MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ec41fe791f4a4274442893045af124ebcbf1fbe61147dba8e54439e2f807d81d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



CoinMiner


Vendor detections: 5


Intelligence 5 IOCs YARA 2 File information Comments

SHA256 hash: ec41fe791f4a4274442893045af124ebcbf1fbe61147dba8e54439e2f807d81d
SHA3-384 hash: 7a5f9e2ed77fe89ea4ace60ff1dc05f0d90760bfd6adaa185ac5d450a6a71f655e307a8d7170d0e4a0b72b8a876f4ac7
SHA1 hash: 2d90a11cc03131382c2e6d0d6021dc0f3efb91a3
MD5 hash: 66e7a17500e1e2170098b7ac54c71abe
humanhash: floor-november-alanine-equal
File name:run-CN.sh
Download: download sample
Signature CoinMiner
File size:6'839 bytes
First seen:2025-08-11 17:55:54 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 192:2I848CzDN1eEXOKDk5+rqaAxayH3MeYV4EMNZlu:hvnP9kPA4Eyu
TLSH T1EAE19605F79199B425DCC168044A1D806D4B512B3D092C18FCEDB5AABF28B6C62FDBFB
Magika shell
Reporter abuse_ch
Tags:CoinMiner sh
URLMalware sample (SHA256 hash)SignatureTags
http://162.248.53.119:8000/mon.sh1e891ab1521b27923233e694f60fdbf0e1b840e657d8b1ffdefd8b5ef5e38964 CoinMinerCoinMiner
http://162.248.53.119:8000/yes.tar.gzn/an/aopendir
https://cdn.tempfile.pro/0c748b9e8bc6b5b4/proc9.binn/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
35
Origin country :
DE DE
Vendor Threat Intelligence
Status:
terminated
Behavior Graph:
%3 guuid=795460e4-1700-0000-5635-47e1040c0000 pid=3076 /usr/bin/sudo guuid=f98e0ce7-1700-0000-5635-47e1090c0000 pid=3081 /tmp/sample.bin guuid=795460e4-1700-0000-5635-47e1040c0000 pid=3076->guuid=f98e0ce7-1700-0000-5635-47e1090c0000 pid=3081 execve guuid=f45b86e7-1700-0000-5635-47e10b0c0000 pid=3083 /usr/bin/systemctl guuid=f98e0ce7-1700-0000-5635-47e1090c0000 pid=3081->guuid=f45b86e7-1700-0000-5635-47e10b0c0000 pid=3083 execve guuid=b65bffe9-1700-0000-5635-47e1120c0000 pid=3090 /usr/bin/bash guuid=f98e0ce7-1700-0000-5635-47e1090c0000 pid=3081->guuid=b65bffe9-1700-0000-5635-47e1120c0000 pid=3090 clone guuid=fe6cadf1-1700-0000-5635-47e1250c0000 pid=3109 /usr/bin/bash guuid=f98e0ce7-1700-0000-5635-47e1090c0000 pid=3081->guuid=fe6cadf1-1700-0000-5635-47e1250c0000 pid=3109 clone guuid=c9483cf2-1700-0000-5635-47e12a0c0000 pid=3114 /usr/bin/id guuid=f98e0ce7-1700-0000-5635-47e1090c0000 pid=3081->guuid=c9483cf2-1700-0000-5635-47e12a0c0000 pid=3114 execve guuid=8b7028f3-1700-0000-5635-47e12e0c0000 pid=3118 /usr/bin/apt-get delete-file write-file guuid=f98e0ce7-1700-0000-5635-47e1090c0000 pid=3081->guuid=8b7028f3-1700-0000-5635-47e12e0c0000 pid=3118 execve guuid=42e450b0-1900-0000-5635-47e1800f0000 pid=3968 /usr/bin/apt-get guuid=f98e0ce7-1700-0000-5635-47e1090c0000 pid=3081->guuid=42e450b0-1900-0000-5635-47e1800f0000 pid=3968 execve guuid=bf44b8b2-1900-0000-5635-47e1870f0000 pid=3975 /usr/bin/mkdir guuid=f98e0ce7-1700-0000-5635-47e1090c0000 pid=3081->guuid=bf44b8b2-1900-0000-5635-47e1870f0000 pid=3975 execve guuid=c41f1db3-1900-0000-5635-47e18a0f0000 pid=3978 /usr/bin/wget dns net send-data write-file guuid=f98e0ce7-1700-0000-5635-47e1090c0000 pid=3081->guuid=c41f1db3-1900-0000-5635-47e18a0f0000 pid=3978 execve guuid=c3b7afdb-1900-0000-5635-47e12a100000 pid=4138 /usr/bin/mv guuid=f98e0ce7-1700-0000-5635-47e1090c0000 pid=3081->guuid=c3b7afdb-1900-0000-5635-47e12a100000 pid=4138 execve guuid=dcc914dc-1900-0000-5635-47e12e100000 pid=4142 /usr/bin/rm guuid=f98e0ce7-1700-0000-5635-47e1090c0000 pid=3081->guuid=dcc914dc-1900-0000-5635-47e12e100000 pid=4142 execve guuid=f80e5ddc-1900-0000-5635-47e130100000 pid=4144 /usr/bin/chmod guuid=f98e0ce7-1700-0000-5635-47e1090c0000 pid=3081->guuid=f80e5ddc-1900-0000-5635-47e130100000 pid=4144 execve guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4146 /usr/lib/dev/systemdev/systemd-mont mprotect-exec net send-data guuid=f98e0ce7-1700-0000-5635-47e1090c0000 pid=3081->guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4146 execve guuid=7816dedc-1900-0000-5635-47e134100000 pid=4148 /usr/bin/sleep guuid=f98e0ce7-1700-0000-5635-47e1090c0000 pid=3081->guuid=7816dedc-1900-0000-5635-47e134100000 pid=4148 execve guuid=f187f0fb-1900-0000-5635-47e1c3100000 pid=4291 /usr/bin/ps guuid=f98e0ce7-1700-0000-5635-47e1090c0000 pid=3081->guuid=f187f0fb-1900-0000-5635-47e1c3100000 pid=4291 execve guuid=438d3e08-1a00-0000-5635-47e1ea100000 pid=4330 /usr/bin/sleep guuid=f98e0ce7-1700-0000-5635-47e1090c0000 pid=3081->guuid=438d3e08-1a00-0000-5635-47e1ea100000 pid=4330 execve guuid=9004d714-1b00-0000-5635-47e121140000 pid=5153 /usr/bin/ps guuid=f98e0ce7-1700-0000-5635-47e1090c0000 pid=3081->guuid=9004d714-1b00-0000-5635-47e121140000 pid=5153 execve guuid=81fa7b19-1b00-0000-5635-47e133140000 pid=5171 /usr/bin/rm guuid=f98e0ce7-1700-0000-5635-47e1090c0000 pid=3081->guuid=81fa7b19-1b00-0000-5635-47e133140000 pid=5171 execve guuid=cd2df319-1b00-0000-5635-47e136140000 pid=5174 /usr/bin/rm guuid=f98e0ce7-1700-0000-5635-47e1090c0000 pid=3081->guuid=cd2df319-1b00-0000-5635-47e136140000 pid=5174 execve guuid=008112ea-1700-0000-5635-47e1130c0000 pid=3091 /usr/bin/wget dns net send-data guuid=b65bffe9-1700-0000-5635-47e1120c0000 pid=3090->guuid=008112ea-1700-0000-5635-47e1130c0000 pid=3091 execve 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=008112ea-1700-0000-5635-47e1130c0000 pid=3091->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 