MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f8560caec2a2cd1f7a969234f3454dac9977d1025093b2e091f6f8b529c919ff. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



CoinMiner


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: f8560caec2a2cd1f7a969234f3454dac9977d1025093b2e091f6f8b529c919ff
SHA3-384 hash: 1020c59926ddec3cb9e7006cd074a3b93ec8ce15f78cd1392ef469c4087b554f30b6f557c057e79886504b538da806d8
SHA1 hash: 61e7c49ab2d1080431901e53c04edf2143b001f2
MD5 hash: aa1ddc0f557b534e2c2e96f62edef491
humanhash: sad-butter-paris-connecticut
File name:mon.sh
Download: download sample
Signature CoinMiner
File size:5'253 bytes
First seen:2025-08-07 17:36:55 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 96:l06z0cic27HP7DTAiVjsAmx793jt0yjtgmu4IL1qFQ2ZV7Raa3d6z0cd:l080c9iHzDNjad935XvIL1qFhH7Rx3dS
TLSH T1B3B1964AF690C6B03C5D81A8A99B74863A06428B4E451D1DF86FF0987F5479871F83FF
Magika shell
Reporter abuse_ch
Tags:CoinMiner sh
URLMalware sample (SHA256 hash)SignatureTags
http://162.248.53.119:8000/mon.sh1e891ab1521b27923233e694f60fdbf0e1b840e657d8b1ffdefd8b5ef5e38964 CoinMinerCoinMiner
http://ip-api.com/json/n/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
40
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
fingerprint
Status:
terminated
Behavior Graph:
%3 guuid=6b9e5b85-1a00-0000-4c06-6cea9f0c0000 pid=3231 /usr/bin/sudo guuid=fe3f0e88-1a00-0000-4c06-6ceaa60c0000 pid=3238 /tmp/sample.bin guuid=6b9e5b85-1a00-0000-4c06-6cea9f0c0000 pid=3231->guuid=fe3f0e88-1a00-0000-4c06-6ceaa60c0000 pid=3238 execve guuid=ab84b888-1a00-0000-4c06-6ceaa70c0000 pid=3239 /usr/bin/whoami guuid=fe3f0e88-1a00-0000-4c06-6ceaa60c0000 pid=3238->guuid=ab84b888-1a00-0000-4c06-6ceaa70c0000 pid=3239 execve guuid=ea35518a-1a00-0000-4c06-6ceaa90c0000 pid=3241 /usr/bin/whoami guuid=fe3f0e88-1a00-0000-4c06-6ceaa60c0000 pid=3238->guuid=ea35518a-1a00-0000-4c06-6ceaa90c0000 pid=3241 execve guuid=d102d78a-1a00-0000-4c06-6ceaab0c0000 pid=3243 /usr/bin/whoami guuid=fe3f0e88-1a00-0000-4c06-6ceaa60c0000 pid=3238->guuid=d102d78a-1a00-0000-4c06-6ceaab0c0000 pid=3243 execve guuid=baa3798b-1a00-0000-4c06-6ceaad0c0000 pid=3245 /usr/bin/bash guuid=fe3f0e88-1a00-0000-4c06-6ceaa60c0000 pid=3238->guuid=baa3798b-1a00-0000-4c06-6ceaad0c0000 pid=3245 clone guuid=08a6928b-1a00-0000-4c06-6ceaaf0c0000 pid=3247 /usr/bin/id guuid=fe3f0e88-1a00-0000-4c06-6ceaa60c0000 pid=3238->guuid=08a6928b-1a00-0000-4c06-6ceaaf0c0000 pid=3247 execve guuid=c36fcf8c-1a00-0000-4c06-6ceab30c0000 pid=3251 /usr/bin/systemctl guuid=fe3f0e88-1a00-0000-4c06-6ceaa60c0000 pid=3238->guuid=c36fcf8c-1a00-0000-4c06-6ceab30c0000 pid=3251 execve guuid=6423fb8e-1a00-0000-4c06-6ceab40c0000 pid=3252 /usr/bin/bash guuid=fe3f0e88-1a00-0000-4c06-6ceaa60c0000 pid=3238->guuid=6423fb8e-1a00-0000-4c06-6ceab40c0000 pid=3252 clone guuid=9160038f-1a00-0000-4c06-6ceab50c0000 pid=3253 /usr/bin/grep guuid=fe3f0e88-1a00-0000-4c06-6ceaa60c0000 pid=3238->guuid=9160038f-1a00-0000-4c06-6ceab50c0000 pid=3253 execve guuid=58fb818f-1a00-0000-4c06-6ceab70c0000 pid=3255 /usr/bin/bash guuid=fe3f0e88-1a00-0000-4c06-6ceaa60c0000 pid=3238->guuid=58fb818f-1a00-0000-4c06-6ceab70c0000 pid=3255 clone guuid=e0ba888f-1a00-0000-4c06-6ceab80c0000 pid=3256 /usr/bin/bash guuid=fe3f0e88-1a00-0000-4c06-6ceaa60c0000 pid=3238->guuid=e0ba888f-1a00-0000-4c06-6ceab80c0000 pid=3256 clone guuid=deb9b58f-1a00-0000-4c06-6ceabb0c0000 pid=3259 /usr/bin/ps guuid=fe3f0e88-1a00-0000-4c06-6ceaa60c0000 pid=3238->guuid=deb9b58f-1a00-0000-4c06-6ceabb0c0000 pid=3259 execve guuid=83b1bc8f-1a00-0000-4c06-6ceabc0c0000 pid=3260 /usr/bin/mawk guuid=fe3f0e88-1a00-0000-4c06-6ceaa60c0000 pid=3238->guuid=83b1bc8f-1a00-0000-4c06-6ceabc0c0000 pid=3260 execve guuid=ac7ec38f-1a00-0000-4c06-6ceabd0c0000 pid=3261 /usr/bin/bash guuid=fe3f0e88-1a00-0000-4c06-6ceaa60c0000 pid=3238->guuid=ac7ec38f-1a00-0000-4c06-6ceabd0c0000 pid=3261 clone guuid=ca488495-1a00-0000-4c06-6ceac30c0000 pid=3267 /usr/bin/bash guuid=fe3f0e88-1a00-0000-4c06-6ceaa60c0000 pid=3238->guuid=ca488495-1a00-0000-4c06-6ceac30c0000 pid=3267 clone guuid=872edd9a-1a00-0000-4c06-6ceace0c0000 pid=3278 /usr/bin/bash guuid=fe3f0e88-1a00-0000-4c06-6ceaa60c0000 pid=3238->guuid=872edd9a-1a00-0000-4c06-6ceace0c0000 pid=3278 clone guuid=21a7b99b-1a00-0000-4c06-6cead20c0000 pid=3282 /usr/bin/curl net send-data guuid=fe3f0e88-1a00-0000-4c06-6ceaa60c0000 pid=3238->guuid=21a7b99b-1a00-0000-4c06-6cead20c0000 pid=3282 execve guuid=9602c39b-1a00-0000-4c06-6cead30c0000 pid=3283 /usr/bin/grep guuid=fe3f0e88-1a00-0000-4c06-6ceaa60c0000 pid=3238->guuid=9602c39b-1a00-0000-4c06-6cead30c0000 pid=3283 execve guuid=d2a8b1ad-1a00-0000-4c06-6cea070d0000 pid=3335 /usr/bin/wget net send-data write-file guuid=fe3f0e88-1a00-0000-4c06-6ceaa60c0000 pid=3238->guuid=d2a8b1ad-1a00-0000-4c06-6cea070d0000 pid=3335 execve guuid=b9f280bf-1a00-0000-4c06-6cea1f0d0000 pid=3359 /usr/bin/chmod guuid=fe3f0e88-1a00-0000-4c06-6ceaa60c0000 pid=3238->guuid=b9f280bf-1a00-0000-4c06-6cea1f0d0000 pid=3359 execve guuid=710c02c0-1a00-0000-4c06-6cea200d0000 pid=3360 /home/sandbox/run.sh guuid=fe3f0e88-1a00-0000-4c06-6ceaa60c0000 pid=3238->guuid=710c02c0-1a00-0000-4c06-6cea200d0000 pid=3360 execve guuid=52b99e34-1e00-0000-4c06-6cea46150000 pid=5446 /usr/bin/rm delete-file guuid=fe3f0e88-1a00-0000-4c06-6ceaa60c0000 pid=3238->guuid=52b99e34-1e00-0000-4c06-6cea46150000 pid=5446 execve guuid=98370c35-1e00-0000-4c06-6cea47150000 pid=5447 /usr/bin/whoami guuid=fe3f0e88-1a00-0000-4c06-6ceaa60c0000 pid=3238->guuid=98370c35-1e00-0000-4c06-6cea47150000 pid=5447 execve guuid=da848235-1e00-0000-4c06-6cea48150000 pid=5448 /usr/bin/whoami guuid=fe3f0e88-1a00-0000-4c06-6ceaa60c0000 pid=3238->guuid=da848235-1e00-0000-4c06-6cea48150000 pid=5448 execve guuid=7d0bfe35-1e00-0000-4c06-6cea49150000 pid=5449 /usr/bin/whoami guuid=fe3f0e88-1a00-0000-4c06-6ceaa60c0000 pid=3238->guuid=7d0bfe35-1e00-0000-4c06-6cea49150000 pid=5449 execve guuid=b16d8d8f-1a00-0000-4c06-6ceab90c0000 pid=3257 /usr/bin/bash