| File name: | amd64 |
| Full analysis: | https://app.any.run/tasks/bf74a5c9-c189-45da-b1d2-1e9e5438f623 |
| Verdict: | Malicious activity |
| Analysis date: | August 19, 2024, 08:55:49 |
| OS: | Ubuntu 22.04.2 |
| MIME: | application/x-pie-executable |
| File info: | ELF 64-bit LSB pie executable, x86-64, version 1 (SYSV), for GNU/Linux 3.2.0, BuildID[sha1]=a5bdb209387e06cba305d4d5db76c52b7cb6ea26, dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, no section header |
| MD5: | B5C92EA2DE82DCC743A736DDFEBA73DF |
| SHA1: | A36673E8D26E842A6C1FDAFA796E965BE9D83E55 |
| SHA256: | 1211514B612E2E902B41167BA361073C7A233473E65D8839F1BAC7A6AE1165A0 |
| SSDEEP: | 98304:LUP5XVpqBAekkUxaOhtK2vZRNt5tCdQZSCr8fd4v1oc2:61u |
| .o | | | ELF Executable and Linkable format (generic) (49.8) |
|---|
| CPUArchitecture: | 64 bit |
|---|---|
| CPUByteOrder: | Little endian |
| ObjectFileType: | Shared object file |
| CPUType: | AMD x86-64 |
PID | CMD | Path | Indicators | Parent process |
|---|---|---|---|---|
| 12938 | /bin/sh -c "sudo chown user /tmp/amd64\.o && chmod +x /tmp/amd64\.o && DISPLAY=:0 sudo -i /tmp/amd64\.o " | /bin/sh | — | any-guest-agent |
User: user Integrity Level: UNKNOWN Exit code: 482 | ||||
| 12939 | sudo chown user /tmp/amd64.o | /usr/bin/sudo | — | sh |
User: user Integrity Level: UNKNOWN Exit code: 0 | ||||
| 12940 | chown user /tmp/amd64.o | /usr/bin/chown | — | sudo |
User: root Integrity Level: UNKNOWN Exit code: 0 | ||||
| 12941 | chmod +x /tmp/amd64.o | /usr/bin/chmod | — | sh |
User: user Integrity Level: UNKNOWN Exit code: 0 | ||||
| 12942 | sudo -i /tmp/amd64.o | /usr/bin/sudo | — | sh |
User: user Integrity Level: UNKNOWN Exit code: 482 | ||||
| 12944 | /tmp/amd64.o | /tmp/amd64.o | — | sudo |
User: root Integrity Level: UNKNOWN Exit code: 482 | ||||
| 12945 | /usr/bin/locale-check C.UTF-8 | /usr/bin/locale-check | — | amd64.o |
User: root Integrity Level: UNKNOWN Exit code: 0 | ||||
| 12946 | -bash --login -c \/tmp\/amd64\.o | /usr/bin/bash | — | amd64.o |
User: root Integrity Level: UNKNOWN Exit code: 0 | ||||
| 12947 | sh -c "cat /usr/etc/debuginfod/*\.urls 2>/dev/null" | /usr/bin/sh | — | bash |
User: root Integrity Level: UNKNOWN Exit code: 0 | ||||
| 12948 | tr \n " " | /usr/bin/tr | — | bash |
User: root Integrity Level: UNKNOWN Exit code: 0 | ||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 12944 | amd64.o | /tmp/fileMmK6Jn | o | |
MD5:— | SHA256:— | |||
| 12944 | amd64.o | /usr/bin/ls | binary | |
MD5:— | SHA256:— | |||
| 12959 | amd64.o | /tmp/fileBNWFOI | o | |
MD5:— | SHA256:— | |||
| 12960 | fileBNWFOI | /etc/.cfg | text | |
MD5:— | SHA256:— | |||
| 13108 | fileo6e70j | /etc/.cfg | text | |
MD5:— | SHA256:— | |||
| 13124 | fileHz0F0q | /etc/.cfg | text | |
MD5:— | SHA256:— | |||
| 13142 | fileQ2PSgR | /etc/.cfg | text | |
MD5:— | SHA256:— | |||
| 13175 | filewZqyW7 | /etc/.cfg | text | |
MD5:— | SHA256:— | |||
| 12960 | fileBNWFOI | /boot/system.pub | o | |
MD5:— | SHA256:— | |||
| 12989 | ls | /tmp/fileILSL0C (deleted) | o | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 204 | 91.189.91.97:80 | http://connectivity-check.ubuntu.com/ | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 185.125.190.17:80 | connectivity-check.ubuntu.com | Canonical Group Limited | GB | unknown |
470 | avahi-daemon | 224.0.0.251:5353 | — | — | — | unknown |
— | — | 185.125.190.97:80 | connectivity-check.ubuntu.com | Canonical Group Limited | GB | unknown |
— | — | 207.211.211.27:443 | odrs.gnome.org | — | US | unknown |
— | — | 91.189.91.97:80 | connectivity-check.ubuntu.com | Canonical Group Limited | US | unknown |
— | — | 185.125.188.59:443 | api.snapcraft.io | Canonical Group Limited | GB | unknown |
— | — | 209.141.53.247:7788 | botbot.ddosvps.cc | PONYNET | US | unknown |
12960 | fileBNWFOI | 209.141.53.247:7788 | botbot.ddosvps.cc | PONYNET | US | unknown |
485 | snapd | 185.125.188.59:443 | api.snapcraft.io | Canonical Group Limited | GB | unknown |
13149 | check-new-release-gtk | 91.189.91.49:443 | connectivity-check.ubuntu.com | Canonical Group Limited | US | unknown |
Domain | IP | Reputation |
|---|---|---|
connectivity-check.ubuntu.com |
| whitelisted |
google.com |
| whitelisted |
odrs.gnome.org |
| whitelisted |
api.snapcraft.io |
| whitelisted |
176.100.168.192.in-addr.arpa |
| unknown |
botbot.ddosvps.cc |
| unknown |
changelogs.ubuntu.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
— | — | Potentially Bad Traffic | ET DNS Query for .cc TLD |
— | — | Potentially Bad Traffic | ET DNS Query for .cc TLD |
12960 | fileBNWFOI | Potentially Bad Traffic | ET DNS Query for .cc TLD |
12960 | fileBNWFOI | Potentially Bad Traffic | ET DNS Query for .cc TLD |
12960 | fileBNWFOI | Potentially Bad Traffic | ET DNS Query for .cc TLD |
12960 | fileBNWFOI | Potentially Bad Traffic | ET DNS Query for .cc TLD |
12960 | fileBNWFOI | Potentially Bad Traffic | ET DNS Query for .cc TLD |
12960 | fileBNWFOI | Potentially Bad Traffic | ET DNS Query for .cc TLD |
12960 | fileBNWFOI | Potentially Bad Traffic | ET DNS Query for .cc TLD |
12960 | fileBNWFOI | Potentially Bad Traffic | ET DNS Query for .cc TLD |