72B 0690ccd5-4816-5f11-94dc-7c585f38cdea ipv4.icanhazip.com:0 guuid=008112ea-1700-0000-5635-47e1130c0000 pid=3091->0690ccd5-4816-5f11-94dc-7c585f38cdea con d0ecfe49-aa79-583f-85c6-85ac97075256 ipv4.icanhazip.com:80 guuid=008112ea-1700-0000-5635-47e1130c0000 pid=3091->d0ecfe49-aa79-583f-85c6-85ac97075256 send: 133B guuid=fe8bb9f1-1700-0000-5635-47e1260c0000 pid=3110 /usr/bin/bash guuid=fe6cadf1-1700-0000-5635-47e1250c0000 pid=3109->guuid=fe8bb9f1-1700-0000-5635-47e1260c0000 pid=3110 clone guuid=c722c2f1-1700-0000-5635-47e1270c0000 pid=3111 /usr/bin/sed guuid=fe6cadf1-1700-0000-5635-47e1250c0000 pid=3109->guuid=c722c2f1-1700-0000-5635-47e1270c0000 pid=3111 execve guuid=fc34caf1-1700-0000-5635-47e1280c0000 pid=3112 /usr/bin/cut guuid=fe6cadf1-1700-0000-5635-47e1250c0000 pid=3109->guuid=fc34caf1-1700-0000-5635-47e1280c0000 pid=3112 execve guuid=a2eb82f4-1700-0000-5635-47e1330c0000 pid=3123 /usr/bin/dpkg guuid=8b7028f3-1700-0000-5635-47e12e0c0000 pid=3118->guuid=a2eb82f4-1700-0000-5635-47e1330c0000 pid=3123 execve guuid=778211fb-1700-0000-5635-47e1430c0000 pid=3139 /usr/lib/apt/methods/mirror guuid=8b7028f3-1700-0000-5635-47e12e0c0000 pid=3118->guuid=778211fb-1700-0000-5635-47e1430c0000 pid=3139 execve guuid=6ff786fc-1700-0000-5635-47e1480c0000 pid=3144 /usr/lib/apt/methods/mirror guuid=8b7028f3-1700-0000-5635-47e12e0c0000 pid=3118->guuid=6ff786fc-1700-0000-5635-47e1480c0000 pid=3144 execve guuid=a2a0a5fd-1700-0000-5635-47e14d0c0000 pid=3149 /usr/lib/apt/methods/file guuid=8b7028f3-1700-0000-5635-47e12e0c0000 pid=3118->guuid=a2a0a5fd-1700-0000-5635-47e14d0c0000 pid=3149 execve guuid=8fdea9ff-1700-0000-5635-47e1510c0000 pid=3153 /usr/lib/apt/methods/file delete-file guuid=8b7028f3-1700-0000-5635-47e12e0c0000 pid=3118->guuid=8fdea9ff-1700-0000-5635-47e1510c0000 pid=3153 execve guuid=78a85801-1800-0000-5635-47e1580c0000 pid=3160 /usr/lib/apt/methods/http guuid=8b7028f3-1700-0000-5635-47e12e0c0000 pid=3118->guuid=78a85801-1800-0000-5635-47e1580c0000 pid=3160 execve guuid=1b01af03-1800-0000-5635-47e15c0c0000 pid=3164 /usr/lib/apt/methods/http dns net send-data write-file guuid=8b7028f3-1700-0000-5635-47e12e0c0000 pid=3118->guuid=1b01af03-1800-0000-5635-47e15c0c0000 pid=3164 execve guuid=c33ce81a-1800-0000-5635-47e1790c0000 pid=3193 /usr/lib/apt/methods/gpgv guuid=8b7028f3-1700-0000-5635-47e12e0c0000 pid=3118->guuid=c33ce81a-1800-0000-5635-47e1790c0000 pid=3193 execve guuid=931a4d1d-1800-0000-5635-47e17a0c0000 pid=3194 /usr/lib/apt/methods/gpgv guuid=8b7028f3-1700-0000-5635-47e12e0c0000 pid=3118->guuid=931a4d1d-1800-0000-5635-47e17a0c0000 pid=3194 execve guuid=dff32b4f-1800-0000-5635-47e1d80c0000 pid=3288 /usr/lib/apt/methods/store guuid=8b7028f3-1700-0000-5635-47e12e0c0000 pid=3118->guuid=dff32b4f-1800-0000-5635-47e1d80c0000 pid=3288 execve guuid=109fdc51-1800-0000-5635-47e1dc0c0000 pid=3292 /usr/lib/apt/methods/store write-file guuid=8b7028f3-1700-0000-5635-47e12e0c0000 pid=3118->guuid=109fdc51-1800-0000-5635-47e1dc0c0000 pid=3292 execve guuid=86e40676-1800-0000-5635-47e1160d0000 pid=3350 /usr/lib/apt/methods/rred guuid=8b7028f3-1700-0000-5635-47e12e0c0000 pid=3118->guuid=86e40676-1800-0000-5635-47e1160d0000 pid=3350 execve guuid=a2cb0383-1800-0000-5635-47e12e0d0000 pid=3374 /usr/lib/apt/methods/rred write-file guuid=8b7028f3-1700-0000-5635-47e12e0c0000 pid=3118->guuid=a2cb0383-1800-0000-5635-47e12e0d0000 pid=3374 execve guuid=3bc867b0-1800-0000-5635-47e17c0d0000 pid=3452 /usr/bin/dpkg guuid=8b7028f3-1700-0000-5635-47e12e0c0000 pid=3118->guuid=3bc867b0-1800-0000-5635-47e17c0d0000 pid=3452 execve guuid=71382dac-1900-0000-5635-47e1730f0000 pid=3955 /usr/bin/dpkg guuid=8b7028f3-1700-0000-5635-47e12e0c0000 pid=3118->guuid=71382dac-1900-0000-5635-47e1730f0000 pid=3955 execve guuid=1b01af03-1800-0000-5635-47e15c0c0000 pid=3164->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 122B 869ebe88-8c1e-5fbb-adb0-cfe48d8d7faf debian.map.fastly.net:443 guuid=1b01af03-1800-0000-5635-47e15c0c0000 pid=3164->869ebe88-8c1e-5fbb-adb0-cfe48d8d7faf send: 5667B guuid=9862d91e-1800-0000-5635-47e17b0c0000 pid=3195 /usr/lib/apt/methods/gpgv delete-file write-file guuid=931a4d1d-1800-0000-5635-47e17a0c0000 pid=3194->guuid=9862d91e-1800-0000-5635-47e17b0c0000 pid=3195 clone guuid=bb7b4934-1800-0000-5635-47e1a70c0000 pid=3239 /usr/lib/apt/methods/gpgv delete-file write-file guuid=931a4d1d-1800-0000-5635-47e17a0c0000 pid=3194->guuid=bb7b4934-1800-0000-5635-47e1a70c0000 pid=3239 clone guuid=ccb1594b-1800-0000-5635-47e1d30c0000 pid=3283 /usr/lib/apt/methods/gpgv delete-file write-file guuid=931a4d1d-1800-0000-5635-47e17a0c0000 pid=3194->guuid=ccb1594b-1800-0000-5635-47e1d30c0000 pid=3283 clone guuid=1af34165-1800-0000-5635-47e1050d0000 pid=3333 /usr/lib/apt/methods/gpgv delete-file write-file guuid=931a4d1d-1800-0000-5635-47e17a0c0000 pid=3194->guuid=1af34165-1800-0000-5635-47e1050d0000 pid=3333 clone guuid=0d03d921-1800-0000-5635-47e17c0c0000 pid=3196 /usr/bin/apt-key write-file guuid=9862d91e-1800-0000-5635-47e17b0c0000 pid=3195->guuid=0d03d921-1800-0000-5635-47e17c0c0000 pid=3196 execve guuid=34937722-1800-0000-5635-47e17d0c0000 pid=3197 /usr/bin/dash guuid=0d03d921-1800-0000-5635-47e17c0c0000 pid=3196->guuid=34937722-1800-0000-5635-47e17d0c0000 pid=3197 clone