcb55-1900-0000-3042-a44073130000 pid=4979 /usr/bin/apt-config guuid=b6110c53-1900-0000-3042-a44068130000 pid=4968->guuid=dffbcb55-1900-0000-3042-a44073130000 pid=4979 execve guuid=872baa57-1900-0000-3042-a4407c130000 pid=4988 /usr/bin/apt-config guuid=b6110c53-1900-0000-3042-a44068130000 pid=4968->guuid=872baa57-1900-0000-3042-a4407c130000 pid=4988 execve guuid=2dddd25e-1900-0000-3042-a44090130000 pid=5008 /usr/bin/apt-config guuid=b6110c53-1900-0000-3042-a44068130000 pid=4968->guuid=2dddd25e-1900-0000-3042-a44090130000 pid=5008 execve guuid=b7296060-1900-0000-3042-a44099130000 pid=5017 /usr/bin/dash guuid=b6110c53-1900-0000-3042-a44068130000 pid=4968->guuid=b7296060-1900-0000-3042-a44099130000 pid=5017 clone guuid=11148360-1900-0000-3042-a4409a130000 pid=5018 /usr/bin/apt-config guuid=b6110c53-1900-0000-3042-a44068130000 pid=4968->guuid=11148360-1900-0000-3042-a4409a130000 pid=5018 execve guuid=7e8f6b62-1900-0000-3042-a440a3130000 pid=5027 /usr/bin/mktemp guuid=b6110c53-1900-0000-3042-a44068130000 pid=4968->guuid=7e8f6b62-1900-0000-3042-a440a3130000 pid=5027 execve guuid=ac459e62-1900-0000-3042-a440a5130000 pid=5029 /usr/bin/chmod guuid=b6110c53-1900-0000-3042-a44068130000 pid=4968->guuid=ac459e62-1900-0000-3042-a440a5130000 pid=5029 execve guuid=4d2cd362-1900-0000-3042-a440a7130000 pid=5031 /usr/bin/dash guuid=b6110c53-1900-0000-3042-a44068130000 pid=4968->guuid=4d2cd362-1900-0000-3042-a440a7130000 pid=5031 clone guuid=3591e062-1900-0000-3042-a440a8130000 pid=5032 /usr/bin/dash guuid=b6110c53-1900-0000-3042-a44068130000 pid=4968->guuid=3591e062-1900-0000-3042-a440a8130000 pid=5032 clone guuid=61053763-1900-0000-3042-a440ad130000 pid=5037 /usr/bin/dash guuid=b6110c53-1900-0000-3042-a44068130000 pid=4968->guuid=61053763-1900-0000-3042-a440ad130000 pid=5037 clone guuid=43c29063-1900-0000-3042-a440b1130000 pid=5041 /usr/bin/dash guuid=b6110c53-1900-0000-3042-a44068130000 pid=4968->guuid=43c29063-1900-0000-3042-a440b1130000 pid=5041 clone guuid=36f99e63-1900-0000-3042-a440b2130000 pid=5042 /usr/bin/gpgv guuid=b6110c53-1900-0000-3042-a44068130000 pid=4968->guuid=36f99e63-1900-0000-3042-a440b2130000 pid=5042 execve guuid=51569765-1900-0000-3042-a440bb130000 pid=5051 /usr/bin/rm delete-file guuid=b6110c53-1900-0000-3042-a44068130000 pid=4968->guuid=51569765-1900-0000-3042-a440bb130000 pid=5051 execve guuid=ea8a4d55-1900-0000-3042-a44070130000 pid=4976 /usr/bin/dpkg guuid=e3307753-1900-0000-3042-a4406b130000 pid=4971->guuid=ea8a4d55-1900-0000-3042-a44070130000 pid=4976 execve guuid=bcfe0b57-1900-0000-3042-a4407a130000 pid=4986 /usr/bin/dpkg guuid=dffbcb55-1900-0000-3042-a44073130000 pid=4979->guuid=bcfe0b57-1900-0000-3042-a4407a130000 pid=4986 execve guuid=055ebe59-1900-0000-3042-a44083130000 pid=4995 /usr/bin/dpkg guuid=872baa57-1900-0000-3042-a4407c130000 pid=4988->guuid=055ebe59-1900-0000-3042-a44083130000 pid=4995 execve guuid=0abfab5f-1900-0000-3042-a44095130000 pid=5013 /usr/bin/dpkg guuid=2dddd25e-1900-0000-3042-a44090130000 pid=5008->guuid=0abfab5f-1900-0000-3042-a44095130000 pid=5013 execve guuid=5fb3fb61-1900-0000-3042-a440a0130000 pid=5024 /usr/bin/dpkg guuid=11148360-1900-0000-3042-a4409a130000 pid=5018->guuid=5fb3fb61-1900-0000-3042-a440a0130000 pid=5024 execve guuid=b16de862-1900-0000-3042-a440a9130000 pid=5033 /usr/bin/dash guuid=3591e062-1900-0000-3042-a440a8130000 pid=5032->guuid=b16de862-1900-0000-3042-a440a9130000 pid=5033 clone guuid=edd0ee62-1900-0000-3042-a440aa130000 pid=5034 /usr/bin/sed guuid=3591e062-1900-0000-3042-a440a8130000 pid=5032->guuid=edd0ee62-1900-0000-3042-a440aa130000 pid=5034 execve guuid=8ff53e63-1900-0000-3042-a440ae130000 pid=5038 /usr/bin/dash guuid=61053763-1900-0000-3042-a440ad130000 pid=5037->guuid=8ff53e63-1900-0000-3042-a440ae130000 pid=5038 clone guuid=13f44363-1900-0000-3042-a440af130000 pid=5039 /usr/bin/sed guuid=61053763-1900-0000-3042-a440ad130000 pid=5037->guuid=13f44363-1900-0000-3042-a440af130000 pid=5039 execve