download:

/and

Full analysis: https://app.any.run/tasks/1cb7d6fe-4d24-458c-879c-75e22ada98a7
Verdict: Malicious activity
Threats:

A botnet is a group of internet-connected devices that are controlled by a single individual or group, often without the knowledge or consent of the device owners. These devices can be used to launch a variety of malicious attacks, such as distributed denial-of-service (DDoS) attacks, spam campaigns, and data theft. Botnet malware is the software that is used to infect devices and turn them into part of a botnet.

Analysis date: April 04, 2025, 20:07:52
OS: Ubuntu 22.04.2
Tags:
mirai
botnet
moobot
Indicators:
MIME: text/plain
File info: ASCII text, with CRLF line terminators
MD5:

F5D0486980C03EB547C154DAF9276458

SHA1:

1A0B453A6EE18AE90A75D859C6DFD935BA5BDF61

SHA256:

52416BD2866FD5BFF683577CD1BAFD19CA179FD9B4366A7F0A478912B35ADEC8

SSDEEP:

48:xwEsWXlff1A29pxCYNLj/a41a2KuK+Xc7tyOT7NhBH8:L71A2NJLG442OE

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • MIRAI has been detected (SURICATA)

      • most-x86 (PID: 39592)
  • SUSPICIOUS

    • Executes commands using command-line interpreter

      • sudo (PID: 39506)
    • Modifies file or directory owner

      • sudo (PID: 39503)
    • Reads passwd file

      • su (PID: 39521)
      • su (PID: 39519)
      • su (PID: 39523)
      • su (PID: 39518)
      • su (PID: 39517)
      • su (PID: 39515)
      • su (PID: 39516)
      • su (PID: 39604)
      • su (PID: 39612)
      • su (PID: 39606)
      • su (PID: 39601)
      • su (PID: 39600)
      • su (PID: 39603)
      • su (PID: 39610)
      • su (PID: 39609)
      • su (PID: 39613)
      • su (PID: 39615)
      • su (PID: 39618)
      • su (PID: 39616)
      • su (PID: 39619)
      • su (PID: 39624)
      • su (PID: 39627)
      • su (PID: 39625)
      • su (PID: 39628)
      • su (PID: 39633)
      • su (PID: 39621)
      • su (PID: 39631)
      • su (PID: 39630)
    • Potential Corporate Privacy Violation

      • busybox (PID: 39537)
      • busybox (PID: 39532)
      • busybox (PID: 39541)
      • busybox (PID: 39556)
      • busybox (PID: 39560)
      • busybox (PID: 39564)
      • busybox (PID: 39582)
      • busybox (PID: 39569)
      • busybox (PID: 39589)
    • Gets information about currently running processes

      • bash (PID: 39508)
    • Connects to the server without a host name

      • busybox (PID: 39532)
      • busybox (PID: 39537)
      • busybox (PID: 39560)
      • busybox (PID: 39541)
      • busybox (PID: 39556)
      • busybox (PID: 39569)
      • busybox (PID: 39582)
      • busybox (PID: 39579)
      • busybox (PID: 39564)
      • busybox (PID: 39586)
      • busybox (PID: 39589)
    • Executes the "rm" command to delete files or directories

      • bash (PID: 39508)
    • Connects to unusual port

      • most-x86 (PID: 39592)
    • Contacting a server suspected of hosting an CnC

      • most-x86 (PID: 39592)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
324
Monitored processes
105
Malicious processes
5
Suspicious processes
7