guuid=8ff9ae22-1800-0000-5635-47e17e0c0000 pid=3198 /usr/bin/apt-config guuid=0d03d921-1800-0000-5635-47e17c0c0000 pid=3196->guuid=8ff9ae22-1800-0000-5635-47e17e0c0000 pid=3198 execve guuid=03572e26-1800-0000-5635-47e1800c0000 pid=3200 /usr/bin/apt-config guuid=0d03d921-1800-0000-5635-47e17c0c0000 pid=3196->guuid=03572e26-1800-0000-5635-47e1800c0000 pid=3200 execve guuid=b20eb427-1800-0000-5635-47e1820c0000 pid=3202 /usr/bin/apt-config guuid=0d03d921-1800-0000-5635-47e17c0c0000 pid=3196->guuid=b20eb427-1800-0000-5635-47e1820c0000 pid=3202 execve guuid=a70e9d29-1800-0000-5635-47e1850c0000 pid=3205 /usr/bin/apt-config guuid=0d03d921-1800-0000-5635-47e17c0c0000 pid=3196->guuid=a70e9d29-1800-0000-5635-47e1850c0000 pid=3205 execve guuid=094cb42b-1800-0000-5635-47e18d0c0000 pid=3213 /usr/bin/dash guuid=0d03d921-1800-0000-5635-47e17c0c0000 pid=3196->guuid=094cb42b-1800-0000-5635-47e18d0c0000 pid=3213 clone guuid=2c01d92b-1800-0000-5635-47e18f0c0000 pid=3215 /usr/bin/apt-config guuid=0d03d921-1800-0000-5635-47e17c0c0000 pid=3196->guuid=2c01d92b-1800-0000-5635-47e18f0c0000 pid=3215 execve guuid=198aff2d-1800-0000-5635-47e1930c0000 pid=3219 /usr/bin/mktemp guuid=0d03d921-1800-0000-5635-47e17c0c0000 pid=3196->guuid=198aff2d-1800-0000-5635-47e1930c0000 pid=3219 execve guuid=c5c35a2e-1800-0000-5635-47e1940c0000 pid=3220 /usr/bin/chmod guuid=0d03d921-1800-0000-5635-47e17c0c0000 pid=3196->guuid=c5c35a2e-1800-0000-5635-47e1940c0000 pid=3220 execve guuid=67e0972e-1800-0000-5635-47e1960c0000 pid=3222 /usr/bin/dash guuid=0d03d921-1800-0000-5635-47e17c0c0000 pid=3196->guuid=67e0972e-1800-0000-5635-47e1960c0000 pid=3222 clone guuid=2daae32e-1800-0000-5635-47e1980c0000 pid=3224 /usr/bin/dash guuid=0d03d921-1800-0000-5635-47e17c0c0000 pid=3196->guuid=2daae32e-1800-0000-5635-47e1980c0000 pid=3224 clone guuid=d0b16c2f-1800-0000-5635-47e19d0c0000 pid=3229 /usr/bin/dash guuid=0d03d921-1800-0000-5635-47e17c0c0000 pid=3196->guuid=d0b16c2f-1800-0000-5635-47e19d0c0000 pid=3229 clone guuid=ba0e5e30-1800-0000-5635-47e1a10c0000 pid=3233 /usr/bin/dash guuid=0d03d921-1800-0000-5635-47e17c0c0000 pid=3196->guuid=ba0e5e30-1800-0000-5635-47e1a10c0000 pid=3233 clone guuid=f5e77730-1800-0000-5635-47e1a20c0000 pid=3234 /usr/bin/gpgv guuid=0d03d921-1800-0000-5635-47e17c0c0000 pid=3196->guuid=f5e77730-1800-0000-5635-47e1a20c0000 pid=3234 execve guuid=0fea6432-1800-0000-5635-47e1a60c0000 pid=3238 /usr/bin/rm delete-file guuid=0d03d921-1800-0000-5635-47e17c0c0000 pid=3196->guuid=0fea6432-1800-0000-5635-47e1a60c0000 pid=3238 execve guuid=3d387525-1800-0000-5635-47e17f0c0000 pid=3199 /usr/bin/dpkg guuid=8ff9ae22-1800-0000-5635-47e17e0c0000 pid=3198->guuid=3d387525-1800-0000-5635-47e17f0c0000 pid=3199 execve guuid=c7462527-1800-0000-5635-47e1810c0000 pid=3201 /usr/bin/dpkg guuid=03572e26-1800-0000-5635-47e1800c0000 pid=3200->guuid=c7462527-1800-0000-5635-47e1810c0000 pid=3201 execve guuid=cfead328-1800-0000-5635-47e1840c0000 pid=3204 /usr/bin/dpkg guuid=b20eb427-1800-0000-5635-47e1820c0000 pid=3202->guuid=cfead328-1800-0000-5635-47e1840c0000 pid=3204 execve guuid=1c87c82a-1800-0000-5635-47e1890c0000 pid=3209 /usr/bin/dpkg guuid=a70e9d29-1800-0000-5635-47e1850c0000 pid=3205->guuid=1c87c82a-1800-0000-5635-47e1890c0000 pid=3209 execve guuid=e74a172d-1800-0000-5635-47e1920c0000 pid=3218 /usr/bin/dpkg guuid=2c01d92b-1800-0000-5635-47e18f0c0000 pid=3215->guuid=e74a172d-1800-0000-5635-47e1920c0000 pid=3218 execve guuid=35f9f02e-1800-0000-5635-47e1990c0000 pid=3225 /usr/bin/dash guuid=2daae32e-1800-0000-5635-47e1980c0000 pid=3224->guuid=35f9f02e-1800-0000-5635-47e1990c0000 pid=3225 clone guuid=3ddbf62e-1800-0000-5635-47e19a0c0000 pid=3226 /usr/bin/sed guuid=2daae32e-1800-0000-5635-47e1980c0000 pid=3224->guuid=3ddbf62e-1800-0000-5635-47e19a0c0000 pid=3226 execve guuid=b84d792f-1800-0000-5635-47e19e0c0000 pid=3230 /usr/bin/dash guuid=d0b16c2f-1800-0000-5635-47e19d0c0000 pid=3229->guuid=b84d792f-1800-0000-5635-47e19e0c0000 pid=3230 clone guuid=f3f9872f-1800-0000-5635-47e19f0c0000 pid=3231 /usr/bin/sed guuid=d0b16c2f-1800-0000-5635-47e19d0c0000 pid=3229->guuid=f3f9872f-1800-0000-5635-47e19f0c0000 pid=3231 execve guuid=901e4835-1800-0000-5635-47e1a90c0000 pid=3241 /usr/bin/apt-key write-file guuid=bb7b4934-1800-0000-5635-47e1a70c0000 pid=3239->guuid=901e4835-1800-0000-5635-47e1a90c0000 pid=3241 execve guuid=58948e35-1800-0000-5635-47e1aa0c0000 pid=3242 /usr/bin/dash guuid=901e4835-1800-0000-5635-47e1a90c0000 pid=3241->guuid=58948e35-1800-0000-5635-47e1aa0c0000 pid=3242 clone guuid=53dba535-1800-0000-5635-47e1ab0c0000 pid=3243 /usr/bin/apt-config guuid=901e4835-1800-0000-5635-47e1a90c0000 pid=3241->guuid=53dba535-1800-0000-5635-47e1ab0c0000 pid=3243 execve guuid=29f1963c-1800-0000-5635-47e1b70c0000 pid=3255 /usr/bin/apt-config guuid=901e4835-1800-0000-5635-47e1a90c0000 pid=3241->guuid=29f1963c-1800-0000-5635-47e1b70c0000 pid=3255 execve guuid=5cf1a83e-1800-0000-5635-47e1be0c0000 pid=3262 /usr/bin/apt-config guuid=901e4835-1800-0000-5635-47e1a90c0000 pid=3241->guuid=5cf1a83e-1800-0000-5635-47e1be0c0000 pid=3262 execve guuid=cb6dfc40-1800-0000-5635-47e1c20c0000 pid=3266 /usr/bin/apt-config guuid=901e4835-1800-0000-5635-47e1a90c0000 pid=3241->guuid=cb6dfc40-1800-0000-5635-47e1c20c0000 pid=3266 execve guuid=e7ff3a43-1800-0000-5635-47e1c40c0000 