| File name: | CamXploit-main.zip |
| Full analysis: | https://app.any.run/tasks/85ca35db-7185-4ad9-9f87-9f75fba1b638 |
| Verdict: | Malicious activity |
| Analysis date: | April 29, 2025, 07:20:48 |
| OS: | Ubuntu 22.04.2 |
| Tags: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v1.0 to extract, compression method=store |
| MD5: | 8CE66D9CBA0BDB05A4504E3A41102B25 |
| SHA1: | 338E500E4A8F35058F20D779611864C5D3B6B66E |
| SHA256: | 2DDC6C88BB226A0BF5581DB23055095EFF35C14B5E9F8B9A53F2E256138475ED |
| SSDEEP: | 12288:jDx++IpVLI5yHRuHla+i4hiRM9Qz1ExSKnpCIa:jDx++IpVPHRuFa+5iRM9QyxScpCIa |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 10 |
|---|---|
| ZipBitFlag: | - |
| ZipCompression: | None |
| ZipModifyDate: | 2025:04:28 07:12:46 |
| ZipCRC: | 0x00000000 |
| ZipCompressedSize: | - |
| ZipUncompressedSize: | - |
| ZipFileName: | CamXploit-main/ |
PID | CMD | Path | Indicators | Parent process |
|---|---|---|---|---|
| 445 | /lib/systemd/systemd-resolved | /usr/lib/systemd/systemd-resolved | systemd | |
User: systemd-resolve Integrity Level: UNKNOWN | ||||
| 40664 | /bin/sh -c "DISPLAY=:0 sudo -iu user file-roller /tmp/CamXploit-main\.zip " | /usr/bin/dash | — | any-guest-agent |
User: user Integrity Level: UNKNOWN | ||||
| 40665 | sudo -iu user file-roller /tmp/CamXploit-main.zip | /usr/bin/sudo | — | dash |
User: root Integrity Level: UNKNOWN | ||||
| 40666 | file-roller /tmp/CamXploit-main.zip | /usr/bin/file-roller | — | sudo |
User: user Integrity Level: UNKNOWN | ||||
| 40667 | /usr/bin/locale-check C.UTF-8 | /usr/bin/locale-check | — | file-roller |
User: user Integrity Level: UNKNOWN Exit code: 0 | ||||
| 40682 | /usr/lib/p7zip/7z l -slt -bd -y -- /tmp/CamXploit-main.zip | /usr/lib/p7zip/7z | — | file-roller |
User: user Integrity Level: UNKNOWN Exit code: 0 | ||||
| 40683 | systemctl --user --global is-enabled snap.snapd-desktop-integration.snapd-desktop-integration.service | /usr/bin/systemctl | — | snapd |
User: root Integrity Level: UNKNOWN Exit code: 0 | ||||
| 40685 | systemctl --user --global is-enabled snap.snapd-desktop-integration.snapd-desktop-integration.service | /usr/bin/systemctl | — | snapd |
User: root Integrity Level: UNKNOWN Exit code: 0 | ||||
| 40686 | systemctl --user --global is-enabled snap.snapd-desktop-integration.snapd-desktop-integration.service | /usr/bin/systemctl | — | snapd |
User: root Integrity Level: UNKNOWN Exit code: 0 | ||||
| 40687 | systemctl --user --global is-enabled snap.snapd-desktop-integration.snapd-desktop-integration.service | /usr/bin/systemctl | — | snapd |
User: root Integrity Level: UNKNOWN Exit code: 0 | ||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 40719 | 7z | /home/user/Desktop/CamXploit-main/CCTV recon.jpg | image | |
MD5:— | SHA256:— | |||
| 40719 | 7z | /home/user/Desktop/CamXploit-main/CamXploit.py | text | |
MD5:— | SHA256:— | |||
| 40719 | 7z | /home/user/Desktop/CamXploit-main/LICENSE | text | |
MD5:— | SHA256:— | |||
| 40719 | 7z | /home/user/Desktop/CamXploit-main/README.md | html | |
MD5:— | SHA256:— | |||
| 40719 | 7z | /home/user/Desktop/CamXploit-main/demo.png | image | |
MD5:— | SHA256:— | |||
| 40719 | 7z | /home/user/Desktop/CamXploit-main/requirements.txt | text | |
MD5:— | SHA256:— | |||
| 40666 | file-roller | /home/user/.local/share/recently-used.xbel | xml | |
MD5:— | SHA256:— | |||
| 40735 | nautilus | /tmp/flatpak-seccomp-Y2N052 (deleted) | binary | |
MD5:— | SHA256:— | |||
| 40735 | nautilus | /home/user/.cache/thumbnails/large/b627d4550cbd6f616ef97cc8001e73a2.png.EQD252 | binary | |
MD5:— | SHA256:— | |||
| 40735 | nautilus | /tmp/flatpak-seccomp-ZHT152 (deleted) | binary | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 204 | 91.189.91.97:80 | http://connectivity-check.ubuntu.com/ | unknown | — | — | whitelisted |
— | — | GET | 204 | 91.189.91.97:80 | http://connectivity-check.ubuntu.com/ | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 91.189.91.97:80 | — | Canonical Group Limited | US | unknown |
484 | avahi-daemon | 224.0.0.251:5353 | — | — | — | unknown |
— | — | 195.181.170.18:443 | odrs.gnome.org | Datacamp Limited | DE | whitelisted |
512 | snapd | 185.125.188.55:443 | api.snapcraft.io | Canonical Group Limited | GB | whitelisted |
512 | snapd | 185.125.188.58:443 | api.snapcraft.io | Canonical Group Limited | GB | whitelisted |
512 | snapd | 185.125.188.59:443 | api.snapcraft.io | Canonical Group Limited | GB | whitelisted |
512 | snapd | 185.125.188.54:443 | api.snapcraft.io | Canonical Group Limited | GB | whitelisted |
40705 | gvfsd-smb-browse | 192.168.100.255:137 | — | — | — | whitelisted |
40792 | python3.10 | 34.117.59.81:443 | ipinfo.io | GOOGLE-CLOUD-PLATFORM | US | whitelisted |
40792 | python3.10 | 129.23.232.233:80 | — | — | US | unknown |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |
odrs.gnome.org |
| whitelisted |
api.snapcraft.io |
| whitelisted |
4.100.168.192.in-addr.arpa |
| unknown |
connectivity-check.ubuntu.com |
| whitelisted |
ipinfo.io |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
445 | systemd-resolved | Device Retrieving External IP Address Detected | ET INFO External IP Lookup Domain in DNS Lookup (ipinfo .io) |
445 | systemd-resolved | Device Retrieving External IP Address Detected | ET INFO External IP Lookup Domain in DNS Lookup (ipinfo .io) |
40792 | python3.10 | Device Retrieving External IP Address Detected | ET INFO Possible External IP Lookup Domain Observed in SNI (ipinfo. io) |