guuid=58fb818f-1a00-0000-4c06-6ceab70c0000 pid=3255->guuid=b16d8d8f-1a00-0000-4c06-6ceab90c0000 pid=3257 clone guuid=93369795-1a00-0000-4c06-6ceac40c0000 pid=3268 /usr/bin/pgrep guuid=ca488495-1a00-0000-4c06-6ceac30c0000 pid=3267->guuid=93369795-1a00-0000-4c06-6ceac40c0000 pid=3268 execve guuid=b3b89f95-1a00-0000-4c06-6ceac50c0000 pid=3269 /usr/bin/bash guuid=ca488495-1a00-0000-4c06-6ceac30c0000 pid=3267->guuid=b3b89f95-1a00-0000-4c06-6ceac50c0000 pid=3269 clone guuid=4b9aef9a-1a00-0000-4c06-6ceacf0c0000 pid=3279 /usr/bin/grep guuid=872edd9a-1a00-0000-4c06-6ceace0c0000 pid=3278->guuid=4b9aef9a-1a00-0000-4c06-6ceacf0c0000 pid=3279 execve b60edd83-de97-543e-8c12-c815cb088ff2 ip-api.com:80 guuid=21a7b99b-1a00-0000-4c06-6cead20c0000 pid=3282->b60edd83-de97-543e-8c12-c815cb088ff2 send: 79B guuid=21a7b99b-1a00-0000-4c06-6cead20c0000 pid=3295 /usr/bin/curl dns net send-data guuid=21a7b99b-1a00-0000-4c06-6cead20c0000 pid=3282->guuid=21a7b99b-1a00-0000-4c06-6cead20c0000 pid=3295 clone 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=21a7b99b-1a00-0000-4c06-6cead20c0000 pid=3295->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 28B 2f67bf0f-8453-5800-9e7b-37101ce5849f 162.248.53.119:8000 guuid=d2a8b1ad-1a00-0000-4c06-6cea070d0000 pid=3335->2f67bf0f-8453-5800-9e7b-37101ce5849f send: 140B guuid=960599c0-1a00-0000-4c06-6cea210d0000 pid=3361 /usr/bin/systemctl guuid=710c02c0-1a00-0000-4c06-6cea200d0000 pid=3360->guuid=960599c0-1a00-0000-4c06-6cea210d0000 pid=3361 execve guuid=745f43c3-1a00-0000-4c06-6cea290d0000 pid=3369 /usr/bin/bash guuid=710c02c0-1a00-0000-4c06-6cea200d0000 pid=3360->guuid=745f43c3-1a00-0000-4c06-6cea290d0000 pid=3369 clone guuid=96e56aca-1a00-0000-4c06-6cea3c0d0000 pid=3388 /usr/bin/bash guuid=710c02c0-1a00-0000-4c06-6cea200d0000 pid=3360->guuid=96e56aca-1a00-0000-4c06-6cea3c0d0000 pid=3388 clone guuid=d3a22acb-1a00-0000-4c06-6cea410d0000 pid=3393 /usr/bin/id guuid=710c02c0-1a00-0000-4c06-6cea200d0000 pid=3360->guuid=d3a22acb-1a00-0000-4c06-6cea410d0000 pid=3393 execve guuid=aa86b5cb-1a00-0000-4c06-6cea420d0000 pid=3394 /usr/bin/apt-get delete-file write-file guuid=710c02c0-1a00-0000-4c06-6cea200d0000 pid=3360->guuid=aa86b5cb-1a00-0000-4c06-6cea420d0000 pid=3394 execve guuid=1d3db9c4-1c00-0000-4c06-6cea11130000 pid=4881 /usr/bin/apt-get guuid=710c02c0-1a00-0000-4c06-6cea200d0000 pid=3360->guuid=1d3db9c4-1c00-0000-4c06-6cea11130000 pid=4881 execve guuid=d8b097c6-1c00-0000-4c06-6cea13130000 pid=4883 /usr/bin/mkdir guuid=710c02c0-1a00-0000-4c06-6cea200d0000 pid=3360->guuid=d8b097c6-1c00-0000-4c06-6cea13130000 pid=4883 execve guuid=99a3f7c6-1c00-0000-4c06-6cea17130000 pid=4887 /usr/bin/wget dns net send-data write-file guuid=710c02c0-1a00-0000-4c06-6cea200d0000 pid=3360->guuid=99a3f7c6-1c00-0000-4c06-6cea17130000 pid=4887 execve guuid=8b2c3ce4-1c00-0000-4c06-6cea76130000 pid=4982 /usr/bin/tar write-file guuid=710c02c0-1a00-0000-4c06-6cea200d0000 pid=3360->guuid=8b2c3ce4-1c00-0000-4c06-6cea76130000 pid=4982 execve guuid=3eaabdee-1c00-0000-4c06-6cea97130000 pid=5015 /usr/bin/mv guuid=710c02c0-1a00-0000-4c06-6cea200d0000 pid=3360->guuid=3eaabdee-1c00-0000-4c06-6cea97130000 pid=5015 execve guuid=af1729ef-1c00-0000-4c06-6cea99130000 pid=5017 /usr/bin/rm guuid=710c02c0-1a00-0000-4c06-6cea200d0000 pid=3360->guuid=af1729ef-1c00-0000-4c06-6cea99130000 pid=5017 execve guuid=4fe46cef-1c00-0000-4c06-6cea9b130000 pid=5019 /usr/bin/chmod guuid=710c02c0-1a00-0000-4c06-6cea200d0000 pid=3360->guuid=4fe46cef-1c00-0000-4c06-6cea9b130000 pid=5019 execve guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5021 /usr/lib/dev/systemdev/systemd-mont mprotect-exec net send-data guuid=710c02c0-1a00-0000-4c06-6cea200d0000 pid=3360->guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5021 execve guuid=640dd1ef-1c00-0000-4c06-6cea9e130000 pid=5022 /usr/bin/sleep guuid=710c02c0-1a00-0000-4c06-6cea200d0000 pid=3360->guuid=640dd1ef-1c00-0000-4c06-6cea9e130000 pid=5022 execve guuid=80715013-1d00-0000-4c06-6cea00140000 pid=5120 /usr/bin/ps guuid=710c02c0-1a00-0000-4c06-6cea200d0000 pid=3360->guuid=80715013-1d00-0000-4c06-6cea00140000 pid=5120 execve guuid=b6a36f22-1d00-0000-4c06-6cea1f140000 pid=5151 /usr/bin/sleep guuid=710c02c0-1a00-0000-4c06-6cea200d0000 pid=3360->guuid=b6a36f22-1d00-0000-4c06-6cea1f140000 pid=5151 execve guuid=aa27952f-1e00-0000-4c06-6cea43150000 pid=5443 /usr/bin/ps guuid=710c02c0-1a00-0000-4c06-6cea200d0000 pid=3360->guuid=aa27952f-1e00-0000-4c06-6cea43150000 pid=5443 execve guuid=12e6c333-1e00-0000-4c06-6cea44150000 pid=5444 /usr/bin/rm guuid=710c02c0-1a00-0000-4c06-6cea200d0000 pid=3360->guuid=12e6c333-1e00-0000-4c06-6cea44150000 pid=5444 execve guuid=1d112934-1e00-0000-4c06-6cea45150000 pid=5445 /usr/bin/rm guuid=710c02c0-1a00-0000-4c06-6cea200d0000 pid=3360->guuid=1d112934-1e00-0000-4c06-6cea45150000 pid=5445 execve guuid=5d2250c3-1a00-0000-4c06-6cea2a0d0000 pid=3370 /usr/bin/wget dns net send-data guuid=745f43c3-1a00-0000-4c06-6cea290d0000 pid=3369->guuid=5d2250c3-1a00-0000-4c06-6cea2a0d0000 pid=3370 execve guuid=5d2250c3-1a00-0000-4c06-6cea2a0d0000 pid=3370->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 72B 0690ccd5-4816-5f11-94dc-7c585f38cdea ipv4.icanhazip.com:0 guuid=5d2250c3-1a00-0000-4c06-6cea2a0d0000 pid=3370->0690ccd5-4816-5f11-94dc-7c585f38cdea con d0ecfe49-aa79-583f-85c6-85ac97075256 ipv4.icanhazip.com:80 guuid=5d2250c3-1a00-0000-4c06-6cea2a0d0000 pid=3370->d0ecfe49-aa79-583f-85c6-85ac97075256 send: 133B guuid=df807bca-1a00-0000-4c06-6cea3d0d0000 pid=3389 /usr/bin/bash guuid=96e56aca-1a00-0000-4c06-6cea3c0d0000 pid=3388->guuid=df807bca-1a00-0000-4c06-6cea3d0d0000 pid=3389 clone guuid=13dd85ca-1a00-0000-4c06-6cea3e0d0000 pid=3390 /usr/bin/sed guuid=96e56aca-1a00-0000-4c06-6cea3c0d0000 pid=3388->guuid=13dd85ca-1a00-0000-4c06-6cea3e0d0000 pid=3390 execve guuid=ac558dca-1a00-0000-4c06-6cea3f0d0000 pid=3391 /usr/bin/cut guuid=96e56aca-1a00-0000-4c06-6cea3c0d0000 pid=3388->guuid=ac558dca-1a00-0000-4c06-6cea3f0d0000 pid=3391 execve