pid=3268 /usr/bin/dash guuid=901e4835-1800-0000-5635-47e1a90c0000 pid=3241->guuid=e7ff3a43-1800-0000-5635-47e1c40c0000 pid=3268 clone guuid=e6d87743-1800-0000-5635-47e1c50c0000 pid=3269 /usr/bin/apt-config guuid=901e4835-1800-0000-5635-47e1a90c0000 pid=3241->guuid=e6d87743-1800-0000-5635-47e1c50c0000 pid=3269 execve guuid=6d418c45-1800-0000-5635-47e1c70c0000 pid=3271 /usr/bin/mktemp guuid=901e4835-1800-0000-5635-47e1a90c0000 pid=3241->guuid=6d418c45-1800-0000-5635-47e1c70c0000 pid=3271 execve guuid=3156db45-1800-0000-5635-47e1c80c0000 pid=3272 /usr/bin/chmod guuid=901e4835-1800-0000-5635-47e1a90c0000 pid=3241->guuid=3156db45-1800-0000-5635-47e1c80c0000 pid=3272 execve guuid=454f2246-1800-0000-5635-47e1c90c0000 pid=3273 /usr/bin/dash guuid=901e4835-1800-0000-5635-47e1a90c0000 pid=3241->guuid=454f2246-1800-0000-5635-47e1c90c0000 pid=3273 clone guuid=a1064446-1800-0000-5635-47e1ca0c0000 pid=3274 /usr/bin/dash guuid=901e4835-1800-0000-5635-47e1a90c0000 pid=3241->guuid=a1064446-1800-0000-5635-47e1ca0c0000 pid=3274 clone guuid=a9fbe446-1800-0000-5635-47e1cd0c0000 pid=3277 /usr/bin/dash guuid=901e4835-1800-0000-5635-47e1a90c0000 pid=3241->guuid=a9fbe446-1800-0000-5635-47e1cd0c0000 pid=3277 clone guuid=81957847-1800-0000-5635-47e1d00c0000 pid=3280 /usr/bin/dash guuid=901e4835-1800-0000-5635-47e1a90c0000 pid=3241->guuid=81957847-1800-0000-5635-47e1d00c0000 pid=3280 clone guuid=05578f47-1800-0000-5635-47e1d10c0000 pid=3281 /usr/bin/gpgv guuid=901e4835-1800-0000-5635-47e1a90c0000 pid=3241->guuid=05578f47-1800-0000-5635-47e1d10c0000 pid=3281 execve guuid=9393cd49-1800-0000-5635-47e1d20c0000 pid=3282 /usr/bin/rm delete-file guuid=901e4835-1800-0000-5635-47e1a90c0000 pid=3241->guuid=9393cd49-1800-0000-5635-47e1d20c0000 pid=3282 execve guuid=e4d20c37-1800-0000-5635-47e1af0c0000 pid=3247 /usr/bin/dpkg guuid=53dba535-1800-0000-5635-47e1ab0c0000 pid=3243->guuid=e4d20c37-1800-0000-5635-47e1af0c0000 pid=3247 execve guuid=bdb90d3e-1800-0000-5635-47e1bc0c0000 pid=3260 /usr/bin/dpkg guuid=29f1963c-1800-0000-5635-47e1b70c0000 pid=3255->guuid=bdb90d3e-1800-0000-5635-47e1bc0c0000 pid=3260 execve guuid=e9bb2d40-1800-0000-5635-47e1c10c0000 pid=3265 /usr/bin/dpkg guuid=5cf1a83e-1800-0000-5635-47e1be0c0000 pid=3262->guuid=e9bb2d40-1800-0000-5635-47e1c10c0000 pid=3265 execve guuid=cb9e7e42-1800-0000-5635-47e1c30c0000 pid=3267 /usr/bin/dpkg guuid=cb6dfc40-1800-0000-5635-47e1c20c0000 pid=3266->guuid=cb9e7e42-1800-0000-5635-47e1c30c0000 pid=3267 execve guuid=2124ea44-1800-0000-5635-47e1c60c0000 pid=3270 /usr/bin/dpkg guuid=e6d87743-1800-0000-5635-47e1c50c0000 pid=3269->guuid=2124ea44-1800-0000-5635-47e1c60c0000 pid=3270 execve guuid=513c5446-1800-0000-5635-47e1cb0c0000 pid=3275 /usr/bin/dash guuid=a1064446-1800-0000-5635-47e1ca0c0000 pid=3274->guuid=513c5446-1800-0000-5635-47e1cb0c0000 pid=3275 clone guuid=c71f6046-1800-0000-5635-47e1cc0c0000 pid=3276 /usr/bin/sed guuid=a1064446-1800-0000-5635-47e1ca0c0000 pid=3274->guuid=c71f6046-1800-0000-5635-47e1cc0c0000 pid=3276 execve guuid=eec9ef46-1800-0000-5635-47e1ce0c0000 pid=3278 /usr/bin/dash guuid=a9fbe446-1800-0000-5635-47e1cd0c0000 pid=3277->guuid=eec9ef46-1800-0000-5635-47e1ce0c0000 pid=3278 clone guuid=ccb6f646-1800-0000-5635-47e1cf0c0000 pid=3279 /usr/bin/sed guuid=a9fbe446-1800-0000-5635-47e1cd0c0000 pid=3277->guuid=ccb6f646-1800-0000-5635-47e1cf0c0000 pid=3279 execve guuid=60ef884c-1800-0000-5635-47e1d40c0000 pid=3284 /usr/bin/apt-key write-file guuid=ccb1594b-1800-0000-5635-47e1d30c0000 pid=3283->guuid=60ef884c-1800-0000-5635-47e1d40c0000 pid=3284 execve guuid=1c44124d-1800-0000-5635-47e1d50c0000 pid=3285 /usr/bin/dash guuid=60ef884c-1800-0000-5635-47e1d40c0000 pid=3284->guuid=1c44124d-1800-0000-5635-47e1d50c0000 pid=3285 clone guuid=c4ab3e4d-1800-0000-5635-47e1d60c0000 pid=3286 /usr/bin/apt-config guuid=60ef884c-1800-0000-5635-47e1d40c0000 pid=3284->guuid=c4ab3e4d-1800-0000-5635-47e1d60c0000 pid=3286 execve guuid=dd820750-1800-0000-5635-47e1d90c0000 pid=3289 /usr/bin/apt-config guuid=60ef884c-1800-0000-5635-47e1d40c0000 pid=3284->guuid=dd820750-1800-0000-5635-47e1d90c0000 pid=3289 execve guuid=e3863f58-1800-0000-5635-47e1e50c0000 pid=3301 /usr/bin/apt-config guuid=60ef884c-1800-0000-5635-47e1d40c0000 pid=3284->guuid=e3863f58-1800-0000-5635-47e1e50c0000 pid=3301 execve guuid=52e7125b-1800-0000-5635-47e1ec0c0000 pid=3308 /usr/bin/apt-config guuid=60ef884c-1800-0000-5635-47e1d40c0000 pid=3284->guuid=52e7125b-1800-0000-5635-47e1ec0c0000 pid=3308 execve guuid=232b9e5d-1800-0000-5635-47e1f00c0000 pid=3312 /usr/bin/dash guuid=60ef884c-1800-0000-5635-47e1d40c0000 pid=3284->guuid=232b9e5d-1800-0000-5635-47e1f00c0000 pid=3312 clone guuid=4b93c35d-1800-0000-5635-47e1f10c0000 pid=3313 /usr/bin/apt-config guuid=60ef884c-1800-0000-5635-47e1d40c0000 pid=3284->guuid=4b93c35d-1800-0000-5635-47e1f10c0000 pid=3313 execve guuid=12744f5f-1800-0000-5635-47e1f80c0000 pid=3320 /usr/bin/mktemp guuid=60ef884c-1800-0000-5635-47e1d40c0000 pid=3284->guuid=12744f5f-1800-0000-5635-47e1f80c0000 pid=3320 execve guuid=9ae2985f-1800-0000-5635-47e1f90c0000 pid=3321 /usr/bin/chmod guuid=60ef884c-1800-0000-5635-47e1d40c0000 pid=3284->guuid=9ae2985f-1800-0000-5635-47e1f90c0000 pid=3321 execve guuid=9418d95f-1800-0000-5635-47e1fa0c0000 pid=3322 /usr/bin/dash