guuid=3c1e1d69-1900-0000-3042-a440c1130000 pid=5057 /usr/bin/apt-key write-file guuid=06a0f167-1900-0000-3042-a440bd130000 pid=5053->guuid=3c1e1d69-1900-0000-3042-a440c1130000 pid=5057 execve guuid=3b967769-1900-0000-3042-a440c2130000 pid=5058 /usr/bin/dash guuid=3c1e1d69-1900-0000-3042-a440c1130000 pid=5057->guuid=3b967769-1900-0000-3042-a440c2130000 pid=5058 clone guuid=0da68f69-1900-0000-3042-a440c3130000 pid=5059 /usr/bin/apt-config guuid=3c1e1d69-1900-0000-3042-a440c1130000 pid=5057->guuid=0da68f69-1900-0000-3042-a440c3130000 pid=5059 execve guuid=6fb6f86a-1900-0000-3042-a440cb130000 pid=5067 /usr/bin/apt-config guuid=3c1e1d69-1900-0000-3042-a440c1130000 pid=5057->guuid=6fb6f86a-1900-0000-3042-a440cb130000 pid=5067 execve guuid=24cd7a6c-1900-0000-3042-a440d4130000 pid=5076 /usr/bin/apt-config guuid=3c1e1d69-1900-0000-3042-a440c1130000 pid=5057->guuid=24cd7a6c-1900-0000-3042-a440d4130000 pid=5076 execve guuid=413fb56d-1900-0000-3042-a440db130000 pid=5083 /usr/bin/apt-config guuid=3c1e1d69-1900-0000-3042-a440c1130000 pid=5057->guuid=413fb56d-1900-0000-3042-a440db130000 pid=5083 execve guuid=06e5356f-1900-0000-3042-a440e3130000 pid=5091 /usr/bin/dash guuid=3c1e1d69-1900-0000-3042-a440c1130000 pid=5057->guuid=06e5356f-1900-0000-3042-a440e3130000 pid=5091 clone guuid=ae3d5d6f-1900-0000-3042-a440e4130000 pid=5092 /usr/bin/apt-config guuid=3c1e1d69-1900-0000-3042-a440c1130000 pid=5057->guuid=ae3d5d6f-1900-0000-3042-a440e4130000 pid=5092 execve guuid=61fb9b71-1900-0000-3042-a440ef130000 pid=5103 /usr/bin/mktemp guuid=3c1e1d69-1900-0000-3042-a440c1130000 pid=5057->guuid=61fb9b71-1900-0000-3042-a440ef130000 pid=5103 execve guuid=ecfccb71-1900-0000-3042-a440f1130000 pid=5105 /usr/bin/chmod guuid=3c1e1d69-1900-0000-3042-a440c1130000 pid=5057->guuid=ecfccb71-1900-0000-3042-a440f1130000 pid=5105 execve guuid=0bcff571-1900-0000-3042-a440f3130000 pid=5107 /usr/bin/dash guuid=3c1e1d69-1900-0000-3042-a440c1130000 pid=5057->guuid=0bcff571-1900-0000-3042-a440f3130000 pid=5107 clone guuid=602c0872-1900-0000-3042-a440f6130000 pid=5110 /usr/bin/dash guuid=3c1e1d69-1900-0000-3042-a440c1130000 pid=5057->guuid=602c0872-1900-0000-3042-a440f6130000 pid=5110 clone guuid=42f86072-1900-0000-3042-a440fb130000 pid=5115 /usr/bin/dash guuid=3c1e1d69-1900-0000-3042-a440c1130000 pid=5057->guuid=42f86072-1900-0000-3042-a440fb130000 pid=5115 clone guuid=b7dbbf72-1900-0000-3042-a440ff130000 pid=5119 /usr/bin/dash guuid=3c1e1d69-1900-0000-3042-a440c1130000 pid=5057->guuid=b7dbbf72-1900-0000-3042-a440ff130000 pid=5119 clone guuid=9db2d472-1900-0000-3042-a44000140000 pid=5120 /usr/bin/gpgv guuid=3c1e1d69-1900-0000-3042-a440c1130000 pid=5057->guuid=9db2d472-1900-0000-3042-a44000140000 pid=5120 execve guuid=54762274-1900-0000-3042-a44007140000 pid=5127 /usr/bin/rm delete-file guuid=3c1e1d69-1900-0000-3042-a440c1130000 pid=5057->guuid=54762274-1900-0000-3042-a44007140000 pid=5127 execve guuid=143c906a-1900-0000-3042-a440c8130000 pid=5064 /usr/bin/dpkg guuid=0da68f69-1900-0000-3042-a440c3130000 pid=5059->guuid=143c906a-1900-0000-3042-a440c8130000 pid=5064 execve guuid=7ba7fe6b-1900-0000-3042-a440d2130000 pid=5074 /usr/bin/dpkg guuid=6fb6f86a-1900-0000-3042-a440cb130000 pid=5067->guuid=7ba7fe6b-1900-0000-3042-a440d2130000 pid=5074 execve guuid=1211596d-1900-0000-3042-a440d8130000 pid=5080 /usr/bin/dpkg guuid=24cd7a6c-1900-0000-3042-a440d4130000 pid=5076->guuid=1211596d-1900-0000-3042-a440d8130000 pid=5080 execve guuid=cbf9b26e-1900-0000-3042-a440df130000 pid=5087 /usr/bin/dpkg guuid=413fb56d-1900-0000-3042-a440db130000 pid=5083->guuid=cbf9b26e-1900-0000-3042-a440df130000 pid=5087 execve guuid=358a1171-1900-0000-3042-a440ed130000 pid=5101 /usr/bin/dpkg guuid=ae3d5d6f-1900-0000-3042-a440e4130000 pid=5092->guuid=358a1171-1900-0000-3042-a440ed130000 pid=5101 execve guuid=8d0d1072-1900-0000-3042-a440f7130000 pid=5111 /usr/bin/dash guuid=602c0872-1900-0000-3042-a440f6130000 pid=5110->guuid=8d0d1072-1900-0000-3042-a440f7130000 