guuid=75b23acd-1a00-0000-4c06-6cea470d0000 pid=3399 /usr/bin/dpkg guuid=aa86b5cb-1a00-0000-4c06-6cea420d0000 pid=3394->guuid=75b23acd-1a00-0000-4c06-6cea470d0000 pid=3399 execve guuid=e60af3cd-1a00-0000-4c06-6cea4a0d0000 pid=3402 /usr/lib/apt/methods/mirror guuid=aa86b5cb-1a00-0000-4c06-6cea420d0000 pid=3394->guuid=e60af3cd-1a00-0000-4c06-6cea4a0d0000 pid=3402 execve guuid=c76a56cf-1a00-0000-4c06-6cea4e0d0000 pid=3406 /usr/lib/apt/methods/mirror guuid=aa86b5cb-1a00-0000-4c06-6cea420d0000 pid=3394->guuid=c76a56cf-1a00-0000-4c06-6cea4e0d0000 pid=3406 execve guuid=afb57cd0-1a00-0000-4c06-6cea510d0000 pid=3409 /usr/lib/apt/methods/file guuid=aa86b5cb-1a00-0000-4c06-6cea420d0000 pid=3394->guuid=afb57cd0-1a00-0000-4c06-6cea510d0000 pid=3409 execve guuid=ea07e9d1-1a00-0000-4c06-6cea560d0000 pid=3414 /usr/lib/apt/methods/file delete-file guuid=aa86b5cb-1a00-0000-4c06-6cea420d0000 pid=3394->guuid=ea07e9d1-1a00-0000-4c06-6cea560d0000 pid=3414 execve guuid=ee8756d3-1a00-0000-4c06-6cea5b0d0000 pid=3419 /usr/lib/apt/methods/http guuid=aa86b5cb-1a00-0000-4c06-6cea420d0000 pid=3394->guuid=ee8756d3-1a00-0000-4c06-6cea5b0d0000 pid=3419 execve guuid=11be69d6-1a00-0000-4c06-6cea640d0000 pid=3428 /usr/lib/apt/methods/http dns net send-data write-file guuid=aa86b5cb-1a00-0000-4c06-6cea420d0000 pid=3394->guuid=11be69d6-1a00-0000-4c06-6cea640d0000 pid=3428 execve guuid=394c8fe7-1a00-0000-4c06-6cea990d0000 pid=3481 /usr/lib/apt/methods/gpgv guuid=aa86b5cb-1a00-0000-4c06-6cea420d0000 pid=3394->guuid=394c8fe7-1a00-0000-4c06-6cea990d0000 pid=3481 execve guuid=5c7b74e8-1a00-0000-4c06-6cea9d0d0000 pid=3485 /usr/lib/apt/methods/gpgv guuid=aa86b5cb-1a00-0000-4c06-6cea420d0000 pid=3394->guuid=5c7b74e8-1a00-0000-4c06-6cea9d0d0000 pid=3485 execve guuid=0e7ed119-1b00-0000-4c06-6cea290e0000 pid=3625 /usr/lib/apt/methods/rred guuid=aa86b5cb-1a00-0000-4c06-6cea420d0000 pid=3394->guuid=0e7ed119-1b00-0000-4c06-6cea290e0000 pid=3625 execve guuid=0392791f-1b00-0000-4c06-6cea2d0e0000 pid=3629 /usr/lib/apt/methods/rred write-file guuid=aa86b5cb-1a00-0000-4c06-6cea420d0000 pid=3394->guuid=0392791f-1b00-0000-4c06-6cea2d0e0000 pid=3629 execve guuid=826c0121-1b00-0000-4c06-6cea2f0e0000 pid=3631 /usr/lib/apt/methods/rred write-file guuid=aa86b5cb-1a00-0000-4c06-6cea420d0000 pid=3394->guuid=826c0121-1b00-0000-4c06-6cea2f0e0000 pid=3631 execve guuid=5dbd7824-1b00-0000-4c06-6cea3a0e0000 pid=3642 /usr/lib/apt/methods/store guuid=aa86b5cb-1a00-0000-4c06-6cea420d0000 pid=3394->guuid=5dbd7824-1b00-0000-4c06-6cea3a0e0000 pid=3642 execve guuid=4204e725-1b00-0000-4c06-6cea400e0000 pid=3648 /usr/lib/apt/methods/store write-file guuid=aa86b5cb-1a00-0000-4c06-6cea420d0000 pid=3394->guuid=4204e725-1b00-0000-4c06-6cea400e0000 pid=3648 execve guuid=12616171-1b00-0000-4c06-6ceaf70e0000 pid=3831 /usr/bin/dpkg guuid=aa86b5cb-1a00-0000-4c06-6cea420d0000 pid=3394->guuid=12616171-1b00-0000-4c06-6ceaf70e0000 pid=3831 execve guuid=9af5f1bf-1c00-0000-4c06-6cea08130000 pid=4872 /usr/bin/dpkg guuid=aa86b5cb-1a00-0000-4c06-6cea420d0000 pid=3394->guuid=9af5f1bf-1c00-0000-4c06-6cea08130000 pid=4872 execve guuid=11be69d6-1a00-0000-4c06-6cea640d0000 pid=3428->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 122B 869ebe88-8c1e-5fbb-adb0-cfe48d8d7faf debian.map.fastly.net:443 guuid=11be69d6-1a00-0000-4c06-6cea640d0000 pid=3428->869ebe88-8c1e-5fbb-adb0-cfe48d8d7faf send: 5997B guuid=0c34dce9-1a00-0000-4c06-6ceaa20d0000 pid=3490 /usr/lib/apt/methods/gpgv delete-file write-file guuid=5c7b74e8-1a00-0000-4c06-6cea9d0d0000 pid=3485->guuid=0c34dce9-1a00-0000-4c06-6ceaa20d0000 pid=3490 clone guuid=22839bfe-1a00-0000-4c06-6ceae40d0000 pid=3556 /usr/lib/apt/methods/gpgv delete-file write-file guuid=5c7b74e8-1a00-0000-4c06-6cea9d0d0000 pid=3485->guuid=22839bfe-1a00-0000-4c06-6ceae40d0000 pid=3556 clone guuid=c4c89613-1b00-0000-4c06-6cea200e0000 pid=3616 /usr/lib/apt/methods/gpgv delete-file write-file guuid=5c7b74e8-1a00-0000-4c06-6cea9d0d0000 pid=3485->guuid=c4c89613-1b00-0000-4c06-6cea200e0000 pid=3616 clone guuid=35e7982d-1b00-0000-4c06-6cea680e0000 pid=3688 /usr/lib/apt/methods/gpgv delete-file write-file guuid=5c7b74e8-1a00-0000-4c06-6cea9d0d0000 pid=3485->guuid=35e7982d-1b00-0000-4c06-6cea680e0000 pid=3688 clone guuid=de2242ed-1a00-0000-4c06-6ceaae0d0000 pid=3502 /usr/bin/apt-key write-file guuid=0c34dce9-1a00-0000-4c06-6ceaa20d0000 pid=3490->guuid=de2242ed-1a00-0000-4c06-6ceaae0d0000 pid=3502 execve guuid=0c58a2ed-1a00-0000-4c06-6ceab00d0000 pid=3504 /usr/bin/dash guuid=de2242ed-1a00-0000-4c06-6ceaae0d0000 pid=3502->guuid=0c58a2ed-1a00-0000-4c06-6ceab00d0000 pid=3504 clone guuid=1218b6ed-1a00-0000-4c06-6ceab10d0000 pid=3505 /usr/bin/apt-config guuid=de2242ed-1a00-0000-4c06-6ceaae0d0000 pid=3502->guuid=1218b6ed-1a00-0000-4c06-6ceab10d0000 pid=3505 execve guuid=879d28f1-1a00-0000-4c06-6ceab80d0000 pid=3512 /usr/bin/apt-config guuid=de2242ed-1a00-0000-4c06-6ceaae0d0000 pid=3502->guuid=879d28f1-1a00-0000-4c06-6ceab80d0000 pid=3512 execve guuid=2cdc76f3-1a00-0000-4c06-6ceac10d0000 pid=3521 /usr/bin/apt-config guuid=de2242ed-1a00-0000-4c06-6ceaae0d0000 pid=3502->guuid=2cdc76f3-1a00-0000-4c06-6ceac10d0000 pid=3521 execve guuid=4e842af6-1a00-0000-4c06-6ceacb0d0000 pid=3531 /usr/bin/apt-config guuid=de2242ed-1a00-0000-4c06-6ceaae0d0000 pid=3502->guuid=4e842af6-1a00-0000-4c06-6ceacb0d0000 pid=3531 execve guuid=019588f7-1a00-0000-4c06-6cead10d0000 pid=3537 /usr/bin/dash guuid=de2242ed-1a00-0000-4c06-6ceaae0d0000 pid=3502->guuid=019588f7-1a00-0000-4c06-6cead10d0000 pid=3537 clone guuid=369ab4f7-1a00-0000-4c06-6cead20d0000 pid=3538 /usr/bin/apt-config guuid=de2242ed-1a00-0000-4c06-6ceaae0d0000 pid=3502->guuid=369ab4f7-1a00-0000-4c06-6cead20d0000 pid=3538 execve guuid=0808f9f8-1a00-0000-4c06-6cead80d0000 pid=3544 /usr/bin/mktemp guuid=de2242ed-1a00-0000-4c06-6ceaae0d0000 pid=3502->guuid=0808f9f8-1a00-0000-4c06-6cead80d0000 pid=3544 execve guuid=7e182bf9-1a00-0000-4c06-6cead90d0000 pid=3545 /usr/bin/chmod guuid=de2242ed-1a00-0000-4c06-6ceaae0d0000 