guuid=60ef884c-1800-0000-5635-47e1d40c0000 pid=3284->guuid=9418d95f-1800-0000-5635-47e1fa0c0000 pid=3322 clone guuid=c9cef15f-1800-0000-5635-47e1fb0c0000 pid=3323 /usr/bin/dash guuid=60ef884c-1800-0000-5635-47e1d40c0000 pid=3284->guuid=c9cef15f-1800-0000-5635-47e1fb0c0000 pid=3323 clone guuid=07a1a060-1800-0000-5635-47e1fe0c0000 pid=3326 /usr/bin/dash guuid=60ef884c-1800-0000-5635-47e1d40c0000 pid=3284->guuid=07a1a060-1800-0000-5635-47e1fe0c0000 pid=3326 clone guuid=1fb98461-1800-0000-5635-47e1010d0000 pid=3329 /usr/bin/dash guuid=60ef884c-1800-0000-5635-47e1d40c0000 pid=3284->guuid=1fb98461-1800-0000-5635-47e1010d0000 pid=3329 clone guuid=c9dfa461-1800-0000-5635-47e1020d0000 pid=3330 /usr/bin/gpgv guuid=60ef884c-1800-0000-5635-47e1d40c0000 pid=3284->guuid=c9dfa461-1800-0000-5635-47e1020d0000 pid=3330 execve guuid=7fd59263-1800-0000-5635-47e1030d0000 pid=3331 /usr/bin/rm delete-file guuid=60ef884c-1800-0000-5635-47e1d40c0000 pid=3284->guuid=7fd59263-1800-0000-5635-47e1030d0000 pid=3331 execve guuid=9086e34e-1800-0000-5635-47e1d70c0000 pid=3287 /usr/bin/dpkg guuid=c4ab3e4d-1800-0000-5635-47e1d60c0000 pid=3286->guuid=9086e34e-1800-0000-5635-47e1d70c0000 pid=3287 execve guuid=f5aa5f51-1800-0000-5635-47e1db0c0000 pid=3291 /usr/bin/dpkg guuid=dd820750-1800-0000-5635-47e1d90c0000 pid=3289->guuid=f5aa5f51-1800-0000-5635-47e1db0c0000 pid=3291 execve guuid=f167235a-1800-0000-5635-47e1ea0c0000 pid=3306 /usr/bin/dpkg guuid=e3863f58-1800-0000-5635-47e1e50c0000 pid=3301->guuid=f167235a-1800-0000-5635-47e1ea0c0000 pid=3306 execve guuid=7975185d-1800-0000-5635-47e1ee0c0000 pid=3310 /usr/bin/dpkg guuid=52e7125b-1800-0000-5635-47e1ec0c0000 pid=3308->guuid=7975185d-1800-0000-5635-47e1ee0c0000 pid=3310 execve guuid=1364cd5e-1800-0000-5635-47e1f50c0000 pid=3317 /usr/bin/dpkg guuid=4b93c35d-1800-0000-5635-47e1f10c0000 pid=3313->guuid=1364cd5e-1800-0000-5635-47e1f50c0000 pid=3317 execve guuid=ff130060-1800-0000-5635-47e1fc0c0000 pid=3324 /usr/bin/dash guuid=c9cef15f-1800-0000-5635-47e1fb0c0000 pid=3323->guuid=ff130060-1800-0000-5635-47e1fc0c0000 pid=3324 clone guuid=0dfb0b60-1800-0000-5635-47e1fd0c0000 pid=3325 /usr/bin/sed guuid=c9cef15f-1800-0000-5635-47e1fb0c0000 pid=3323->guuid=0dfb0b60-1800-0000-5635-47e1fd0c0000 pid=3325 execve guuid=4dd4ab60-1800-0000-5635-47e1ff0c0000 pid=3327 /usr/bin/dash guuid=07a1a060-1800-0000-5635-47e1fe0c0000 pid=3326->guuid=4dd4ab60-1800-0000-5635-47e1ff0c0000 pid=3327 clone guuid=b29ab360-1800-0000-5635-47e1000d0000 pid=3328 /usr/bin/sed guuid=07a1a060-1800-0000-5635-47e1fe0c0000 pid=3326->guuid=b29ab360-1800-0000-5635-47e1000d0000 pid=3328 execve guuid=1c31d765-1800-0000-5635-47e1070d0000 pid=3335 /usr/bin/apt-key write-file guuid=1af34165-1800-0000-5635-47e1050d0000 pid=3333->guuid=1c31d765-1800-0000-5635-47e1070d0000 pid=3335 execve guuid=da650966-1800-0000-5635-47e1090d0000 pid=3337 /usr/bin/dash guuid=1c31d765-1800-0000-5635-47e1070d0000 pid=3335->guuid=da650966-1800-0000-5635-47e1090d0000 pid=3337 clone guuid=b8bc2766-1800-0000-5635-47e10a0d0000 pid=3338 /usr/bin/apt-config guuid=1c31d765-1800-0000-5635-47e1070d0000 pid=3335->guuid=b8bc2766-1800-0000-5635-47e10a0d0000 pid=3338 execve guuid=ff04016d-1800-0000-5635-47e1100d0000 pid=3344 /usr/bin/apt-config guuid=1c31d765-1800-0000-5635-47e1070d0000 pid=3335->guuid=ff04016d-1800-0000-5635-47e1100d0000 pid=3344 execve guuid=9f1c0171-1800-0000-5635-47e1120d0000 pid=3346 /usr/bin/apt-config guuid=1c31d765-1800-0000-5635-47e1070d0000 pid=3335->guuid=9f1c0171-1800-0000-5635-47e1120d0000 pid=3346 execve guuid=4f8bcd74-1800-0000-5635-47e1140d0000 pid=3348 /usr/bin/apt-config guuid=1c31d765-1800-0000-5635-47e1070d0000 pid=3335->guuid=4f8bcd74-1800-0000-5635-47e1140d0000 pid=3348 execve guuid=00f93276-1800-0000-5635-47e1170d0000 pid=3351 /usr/bin/dash guuid=1c31d765-1800-0000-5635-47e1070d0000 pid=3335->guuid=00f93276-1800-0000-5635-47e1170d0000 pid=3351 clone guuid=d6c95676-1800-0000-5635-47e1180d0000 pid=3352 /usr/bin/apt-config guuid=1c31d765-1800-0000-5635-47e1070d0000 pid=3335->guuid=d6c95676-1800-0000-5635-47e1180d0000 pid=3352 execve guuid=d022e477-1800-0000-5635-47e11a0d0000 pid=3354 /usr/bin/mktemp guuid=1c31d765-1800-0000-5635-47e1070d0000 pid=3335->guuid=d022e477-1800-0000-5635-47e11a0d0000 pid=3354 execve guuid=2af52378-1800-0000-5635-47e11b0d0000 pid=3355 /usr/bin/chmod guuid=1c31d765-1800-0000-5635-47e1070d0000 pid=3335->guuid=2af52378-1800-0000-5635-47e11b0d0000 pid=3355 execve guuid=5d7b5f78-1800-0000-5635-47e11c0d0000 pid=3356 /usr/bin/dash guuid=1c31d765-1800-0000-5635-47e1070d0000 pid=3335->guuid=5d7b5f78-1800-0000-5635-47e11c0d0000 pid=3356 clone guuid=a1847c78-1800-0000-5635-47e11d0d0000 pid=3357 /usr/bin/dash guuid=1c31d765-1800-0000-5635-47e1070d0000 pid=3335->guuid=a1847c78-1800-0000-5635-47e11d0d0000 pid=3357 clone guuid=7733ec78-1800-0000-5635-47e1200d0000 pid=3360 /usr/bin/dash guuid=1c31d765-1800-0000-5635-47e1070d0000 pid=3335->guuid=7733ec78-1800-0000-5635-47e1200d0000 pid=3360 clone guuid=928e6a79-1800-0000-5635-47e1230d0000 pid=3363 /usr/bin/dash guuid=1c31d765-1800-0000-5635-47e1070d0000 pid=3335->guuid=928e6a79-1800-0000-5635-47e1230d0000 pid=3363 clone guuid=460c7d79-1800-0000-5635-47e1240d0000 pid=3364 /usr/bin/gpgv guuid=1c31d765-1800-0000-5635-47e1070d0000 