pid=5111 clone guuid=75c01772-1900-0000-3042-a440f8130000 pid=5112 /usr/bin/sed guuid=602c0872-1900-0000-3042-a440f6130000 pid=5110->guuid=75c01772-1900-0000-3042-a440f8130000 pid=5112 execve guuid=87396772-1900-0000-3042-a440fd130000 pid=5117 /usr/bin/dash guuid=42f86072-1900-0000-3042-a440fb130000 pid=5115->guuid=87396772-1900-0000-3042-a440fd130000 pid=5117 clone guuid=ef236b72-1900-0000-3042-a440fe130000 pid=5118 /usr/bin/sed guuid=42f86072-1900-0000-3042-a440fb130000 pid=5115->guuid=ef236b72-1900-0000-3042-a440fe130000 pid=5118 execve guuid=b40c8a75-1900-0000-3042-a44011140000 pid=5137 /usr/bin/apt-key write-file guuid=2d4fd774-1900-0000-3042-a4400a140000 pid=5130->guuid=b40c8a75-1900-0000-3042-a44011140000 pid=5137 execve guuid=f825c075-1900-0000-3042-a44013140000 pid=5139 /usr/bin/dash guuid=b40c8a75-1900-0000-3042-a44011140000 pid=5137->guuid=f825c075-1900-0000-3042-a44013140000 pid=5139 clone guuid=0059f075-1900-0000-3042-a44014140000 pid=5140 /usr/bin/apt-config guuid=b40c8a75-1900-0000-3042-a44011140000 pid=5137->guuid=0059f075-1900-0000-3042-a44014140000 pid=5140 execve guuid=a27b117b-1900-0000-3042-a4402f140000 pid=5167 /usr/bin/apt-config guuid=b40c8a75-1900-0000-3042-a44011140000 pid=5137->guuid=a27b117b-1900-0000-3042-a4402f140000 pid=5167 execve guuid=f9ab707c-1900-0000-3042-a44035140000 pid=5173 /usr/bin/apt-config guuid=b40c8a75-1900-0000-3042-a44011140000 pid=5137->guuid=f9ab707c-1900-0000-3042-a44035140000 pid=5173 execve guuid=5c5ca57d-1900-0000-3042-a4403c140000 pid=5180 /usr/bin/apt-config guuid=b40c8a75-1900-0000-3042-a44011140000 pid=5137->guuid=5c5ca57d-1900-0000-3042-a4403c140000 pid=5180 execve guuid=baeb7882-1900-0000-3042-a4404b140000 pid=5195 /usr/bin/dash guuid=b40c8a75-1900-0000-3042-a44011140000 pid=5137->guuid=baeb7882-1900-0000-3042-a4404b140000 pid=5195 clone guuid=2428a782-1900-0000-3042-a4404c140000 pid=5196 /usr/bin/apt-config guuid=b40c8a75-1900-0000-3042-a44011140000 pid=5137->guuid=2428a782-1900-0000-3042-a4404c140000 pid=5196 execve guuid=b259da83-1900-0000-3042-a44053140000 pid=5203 /usr/bin/mktemp guuid=b40c8a75-1900-0000-3042-a44011140000 pid=5137->guuid=b259da83-1900-0000-3042-a44053140000 pid=5203 execve guuid=a1851184-1900-0000-3042-a44055140000 pid=5205 /usr/bin/chmod guuid=b40c8a75-1900-0000-3042-a44011140000 pid=5137->guuid=a1851184-1900-0000-3042-a44055140000 pid=5205 execve guuid=1ae93f84-1900-0000-3042-a44056140000 pid=5206 /usr/bin/dash guuid=b40c8a75-1900-0000-3042-a44011140000 pid=5137->guuid=1ae93f84-1900-0000-3042-a44056140000 pid=5206 clone guuid=ea7e5184-1900-0000-3042-a44058140000 pid=5208 /usr/bin/dash guuid=b40c8a75-1900-0000-3042-a44011140000 pid=5137->guuid=ea7e5184-1900-0000-3042-a44058140000 pid=5208 clone guuid=6a8aa884-1900-0000-3042-a4405c140000 pid=5212 /usr/bin/dash guuid=b40c8a75-1900-0000-3042-a44011140000 pid=5137->guuid=6a8aa884-1900-0000-3042-a4405c140000 pid=5212 clone guuid=5bb30385-1900-0000-3042-a44060140000 pid=5216 /usr/bin/dash guuid=b40c8a75-1900-0000-3042-a44011140000 pid=5137->guuid=5bb30385-1900-0000-3042-a44060140000 pid=5216 clone guuid=22921585-1900-0000-3042-a44062140000 pid=5218 /usr/bin/gpgv guuid=b40c8a75-1900-0000-3042-a44011140000 pid=5137->guuid=22921585-1900-0000-3042-a44062140000 pid=5218 execve guuid=63164986-1900-0000-3042-a44068140000 pid=5224 /usr/bin/rm delete-file guuid=b40c8a75-1900-0000-3042-a44011140000 pid=5137->guuid=63164986-1900-0000-3042-a44068140000 pid=5224 execve guuid=94c1c576-1900-0000-3042-a4401c140000 pid=5148 /usr/bin/dpkg guuid=0059f075-1900-0000-3042-a44014140000 pid=5140->guuid=94c1c576-1900-0000-3042-a4401c140000 pid=5148 execve guuid=448b117c-1900-0000-3042-a44033140000 pid=5171 /usr/bin/dpkg guuid=a27b117b-1900-0000-3042-a4402f140000 pid=5167->guuid=448b117c-1900-0000-3042-a44033140000 pid=5171 execve guuid=58bb3d7d-1900-0000-3042-a44039140000 pid=5177 /usr/bin/dpkg guuid=f9ab707c-1900-0000-3042-a44035140000 pid=5173->guuid=58bb3d7d-1900-0000-3042-a44039140000 