pid=3502->guuid=7e182bf9-1a00-0000-4c06-6cead90d0000 pid=3545 execve guuid=120c5df9-1a00-0000-4c06-6ceada0d0000 pid=3546 /usr/bin/dash guuid=de2242ed-1a00-0000-4c06-6ceaae0d0000 pid=3502->guuid=120c5df9-1a00-0000-4c06-6ceada0d0000 pid=3546 clone guuid=552574f9-1a00-0000-4c06-6ceadb0d0000 pid=3547 /usr/bin/dash guuid=de2242ed-1a00-0000-4c06-6ceaae0d0000 pid=3502->guuid=552574f9-1a00-0000-4c06-6ceadb0d0000 pid=3547 clone guuid=886c03fa-1a00-0000-4c06-6ceade0d0000 pid=3550 /usr/bin/dash guuid=de2242ed-1a00-0000-4c06-6ceaae0d0000 pid=3502->guuid=886c03fa-1a00-0000-4c06-6ceade0d0000 pid=3550 clone guuid=64cabefa-1a00-0000-4c06-6ceae10d0000 pid=3553 /usr/bin/dash guuid=de2242ed-1a00-0000-4c06-6ceaae0d0000 pid=3502->guuid=64cabefa-1a00-0000-4c06-6ceae10d0000 pid=3553 clone guuid=9312d3fa-1a00-0000-4c06-6ceae20d0000 pid=3554 /usr/bin/gpgv guuid=de2242ed-1a00-0000-4c06-6ceaae0d0000 pid=3502->guuid=9312d3fa-1a00-0000-4c06-6ceae20d0000 pid=3554 execve guuid=c7cd00fd-1a00-0000-4c06-6ceae30d0000 pid=3555 /usr/bin/rm delete-file guuid=de2242ed-1a00-0000-4c06-6ceaae0d0000 pid=3502->guuid=c7cd00fd-1a00-0000-4c06-6ceae30d0000 pid=3555 execve guuid=bb3a4bf0-1a00-0000-4c06-6ceab60d0000 pid=3510 /usr/bin/dpkg guuid=1218b6ed-1a00-0000-4c06-6ceab10d0000 pid=3505->guuid=bb3a4bf0-1a00-0000-4c06-6ceab60d0000 pid=3510 execve guuid=126edef2-1a00-0000-4c06-6ceabe0d0000 pid=3518 /usr/bin/dpkg guuid=879d28f1-1a00-0000-4c06-6ceab80d0000 pid=3512->guuid=126edef2-1a00-0000-4c06-6ceabe0d0000 pid=3518 execve guuid=182e94f5-1a00-0000-4c06-6ceac80d0000 pid=3528 /usr/bin/dpkg guuid=2cdc76f3-1a00-0000-4c06-6ceac10d0000 pid=3521->guuid=182e94f5-1a00-0000-4c06-6ceac80d0000 pid=3528 execve guuid=68b011f7-1a00-0000-4c06-6ceacf0d0000 pid=3535 /usr/bin/dpkg guuid=4e842af6-1a00-0000-4c06-6ceacb0d0000 pid=3531->guuid=68b011f7-1a00-0000-4c06-6ceacf0d0000 pid=3535 execve guuid=cd8491f8-1a00-0000-4c06-6cead70d0000 pid=3543 /usr/bin/dpkg guuid=369ab4f7-1a00-0000-4c06-6cead20d0000 pid=3538->guuid=cd8491f8-1a00-0000-4c06-6cead70d0000 pid=3543 execve guuid=5fe681f9-1a00-0000-4c06-6ceadc0d0000 pid=3548 /usr/bin/dash guuid=552574f9-1a00-0000-4c06-6ceadb0d0000 pid=3547->guuid=5fe681f9-1a00-0000-4c06-6ceadc0d0000 pid=3548 clone guuid=b1038bf9-1a00-0000-4c06-6ceadd0d0000 pid=3549 /usr/bin/sed guuid=552574f9-1a00-0000-4c06-6ceadb0d0000 pid=3547->guuid=b1038bf9-1a00-0000-4c06-6ceadd0d0000 pid=3549 execve guuid=810c15fa-1a00-0000-4c06-6ceadf0d0000 pid=3551 /usr/bin/dash guuid=886c03fa-1a00-0000-4c06-6ceade0d0000 pid=3550->guuid=810c15fa-1a00-0000-4c06-6ceadf0d0000 pid=3551 clone guuid=edcd1efa-1a00-0000-4c06-6ceae00d0000 pid=3552 /usr/bin/sed guuid=886c03fa-1a00-0000-4c06-6ceade0d0000 pid=3550->guuid=edcd1efa-1a00-0000-4c06-6ceae00d0000 pid=3552 execve guuid=7d317fff-1a00-0000-4c06-6ceae80d0000 pid=3560 /usr/bin/apt-key write-file guuid=22839bfe-1a00-0000-4c06-6ceae40d0000 pid=3556->guuid=7d317fff-1a00-0000-4c06-6ceae80d0000 pid=3560 execve guuid=86dfc0ff-1a00-0000-4c06-6ceae90d0000 pid=3561 /usr/bin/dash guuid=7d317fff-1a00-0000-4c06-6ceae80d0000 pid=3560->guuid=86dfc0ff-1a00-0000-4c06-6ceae90d0000 pid=3561 clone guuid=8fe6e2ff-1a00-0000-4c06-6ceaea0d0000 pid=3562 /usr/bin/apt-config guuid=7d317fff-1a00-0000-4c06-6ceae80d0000 pid=3560->guuid=8fe6e2ff-1a00-0000-4c06-6ceaea0d0000 pid=3562 execve guuid=8f7abb02-1b00-0000-4c06-6ceaf20d0000 pid=3570 /usr/bin/apt-config guuid=7d317fff-1a00-0000-4c06-6ceae80d0000 pid=3560->guuid=8f7abb02-1b00-0000-4c06-6ceaf20d0000 pid=3570 execve guuid=e0dbc308-1b00-0000-4c06-6ceafb0d0000 pid=3579 /usr/bin/apt-config guuid=7d317fff-1a00-0000-4c06-6ceae80d0000 pid=3560->guuid=e0dbc308-1b00-0000-4c06-6ceafb0d0000 pid=3579 execve guuid=49165a0a-1b00-0000-4c06-6cea010e0000 pid=3585 /usr/bin/apt-config guuid=7d317fff-1a00-0000-4c06-6ceae80d0000 pid=3560->guuid=49165a0a-1b00-0000-4c06-6cea010e0000 pid=3585 execve guuid=727e460c-1b00-0000-4c06-6cea030e0000 pid=3587 /usr/bin/dash guuid=7d317fff-1a00-0000-4c06-6ceae80d0000 pid=3560->guuid=727e460c-1b00-0000-4c06-6cea030e0000 pid=3587 clone guuid=de12920c-1b00-0000-4c06-6cea040e0000 pid=3588 /usr/bin/apt-config guuid=7d317fff-1a00-0000-4c06-6ceae80d0000 pid=3560->guuid=de12920c-1b00-0000-4c06-6cea040e0000 pid=3588 execve guuid=f530850e-1b00-0000-4c06-6cea070e0000 pid=3591 /usr/bin/mktemp guuid=7d317fff-1a00-0000-4c06-6ceae80d0000 pid=3560->guuid=f530850e-1b00-0000-4c06-6cea070e0000 pid=3591 execve guuid=9cb9dc0e-1b00-0000-4c06-6cea080e0000 pid=3592 /usr/bin/chmod guuid=7d317fff-1a00-0000-4c06-6ceae80d0000 pid=3560->guuid=9cb9dc0e-1b00-0000-4c06-6cea080e0000 pid=3592 execve guuid=88971b0f-1b00-0000-4c06-6cea090e0000 pid=3593 /usr/bin/dash guuid=7d317fff-1a00-0000-4c06-6ceae80d0000 pid=3560->guuid=88971b0f-1b00-0000-4c06-6cea090e0000 pid=3593 clone guuid=4f2c3c0f-1b00-0000-4c06-6cea0a0e0000 pid=3594 /usr/bin/dash guuid=7d317fff-1a00-0000-4c06-6ceae80d0000 pid=3560->guuid=4f2c3c0f-1b00-0000-4c06-6cea0a0e0000 pid=3594 clone guuid=48f5b10f-1b00-0000-4c06-6cea0d0e0000 pid=3597 /usr/bin/dash guuid=7d317fff-1a00-0000-4c06-6ceae80d0000 pid=3560->guuid=48f5b10f-1b00-0000-4c06-6cea0d0e0000 pid=3597 clone guuid=54432910-1b00-0000-4c06-6cea110e0000 pid=3601 /usr/bin/dash guuid=7d317fff-1a00-0000-4c06-6ceae80d0000 pid=3560->guuid=54432910-1b00-0000-4c06-6cea110e0000 pid=3601 clone guuid=efa93f10-1b00-0000-4c06-6cea130e0000 pid=3603 /usr/bin/gpgv guuid=7d317fff-1a00-0000-4c06-6ceae80d0000 pid=3560->guuid=efa93f10-1b00-0000-4c06-6cea130e0000 pid=3603 execve guuid=d828c812-1b00-0000-4c06-6cea1c0e0000 pid=3612 /usr/bin/rm delete-file guuid=7d317fff-1a00-0000-4c06-6ceae80d0000 pid=3560->guuid=d828c812-1b00-0000-4c06-6cea1c0e0000 pid=3612 execve guuid=97c84802-1b00-0000-4c06-6ceaef0d0000 pid=3567 /usr/bin/dpkg guuid=8fe6e2ff-1a00-0000-4c06-6ceaea0d0000 pid=3562->guuid=97c84802-1b00-0000-4c06-6ceaef0d0000 pid=3567 execve guuid=f47ac203-1b00-0000-4c06-6ceaf70d0000 pid=3575 /usr/bin/dpkg guuid=8f7abb02-1b00-0000-4c06-6ceaf20d0000 