| File name: | application.gz |
| Full analysis: | https://app.any.run/tasks/1f96f1e3-7da0-4b6a-8fff-16d70a5d93dd |
| Verdict: | Malicious activity |
| Analysis date: | May 03, 2024, 01:49:36 |
| OS: | Ubuntu 22.04.2 |
| MIME: | application/gzip |
| File info: | gzip compressed data, from Unix, original size modulo 2^32 1402 |
| MD5: | 58DABAC4471F37C945F50A6041236D51 |
| SHA1: | 6E3C15DF01EE5147DB59DF21FADF25B949F3AACF |
| SHA256: | 344D86AEDF7F6F83AB2C29B369485C04CF7D54D7EE3A9F22FD9CA5552A2BF30F |
| SSDEEP: | 48:wn+Av5O2px4k5PneLcTl7KaIB/IDloQqgOEB5HKn:wn+AM2px4ktnJp7KaIB/eGvEB5HK |
| .z/gz/gzip | | | GZipped data (100) |
|---|
| Compression: | Deflated |
|---|---|
| Flags: | (none) |
| ModifyDate: | 0000:00:00 00:00:00 |
| ExtraFlags: | (none) |
| OperatingSystem: | Unix |
PID | CMD | Path | Indicators | Parent process |
|---|---|---|---|---|
| 9263 | /bin/sh -c "DISPLAY=:0 sudo -iu user file-roller /home/user/Desktop/application\.gz " | /bin/sh | — | any-guest-agent |
User: user Integrity Level: UNKNOWN | ||||
| 9264 | sudo -iu user file-roller /home/user/Desktop/application.gz | /usr/bin/sudo | — | sh |
User: user Integrity Level: UNKNOWN | ||||
| 9265 | file-roller /home/user/Desktop/application.gz | /usr/bin/file-roller | — | sudo |
User: user Integrity Level: UNKNOWN | ||||
| 9266 | /usr/bin/locale-check C.UTF-8 | /usr/bin/locale-check | — | file-roller |
User: user Integrity Level: UNKNOWN Exit code: 0 | ||||
| 9280 | gzip -l -q /home/user/Desktop/application.gz | /usr/bin/gzip | — | file-roller |
User: user Integrity Level: UNKNOWN Exit code: 9265 | ||||
| 9281 | cp -f /home/user/Desktop/application.gz /home/user/.cache/.fr-gDgkKn/application.gz | /usr/bin/cp | — | file-roller |
User: user Integrity Level: UNKNOWN Exit code: 9265 | ||||
| 9282 | gzip -f -d -n /home/user/.cache/.fr-gDgkKn/application.gz | /usr/bin/gzip | — | file-roller |
User: user Integrity Level: UNKNOWN Exit code: 496 | ||||
| 9283 | cp -f /home/user/.cache/.fr-gDgkKn/application /home/user/.cache/.fr-rjbERD/application | /usr/bin/cp | — | file-roller |
User: user Integrity Level: UNKNOWN Exit code: 496 | ||||
| 9284 | rm -rf /home/user/.cache/.fr-gDgkKn | /usr/bin/rm | — | file-roller |
User: user Integrity Level: UNKNOWN Exit code: 496 | ||||
| 9304 | /lib/systemd/systemd-hostnamed | /lib/systemd/systemd-hostnamed | — | systemd |
User: root Integrity Level: UNKNOWN Exit code: 9314 | ||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 9265 | file-roller | /dconf/user | — | |
MD5:— | SHA256:— | |||
| 9265 | file-roller | /home/user/.local/share/recently-used.xbel.EC31M2 | — | |
MD5:— | SHA256:— | |||
| 9281 | cp | /home/user/.cache/.fr-gDgkKn/application.gz | — | |
MD5:— | SHA256:— | |||
| 9282 | gzip | /home/user/.cache/.fr-gDgkKn/application | — | |
MD5:— | SHA256:— | |||
| 9283 | cp | /home/user/.cache/.fr-rjbERD/application | — | |
MD5:— | SHA256:— | |||
| 9307 | cp | /home/user/.cache/.fr-efmoiL/application.gz | — | |
MD5:— | SHA256:— | |||
| 9309 | gzip | /home/user/.cache/.fr-efmoiL/application | — | |
MD5:— | SHA256:— | |||
| 9310 | cp | /home/user/Documents/application | — | |
MD5:— | SHA256:— | |||
| 9265 | file-roller | /home/user/.local/share/recently-used.xbel.O3R6M2 | — | |
MD5:— | SHA256:— | |||
| 9320 | nautilus | /home/user/.local/share/nautilus/tags/meta.db-wal | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 204 | 185.125.190.98:80 | http://connectivity-check.ubuntu.com/ | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 224.0.0.251:5353 | — | — | — | unknown |
— | — | 185.125.190.98:80 | — | Canonical Group Limited | GB | unknown |
— | — | 91.189.91.49:80 | — | Canonical Group Limited | US | unknown |
— | — | 185.125.188.55:443 | api.snapcraft.io | Canonical Group Limited | GB | unknown |
— | — | 185.125.188.54:443 | api.snapcraft.io | Canonical Group Limited | GB | unknown |
Domain | IP | Reputation |
|---|---|---|
169.100.168.192.in-addr.arpa |
| unknown |
connectivity-check.ubuntu.com |
| unknown |
api.snapcraft.io |
| unknown |