| File name: | .diicot |
| Full analysis: | https://app.any.run/tasks/70f5cbe0-9180-471f-8fad-ecf71b8b792f |
| Verdict: | Malicious activity |
| Threats: | Crypto mining malware is a resource-intensive threat that infiltrates computers with the purpose of mining cryptocurrencies. This type of threat can be deployed either on an infected machine or a compromised website. In both cases the miner will utilize the computing power of the device and its network bandwidth. |
| Analysis date: | March 21, 2024, 16:14:59 |
| OS: | Ubuntu 22.04.2 |
| Tags: | |
| Indicators: | |
| MIME: | application/x-executable |
| File info: | ELF 64-bit LSB executable, x86-64, version 1 (GNU/Linux), statically linked, no section header |
| MD5: | F0962F1BEA790116674333F1EC70FB20 |
| SHA1: | B4534C33DED292B9D2E78927D415526663E111AF |
| SHA256: | 402291E80A48CE927C059A3348FDF08EF7DB4FB461AB28BF16631D9E4C747C81 |
| SSDEEP: | 12288:CvT10wOXna46mIcHhtHDbGb0eWdOMWvE6rBZ:CL10wga46mIChtHub0eWdOMWvEEBZ |
| .o | | | ELF Executable and Linkable format (generic) (100) |
|---|
| CPUArchitecture: | 64 bit |
|---|---|
| CPUByteOrder: | Little endian |
| ObjectFileType: | Executable file |
| CPUType: | AMD x86-64 |
PID | CMD | Path | Indicators | Parent process |
|---|---|---|---|---|
| 9262 | /bin/sh -c "sudo chown user \"/tmp/70f5cbe0-9180-471f-8fad-ecf71b8b792f\.o\" && chmod +x \"/tmp/70f5cbe0-9180-471f-8fad-ecf71b8b792f\.o\" && DISPLAY=:0 sudo -i \"/tmp/70f5cbe0-9180-471f-8fad-ecf71b8b792f\.o\" " | /bin/sh | — | any-guest-agent |
User: user Integrity Level: UNKNOWN Exit code: 9354 | ||||
| 9263 | sudo chown user /tmp/70f5cbe0-9180-471f-8fad-ecf71b8b792f.o | /usr/bin/sudo | — | sh |
User: user Integrity Level: UNKNOWN Exit code: 0 | ||||
| 9264 | chown user /tmp/70f5cbe0-9180-471f-8fad-ecf71b8b792f.o | /usr/bin/chown | — | sudo |
User: root Integrity Level: UNKNOWN Exit code: 0 | ||||
| 9265 | chmod +x /tmp/70f5cbe0-9180-471f-8fad-ecf71b8b792f.o | /usr/bin/chmod | — | sh |
User: user Integrity Level: UNKNOWN Exit code: 0 | ||||
| 9266 | sudo -i /tmp/70f5cbe0-9180-471f-8fad-ecf71b8b792f.o | /usr/bin/sudo | — | sh |
User: user Integrity Level: UNKNOWN Exit code: 9354 | ||||
| 9267 | /tmp/70f5cbe0-9180-471f-8fad-ecf71b8b792f.o -c | /bin/bash | — | sudo |
User: root Integrity Level: UNKNOWN Exit code: 9354 | ||||
| 9268 | /usr/bin/locale-check C.UTF-8 | /usr/bin/locale-check | — | bash |
User: root Integrity Level: UNKNOWN Exit code: 0 | ||||
| 9269 | -bash --login -c \/tmp\/70f5cbe0-9180-471f-8fad-ecf71b8b792f\.o | /usr/bin/bash | — | bash |
User: root Integrity Level: UNKNOWN Exit code: 0 | ||||
| 9270 | sh -c "cat /usr/etc/debuginfod/*\.urls 2>/dev/null" | /usr/bin/sh | — | bash |
User: root Integrity Level: UNKNOWN Exit code: 0 | ||||
| 9271 | tr \n " " | /usr/bin/tr | — | bash |
User: root Integrity Level: UNKNOWN Exit code: 0 | ||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 9267 | bash | /var/tmp/.ladyg0g0/.pr1nc35 | — | |
MD5:— | SHA256:— | |||
| 9267 | bash | /usr/bin/.locatione | — | |
MD5:— | SHA256:— | |||
| 9283 | awk | /var/tmp/x.sh | — | |
MD5:— | SHA256:— | |||
| 9287 | wget | /var/tmp/Documents/Opera | — | |
MD5:— | SHA256:— | |||
| 9267 | bash | /var/tmp/Documents/config.json | — | |
MD5:— | SHA256:— | |||
| 9267 | bash | /root/.ssh/authorized_keys | — | |
MD5:— | SHA256:— | |||
| 9267 | bash | /var/tmp/Documents/.5p4rk3l5 | — | |
MD5:— | SHA256:— | |||
| 9323 | crontab | /var/spool/cron/crontabs/tmp.mMwYmO | — | |
MD5:— | SHA256:— | |||
| 9267 | bash | /var/tmp/Documents/.b4nd1d0 | — | |
MD5:— | SHA256:— | |||
| 9267 | bash | /usr/bin/sshd | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 200 | 94.156.68.141:80 | http://94.156.68.141/.NzJjOTYw/Opera | BG | binary | 7.66 Mb | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 185.125.188.54:443 | api.snapcraft.io | Canonical Group Limited | GB | unknown |
— | — | 185.125.188.55:443 | api.snapcraft.io | Canonical Group Limited | GB | unknown |
— | — | 185.125.188.59:443 | api.snapcraft.io | Canonical Group Limited | GB | unknown |
— | — | 224.0.0.251:5353 | — | — | — | unknown |
— | — | 94.156.68.141:80 | — | Terasyst Ltd | BG | unknown |
— | — | 91.92.251.113:7777 | — | Natskovi & Sie Ltd. | BG | unknown |
Domain | IP | Reputation |
|---|---|---|
api.snapcraft.io |
| unknown |
27.100.168.192.in-addr.arpa |
| unknown |
connectivity-check.ubuntu.com |
| unknown |
PID | Process | Class | Message |
|---|---|---|---|
— | — | Potential Corporate Privacy Violation | ET POLICY Executable and linking format (ELF) file download Over HTTP |
— | — | Potential Corporate Privacy Violation | ET POLICY Cryptocurrency Miner Checkin |
— | — | Misc Attack | ET DROP Spamhaus DROP Listed Traffic Inbound group 7 |