pid=5177 execve guuid=02467f7e-1900-0000-3042-a44040140000 pid=5184 /usr/bin/dpkg guuid=5c5ca57d-1900-0000-3042-a4403c140000 pid=5180->guuid=02467f7e-1900-0000-3042-a44040140000 pid=5184 execve guuid=51297e83-1900-0000-3042-a44051140000 pid=5201 /usr/bin/dpkg guuid=2428a782-1900-0000-3042-a4404c140000 pid=5196->guuid=51297e83-1900-0000-3042-a44051140000 pid=5201 execve guuid=cffa5984-1900-0000-3042-a44059140000 pid=5209 /usr/bin/dash guuid=ea7e5184-1900-0000-3042-a44058140000 pid=5208->guuid=cffa5984-1900-0000-3042-a44059140000 pid=5209 clone guuid=d6895f84-1900-0000-3042-a4405a140000 pid=5210 /usr/bin/sed guuid=ea7e5184-1900-0000-3042-a44058140000 pid=5208->guuid=d6895f84-1900-0000-3042-a4405a140000 pid=5210 execve guuid=9cebb284-1900-0000-3042-a4405d140000 pid=5213 /usr/bin/dash guuid=6a8aa884-1900-0000-3042-a4405c140000 pid=5212->guuid=9cebb284-1900-0000-3042-a4405d140000 pid=5213 clone guuid=4099b784-1900-0000-3042-a4405e140000 pid=5214 /usr/bin/sed guuid=6a8aa884-1900-0000-3042-a4405c140000 pid=5212->guuid=4099b784-1900-0000-3042-a4405e140000 pid=5214 execve guuid=af168487-1900-0000-3042-a4406d140000 pid=5229 /usr/bin/apt-key write-file guuid=9bb9f886-1900-0000-3042-a4406a140000 pid=5226->guuid=af168487-1900-0000-3042-a4406d140000 pid=5229 execve guuid=531fb887-1900-0000-3042-a4406f140000 pid=5231 /usr/bin/dash guuid=af168487-1900-0000-3042-a4406d140000 pid=5229->guuid=531fb887-1900-0000-3042-a4406f140000 pid=5231 clone guuid=5272ca87-1900-0000-3042-a44070140000 pid=5232 /usr/bin/apt-config guuid=af168487-1900-0000-3042-a4406d140000 pid=5229->guuid=5272ca87-1900-0000-3042-a44070140000 pid=5232 execve guuid=ee7f3d89-1900-0000-3042-a44078140000 pid=5240 /usr/bin/apt-config guuid=af168487-1900-0000-3042-a4406d140000 pid=5229->guuid=ee7f3d89-1900-0000-3042-a44078140000 pid=5240 execve guuid=f565a58a-1900-0000-3042-a4407c140000 pid=5244 /usr/bin/apt-config guuid=af168487-1900-0000-3042-a4406d140000 pid=5229->guuid=f565a58a-1900-0000-3042-a4407c140000 pid=5244 execve guuid=c6d3fa8b-1900-0000-3042-a4407e140000 pid=5246 /usr/bin/apt-config guuid=af168487-1900-0000-3042-a4406d140000 pid=5229->guuid=c6d3fa8b-1900-0000-3042-a4407e140000 pid=5246 execve guuid=230ac590-1900-0000-3042-a44080140000 pid=5248 /usr/bin/dash guuid=af168487-1900-0000-3042-a4406d140000 pid=5229->guuid=230ac590-1900-0000-3042-a44080140000 pid=5248 clone guuid=cfb10391-1900-0000-3042-a44081140000 pid=5249 /usr/bin/apt-config guuid=af168487-1900-0000-3042-a4406d140000 pid=5229->guuid=cfb10391-1900-0000-3042-a44081140000 pid=5249 execve guuid=5464d792-1900-0000-3042-a44083140000 pid=5251 /usr/bin/mktemp guuid=af168487-1900-0000-3042-a4406d140000 pid=5229->guuid=5464d792-1900-0000-3042-a44083140000 pid=5251 execve guuid=9abd1793-1900-0000-3042-a44084140000 pid=5252 /usr/bin/chmod guuid=af168487-1900-0000-3042-a4406d140000 pid=5229->guuid=9abd1793-1900-0000-3042-a44084140000 pid=5252 execve guuid=f2dd3d93-1900-0000-3042-a44085140000 pid=5253 /usr/bin/dash guuid=af168487-1900-0000-3042-a4406d140000 pid=5229->guuid=f2dd3d93-1900-0000-3042-a44085140000 pid=5253 clone guuid=80f14d93-1900-0000-3042-a44086140000 pid=5254 /usr/bin/dash guuid=af168487-1900-0000-3042-a4406d140000 pid=5229->guuid=80f14d93-1900-0000-3042-a44086140000 pid=5254 clone guuid=7a18a293-1900-0000-3042-a44089140000 pid=5257 /usr/bin/dash guuid=af168487-1900-0000-3042-a4406d140000 pid=5229->guuid=7a18a293-1900-0000-3042-a44089140000 pid=5257 clone guuid=a8950b94-1900-0000-3042-a4408c140000 pid=5260 /usr/bin/dash guuid=af168487-1900-0000-3042-a4406d140000 pid=5229->guuid=a8950b94-1900-0000-3042-a4408c140000 pid=5260 clone guuid=e7c51994-1900-0000-3042-a4408d140000 pid=5261 /usr/bin/gpgv guuid=af168487-1900-0000-3042-a4406d140000 pid=5229->guuid=e7c51994-1900-0000-3042-a4408d140000 pid=5261 execve guuid=72f09795-1900-0000-3042-a4408f140000 pid=5263 /usr/bin/rm delete-file guuid=af168487-1900-0000-3042-a4406d140000 