pid=3335->guuid=460c7d79-1800-0000-5635-47e1240d0000 pid=3364 execve guuid=434a1e7b-1800-0000-5635-47e1250d0000 pid=3365 /usr/bin/rm delete-file guuid=1c31d765-1800-0000-5635-47e1070d0000 pid=3335->guuid=434a1e7b-1800-0000-5635-47e1250d0000 pid=3365 execve guuid=00db5b67-1800-0000-5635-47e10e0d0000 pid=3342 /usr/bin/dpkg guuid=b8bc2766-1800-0000-5635-47e10a0d0000 pid=3338->guuid=00db5b67-1800-0000-5635-47e10e0d0000 pid=3342 execve guuid=3edb1870-1800-0000-5635-47e1110d0000 pid=3345 /usr/bin/dpkg guuid=ff04016d-1800-0000-5635-47e1100d0000 pid=3344->guuid=3edb1870-1800-0000-5635-47e1110d0000 pid=3345 execve guuid=103d3974-1800-0000-5635-47e1130d0000 pid=3347 /usr/bin/dpkg guuid=9f1c0171-1800-0000-5635-47e1120d0000 pid=3346->guuid=103d3974-1800-0000-5635-47e1130d0000 pid=3347 execve guuid=d936aa75-1800-0000-5635-47e1150d0000 pid=3349 /usr/bin/dpkg guuid=4f8bcd74-1800-0000-5635-47e1140d0000 pid=3348->guuid=d936aa75-1800-0000-5635-47e1150d0000 pid=3349 execve guuid=08596577-1800-0000-5635-47e1190d0000 pid=3353 /usr/bin/dpkg guuid=d6c95676-1800-0000-5635-47e1180d0000 pid=3352->guuid=08596577-1800-0000-5635-47e1190d0000 pid=3353 execve guuid=43518778-1800-0000-5635-47e11e0d0000 pid=3358 /usr/bin/dash guuid=a1847c78-1800-0000-5635-47e11d0d0000 pid=3357->guuid=43518778-1800-0000-5635-47e11e0d0000 pid=3358 clone guuid=ce2e8e78-1800-0000-5635-47e11f0d0000 pid=3359 /usr/bin/sed guuid=a1847c78-1800-0000-5635-47e11d0d0000 pid=3357->guuid=ce2e8e78-1800-0000-5635-47e11f0d0000 pid=3359 execve guuid=2afefc78-1800-0000-5635-47e1210d0000 pid=3361 /usr/bin/dash guuid=7733ec78-1800-0000-5635-47e1200d0000 pid=3360->guuid=2afefc78-1800-0000-5635-47e1210d0000 pid=3361 clone guuid=b4bb0279-1800-0000-5635-47e1220d0000 pid=3362 /usr/bin/sed guuid=7733ec78-1800-0000-5635-47e1200d0000 pid=3360->guuid=b4bb0279-1800-0000-5635-47e1220d0000 pid=3362 execve guuid=ba49e3b1-1900-0000-5635-47e1840f0000 pid=3972 /usr/bin/dpkg guuid=42e450b0-1900-0000-5635-47e1800f0000 pid=3968->guuid=ba49e3b1-1900-0000-5635-47e1840f0000 pid=3972 execve guuid=c41f1db3-1900-0000-5635-47e18a0f0000 pid=3978->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 68B b4e27614-81b3-59ca-8787-716d0d292a6d cdn.tempfile.pro:0 guuid=c41f1db3-1900-0000-5635-47e18a0f0000 pid=3978->b4e27614-81b3-59ca-8787-716d0d292a6d con e0beffae-5a5b-5021-9f66-3b7bd68d1c4e cdn.tempfile.pro:443 guuid=c41f1db3-1900-0000-5635-47e18a0f0000 pid=3978->e0beffae-5a5b-5021-9f66-3b7bd68d1c4e send: 776B 1bb9f4ee-b940-5756-8449-f219f2617353 162.248.53.119:9443 guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4146->1bb9f4ee-b940-5756-8449-f219f2617353 send: 960B guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4160 /usr/lib/dev/systemdev/systemd-mont write-file zombie guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4146->guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4160 clone guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4163 /usr/lib/dev/systemdev/systemd-mont guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4146->guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4163 clone guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4164 /usr/lib/dev/systemdev/systemd-mont guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4146->guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4164 clone guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4165 /usr/lib/dev/systemdev/systemd-mont guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4146->guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4165 clone guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4166 /usr/lib/dev/systemdev/systemd-mont guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4146->guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4166 clone guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4264 /usr/lib/dev/systemdev/systemd-mont guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4146->guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4264 clone guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4266 /usr/lib/dev/systemdev/systemd-mont guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4146->guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4266 clone guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4268 /usr/lib/dev/systemdev/systemd-mont guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4146->guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4268 clone guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4269 /usr/lib/dev/systemdev/systemd-mont guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4146->guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4269 clone guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4296 /usr/lib/dev/systemdev/systemd-mont guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4146->guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4296 clone guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4297 /usr/lib/dev/systemdev/systemd-mont guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4146->guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4297 clone guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4298 /usr/lib/dev/systemdev/systemd-mont guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4146->guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4298 