| File name: | Security alert_ new or unusual X login.eml |
| Full analysis: | https://app.any.run/tasks/8b1cb7aa-3c63-4ac8-bbc3-d10f35a621e4 |
| Verdict: | Malicious activity |
| Analysis date: | April 09, 2024, 13:28:23 |
| OS: | Ubuntu 22.04.2 |
| Tags: | |
| Indicators: | |
| MIME: | message/rfc822 |
| File info: | RFC 822 mail, ASCII text, with CRLF line terminators |
| MD5: | DCCBE40B2CA745045A0D8458D10788FB |
| SHA1: | 328726D030A7B077D84CA6AC0BBA38E1B1B5C8C4 |
| SHA256: | 18AED834DFAAF50ED61F5693927E3D899411602593C433B3D63023837847ACEE |
| SSDEEP: | 768:ll/vRsIAq1vHfzX9LhpulAwKCfCXHCCsJrs3:llR33ZElAwKBXHsJrs3 |
| .eml | | | E-Mail message (Var. 5) (100) |
|---|
PID | CMD | Path | Indicators | Parent process |
|---|---|---|---|---|
| 9307 | /bin/sh -c "DISPLAY=:0 sudo -iu user nautilus \"/tmp/Security alert_ new or unusual X login\.eml\" " | /bin/sh | — | any-guest-agent |
User: user Integrity Level: UNKNOWN | ||||
| 9308 | sudo -iu user nautilus "/tmp/Security alert_ new or unusual X login\.eml" | /usr/bin/sudo | — | sh |
User: user Integrity Level: UNKNOWN | ||||
| 9309 | nautilus "/tmp/Security alert_ new or unusual X login\.eml" | /usr/bin/nautilus | — | sudo |
User: user Integrity Level: UNKNOWN | ||||
| 9310 | /usr/bin/locale-check C.UTF-8 | /usr/bin/locale-check | — | nautilus |
User: user Integrity Level: UNKNOWN Exit code: 0 | ||||
| 9331 | /lib/systemd/systemd-hostnamed | /lib/systemd/systemd-hostnamed | — | systemd |
User: root Integrity Level: UNKNOWN | ||||
| 9338 | nautilus "/tmp/Security alert_ new or unusual X login\.eml" | /usr/bin/nautilus | — | nautilus |
User: user Integrity Level: UNKNOWN Exit code: 496 | ||||
| 9339 | /usr/lib/thunderbird/thunderbird "/tmp/Security alert_ new or unusual X login\.eml" | /usr/lib/thunderbird/thunderbird | — | nautilus |
User: user Integrity Level: UNKNOWN | ||||
| 9341 | /bin/sh /usr/bin/which /usr/bin/thunderbird | /usr/bin/which | — | thunderbird |
User: user Integrity Level: UNKNOWN Exit code: 496 | ||||
| 9342 | /usr/lib/thunderbird/thunderbird "/tmp/Security alert_ new or unusual X login\.eml" | /usr/lib/thunderbird/thunderbird | — | thunderbird |
User: user Integrity Level: UNKNOWN Exit code: 496 | ||||
| 9347 | /usr/lib/thunderbird/glxtest -f 12 | /usr/lib/thunderbird/glxtest | — | thunderbird |
User: user Integrity Level: UNKNOWN Exit code: 496 | ||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 9309 | nautilus | /home/user/.local/share/nautilus/tags/meta.db-wal | — | |
MD5:— | SHA256:— | |||
| 9309 | nautilus | /home/user/.local/share/nautilus/tags/meta.db-shm | — | |
MD5:— | SHA256:— | |||
| 9309 | nautilus | /home/user/.local/share/nautilus/tags/.meta.isrunning | — | |
MD5:— | SHA256:— | |||
| 9339 | thunderbird | /home/user/.thunderbird/Crash Reports/InstallTime20231024181440 | — | |
MD5:— | SHA256:— | |||
| 9339 | thunderbird | /tmp/thunderbird/.parentlock | — | |
MD5:— | SHA256:— | |||
| 9339 | thunderbird | /home/user/.thunderbird/s8bbvwlb.default-release/times.json | — | |
MD5:— | SHA256:— | |||
| 9339 | thunderbird | /home/user/.thunderbird/hvu18slo.default/times.json | — | |
MD5:— | SHA256:— | |||
| 9339 | thunderbird | /home/user/.thunderbird/installs.ini | — | |
MD5:— | SHA256:— | |||
| 9339 | thunderbird | /home/user/.thunderbird/profiles.ini | — | |
MD5:— | SHA256:— | |||
| 9339 | thunderbird | /home/user/.thunderbird/s8bbvwlb.default-release/.parentlock | — | |
MD5:— | SHA256:— | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 212.102.56.178:443 | — | Datacamp Limited | DE | unknown |
— | — | 224.0.0.251:5353 | — | — | — | unknown |
— | — | 212.102.56.181:443 | — | Datacamp Limited | DE | unknown |
— | — | 13.224.189.48:443 | services.addons.thunderbird.net | AMAZON-02 | US | unknown |
— | — | 185.125.188.59:443 | api.snapcraft.io | Canonical Group Limited | GB | unknown |
— | — | 185.125.188.55:443 | api.snapcraft.io | Canonical Group Limited | GB | unknown |
Domain | IP | Reputation |
|---|---|---|
connectivity-check.ubuntu.com |
| unknown |
83.100.168.192.in-addr.arpa |
| unknown |
services.addons.thunderbird.net |
| whitelisted |
api.snapcraft.io |
| unknown |