pid=5229->guuid=72f09795-1900-0000-3042-a4408f140000 pid=5263 execve guuid=1bd2d688-1900-0000-3042-a44075140000 pid=5237 /usr/bin/dpkg guuid=5272ca87-1900-0000-3042-a44070140000 pid=5232->guuid=1bd2d688-1900-0000-3042-a44075140000 pid=5237 execve guuid=bba6408a-1900-0000-3042-a4407b140000 pid=5243 /usr/bin/dpkg guuid=ee7f3d89-1900-0000-3042-a44078140000 pid=5240->guuid=bba6408a-1900-0000-3042-a4407b140000 pid=5243 execve guuid=54f4848b-1900-0000-3042-a4407d140000 pid=5245 /usr/bin/dpkg guuid=f565a58a-1900-0000-3042-a4407c140000 pid=5244->guuid=54f4848b-1900-0000-3042-a4407d140000 pid=5245 execve guuid=3d0f0c8d-1900-0000-3042-a4407f140000 pid=5247 /usr/bin/dpkg guuid=c6d3fa8b-1900-0000-3042-a4407e140000 pid=5246->guuid=3d0f0c8d-1900-0000-3042-a4407f140000 pid=5247 execve guuid=03045e92-1900-0000-3042-a44082140000 pid=5250 /usr/bin/dpkg guuid=cfb10391-1900-0000-3042-a44081140000 pid=5249->guuid=03045e92-1900-0000-3042-a44082140000 pid=5250 execve guuid=fead5693-1900-0000-3042-a44087140000 pid=5255 /usr/bin/dash guuid=80f14d93-1900-0000-3042-a44086140000 pid=5254->guuid=fead5693-1900-0000-3042-a44087140000 pid=5255 clone guuid=8f065b93-1900-0000-3042-a44088140000 pid=5256 /usr/bin/sed guuid=80f14d93-1900-0000-3042-a44086140000 pid=5254->guuid=8f065b93-1900-0000-3042-a44088140000 pid=5256 execve guuid=b9f1aa93-1900-0000-3042-a4408a140000 pid=5258 /usr/bin/dash guuid=7a18a293-1900-0000-3042-a44089140000 pid=5257->guuid=b9f1aa93-1900-0000-3042-a4408a140000 pid=5258 clone guuid=f1abb293-1900-0000-3042-a4408b140000 pid=5259 /usr/bin/sed guuid=7a18a293-1900-0000-3042-a44089140000 pid=5257->guuid=f1abb293-1900-0000-3042-a4408b140000 pid=5259 execve guuid=635f4d1c-1b00-0000-3042-a440f1140000 pid=5361 /usr/bin/dpkg guuid=2bd90c03-1b00-0000-3042-a440f0140000 pid=5360->guuid=635f4d1c-1b00-0000-3042-a440f1140000 pid=5361 execve guuid=16f0a21d-1b00-0000-3042-a440f3140000 pid=5363->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 164B 75aab096-419b-50ef-be46-7d76b6a90e4c github.com:443 guuid=16f0a21d-1b00-0000-3042-a440f3140000 pid=5363->75aab096-419b-50ef-be46-7d76b6a90e4c send: 783B f8c5e44f-328d-5324-8bbd-da50752b9120 release-assets.githubusercontent.com:0 guuid=16f0a21d-1b00-0000-3042-a440f3140000 pid=5363->f8c5e44f-328d-5324-8bbd-da50752b9120 con f0eebea5-e97d-507c-a771-59cac353877c release-assets.githubusercontent.com:443 guuid=16f0a21d-1b00-0000-3042-a440f3140000 pid=5363->f0eebea5-e97d-507c-a771-59cac353877c send: 1610B 2f50a59f-2358-5b5c-aa0a-c8fc64202aee hosts-to-ignore.ignorelist.com:1443 guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5368->2f50a59f-2358-5b5c-aa0a-c8fc64202aee send: 859B guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5372 /usr/lib/dev/systemdev/dns-filter write-file zombie guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5368->guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5372 clone guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5373 /usr/lib/dev/systemdev/dns-filter dns net send-data guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5368->guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5373 clone guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5374 /usr/lib/dev/systemdev/dns-filter guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5368->guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5374 clone guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5375 /usr/lib/dev/systemdev/dns-filter guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5368->guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5375 clone guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5376 /usr/lib/dev/systemdev/dns-filter guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5368->guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5376 clone guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5381 /usr/lib/dev/systemdev/dns-filter guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5368->guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5381 