pid=3570->guuid=f47ac203-1b00-0000-4c06-6ceaf70d0000 pid=3575 execve guuid=9100db09-1b00-0000-4c06-6ceafe0d0000 pid=3582 /usr/bin/dpkg guuid=e0dbc308-1b00-0000-4c06-6ceafb0d0000 pid=3579->guuid=9100db09-1b00-0000-4c06-6ceafe0d0000 pid=3582 execve guuid=f71baa0b-1b00-0000-4c06-6cea020e0000 pid=3586 /usr/bin/dpkg guuid=49165a0a-1b00-0000-4c06-6cea010e0000 pid=3585->guuid=f71baa0b-1b00-0000-4c06-6cea020e0000 pid=3586 execve guuid=8773e60d-1b00-0000-4c06-6cea060e0000 pid=3590 /usr/bin/dpkg guuid=de12920c-1b00-0000-4c06-6cea040e0000 pid=3588->guuid=8773e60d-1b00-0000-4c06-6cea060e0000 pid=3590 execve guuid=04914a0f-1b00-0000-4c06-6cea0b0e0000 pid=3595 /usr/bin/dash guuid=4f2c3c0f-1b00-0000-4c06-6cea0a0e0000 pid=3594->guuid=04914a0f-1b00-0000-4c06-6cea0b0e0000 pid=3595 clone guuid=17da500f-1b00-0000-4c06-6cea0c0e0000 pid=3596 /usr/bin/sed guuid=4f2c3c0f-1b00-0000-4c06-6cea0a0e0000 pid=3594->guuid=17da500f-1b00-0000-4c06-6cea0c0e0000 pid=3596 execve guuid=b484bd0f-1b00-0000-4c06-6cea0e0e0000 pid=3598 /usr/bin/dash guuid=48f5b10f-1b00-0000-4c06-6cea0d0e0000 pid=3597->guuid=b484bd0f-1b00-0000-4c06-6cea0e0e0000 pid=3598 clone guuid=0c41c40f-1b00-0000-4c06-6cea0f0e0000 pid=3599 /usr/bin/sed guuid=48f5b10f-1b00-0000-4c06-6cea0d0e0000 pid=3597->guuid=0c41c40f-1b00-0000-4c06-6cea0f0e0000 pid=3599 execve guuid=70830e17-1b00-0000-4c06-6cea240e0000 pid=3620 /usr/bin/apt-key write-file guuid=c4c89613-1b00-0000-4c06-6cea200e0000 pid=3616->guuid=70830e17-1b00-0000-4c06-6cea240e0000 pid=3620 execve guuid=22d34517-1b00-0000-4c06-6cea250e0000 pid=3621 /usr/bin/dash guuid=70830e17-1b00-0000-4c06-6cea240e0000 pid=3620->guuid=22d34517-1b00-0000-4c06-6cea250e0000 pid=3621 clone guuid=9eb65617-1b00-0000-4c06-6cea260e0000 pid=3622 /usr/bin/apt-config guuid=70830e17-1b00-0000-4c06-6cea240e0000 pid=3620->guuid=9eb65617-1b00-0000-4c06-6cea260e0000 pid=3622 execve guuid=3dda1f19-1b00-0000-4c06-6cea280e0000 pid=3624 /usr/bin/apt-config guuid=70830e17-1b00-0000-4c06-6cea240e0000 pid=3620->guuid=3dda1f19-1b00-0000-4c06-6cea280e0000 pid=3624 execve guuid=b483bd1a-1b00-0000-4c06-6cea2b0e0000 pid=3627 /usr/bin/apt-config guuid=70830e17-1b00-0000-4c06-6cea240e0000 pid=3620->guuid=b483bd1a-1b00-0000-4c06-6cea2b0e0000 pid=3627 execve guuid=d5085921-1b00-0000-4c06-6cea300e0000 pid=3632 /usr/bin/apt-config guuid=70830e17-1b00-0000-4c06-6cea240e0000 pid=3620->guuid=d5085921-1b00-0000-4c06-6cea300e0000 pid=3632 execve guuid=c4a8ac27-1b00-0000-4c06-6cea450e0000 pid=3653 /usr/bin/dash guuid=70830e17-1b00-0000-4c06-6cea240e0000 pid=3620->guuid=c4a8ac27-1b00-0000-4c06-6cea450e0000 pid=3653 clone guuid=01b8f927-1b00-0000-4c06-6cea460e0000 pid=3654 /usr/bin/apt-config guuid=70830e17-1b00-0000-4c06-6cea240e0000 pid=3620->guuid=01b8f927-1b00-0000-4c06-6cea460e0000 pid=3654 execve guuid=4d1de829-1b00-0000-4c06-6cea4e0e0000 pid=3662 /usr/bin/mktemp guuid=70830e17-1b00-0000-4c06-6cea240e0000 pid=3620->guuid=4d1de829-1b00-0000-4c06-6cea4e0e0000 pid=3662 execve guuid=098d212a-1b00-0000-4c06-6cea500e0000 pid=3664 /usr/bin/chmod guuid=70830e17-1b00-0000-4c06-6cea240e0000 pid=3620->guuid=098d212a-1b00-0000-4c06-6cea500e0000 pid=3664 execve guuid=363c4f2a-1b00-0000-4c06-6cea520e0000 pid=3666 /usr/bin/dash guuid=70830e17-1b00-0000-4c06-6cea240e0000 pid=3620->guuid=363c4f2a-1b00-0000-4c06-6cea520e0000 pid=3666 clone guuid=59b47c2a-1b00-0000-4c06-6cea530e0000 pid=3667 /usr/bin/dash guuid=70830e17-1b00-0000-4c06-6cea240e0000 pid=3620->guuid=59b47c2a-1b00-0000-4c06-6cea530e0000 pid=3667 clone guuid=2929e42a-1b00-0000-4c06-6cea580e0000 pid=3672 /usr/bin/dash guuid=70830e17-1b00-0000-4c06-6cea240e0000 pid=3620->guuid=2929e42a-1b00-0000-4c06-6cea580e0000 pid=3672 clone guuid=85644c2b-1b00-0000-4c06-6cea5c0e0000 pid=3676 /usr/bin/dash guuid=70830e17-1b00-0000-4c06-6cea240e0000 pid=3620->guuid=85644c2b-1b00-0000-4c06-6cea5c0e0000 pid=3676 clone guuid=6d3c592b-1b00-0000-4c06-6cea5e0e0000 pid=3678 /usr/bin/gpgv guuid=70830e17-1b00-0000-4c06-6cea240e0000 pid=3620->guuid=6d3c592b-1b00-0000-4c06-6cea5e0e0000 pid=3678 execve guuid=cfcbac2c-1b00-0000-4c06-6cea640e0000 pid=3684 /usr/bin/rm delete-file guuid=70830e17-1b00-0000-4c06-6cea240e0000 pid=3620->guuid=cfcbac2c-1b00-0000-4c06-6cea640e0000 pid=3684 execve guuid=54fe9018-1b00-0000-4c06-6cea270e0000 pid=3623 /usr/bin/dpkg guuid=9eb65617-1b00-0000-4c06-6cea260e0000 pid=3622->guuid=54fe9018-1b00-0000-4c06-6cea270e0000 pid=3623 execve guuid=59a4351a-1b00-0000-4c06-6cea2a0e0000 pid=3626 /usr/bin/dpkg guuid=3dda1f19-1b00-0000-4c06-6cea280e0000 pid=3624->guuid=59a4351a-1b00-0000-4c06-6cea2a0e0000 pid=3626 execve guuid=a792421c-1b00-0000-4c06-6cea2c0e0000 pid=3628 /usr/bin/dpkg guuid=b483bd1a-1b00-0000-4c06-6cea2b0e0000 pid=3627->guuid=a792421c-1b00-0000-4c06-6cea2c0e0000 pid=3628 execve guuid=5e987c22-1b00-0000-4c06-6cea350e0000 pid=3637 /usr/bin/dpkg guuid=d5085921-1b00-0000-4c06-6cea300e0000 pid=3632->guuid=5e987c22-1b00-0000-4c06-6cea350e0000 pid=3637 execve guuid=e5984629-1b00-0000-4c06-6cea4b0e0000 pid=3659 /usr/bin/dpkg guuid=01b8f927-1b00-0000-4c06-6cea460e0000 pid=3654->guuid=e5984629-1b00-0000-4c06-6cea4b0e0000 pid=3659 execve guuid=cfda832a-1b00-0000-4c06-6cea540e0000 pid=3668 /usr/bin/dash guuid=59b47c2a-1b00-0000-4c06-6cea530e0000 pid=3667->guuid=cfda832a-1b00-0000-4c06-6cea540e0000 pid=3668 clone guuid=42738a2a-1b00-0000-4c06-6cea560e0000 pid=3670 /usr/bin/sed guuid=59b47c2a-1b00-0000-4c06-6cea530e0000 pid=3667->guuid=42738a2a-1b00-0000-4c06-6cea560e0000 pid=3670 execve guuid=13aeeb2a-1b00-0000-4c06-6cea590e0000 pid=3673 /usr/bin/dash guuid=2929e42a-1b00-0000-4c06-6cea580e0000 pid=3672->guuid=13aeeb2a-1b00-0000-4c06-6cea590e0000 pid=3673 clone guuid=7c5bf12a-1b00-0000-4c06-6cea5a0e0000 pid=3674 /usr/bin/sed guuid=2929e42a-1b00-0000-4c06-6cea580e0000 pid=3672->guuid=7c5bf12a-1b00-0000-4c06-6cea5a0e0000 pid=3674 execve guuid=03c7752e-1b00-0000-4c06-6cea6b0e0000 pid=3691 /usr/bin/apt-key write-file guuid=35e7982d-1b00-0000-4c06-6cea680e0000 pid=3688->guuid=03c7752e-1b00-0000-4c06-6cea6b0e0000 