File name:

email (3).eml

Full analysis: https://app.any.run/tasks/00806241-8cc2-459d-a4a6-0a61a6c38302
Verdict: Malicious activity
Analysis date: April 14, 2025, 19:35:14
OS: Ubuntu 22.04.2
MIME: message/rfc822
File info: RFC 822 mail, ASCII text, with very long lines (347), with CRLF line terminators
MD5:

F0BF2735082644F42AF1B76BA8D3A133

SHA1:

18AC82F9FD7B43AAF61EDE3B9F213616EA6D6F52

SHA256:

6AE3277852F21921ADE52767FB261F7EFE9790E5E8326C3E20806484966779AA

SSDEEP:

384:q08OvFbCwtV5HzN3qVnVu7rsldPYFKSss4mjRlfCjwSD:V8OvFbZtV5HzN3OnwrslMKEjXa8SD

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executes commands using command-line interpreter

      • sudo (PID: 40666)
    • Reads passwd file

      • thunderbird (PID: 40667)
      • glxtest (PID: 40676)
    • Reads profile file

      • thunderbird (PID: 40667)
    • Check the Environment Variables Related to System Identification (os-release)

      • python3.10 (PID: 40695)
      • thunderbird (PID: 40667)
    • Reads /proc/mounts (likely used to find writable filesystems)

      • thunderbird (PID: 40667)
  • INFO

    • Checks timezone

      • python3.10 (PID: 40695)
      • thunderbird (PID: 40667)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.eml | E-Mail message (Var. 5) (100)
No data.
screenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
235
Monitored processes
13
Malicious processes
0
Suspicious processes
1

Behavior graph

Click at the process to see the details
start dash no specs sudo no specs thunderbird locale-check no specs dash no specs thunderbird no specs systemctl no specs glxtest no specs systemctl no specs python3.10 no specs systemctl no specs systemctl no specs systemctl no specs

Process information

PID
CMD
Path
Indicators
Parent process
40665/bin/sh -c "DISPLAY=:0 sudo -iu user thunderbird \"/tmp/email (3)\.eml\" "/usr/bin/dashany-guest-agent
User:
user
Integrity Level:
UNKNOWN
40666sudo -iu user thunderbird "/tmp/email (3)\.eml"/usr/bin/sudodash
User:
root
Integrity Level:
UNKNOWN
40667/usr/lib/thunderbird/thunderbird "/tmp/email (3)\.eml"/usr/lib/thunderbird/thunderbird
sudo
User:
user
Integrity Level:
UNKNOWN
40668/usr/bin/locale-check C.UTF-8/usr/bin/locale-checkthunderbird
User:
user
Integrity Level:
UNKNOWN
Exit code:
0
40669/bin/sh /usr/bin/which /usr/bin/thunderbird/usr/bin/dashthunderbird
User:
user
Integrity Level:
UNKNOWN
Exit code:
0
40670/usr/lib/thunderbird/thunderbird "/tmp/email (3)\.eml"/usr/lib/thunderbird/thunderbirdthunderbird
User:
user
Integrity Level:
UNKNOWN
Exit code:
0
40673systemctl --user --global is-enabled snap.snapd-desktop-integration.snapd-desktop-integration.service/usr/bin/systemctlsnapd
User:
root
Integrity Level:
UNKNOWN
Exit code:
0
40676/usr/lib/thunderbird/glxtest -f 12/usr/lib/thunderbird/glxtestthunderbird
User:
user
Integrity Level:
UNKNOWN
Exit code:
0
40692systemctl --user --global is-enabled snap.snapd-desktop-integration.snapd-desktop-integration.service/usr/bin/systemctlsnapd
User:
root
Integrity Level:
UNKNOWN
Exit code:
0
40695/usr/bin/python3 -Es /usr/bin/lsb_release -idrc/usr/bin/python3.10thunderbird
User:
user
Integrity Level:
UNKNOWN
Exit code:
0
Executable files
2
Suspicious files
77
Text files
13
Unknown types
0

