| File name: | brutils_2.7-0_amd64.deb |
| Full analysis: | https://app.any.run/tasks/4c7b9ce2-7009-4ec3-b02e-e9326b86e610 |
| Verdict: | Malicious activity |
| Analysis date: | April 29, 2025, 11:38:21 |
| OS: | Ubuntu 22.04.2 |
| MIME: | application/vnd.debian.binary-package |
| File info: | Debian binary package (format 2.0), with control.tar.xz , data compression xz |
| MD5: | 480011A6E71DB7E49883CB6B76959FE1 |
| SHA1: | 123D952C035FF656D58B526A56A27D924B813EA4 |
| SHA256: | 172AFBEB056712EAA355934676EB40B3922C0F6F5A7524453F98873F2D791936 |
| SSDEEP: | 24576:4o9GkJeNMCB/3QDjDvRoNpxlBDrnMzEC11Z8Ilvi:4o9GkwNMCB/3kjDvRoNpxlBDrnMzEC1m |
| .deb | | | Debian Linux Package (77.4) |
|---|---|---|
| .ar | | | ar archive (22.5) |
| CreateDate: | 2024:01:08 09:15:23+00:00 |
|---|
PID | CMD | Path | Indicators | Parent process |
|---|---|---|---|---|
| 40656 | /bin/sh -c "DISPLAY=:0 sudo -iu user sudo dpkg -i /tmp/brutils_2\.7-0_amd64\.deb " | /usr/bin/dash | — | any-guest-agent |
User: user Integrity Level: UNKNOWN Exit code: 256 | ||||
| 40657 | sudo -iu user sudo dpkg -i /tmp/brutils_2.7-0_amd64.deb | /usr/bin/sudo | — | dash |
User: root Integrity Level: UNKNOWN Exit code: 256 | ||||
| 40659 | systemctl --user --global is-enabled snap.snapd-desktop-integration.snapd-desktop-integration.service | /usr/bin/systemctl | — | snapd |
User: root Integrity Level: UNKNOWN Exit code: 0 | ||||
| 40661 | sudo dpkg -i /tmp/brutils_2.7-0_amd64.deb | /usr/bin/sudo | — | sudo |
User: root Integrity Level: UNKNOWN Exit code: 256 | ||||
| 40662 | /usr/bin/locale-check C.UTF-8 | /usr/bin/locale-check | — | sudo |
User: user Integrity Level: UNKNOWN Exit code: 0 | ||||
| 40663 | dpkg -i /tmp/brutils_2.7-0_amd64.deb | /usr/bin/dpkg | — | sudo |
User: root Integrity Level: UNKNOWN Exit code: 256 | ||||
| 40664 | dpkg-split -Qao /var/lib/dpkg/reassemble.deb /tmp/brutils_2.7-0_amd64.deb | /usr/bin/dpkg-split | — | dpkg |
User: root Integrity Level: UNKNOWN Exit code: 256 | ||||
| 40665 | dpkg-deb --control /tmp/brutils_2.7-0_amd64.deb /var/lib/dpkg/tmp.ci | /usr/bin/dpkg-deb | — | dpkg |
User: root Integrity Level: UNKNOWN Exit code: 0 | ||||
| 40666 | dpkg-deb --control /tmp/brutils_2.7-0_amd64.deb /var/lib/dpkg/tmp.ci | /usr/bin/dpkg-deb | — | dpkg-deb |
User: root Integrity Level: UNKNOWN Exit code: 0 | ||||
| 40667 | dpkg-deb --control /tmp/brutils_2.7-0_amd64.deb /var/lib/dpkg/tmp.ci | /usr/bin/dpkg-deb | — | dpkg-deb |
User: root Integrity Level: UNKNOWN Exit code: 0 | ||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 40668 | tar | /var/lib/dpkg/tmp.ci/conffiles | text | |
MD5:— | SHA256:— | |||
| 40668 | tar | /var/lib/dpkg/tmp.ci/control | text | |
MD5:— | SHA256:— | |||
| 40668 | tar | /var/lib/dpkg/tmp.ci/md5sums | text | |
MD5:— | SHA256:— | |||
| 40663 | dpkg | /var/lib/dpkg/tmp.ci/conffiles | text | |
MD5:— | SHA256:— | |||
| 40663 | dpkg | /var/lib/dpkg/tmp.ci/control | text | |
MD5:— | SHA256:— | |||
| 40663 | dpkg | /var/lib/dpkg/tmp.ci/md5sums | text | |
MD5:— | SHA256:— | |||
| 40663 | dpkg | /var/lib/dpkg/updates/0000 | text | |
MD5:— | SHA256:— | |||
| 40663 | dpkg | /etc/brutils/local.conf.dpkg-new | text | |
MD5:— | SHA256:— | |||
| 40663 | dpkg | /usr/sbin/brutils | text | |
MD5:— | SHA256:— | |||
| 40663 | dpkg | /usr/share/brutils/backup/BLOCKCLONE/default/400_copy_disk_struct_files.sh | text | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 204 | 91.189.91.98:80 | http://connectivity-check.ubuntu.com/ | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 185.125.190.49:80 | — | Canonical Group Limited | GB | unknown |
— | — | 185.125.190.98:80 | — | Canonical Group Limited | GB | unknown |
484 | avahi-daemon | 224.0.0.251:5353 | — | — | — | unknown |
— | — | 91.189.91.98:80 | — | Canonical Group Limited | US | unknown |
— | — | 195.181.170.19:443 | odrs.gnome.org | Datacamp Limited | DE | whitelisted |
— | — | 185.125.188.58:443 | api.snapcraft.io | Canonical Group Limited | GB | whitelisted |
512 | snapd | 185.125.188.55:443 | api.snapcraft.io | Canonical Group Limited | GB | whitelisted |
512 | snapd | 185.125.188.54:443 | api.snapcraft.io | Canonical Group Limited | GB | whitelisted |
512 | snapd | 185.125.188.59:443 | api.snapcraft.io | Canonical Group Limited | GB | whitelisted |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |
odrs.gnome.org |
| whitelisted |
api.snapcraft.io |
| whitelisted |
4.100.168.192.in-addr.arpa |
| unknown |
connectivity-check.ubuntu.com |
| whitelisted |