| File name: | SH1.zip |
| Full analysis: | https://app.any.run/tasks/94d89f0f-fc2a-4c12-8ce9-388ed3654fd8 |
| Verdict: | Malicious activity |
| Threats: | A botnet is a group of internet-connected devices that are controlled by a single individual or group, often without the knowledge or consent of the device owners. These devices can be used to launch a variety of malicious attacks, such as distributed denial-of-service (DDoS) attacks, spam campaigns, and data theft. Botnet malware is the software that is used to infect devices and turn them into part of a botnet. |
| Analysis date: | May 19, 2025, 03:47:15 |
| OS: | Ubuntu 22.04.2 |
| Tags: | |
| Indicators: | |
| MIME: | application/zip |
| File info: | Zip archive data, at least v5.1 to extract, compression method=AES Encrypted |
| MD5: | 96A40592135647B3F9ACD18D2B49BA7E |
| SHA1: | 906B5838BB0F267BB9AFE1742E655170BDA5408F |
| SHA256: | B2C8C7CD3F5A5C99E632EEFDA64F02F91651948B18363072477A8269AFB6C0CC |
| SSDEEP: | 12:5fGyfTQkydxxufLuScOESM+a7gYOKpY1QlfhkkydxxPa4:HkkOxufylO3MlrOKpphkkOxl |
| .zip | | | ZIP compressed archive (100) |
|---|
| ZipRequiredVersion: | 51 |
|---|---|
| ZipBitFlag: | 0x0003 |
| ZipCompression: | Unknown (99) |
| ZipModifyDate: | 2025:05:19 03:46:12 |
| ZipCRC: | 0xd4e3c650 |
| ZipCompressedSize: | 313 |
| ZipUncompressedSize: | 2940 |
| ZipFileName: | 92e6bd4a0f55b50f287e31bf824ea4fe7302f3dbca37493e1a00c70d0f13ca36.sh |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 39850 | /bin/sh -c "DISPLAY=:0 sudo -iu user file-roller /tmp/SH1\.zip " | /usr/bin/dash | — | oF5qt7VjSoEVMhQn | |||||||||||
User: user Integrity Level: UNKNOWN Exit code: 0 Modules
| |||||||||||||||
| 39851 | sudo -iu user file-roller /tmp/SH1.zip | /usr/bin/sudo | — | dash | |||||||||||
User: root Integrity Level: UNKNOWN Exit code: 0 Modules
| |||||||||||||||
| 39852 | file-roller /tmp/SH1.zip | /usr/bin/file-roller | — | sudo | |||||||||||
User: user Integrity Level: UNKNOWN Exit code: 0 Modules
| |||||||||||||||
| 39853 | /usr/bin/locale-check C.UTF-8 | /usr/bin/locale-check | — | file-roller | |||||||||||
User: user Integrity Level: UNKNOWN Exit code: 0 Modules
| |||||||||||||||
| 39867 | /usr/lib/p7zip/7z l -slt -bd -y -- /tmp/SH1.zip | /usr/lib/p7zip/7z | — | file-roller | |||||||||||
User: user Integrity Level: UNKNOWN Exit code: 0 Modules
| |||||||||||||||
| 39872 | /usr/lib/NetworkManager/nm-dispatcher | /usr/lib/NetworkManager/nm-dispatcher | — | systemd | |||||||||||
User: root Integrity Level: UNKNOWN Exit code: 0 Modules
| |||||||||||||||
| 39873 | /usr/bin/dbus-daemon --session --address=systemd: --nofork --nopidfile --systemd-activation --syslog-only | /usr/bin/dbus-daemon | — | dbus-daemon | |||||||||||
User: user Integrity Level: UNKNOWN Exit code: 9 | |||||||||||||||
| 39874 | /usr/libexec/gnome-shell-portal-helper | /usr/libexec/gnome-shell-portal-helper | — | dbus-daemon | |||||||||||
User: user Integrity Level: UNKNOWN Exit code: 0 Modules
| |||||||||||||||
| 39883 | /bin/sh -e /etc/NetworkManager/dispatcher.d/01-ifupdown connectivity-change | /usr/bin/dash | — | nm-dispatcher | |||||||||||
User: root Integrity Level: UNKNOWN Exit code: 0 Modules
| |||||||||||||||
| 39884 | /bin/sh -e /etc/NetworkManager/dispatcher.d/01-ifupdown connectivity-change | /usr/bin/dash | — | nm-dispatcher | |||||||||||
User: root Integrity Level: UNKNOWN Exit code: 0 Modules
| |||||||||||||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 40008 | nautilus | /home/user/.local/share/nautilus/tags/meta.db | binary | |
MD5:— | SHA256:— | |||
| 40059 | nautilus | /home/user/.local/share/nautilus/tags/meta.db | binary | |
MD5:— | SHA256:— | |||
| 39852 | file-roller | /home/user/.local/share/recently-used.xbel | xml | |