clone guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4299 /usr/lib/dev/systemdev/systemd-mont guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4146->guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4299 clone guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4312 /usr/lib/dev/systemdev/systemd-mont guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4146->guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4312 clone guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4313 /usr/lib/dev/systemdev/systemd-mont guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4146->guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4313 clone guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4314 /usr/lib/dev/systemdev/systemd-mont guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4146->guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4314 clone guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4315 /usr/lib/dev/systemdev/systemd-mont guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4146->guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4315 clone guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4331 /usr/lib/dev/systemdev/systemd-mont guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4146->guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4331 clone guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4332 /usr/lib/dev/systemdev/systemd-mont guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4146->guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4332 clone guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4333 /usr/lib/dev/systemdev/systemd-mont guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4146->guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4333 clone guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4334 /usr/lib/dev/systemdev/systemd-mont guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4146->guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4334 clone guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4357 /usr/lib/dev/systemdev/systemd-mont guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4146->guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4357 clone guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4358 /usr/lib/dev/systemdev/systemd-mont guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4146->guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4358 clone guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4359 /usr/lib/dev/systemdev/systemd-mont guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4146->guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4359 clone guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4360 /usr/lib/dev/systemdev/systemd-mont guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4146->guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4360 clone guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4384 /usr/lib/dev/systemdev/systemd-mont guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4146->guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4384 clone guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4385 /usr/lib/dev/systemdev/systemd-mont guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4146->guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4385 clone guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4386 /usr/lib/dev/systemdev/systemd-mont guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4146->guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4386 clone guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4387 /usr/lib/dev/systemdev/systemd-mont guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4146->guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4387 clone guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4424 /usr/lib/dev/systemdev/systemd-mont guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4146->guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4424 clone guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4425 /usr/lib/dev/systemdev/systemd-mont guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4146->guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4425 clone guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4427 /usr/lib/dev/systemdev/systemd-mont guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4146->guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4427 clone guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4428 /usr/lib/dev/systemdev/systemd-mont guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4146->guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4428 clone guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4457 /usr/lib/dev/systemdev/systemd-mont guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4146->guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4457 clone guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4458 /usr/lib/dev/systemdev/systemd-mont guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4146->guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4458 clone guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4459 /usr/lib/dev/systemdev/systemd-mont guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4146->guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4459 clone guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4460 /usr/lib/dev/systemdev/systemd-mont guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4146->guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4460 clone guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4490 /usr/lib/dev/systemdev/systemd-mont guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4146->guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4490 clone guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4491 /usr/lib/dev/systemdev/systemd-mont guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4146->guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4491 clone guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4492 /usr/lib/dev/systemdev/systemd-mont guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4146->guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4492 clone guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4493 /usr/lib/dev/systemdev/systemd-mont guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4146->guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4493 clone guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4514 /usr/lib/dev/systemdev/systemd-mont guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4146->guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4514 clone guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4515 /usr/lib/dev/systemdev/systemd-mont guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4146->guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4515 clone guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4516 /usr/lib/dev/systemdev/systemd-mont guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4146->guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4516 clone guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4517 /usr/lib/dev/systemdev/systemd-mont guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4146->guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4517 clone guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4547 /usr/lib/dev/systemdev/systemd-mont guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4146->guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4547 clone guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4548 /usr/lib/dev/systemdev/systemd-mont guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4146->guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4548 clone guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4549 /usr/lib/dev/systemdev/systemd-mont guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4146->guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4549 clone guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4550 /usr/lib/dev/systemdev/systemd-mont guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4146->guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4550 clone guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4577 /usr/lib/dev/systemdev/systemd-mont guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4146->guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4577 clone guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4578 /usr/lib/dev/systemdev/systemd-mont guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4146->guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4578 clone guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4579 /usr/lib/dev/systemdev/systemd-mont guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4146->guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4579 clone guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4580 /usr/lib/dev/systemdev/systemd-mont guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4146->guuid=be3fd0dc-1900-0000-5635-47e132100000 pid=4580 clone
Verdict:
Malicious
Threat:
HEUR:Downloader.Shell.Miner
Threat name:
Linux.Trojan.Generic
Status:
Suspicious
First seen:
2025-08-11 17:56:33 UTC
File Type:
Text (Shell)
AV detection:
8 of 38 (21.05%)
Threat level:
  5/5
Result
Malware family:
xmrig_linux
Score:
  10/10
Tags:
family:xmrig family:xmrig_linux antivm defense_evasion discovery linux miner upx
Behaviour
Enumerates kernel/hardware configuration
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads CPU attributes
UPX packed file
Checks hardware identifiers (DMI)
Enumerates running processes
Reads hardware information
File and Directory Permissions Modification
Executes dropped EXE
XMRig Miner payload
Xmrig family
Xmrig_linux family
xmrig
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:SUSP_LNX_SH_CryptoMiner_Indicators_Dec20_1
Author:Florian Roth (Nextron Systems)
Description:Detects helper script used in a crypto miner campaign
Reference:https://www.intezer.com/blog/research/new-golang-worm-drops-xmrig-miner-on-servers/
Rule name:SUSP_LNX_SH_CryptoMiner_Indicators_Dec20_1_RID364E
Author:Florian Roth
Description:Detects helper script used in a crypto miner campaign
Reference:https://www.intezer.com/blog/research/new-golang-worm-drops-xmrig-miner-on-servers/

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Distributed via web download

Comments