pid=3691 execve guuid=dcd8ac2e-1b00-0000-4c06-6cea6c0e0000 pid=3692 /usr/bin/dash guuid=03c7752e-1b00-0000-4c06-6cea6b0e0000 pid=3691->guuid=dcd8ac2e-1b00-0000-4c06-6cea6c0e0000 pid=3692 clone guuid=21e0c92e-1b00-0000-4c06-6cea6d0e0000 pid=3693 /usr/bin/apt-config guuid=03c7752e-1b00-0000-4c06-6cea6b0e0000 pid=3691->guuid=21e0c92e-1b00-0000-4c06-6cea6d0e0000 pid=3693 execve guuid=8acdd232-1b00-0000-4c06-6cea750e0000 pid=3701 /usr/bin/apt-config guuid=03c7752e-1b00-0000-4c06-6cea6b0e0000 pid=3691->guuid=8acdd232-1b00-0000-4c06-6cea750e0000 pid=3701 execve guuid=28f06234-1b00-0000-4c06-6cea770e0000 pid=3703 /usr/bin/apt-config guuid=03c7752e-1b00-0000-4c06-6cea6b0e0000 pid=3691->guuid=28f06234-1b00-0000-4c06-6cea770e0000 pid=3703 execve guuid=d4d30336-1b00-0000-4c06-6cea7c0e0000 pid=3708 /usr/bin/apt-config guuid=03c7752e-1b00-0000-4c06-6cea6b0e0000 pid=3691->guuid=d4d30336-1b00-0000-4c06-6cea7c0e0000 pid=3708 execve guuid=05ceba37-1b00-0000-4c06-6cea820e0000 pid=3714 /usr/bin/dash guuid=03c7752e-1b00-0000-4c06-6cea6b0e0000 pid=3691->guuid=05ceba37-1b00-0000-4c06-6cea820e0000 pid=3714 clone guuid=8d69dd37-1b00-0000-4c06-6cea830e0000 pid=3715 /usr/bin/apt-config guuid=03c7752e-1b00-0000-4c06-6cea6b0e0000 pid=3691->guuid=8d69dd37-1b00-0000-4c06-6cea830e0000 pid=3715 execve guuid=e692273e-1b00-0000-4c06-6cea8e0e0000 pid=3726 /usr/bin/mktemp guuid=03c7752e-1b00-0000-4c06-6cea6b0e0000 pid=3691->guuid=e692273e-1b00-0000-4c06-6cea8e0e0000 pid=3726 execve guuid=89e97b3e-1b00-0000-4c06-6cea900e0000 pid=3728 /usr/bin/chmod guuid=03c7752e-1b00-0000-4c06-6cea6b0e0000 pid=3691->guuid=89e97b3e-1b00-0000-4c06-6cea900e0000 pid=3728 execve guuid=b756b53e-1b00-0000-4c06-6cea920e0000 pid=3730 /usr/bin/dash guuid=03c7752e-1b00-0000-4c06-6cea6b0e0000 pid=3691->guuid=b756b53e-1b00-0000-4c06-6cea920e0000 pid=3730 clone guuid=61accb3e-1b00-0000-4c06-6cea930e0000 pid=3731 /usr/bin/dash guuid=03c7752e-1b00-0000-4c06-6cea6b0e0000 pid=3691->guuid=61accb3e-1b00-0000-4c06-6cea930e0000 pid=3731 clone guuid=b0c7643f-1b00-0000-4c06-6cea960e0000 pid=3734 /usr/bin/dash guuid=03c7752e-1b00-0000-4c06-6cea6b0e0000 pid=3691->guuid=b0c7643f-1b00-0000-4c06-6cea960e0000 pid=3734 clone guuid=3f721b40-1b00-0000-4c06-6cea9b0e0000 pid=3739 /usr/bin/dash guuid=03c7752e-1b00-0000-4c06-6cea6b0e0000 pid=3691->guuid=3f721b40-1b00-0000-4c06-6cea9b0e0000 pid=3739 clone guuid=4a882d40-1b00-0000-4c06-6cea9c0e0000 pid=3740 /usr/bin/gpgv guuid=03c7752e-1b00-0000-4c06-6cea6b0e0000 pid=3691->guuid=4a882d40-1b00-0000-4c06-6cea9c0e0000 pid=3740 execve guuid=76dca843-1b00-0000-4c06-6ceaa20e0000 pid=3746 /usr/bin/rm delete-file guuid=03c7752e-1b00-0000-4c06-6cea6b0e0000 pid=3691->guuid=76dca843-1b00-0000-4c06-6ceaa20e0000 pid=3746 execve guuid=f8443e32-1b00-0000-4c06-6cea730e0000 pid=3699 /usr/bin/dpkg guuid=21e0c92e-1b00-0000-4c06-6cea6d0e0000 pid=3693->guuid=f8443e32-1b00-0000-4c06-6cea730e0000 pid=3699 execve guuid=aa5feb33-1b00-0000-4c06-6cea760e0000 pid=3702 /usr/bin/dpkg guuid=8acdd232-1b00-0000-4c06-6cea750e0000 pid=3701->guuid=aa5feb33-1b00-0000-4c06-6cea760e0000 pid=3702 execve guuid=85e36a35-1b00-0000-4c06-6cea7b0e0000 pid=3707 /usr/bin/dpkg guuid=28f06234-1b00-0000-4c06-6cea770e0000 pid=3703->guuid=85e36a35-1b00-0000-4c06-6cea7b0e0000 pid=3707 execve guuid=9d545a37-1b00-0000-4c06-6cea800e0000 pid=3712 /usr/bin/dpkg guuid=d4d30336-1b00-0000-4c06-6cea7c0e0000 pid=3708->guuid=9d545a37-1b00-0000-4c06-6cea800e0000 pid=3712 execve guuid=d3d9d838-1b00-0000-4c06-6cea850e0000 pid=3717 /usr/bin/dpkg guuid=8d69dd37-1b00-0000-4c06-6cea830e0000 pid=3715->guuid=d3d9d838-1b00-0000-4c06-6cea850e0000 pid=3717 execve guuid=0678d43e-1b00-0000-4c06-6cea940e0000 pid=3732 /usr/bin/dash guuid=61accb3e-1b00-0000-4c06-6cea930e0000 pid=3731->guuid=0678d43e-1b00-0000-4c06-6cea940e0000 pid=3732 clone guuid=6440dd3e-1b00-0000-4c06-6cea950e0000 pid=3733 /usr/bin/sed guuid=61accb3e-1b00-0000-4c06-6cea930e0000 pid=3731->guuid=6440dd3e-1b00-0000-4c06-6cea950e0000 pid=3733 execve guuid=d778713f-1b00-0000-4c06-6cea980e0000 pid=3736 /usr/bin/dash guuid=b0c7643f-1b00-0000-4c06-6cea960e0000 pid=3734->guuid=d778713f-1b00-0000-4c06-6cea980e0000 pid=3736 clone guuid=4b3a793f-1b00-0000-4c06-6cea990e0000 pid=3737 /usr/bin/sed guuid=b0c7643f-1b00-0000-4c06-6cea960e0000 pid=3734->guuid=4b3a793f-1b00-0000-4c06-6cea990e0000 pid=3737 execve guuid=7704e2c5-1c00-0000-4c06-6cea12130000 pid=4882 /usr/bin/dpkg guuid=1d3db9c4-1c00-0000-4c06-6cea11130000 pid=4881->guuid=7704e2c5-1c00-0000-4c06-6cea12130000 pid=4882 execve guuid=99a3f7c6-1c00-0000-4c06-6cea17130000 pid=4887->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 164B 75aab096-419b-50ef-be46-7d76b6a90e4c github.com:443 guuid=99a3f7c6-1c00-0000-4c06-6cea17130000 pid=4887->75aab096-419b-50ef-be46-7d76b6a90e4c send: 802B f8c5e44f-328d-5324-8bbd-da50752b9120 release-assets.githubusercontent.com:0 guuid=99a3f7c6-1c00-0000-4c06-6cea17130000 pid=4887->f8c5e44f-328d-5324-8bbd-da50752b9120 con f0eebea5-e97d-507c-a771-59cac353877c release-assets.githubusercontent.com:443 guuid=99a3f7c6-1c00-0000-4c06-6cea17130000 pid=4887->f0eebea5-e97d-507c-a771-59cac353877c send: 1660B guuid=ab4eabe4-1c00-0000-4c06-6cea79130000 pid=4985 /usr/bin/gzip guuid=8b2c3ce4-1c00-0000-4c06-6cea76130000 pid=4982->guuid=ab4eabe4-1c00-0000-4c06-6cea79130000 pid=4985 execve 1bb9f4ee-b940-5756-8449-f219f2617353 162.248.53.119:9443 guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5021->1bb9f4ee-b940-5756-8449-f219f2617353 send: 960B guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5040 /usr/lib/dev/systemdev/systemd-mont write-file guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5021->guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5040 clone guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5042 /usr/lib/dev/systemdev/systemd-mont guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5021->guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5042 clone guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5043 /usr/lib/dev/systemdev/systemd-mont guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5021->guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5043 clone guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5044 /usr/lib/dev/systemdev/systemd-mont guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5021->guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5044 clone guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5045 /usr/lib/dev/systemdev/systemd-mont guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5021->guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5045 clone guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5098 /usr/lib/dev/systemdev/systemd-mont guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5021->guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5098 clone guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5099 /usr/lib/dev/systemdev/systemd-mont guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5021->guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5099 clone guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5100 /usr/lib/dev/systemdev/systemd-mont guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5021->guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5100 clone guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5101 /usr/lib/dev/systemdev/systemd-mont guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5021->guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5101 clone guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5114 /usr/lib/dev/systemdev/systemd-mont guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5021->guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5114 clone guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5115 /usr/lib/dev/systemdev/systemd-mont guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5021->guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5115 clone guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5116 /usr/lib/dev/systemdev/systemd-mont guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5021->guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5116 clone guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5117 /usr/lib/dev/systemdev/systemd-mont guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5021->guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5117 clone guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5125 /usr/lib/dev/systemdev/systemd-mont guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5021->guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5125 clone guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5126 /usr/lib/dev/systemdev/systemd-mont guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5021->guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5126 clone guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5127 /usr/lib/dev/systemdev/systemd-mont guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5021->guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5127 clone guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5128 /usr/lib/dev/systemdev/systemd-mont guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5021->guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5128 clone guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5140 /usr/lib/dev/systemdev/systemd-mont guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5021->guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5140 clone guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5141 /usr/lib/dev/systemdev/systemd-mont guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5021->guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5141 clone guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5142 /usr/lib/dev/systemdev/systemd-mont guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5021->guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5142 clone guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5143 /usr/lib/dev/systemdev/systemd-mont guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5021->guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5143 clone guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5157 /usr/lib/dev/systemdev/systemd-mont guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5021->guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5157 clone guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5158 /usr/lib/dev/systemdev/systemd-mont guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5021->guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5158 clone guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5159 /usr/lib/dev/systemdev/systemd-mont guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5021->guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5159 clone guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5160 /usr/lib/dev/systemdev/systemd-mont guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5021->guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5160 clone guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5171 /usr/lib/dev/systemdev/systemd-mont guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5021->guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5171 clone guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5172 /usr/lib/dev/systemdev/systemd-mont guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5021->guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5172 clone guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5173 /usr/lib/dev/systemdev/systemd-mont guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5021->guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5173 clone guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5174 /usr/lib/dev/systemdev/systemd-mont guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5021->guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5174 