clone guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5382 /usr/lib/dev/systemdev/dns-filter guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5368->guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5382 clone guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5383 /usr/lib/dev/systemdev/dns-filter guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5368->guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5383 clone guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5384 /usr/lib/dev/systemdev/dns-filter guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5368->guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5384 clone guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5386 /usr/lib/dev/systemdev/dns-filter guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5368->guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5386 clone guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5387 /usr/lib/dev/systemdev/dns-filter guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5368->guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5387 clone guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5388 /usr/lib/dev/systemdev/dns-filter guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5368->guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5388 clone guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5389 /usr/lib/dev/systemdev/dns-filter guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5368->guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5389 clone guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5390 /usr/lib/dev/systemdev/dns-filter guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5368->guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5390 clone guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5391 /usr/lib/dev/systemdev/dns-filter guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5368->guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5391 clone guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5392 /usr/lib/dev/systemdev/dns-filter guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5368->guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5392 clone guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5393 /usr/lib/dev/systemdev/dns-filter guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5368->guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5393 clone guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5394 /usr/lib/dev/systemdev/dns-filter guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5368->guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5394 clone guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5395 /usr/lib/dev/systemdev/dns-filter guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5368->guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5395 clone guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5396 /usr/lib/dev/systemdev/dns-filter guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5368->guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5396 clone guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5397 /usr/lib/dev/systemdev/dns-filter guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5368->guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5397 clone guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5398 /usr/lib/dev/systemdev/dns-filter guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5368->guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5398 clone guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5399 /usr/lib/dev/systemdev/dns-filter guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5368->guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5399 clone guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5400 /usr/lib/dev/systemdev/dns-filter guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5368->guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5400 clone guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5401 /usr/lib/dev/systemdev/dns-filter guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5368->guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5401 clone guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5402 /usr/lib/dev/systemdev/dns-filter guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5368->guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5402 clone guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5403 /usr/lib/dev/systemdev/dns-filter guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5368->guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5403 clone guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5404 /usr/lib/dev/systemdev/dns-filter guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5368->guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5404 clone guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5405 /usr/lib/dev/systemdev/dns-filter guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5368->guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5405 clone guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5406 /usr/lib/dev/systemdev/dns-filter guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5368->guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5406 clone guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5407 /usr/lib/dev/systemdev/dns-filter guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5368->guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5407 clone guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5408 /usr/lib/dev/systemdev/dns-filter guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5368->guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5408 clone guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5409 /usr/lib/dev/systemdev/dns-filter guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5368->guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5409 clone guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5410 /usr/lib/dev/systemdev/dns-filter guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5368->guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5410 clone guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5411 /usr/lib/dev/systemdev/dns-filter guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5368->guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5411 clone guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5412 /usr/lib/dev/systemdev/dns-filter guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5368->guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5412 clone guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5413 /usr/lib/dev/systemdev/dns-filter guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5368->guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5413 clone guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5414 /usr/lib/dev/systemdev/dns-filter guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5368->guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5414 clone guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5415 /usr/lib/dev/systemdev/dns-filter guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5368->guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5415 clone guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5416 /usr/lib/dev/systemdev/dns-filter guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5368->guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5416 clone guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5417 /usr/lib/dev/systemdev/dns-filter guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5368->guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5417 clone guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5418 /usr/lib/dev/systemdev/dns-filter guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5368->guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5418 clone guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5419 /usr/lib/dev/systemdev/dns-filter guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5368->guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5419 clone guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5420 /usr/lib/dev/systemdev/dns-filter guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5368->guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5420 clone guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5421 /usr/lib/dev/systemdev/dns-filter guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5368->guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5421 clone guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5429 /usr/lib/dev/systemdev/dns-filter guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5368->guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5429 clone guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5430 /usr/lib/dev/systemdev/dns-filter guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5368->guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5430 clone guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5431 /usr/lib/dev/systemdev/dns-filter guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5368->guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5431 clone guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5432 /usr/lib/dev/systemdev/dns-filter guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5368->guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5432 clone guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5433 /usr/lib/dev/systemdev/dns-filter guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5368->guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5433 clone guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5434 /usr/lib/dev/systemdev/dns-filter guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5368->guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5434 clone guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5435 /usr/lib/dev/systemdev/dns-filter guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5368->guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5435 clone guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5436 /usr/lib/dev/systemdev/dns-filter guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5368->guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5436 clone guuid=58432f4f-1b00-0000-3042-a440f8140000 pid=5373->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 96B guuid=39835d8e-1c00-0000-3042-a44055150000 pid=5461 /usr/bin/bash guuid=9c70418e-1c00-0000-3042-a44053150000 pid=5459->guuid=39835d8e-1c00-0000-3042-a44055150000 pid=5461 clone
Threat name:
Script-PowerShell.Trojan.Heuristic
Status:
Malicious
First seen:
2025-08-27 13:53:45 UTC
File Type:
Text (Shell)
AV detection:
9 of 24 (37.50%)
Threat level:
  2/5
Result
Malware family:
xmrig_linux
Score:
  10/10
Tags:
family:xmrig family:xmrig_linux antivm defense_evasion discovery execution linux miner persistence privilege_escalation
Behaviour
Enumerates kernel/hardware configuration
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads CPU attributes
Checks hardware identifiers (DMI)
Creates/modifies Cron job
Enumerates running processes
Reads hardware information
File and Directory Permissions Modification
Executes dropped EXE
XMRig Miner payload
Xmrig family
Xmrig_linux family
xmrig
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

CoinMiner

sh e3b35476ea7d4de4b689a952ab25ed5ad1063149a03c0f342cfba9ad26bd614a

(this sample)

4537e474274cf7e7e1920f0ba0ccd7fc219b2698a5af85689649ceb7962953ce

  
Delivery method
Distributed via web download
  
Dropping
MD5 0782916ee8c331309e8fd467529ed93d
  
Dropping
SHA256 4537e474274cf7e7e1920f0ba0ccd7fc219b2698a5af85689649ceb7962953ce

Comments