MD5:— | SHA256:— | |||
| 39988 | 7z | /home/user/Desktop/92e6bd4a0f55b50f287e31bf824ea4fe7302f3dbca37493e1a00c70d0f13ca36.sh | text | |
MD5:— | SHA256:— | |||
| 40008 | nautilus | /home/user/.local/share/nautilus/tags/meta.db-shm (deleted) | binary | |
MD5:— | SHA256:— | |||
| 40059 | nautilus | /home/user/.local/share/nautilus/tags/meta.db-shm (deleted) | binary | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
488 | NetworkManager | GET | 404 | 185.125.190.49:80 | http://connectivity-check.ubuntu.com/ | unknown | — | — | whitelisted |
488 | NetworkManager | GET | 404 | 185.125.190.96:80 | http://connectivity-check.ubuntu.com/ | unknown | — | — | whitelisted |
488 | NetworkManager | GET | 404 | 185.125.190.96:80 | http://connectivity-check.ubuntu.com/ | unknown | — | — | whitelisted |
39892 | WebKitNetworkProcess | GET | 404 | 151.101.65.91:80 | http://nmcheck.gnome.org/ | unknown | — | — | whitelisted |
488 | NetworkManager | GET | 404 | 185.125.190.96:80 | http://connectivity-check.ubuntu.com/ | unknown | — | — | whitelisted |
488 | NetworkManager | GET | 404 | 185.125.190.96:80 | http://connectivity-check.ubuntu.com/ | unknown | — | — | whitelisted |
488 | NetworkManager | GET | 404 | 185.125.190.96:80 | http://connectivity-check.ubuntu.com/ | unknown | — | — | whitelisted |
488 | NetworkManager | GET | 404 | 185.125.190.48:80 | http://connectivity-check.ubuntu.com/ | unknown | — | — | whitelisted |
488 | NetworkManager | GET | 404 | 91.189.91.49:80 | http://connectivity-check.ubuntu.com/ | unknown | — | — | whitelisted |
40084 | wget | GET | 404 | 93.95.115.175:80 | http://93.95.115.175/hiddenbin/boatnet.x86 | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
484 | avahi-daemon | 224.0.0.251:5353 | — | — | — | unknown |
488 | NetworkManager | 185.125.190.49:80 | connectivity-check.ubuntu.com | Canonical Group Limited | GB | whitelisted |
39892 | WebKitNetworkProcess | 151.101.65.91:80 | nmcheck.gnome.org | FASTLY | US | whitelisted |
488 | NetworkManager | 185.125.190.96:80 | connectivity-check.ubuntu.com | Canonical Group Limited | GB | whitelisted |
488 | NetworkManager | 185.125.190.48:80 | connectivity-check.ubuntu.com | Canonical Group Limited | GB | whitelisted |
39962 | gvfsd-smb-browse | 192.168.100.255:137 | — | — | — | whitelisted |
488 | NetworkManager | 91.189.91.49:80 | connectivity-check.ubuntu.com | Canonical Group Limited | US | whitelisted |
40084 | wget | 93.95.115.175:80 | — | — | NL | unknown |
40085 | curl | 93.95.115.175:80 | — | — | NL | unknown |
40122 | wget | 93.95.115.175:80 | — | — | NL | unknown |
Domain | IP | Reputation |
|---|---|---|
connectivity-check.ubuntu.com |
| whitelisted |
google.com |
| whitelisted |
4.100.168.192.in-addr.arpa |
| unknown |
nmcheck.gnome.org |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
40084 | wget | Potentially Bad Traffic | ET INFO x86 File Download Request from IP Address |
40084 | wget | Potentially Bad Traffic | ET HUNTING Suspicious GET Request for .x86 |
40085 | curl | Potentially Bad Traffic | ET HUNTING Suspicious GET Request for .x86 |
40085 | curl | Potentially Bad Traffic | ET INFO x86 File Download Request from IP Address |
40085 | curl | Potentially Bad Traffic | ET HUNTING curl User-Agent to Dotted Quad |
40123 | curl | A Network Trojan was detected | AV INFO Possible Mirai .mips Executable Download |
40155 | curl | Potentially Bad Traffic | ET HUNTING curl User-Agent to Dotted Quad |
40123 | curl | Potentially Bad Traffic | ET INFO MIPS File Download Request from IP Address |
40245 | wget | Potentially Bad Traffic | ET INFO X86_64 File Download Request from IP Address |
40213 | wget | Potentially Bad Traffic | ET HUNTING Suspicious GET Request for .i686 File |