clone guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5184 /usr/lib/dev/systemdev/systemd-mont guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5021->guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5184 clone guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5185 /usr/lib/dev/systemdev/systemd-mont guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5021->guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5185 clone guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5186 /usr/lib/dev/systemdev/systemd-mont guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5021->guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5186 clone guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5187 /usr/lib/dev/systemdev/systemd-mont guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5021->guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5187 clone guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5201 /usr/lib/dev/systemdev/systemd-mont guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5021->guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5201 clone guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5202 /usr/lib/dev/systemdev/systemd-mont guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5021->guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5202 clone guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5203 /usr/lib/dev/systemdev/systemd-mont guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5021->guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5203 clone guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5204 /usr/lib/dev/systemdev/systemd-mont guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5021->guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5204 clone guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5211 /usr/lib/dev/systemdev/systemd-mont guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5021->guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5211 clone guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5212 /usr/lib/dev/systemdev/systemd-mont guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5021->guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5212 clone guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5213 /usr/lib/dev/systemdev/systemd-mont guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5021->guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5213 clone guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5214 /usr/lib/dev/systemdev/systemd-mont guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5021->guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5214 clone guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5221 /usr/lib/dev/systemdev/systemd-mont guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5021->guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5221 clone guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5222 /usr/lib/dev/systemdev/systemd-mont guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5021->guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5222 clone guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5223 /usr/lib/dev/systemdev/systemd-mont guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5021->guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5223 clone guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5224 /usr/lib/dev/systemdev/systemd-mont guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5021->guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5224 clone guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5246 /usr/lib/dev/systemdev/systemd-mont guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5021->guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5246 clone guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5247 /usr/lib/dev/systemdev/systemd-mont guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5021->guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5247 clone guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5248 /usr/lib/dev/systemdev/systemd-mont guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5021->guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5248 clone guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5249 /usr/lib/dev/systemdev/systemd-mont guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5021->guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5249 clone guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5282 /usr/lib/dev/systemdev/systemd-mont guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5021->guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5282 clone guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5283 /usr/lib/dev/systemdev/systemd-mont guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5021->guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5283 clone guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5284 /usr/lib/dev/systemdev/systemd-mont guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5021->guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5284 clone guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5285 /usr/lib/dev/systemdev/systemd-mont guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5021->guuid=758cbcef-1c00-0000-4c06-6cea9d130000 pid=5285 clone
Verdict:
Malicious
Threat:
HEUR:Trojan-Downloader.Shell.Agent
Threat name:
Script.Trojan.Heuristic
Status:
Malicious
First seen:
2025-08-07 17:37:37 UTC
File Type:
Text (Shell)
AV detection:
8 of 24 (33.33%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  6/10
Tags:
antivm discovery execution linux persistence privilege_escalation
Behaviour
Enumerates kernel/hardware configuration
Reads runtime system information
Checks CPU configuration
Reads CPU attributes
Creates/modifies Cron job
Enumerates running processes
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments