File name: | 23ca4ab1518ff76f5037ea12f367a469 |
Full analysis: | https://app.any.run/tasks/3e745a78-de28-4713-abca-a245ba7604e9 |
Verdict: | Malicious activity |
Analysis date: | June 20, 2024, 07:18:32 |
OS: | Ubuntu 22.04.2 |
MIME: | application/x-executable |
File info: | ELF 64-bit LSB executable, x86-64, version 1 (SYSV), statically linked, no section header |
MD5: | 23CA4AB1518FF76F5037EA12F367A469 |
SHA1: | 1001B06820145AC69F3D440F1CC25990EB14CC71 |
SHA256: | 7DB9189AFD00C2B60B7F892EF1B86D040FB1CF02145C7D2E414EF77BA3335C11 |
SSDEEP: | 98304:bJjRec8aRUljSYGXyEs7f30dFiyZbLuMqiRQwqF6/NdDfQQKebvEg1WqtAxdxk08:3uGbF |
.o | | | ELF Executable and Linkable format (generic) (49.8) |
---|
CPUArchitecture: | 64 bit |
---|---|
CPUByteOrder: | Little endian |
ObjectFileType: | Executable file |
CPUType: | AMD x86-64 |
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
12915 | /bin/sh -c "sudo chown user /tmp/23ca4ab1518ff76f5037ea12f367a469\.o && chmod +x /tmp/23ca4ab1518ff76f5037ea12f367a469\.o && DISPLAY=:0 sudo -i /tmp/23ca4ab1518ff76f5037ea12f367a469\.o " | /bin/sh | — | any-guest-agent |
User: user Integrity Level: UNKNOWN | ||||
12916 | sudo chown user /tmp/23ca4ab1518ff76f5037ea12f367a469.o | /usr/bin/sudo | — | sh |
User: user Integrity Level: UNKNOWN Exit code: 0 | ||||
12917 | chown user /tmp/23ca4ab1518ff76f5037ea12f367a469.o | /usr/bin/chown | — | sudo |
User: root Integrity Level: UNKNOWN Exit code: 0 | ||||
12918 | chmod +x /tmp/23ca4ab1518ff76f5037ea12f367a469.o | /usr/bin/chmod | — | sh |
User: user Integrity Level: UNKNOWN Exit code: 0 | ||||
12919 | sudo -i /tmp/23ca4ab1518ff76f5037ea12f367a469.o | /usr/bin/sudo | — | sh |
User: user Integrity Level: UNKNOWN | ||||
12920 | /tmp/23ca4ab1518ff76f5037ea12f367a469.o | /tmp/23ca4ab1518ff76f5037ea12f367a469.o | sudo | |
User: root Integrity Level: UNKNOWN Exit code: 12934 | ||||
12921 | /usr/bin/locale-check C.UTF-8 | /usr/bin/locale-check | — | 23ca4ab1518ff76f5037ea12f367a469.o |
User: root Integrity Level: UNKNOWN Exit code: 0 | ||||
12922 | -bash --login -c \/tmp\/23ca4ab1518ff76f5037ea12f367a469\.o | /usr/bin/bash | — | 23ca4ab1518ff76f5037ea12f367a469.o |
User: root Integrity Level: UNKNOWN Exit code: 0 | ||||
12923 | sh -c "cat /usr/etc/debuginfod/*\.urls 2>/dev/null" | /usr/bin/sh | — | bash |
User: root Integrity Level: UNKNOWN Exit code: 0 | ||||
12924 | tr \n " " | /usr/bin/tr | — | bash |
User: root Integrity Level: UNKNOWN Exit code: 0 |
PID | Process | Filename | Type | |
---|---|---|---|---|
12920 | 23ca4ab1518ff76f5037ea12f367a469.o | /usr/bin/geomi | binary | |
MD5:— | SHA256:— | |||
12934 | geomi | /etc/systemd/system/geomi.service | text | |
MD5:— | SHA256:— |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
13000 | geomi | GET | 200 | 52.210.188.244:80 | http://checkip.amazonaws.com/ | unknown | — | — | — |
13000 | geomi | GET | 302 | 34.117.186.192:80 | http://ipinfo.io/country | unknown | — | — | — |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
— | — | 195.181.175.16:443 | odrs.gnome.org | Datacamp Limited | DE | unknown |
470 | avahi-daemon | 224.0.0.251:5353 | — | — | — | unknown |
— | — | 185.125.188.55:443 | api.snapcraft.io | Canonical Group Limited | GB | unknown |
12920 | 23ca4ab1518ff76f5037ea12f367a469.o | 104.16.249.249:443 | cloudflare-dns.com | CLOUDFLARENET | — | unknown |
12934 | geomi | 104.16.249.249:443 | cloudflare-dns.com | CLOUDFLARENET | — | unknown |
12920 | 23ca4ab1518ff76f5037ea12f367a469.o | 116.203.98.109:443 | api.opennic.org | Hetzner Online GmbH | DE | unknown |
— | — | 116.203.98.109:443 | api.opennic.org | Hetzner Online GmbH | DE | unknown |
485 | snapd | 185.125.188.54:443 | api.snapcraft.io | Canonical Group Limited | GB | unknown |
13000 | geomi | 104.16.248.249:443 | cloudflare-dns.com | CLOUDFLARENET | — | unknown |
13000 | geomi | 116.203.98.109:443 | api.opennic.org | Hetzner Online GmbH | DE | unknown |
Domain | IP | Reputation |
---|---|---|
odrs.gnome.org |
| unknown |
api.snapcraft.io |
| unknown |
cloudflare-dns.com |
| unknown |
api.opennic.org |
| unknown |
checkip.amazonaws.com |
| unknown |
ipinfo.io |
| unknown |
163.100.168.192.in-addr.arpa |
| unknown |
connectivity-check.ubuntu.com |
| unknown |