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
39502/bin/sh -c "sudo chown user /home/user/Desktop/and\.sh && chmod +x /home/user/Desktop/and\.sh && DISPLAY=:0 sudo -iu user /home/user/Desktop/and\.sh "/usr/bin/dashany-guest-agent
User:
root
Integrity Level:
UNKNOWN
Exit code:
32512
39503sudo chown user /home/user/Desktop/and.sh/usr/bin/sudodash
User:
root
Integrity Level:
UNKNOWN
Exit code:
0
39504chown user /home/user/Desktop/and.sh/usr/bin/chownsudo
User:
root
Integrity Level:
UNKNOWN
Exit code:
0
39505chmod +x /home/user/Desktop/and.sh/usr/bin/chmoddash
User:
root
Integrity Level:
UNKNOWN
Exit code:
0
39506sudo -iu user /home/user/Desktop/and.sh/usr/bin/sudodash
User:
root
Integrity Level:
UNKNOWN
Exit code:
32512
39508-bash --login -c \/home\/user\/Desktop\/and\.sh/usr/bin/bashsudo
User:
user
Integrity Level:
UNKNOWN
Exit code:
32512
39509/usr/bin/locale-check C.UTF-8/usr/bin/locale-checkbash
User:
user
Integrity Level:
UNKNOWN
Exit code:
0
39510pkill -f M /usr/bin/pgrepbash
User:
user
Integrity Level:
UNKNOWN
Exit code:
256
39511pkill -f arm7 /usr/bin/pgrepbash
User:
user
Integrity Level:
UNKNOWN
Exit code:
256
39512pkill -f arm /usr/bin/pgrepbash
User:
user
Integrity Level:
UNKNOWN
Exit code:
256
Executable files
0
Suspicious files
9
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
39537busybox/home/user/most-arm5binary
MD5:F64BB639D4976D9619142099C36575EB
SHA256:DFEC1811A2F321836DCC35FDBD5AEB3C5FDA5A147E77627175845BD3B0485DA2
39556busybox/home/user/most-arm7binary
MD5:195675D92DAE0688673D2986243FFA96
SHA256:FA82AE0A9EECA06A2424252F18830389374A2C3F6442957A35865E54E44F58B1
39532busybox/home/user/most-armbinary
MD5:AC100D58B348C04AA11F58F28736B63D
SHA256:01C67A63C18667827F4F7BB6F90FDE49026289B9F146AFCC449B03A598C22274
39560busybox/home/user/most-m68kbinary
MD5:E2A880BA260F6ADCED9B7C72DF5CF40E
SHA256:23C7B3B8A9D2BA629C8E2C946D472FADC26365D2B93651390519EE3FAF1A871B
39524busybox/home/user/atext
MD5:F775AB0EB4D0EEDB1970413BF5BF40B4
SHA256:ACDA26FE90BF774C981F53FE0F5BC3D35B4EAE204D081467E708A7DBE5A25501
39541busybox/home/user/most-arm6binary
MD5:5C5666BC417203A4F70218C88FC84DF3
SHA256:727C74C22A920B98048078BF6DF9012C46D8EA28DD97663D59F92258ACB822EF
39582busybox/home/user/most-sh4binary
MD5:57204E5E966320E4852A8859A2F47B61
SHA256:80059CFA9BA989FC85FEF27742784A6CB4E1ECA63182C82835F945A64E7BAB35
39564busybox/home/user/most-mipsbinary
MD5:34595401EB2ADC9BCA926E12500256AA
SHA256:AADF1C26FE25656F01FBE1A7C508CD0BDEA6F248A519FB12D4D07570905C3006
39569busybox/home/user/most-mpslbinary
MD5:581EEAC3A57D7F83CA6EF120098790CD
SHA256:B1AC37596B91C36DC800BE0A10B02A7E93DE76C4B0B98946AEB37DC5CC575D99
39589busybox/home/user/most-x86binary
MD5:80D71A84F06C7CBA118FDB7DCC087AB2
SHA256:CA2C68D100EFF3B8B82515E585BB33D1817CAA39FF5B2985339B1791DAD6EDB5
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
14
TCP/UDP connections
26
DNS requests
17
Threats
39

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
39541
busybox
GET
200
160.191.243.33:80
http://160.191.243.33/most-arm6
JP
binary
143 Kb
unknown
39524
busybox
GET
200
160.191.243.33:80
http://160.191.243.33/a
JP
text
924 b
unknown
GET
204
185.125.190.96:80
http://connectivity-check.ubuntu.com/
GB
whitelisted
39560
busybox
GET
200
160.191.243.33:80
http://160.191.243.33/most-m68k
JP
binary
149 Kb
unknown
39564
busybox
GET
200
160.191.243.33:80
http://160.191.243.33/most-mips
JP
binary
177 Kb
unknown
39569
busybox
GET
200
160.191.243.33:80
http://160.191.243.33/most-mpsl
JP
binary
177 Kb
unknown
39579
busybox
GET
404
160.191.243.33:80
http://160.191.243.33/most-ppc
JP
html
206 b
unknown
39582
busybox
GET
200
160.191.243.33:80
http://160.191.243.33/most-sh4
JP
binary
118 Kb
unknown
39586
busybox
GET
404
160.191.243.33:80
http://160.191.243.33/most-spc
JP
html
206 b
unknown
39556
busybox
GET
200
160.191.243.33:80
http://160.191.243.33/most-arm7
JP
binary
180 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
484
avahi-daemon
224.0.0.251:5353
unknown
91.189.91.48:80
connectivity-check.ubuntu.com
Canonical Group Limited
US
whitelisted
185.125.190.96:80
connectivity-check.ubuntu.com
Canonical Group Limited
GB
whitelisted
195.181.170.19:443
odrs.gnome.org
Datacamp Limited
DE
whitelisted
512
snapd
185.125.188.58:443
api.snapcraft.io
Canonical Group Limited
GB
whitelisted
39524
busybox
160.191.243.33:80
net-killer.ooguy.com
JP
unknown
512
snapd
185.125.188.55:443
api.snapcraft.io
Canonical Group Limited
GB
whitelisted
512
snapd
185.125.188.54:443
api.snapcraft.io
Canonical Group Limited
GB
whitelisted
39532
busybox
160.191.243.33:80
net-killer.ooguy.com
JP
unknown
39537
busybox
160.191.243.33:80
net-killer.ooguy.com
JP
unknown

DNS requests

Domain
IP
Reputation
connectivity-check.ubuntu.com
  • 185.125.190.96
  • 91.189.91.48
  • 91.189.91.96
  • 185.125.190.48
  • 185.125.190.18
  • 91.189.91.49
  • 91.189.91.98
  • 185.125.190.17
  • 185.125.190.97
  • 185.125.190.49
  • 91.189.91.97
  • 185.125.190.98
  • 2620:2d:4002:1::197
  • 2001:67c:1562::23
  • 2620:2d:4002:1::198
  • 2620:2d:4000:1::2a
  • 2620:2d:4000:1::98
  • 2620:2d:4000:1::97
  • 2620:2d:4000:1::2b
  • 2001:67c:1562::24
  • 2620:2d:4000:1::96
  • 2620:2d:4000:1::23
  • 2620:2d:4002:1::196
  • 2620:2d:4000:1::22
whitelisted
google.com
  • 216.58.206.78
  • 2a00:1450:4001:82b::200e
whitelisted
odrs.gnome.org
  • 195.181.170.19
  • 212.102.56.178
  • 169.150.255.181
  • 169.150.255.184
  • 195.181.175.40
  • 37.19.194.81
  • 207.211.211.26
  • 2a02:6ea0:c700::19
  • 2a02:6ea0:c700::101
  • 2a02:6ea0:c700::18
  • 2a02:6ea0:c700::11
  • 2a02:6ea0:c700::112
  • 2a02:6ea0:c700::107
  • 2a02:6ea0:c700::21
whitelisted
api.snapcraft.io
  • 185.125.188.58
  • 185.125.188.55
  • 185.125.188.54
  • 185.125.188.59
  • 2620:2d:4000:1010::42
  • 2620:2d:4000:1010::117
  • 2620:2d:4000:1010::344
  • 2620:2d:4000:1010::6d
whitelisted
12.100.168.192.in-addr.arpa
unknown
net-killer.ooguy.com
  • 160.191.243.33
unknown

Threats

PID
Process
Class
Message
39532
busybox
Potential Corporate Privacy Violation
ET INFO Executable and linking format (ELF) file download Over HTTP
39537
busybox
Potential Corporate Privacy Violation
ET INFO Executable and linking format (ELF) file download Over HTTP
39541
busybox
Potential Corporate Privacy Violation
ET INFO Executable and linking format (ELF) file download Over HTTP
39556
busybox
Potential Corporate Privacy Violation
ET INFO Executable and linking format (ELF) file download Over HTTP
39560
busybox
Potential Corporate Privacy Violation
ET INFO Executable and linking format (ELF) file download Over HTTP
39564
busybox
Potential Corporate Privacy Violation
ET INFO Executable and linking format (ELF) file download Over HTTP
39569
busybox
Potential Corporate Privacy Violation
ET INFO Executable and linking format (ELF) file download Over HTTP
39582
busybox
Potential Corporate Privacy Violation
ET INFO Executable and linking format (ELF) file download Over HTTP
39592
most-x86
Potentially Bad Traffic
ET DYN_DNS DYNAMIC_DNS Query to a *.ooguy .com Domain
39589
busybox
Potential Corporate Privacy Violation
ET INFO Executable and linking format (ELF) file download Over HTTP
No debug info