URL: | https://github.com/DRMStuff/o11-OTT-v2.2b1/tree/main |
Full analysis: | https://app.any.run/tasks/71df6d5b-68b6-4dcf-9f07-607e1b30726a |
Verdict: | Malicious activity |
Analysis date: | June 17, 2024, 20:04:37 |
OS: | Ubuntu 22.04.2 |
MD5: | 07C4FB98CE0588ED764197967DC675F3 |
SHA1: | 1548C6D2E5C3CF2B0167A0A9A7C95C1859C344C8 |
SHA256: | 4F5C08F258CEA4C95FD9D95FCB5AD90E428E9AAF18FB8C90D47AB8BDE81E0ECD |
SSDEEP: | 3:N8tEdvWWsIqY7TGATRn:2uVsIf77TRn |
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
12916 | /bin/sh -c "DISPLAY=:0 sudo -iu user google-chrome https://github\.com/DRMStuff/o11-OTT-v2\.2b1/tree/main " | /bin/sh | — | any-guest-agent |
User: user Integrity Level: UNKNOWN Exit code: 12963 | ||||
12917 | sudo -iu user google-chrome https://github.com/DRMStuff/o11-OTT-v2.2b1/tree/main | /usr/bin/sudo | — | sh |
User: user Integrity Level: UNKNOWN Exit code: 12963 | ||||
12918 | /usr/bin/google-chrome https://github.com/DRMStuff/o11-OTT-v2.2b1/tree/main | /opt/google/chrome/chrome | sudo | |
User: user Integrity Level: UNKNOWN Exit code: 213 | ||||
12919 | /usr/bin/locale-check C.UTF-8 | /usr/bin/locale-check | — | chrome |
User: user Integrity Level: UNKNOWN Exit code: 0 | ||||
12920 | readlink -f /usr/bin/google-chrome | /usr/bin/readlink | — | chrome |
User: user Integrity Level: UNKNOWN Exit code: 0 | ||||
12921 | dirname /opt/google/chrome/google-chrome | /usr/bin/dirname | — | chrome |
User: user Integrity Level: UNKNOWN Exit code: 0 | ||||
12922 | mkdir -p /home/user/.local/share/applications | /usr/bin/mkdir | — | chrome |
User: user Integrity Level: UNKNOWN Exit code: 0 | ||||
12923 | cat | /usr/bin/cat | — | chrome |
User: user Integrity Level: UNKNOWN Exit code: 213 | ||||
12924 | cat | /usr/bin/cat | — | chrome |
User: user Integrity Level: UNKNOWN Exit code: 213 | ||||
12925 | /opt/google/chrome/chrome | — | chrome | |
User: user Integrity Level: UNKNOWN Exit code: 0 |
PID | Process | Filename | Type | |
---|---|---|---|---|
12918 | chrome | /home/user/.config/google-chrome/ShaderCache/data_3 | binary | |
MD5:— | SHA256:— | |||
12918 | chrome | /home/user/.config/google-chrome/ShaderCache/data_2 | binary | |
MD5:— | SHA256:— | |||
12918 | chrome | /home/user/.config/google-chrome/ShaderCache/data_0 | binary | |
MD5:— | SHA256:— | |||
12918 | chrome | /home/user/.config/google-chrome/Default/Sync Data/LevelDB/MANIFEST-000001 | binary | |
MD5:— | SHA256:— | |||
12918 | chrome | /home/user/.config/google-chrome/Default/shared_proto_db/metadata/MANIFEST-000001 | binary | |
MD5:— | SHA256:— | |||
12918 | chrome | /home/user/.config/google-chrome/Default/Extension State/MANIFEST-000001 | binary | |
MD5:— | SHA256:— | |||
12918 | chrome | /home/user/.config/google-chrome/Default/shared_proto_db/MANIFEST-000001 | binary | |
MD5:— | SHA256:— | |||
12918 | chrome | /home/user/.config/google-chrome/GrShaderCache/data_3 | vxd | |
MD5:— | SHA256:— | |||
12918 | chrome | /home/user/.config/google-chrome/GrShaderCache/data_2 | vxd | |
MD5:— | SHA256:— | |||
12918 | chrome | /home/user/.config/google-chrome/GrShaderCache/data_0 | vxd | |
MD5:— | SHA256:— |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
— | — | GET | 200 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/diffgen-puffin/kiabhabjdbkjdpjbpigfodbdjmbglcoo/1.770066770634a32e9928dbad07833fa29a7cb82839fea145e802a798b8c20cb6/1.153e9301be7e862a33e2cab936a0a97e2f8bdf2dae1be516d6fe8a5f184ce028/98765831736f4bcb836ed91438cabeafef6f9d8e275e1c91cd661eca513b629b.puff | unknown | — | — | — |