Dropped files

PID
Process
Filename
Type
40676glxtest/home/user/.cache/mesa_shader_cache/indexbinary
MD5:
SHA256:
40667thunderbird/home/user/.thunderbird/Crash Reports/InstallTime20231024181440text
MD5:
SHA256:
40667thunderbird/home/user/.thunderbird/3flhwdhw.default-release/times.jsonbinary
MD5:
SHA256:
40667thunderbird/home/user/.thunderbird/qfsb5dfm.default/times.jsonbinary
MD5:
SHA256:
40667thunderbird/home/user/.thunderbird/installs.initext
MD5:
SHA256:
40667thunderbird/home/user/.thunderbird/profiles.initext
MD5:
SHA256:
40667thunderbird/home/user/.thunderbird/3flhwdhw.default-release/compatibility.initext
MD5:
SHA256:
40667thunderbird/home/user/.thunderbird/3flhwdhw.default-release/cookies.sqlite-journal (deleted)binary
MD5:
SHA256:
40667thunderbird/home/user/.thunderbird/3flhwdhw.default-release/pkcs11.txttext
MD5:
SHA256:
40667thunderbird/home/user/.thunderbird/3flhwdhw.default-release/cert9.db-journal (deleted)binary
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
18
DNS requests
15
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
204
185.125.190.48:80
http://connectivity-check.ubuntu.com/
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
185.125.190.48:80
connectivity-check.ubuntu.com
Canonical Group Limited
GB
whitelisted
484
avahi-daemon
224.0.0.251:5353
unknown
207.211.211.27:443
odrs.gnome.org
US
whitelisted
512
snapd
185.125.188.54:443
api.snapcraft.io
Canonical Group Limited
GB
whitelisted
512
snapd
185.125.188.58:443
api.snapcraft.io
Canonical Group Limited
GB
whitelisted
512
snapd
185.125.188.55:443
api.snapcraft.io
Canonical Group Limited
GB
whitelisted
512
snapd
185.125.188.59:443
api.snapcraft.io
Canonical Group Limited
GB
whitelisted
40667
thunderbird
3.167.227.80:443
services.addons.thunderbird.net
US
whitelisted
40667
thunderbird
104.26.3.27:443
thunderbird-settings.thunderbird.net
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.186.46
  • 2a00:1450:4001:827::200e
whitelisted
connectivity-check.ubuntu.com
  • 185.125.190.48
  • 185.125.190.96
  • 91.189.91.98
  • 185.125.190.17
  • 185.125.190.97
  • 185.125.190.49
  • 185.125.190.18
  • 91.189.91.48
  • 91.189.91.97
  • 185.125.190.98
  • 91.189.91.49
  • 91.189.91.96
  • 2001:67c:1562::24
  • 2620:2d:4002:1::198
  • 2620:2d:4000:1::2b
  • 2620:2d:4000:1::97
  • 2620:2d:4002:1::197
  • 2620:2d:4000:1::23
  • 2620:2d:4000:1::98
  • 2620:2d:4000:1::22
  • 2620:2d:4000:1::2a
  • 2620:2d:4002:1::196
  • 2620:2d:4000:1::96
  • 2001:67c:1562::23
whitelisted
odrs.gnome.org
  • 207.211.211.27
  • 195.181.175.40
  • 37.19.194.80
  • 169.150.255.183
  • 212.102.56.179
  • 169.150.255.181
  • 195.181.170.18
  • 2a02:6ea0:c700::107
  • 2a02:6ea0:c700::18
  • 2a02:6ea0:c700::101
  • 2a02:6ea0:c700::21
  • 2a02:6ea0:c700::11
  • 2a02:6ea0:c700::112
  • 2a02:6ea0:c700::19
whitelisted
api.snapcraft.io
  • 185.125.188.54
  • 185.125.188.58
  • 185.125.188.59
  • 185.125.188.55
  • 2620:2d:4000:1010::6d
  • 2620:2d:4000:1010::344
  • 2620:2d:4000:1010::42
  • 2620:2d:4000:1010::117
whitelisted
services.addons.thunderbird.net
  • 3.167.227.80
  • 3.167.227.14
  • 3.167.227.56
  • 3.167.227.19
  • 2600:9000:27e6:1400:c:19e4:9800:93a1
  • 2600:9000:27e6:f400:c:19e4:9800:93a1
  • 2600:9000:27e6:3800:c:19e4:9800:93a1
  • 2600:9000:27e6:da00:c:19e4:9800:93a1
  • 2600:9000:27e6:7c00:c:19e4:9800:93a1
  • 2600:9000:27e6:2e00:c:19e4:9800:93a1
  • 2600:9000:27e6:4a00:c:19e4:9800:93a1
  • 2600:9000:27e6:ee00:c:19e4:9800:93a1
whitelisted
15.100.168.192.in-addr.arpa
unknown
thunderbird-settings.thunderbird.net
  • 104.26.3.27
  • 104.26.2.27
  • 172.67.74.82
  • 2606:4700:20::681a:21b
  • 2606:4700:20::681a:31b
  • 2606:4700:20::ac43:4a52
whitelisted

Threats

No threats detected
No debug info