| File name: | xmr-go.sh |
| Full analysis: | https://app.any.run/tasks/14a46791-32ec-4dd2-a9b8-555fa3394ea5 |
| Verdict: | Malicious activity |
| Threats: | Crypto mining malware is a resource-intensive threat that infiltrates computers with the purpose of mining cryptocurrencies. This type of threat can be deployed either on an infected machine or a compromised website. In both cases the miner will utilize the computing power of the device and its network bandwidth. |
| Analysis date: | January 11, 2025, 05:20:17 |
| OS: | Ubuntu 22.04.2 LTS |
| Tags: | |
| Indicators: | |
| MIME: | text/x-shellscript |
| File info: | Bourne-Again shell script, ASCII text executable |
| MD5: | FC26B835A1A99DC335BCDBB2B35904D8 |
| SHA1: | 13A29189F034B6A4F1CE03192ED24A22B3504C13 |
| SHA256: | 9B12E445E40F04928D7836B9E94F134396B889271A3E50C17EFB2DA71C885952 |
| SSDEEP: | 12:TmHiKMHxlTcViocNPTUpHb2Hoyz+S6JRKlfU2wDthKl5lKl8KlYKYRKlX2wDthKA:Eix3TcVBcFTwso0+dJRcfgJhc5lc8cYs |
| .sh | | | Linux/UNIX shell script (100) |
|---|
PID | CMD | Path | Indicators | Parent process |
|---|---|---|---|---|
| 38737 | /bin/sh -c "sudo chown user /tmp/xmr-go\.sh && chmod +x /tmp/xmr-go\.sh && DISPLAY=:0 sudo -iu user /tmp/xmr-go\.sh " | /usr/bin/dash | — | any-guest-agent |
User: root Integrity Level: UNKNOWN | ||||
| 38738 | sudo chown user /tmp/xmr-go.sh | /usr/bin/sudo | — | dash |
User: root Integrity Level: UNKNOWN Exit code: 0 | ||||
| 38739 | chown user /tmp/xmr-go.sh | /usr/bin/chown | — | sudo |
User: root Integrity Level: UNKNOWN Exit code: 0 | ||||
| 38740 | chmod +x /tmp/xmr-go.sh | /usr/bin/chmod | — | dash |
User: root Integrity Level: UNKNOWN Exit code: 0 | ||||
| 38741 | sudo -iu user /tmp/xmr-go.sh | /usr/bin/sudo | — | dash |
User: root Integrity Level: UNKNOWN | ||||
| 38742 | /bin/bash /tmp/xmr-go.sh | /usr/bin/bash | — | sudo |
User: user Integrity Level: UNKNOWN | ||||
| 38743 | /usr/bin/locale-check C.UTF-8 | /usr/bin/locale-check | — | bash |
User: user Integrity Level: UNKNOWN Exit code: 0 | ||||
| 38744 | uname -m | /usr/bin/uname | — | bash |
User: user Integrity Level: UNKNOWN Exit code: 0 | ||||
| 38745 | crontab -r | /usr/bin/crontab | — | bash |
User: user Integrity Level: UNKNOWN Exit code: 256 | ||||
| 38746 | sudo -n "crontab -r" | /usr/bin/sudo | — | bash |
User: root Integrity Level: UNKNOWN Exit code: 256 | ||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 38791 | xmr_linux_amd64 | /etc/hosts | text | |
MD5:— | SHA256:— | |||
| 38791 | xmr_linux_amd64 | /config/.config/openbox/autostart | text | |
MD5:— | SHA256:— | |||
| 38791 | xmr_linux_amd64 | /tmp/xmrig/xmrig-6.22.0/xmrig | o | |
MD5:— | SHA256:— | |||
| 38791 | xmr_linux_amd64 | /tmp/xmrig/xmrig-6.22.0/config.json | binary | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 204 | 185.125.190.96:80 | http://connectivity-check.ubuntu.com/ | unknown | — | — | whitelisted |
— | — | GET | 204 | 185.125.190.96:80 | http://connectivity-check.ubuntu.com/ | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 185.125.190.96:80 | connectivity-check.ubuntu.com | Canonical Group Limited | GB | whitelisted |
484 | avahi-daemon | 224.0.0.251:5353 | — | — | — | unknown |
— | — | 140.82.121.4:443 | github.com | GITHUB | US | shared |
— | — | 185.199.110.133:443 | raw.githubusercontent.com | FASTLY | US | shared |
38791 | xmr_linux_amd64 | 172.67.74.152:443 | api.ipify.org | CLOUDFLARENET | US | shared |
38791 | xmr_linux_amd64 | 104.21.4.25:443 | vmtracker.freechildporninthisserver.lol | CLOUDFLARENET | — | unknown |
38791 | xmr_linux_amd64 | 140.82.121.4:443 | github.com | GITHUB | US | shared |
38791 | xmr_linux_amd64 | 185.199.108.133:443 | raw.githubusercontent.com | FASTLY | US | shared |
38805 | xmrig | 75.119.158.0:3222 | — | Contabo GmbH | DE | unknown |
Domain | IP | Reputation |
|---|---|---|
connectivity-check.ubuntu.com |
| whitelisted |
google.com |
| whitelisted |
github.com |
| shared |
raw.githubusercontent.com |
| shared |
api.ipify.org |
| shared |
vmtracker.freechildporninthisserver.lol |
| unknown |
objects.githubusercontent.com |
| shared |
109.100.168.192.in-addr.arpa |
| unknown |
PID | Process | Class | Message |
|---|---|---|---|
445 | systemd-resolved | Not Suspicious Traffic | INFO [ANY.RUN] Attempting to access raw user content on GitHub |
445 | systemd-resolved | Not Suspicious Traffic | INFO [ANY.RUN] Attempting to access raw user content on GitHub |
445 | systemd-resolved | Misc activity | ET INFO External IP Lookup Domain (ipify .org) in DNS Lookup |
445 | systemd-resolved | Misc activity | ET INFO External IP Lookup Domain (ipify .org) in DNS Lookup |
38791 | xmr_linux_amd64 | Misc activity | ET INFO External IP Address Lookup Domain (ipify .org) in TLS SNI |
38805 | xmrig | Potential Corporate Privacy Violation | ET POLICY Cryptocurrency Miner Checkin |
38805 | xmrig | Potential Corporate Privacy Violation | ET POLICY Cryptocurrency Miner Checkin |