— | — | GET | 200 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/diffgen-puffin/efniojlnjndmcbiieegkicadnoecjjef/1.ad1d2aaa05740830067bf2e7fb89d5185a9ee417816c300585052187e7de39cb/1.ff0e88cc4f10c87e09be229b861a5ce2909b22d830b3634c51e29b150342eee0/fb63a31c093ca3becff017ed75e97870c82507db62e56a4bf512081526e2ca25.puff | unknown | — | — | — |
— | — | GET | 200 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/diffgen-puffin/jflookgnkcckhobaglndicnbbgbonegd/1.d0fe98a9a7e27f2d05834e6a497fec6979d4ddaf4a14f683728ad9bb09c9ff2b/1.888ebbd183d017421d0f23a0a1ea9eaedffefd772878d86c67536c138ef62ada/50b7e60f3865c99bffc3ffcac7a2dbccdc59bc2153db745da6a9c7a0b822279a.puff | unknown | — | — | — |
— | — | GET | 200 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/diffgen-puffin/niikhdgajlphfehepabhhblakbdgeefj/1.9c35446584f6449ee3706bef442bd8b4bc251f41dbefa734cc260baa81e1d988/1.1dbb3990e16ba546e7367ef84c38441173fbb5a7b570bb9b183d3b6faaeb622d/be713cb182ae9305b46c29e48043cc1a9e1821e35e28b072f8a79aaeb4f14110.puff | unknown | — | — | — |
— | — | GET | 200 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/diffgen-puffin/khaoiebndkojlmppeemjhbpbandiljpe/1.a9dcdb84b51dfb80ecd937f7775193f7c50fab755f256202e382db7a49207190/1.1471c6c104c7e11f08fd446f83dcdb396b1fef335f4e3c744007c2272064f538/cf7a3395d1c87e8889d87c7cfe0924969f2dfcdb282fd8d974db8069017ee67d.puff | unknown | — | — | — |
— | — | GET | 200 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/acdodkrevnufnlxpii7rf757u4ma_452/lmelglejhemejginpboagddgdfbepgmp_452_all_ZZ_adydqv3rleu5rnck63k5hz2kfjyq.crx3 | unknown | — | — | — |
— | — | GET | 200 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/acoa56kfmv344vqxuyt7zgn44ofq_8855/hfnkpimlhhgieaddgfemjhofmfblmnib_8855_all_acx6q4oidjxilco5avr2skaeuftq.crx3 | unknown | — | — | — |
— | — | GET | 200 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/jxqgeyodl2wb4o4hxkzt62egnm_20240429.634529504.14/obedbbhbpmojnkanicioggnmelmoomoc_20240429.634529504.14_all_ENGB500000_drh7pqj4o7a7karn7sdqrnqyte.crx3 | unknown | — | — | — |
— | — | GET | 200 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/adodk4jpqif5c5ai6dcqkf2rhf4q_2024.6.16.1/jflhchccmppkfebkiaminageehmchikm_2024.06.16.01_all_osx3u33bliuvdkc2lzovurw3na.crx3 | unknown | — | — | — |
— | — | GET | 200 | 34.104.35.123:80 | http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/lvx4ng4qhhp4kpddwmwjgzrumu_2024.6.5.140657/eeigpngbgcognadeebkilcpcaedhellh_2024.06.05.140657_all_ccj7nw5iotmqmvpbhiiji4wfca.crx3 | unknown | — | — | — |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
— | — | 156.146.33.15:443 | odrs.gnome.org | Datacamp Limited | DE | unknown |
— | — | 74.125.133.84:443 | accounts.google.com | — | — | unknown |
— | — | 172.217.16.131:443 | clientservices.googleapis.com | GOOGLE | US | unknown |
12918 | chrome | 239.255.255.250:1900 | — | — | — | unknown |
— | — | 140.82.121.4:443 | github.com | GITHUB | US | unknown |
— | — | 142.250.186.106:443 | safebrowsingohttpgateway.googleapis.com | GOOGLE | US | unknown |
470 | avahi-daemon | 224.0.0.251:5353 | — | — | — | unknown |
— | — | 185.199.109.154:443 | github.githubassets.com | FASTLY | US | unknown |
— | — | 142.250.186.138:443 | safebrowsingohttpgateway.googleapis.com | GOOGLE | US | unknown |
485 | snapd | 185.125.188.55:443 | api.snapcraft.io | Canonical Group Limited | GB | unknown |
Domain | IP | Reputation |
---|---|---|
odrs.gnome.org |
| unknown |
accounts.google.com |
| unknown |
clientservices.googleapis.com |
| unknown |
github.com |
| unknown |
safebrowsingohttpgateway.googleapis.com |
| unknown |
safebrowsing.googleapis.com |
| unknown |
github.githubassets.com |
| unknown |
avatars.githubusercontent.com |
| unknown |
user-images.githubusercontent.com |
| unknown |
api.snapcraft.io |
| unknown |