File name:

email(10).eml

Full analysis: https://app.any.run/tasks/58e63581-39c5-4a72-aeb8-8b86f5631770
Verdict: Malicious activity
Analysis date: July 10, 2024, 19:03:39
OS: Ubuntu 22.04.2
Tags:
spam
MIME: message/rfc822
File info: RFC 822 mail, ASCII text, with CRLF line terminators
MD5:

3410372D31BEF0C2C501D1BB462E5CAE

SHA1:

D02537248F0776B36885BE7CCC47C018ED847F50

SHA256:

C6F9F15CFB692E4D428B3095DF43092B6544AB6D2B61008A886D4782D15C4324

SSDEEP:

192:Y/ie8ioCuxtsYbhUt5DG2/NSya8ZafoElHl+FTZmUZY/UvOoPU90GTUKt1w78/y5:YMio1kwhs5D+/VZl+FTQFIUQK/M/bd

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Checks DMI information (probably VM detection)

      • systemd-hostnamed (PID: 13121)
    • Reads /proc/mounts (likely used to find writable filesystems)

      • thunderbird (PID: 12939)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.eml | E-Mail message (Var. 5) (100)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
231
Monitored processes
18
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
sh no specs sh no specs systemctl no specs systemctl no specs systemctl no specs systemctl no specs systemctl no specs systemctl no specs thunderbird which no specs thunderbird no specs glxtest no specs lsb_release no specs thunderbird no specs dbus-daemon no specs nautilus no specs systemd-hostnamed no specs thunderbird no specs

Process information

PID
CMD
Path
Indicators
Parent process
12931sh -c "file --mime-type /tmp/email(10)\.eml"/bin/shany-guest-agent
User:
root
Integrity Level:
UNKNOWN
Exit code:
0
12932/bin/sh -c "DISPLAY=:0 sudo -iu user nautilus /tmp/email(10)\.eml "/bin/shany-guest-agent
User:
user
Integrity Level:
UNKNOWN
Exit code:
0
12933systemctl --user --global is-enabled snap.snapd-desktop-integration.snapd-desktop-integration.service/usr/bin/systemctlsnapd
User:
root
Integrity Level:
UNKNOWN
Exit code:
0
12934systemctl --user --global is-enabled snap.snapd-desktop-integration.snapd-desktop-integration.service/usr/bin/systemctlsnapd
User:
root
Integrity Level:
UNKNOWN
Exit code:
0
12935systemctl --user --global is-enabled snap.snapd-desktop-integration.snapd-desktop-integration.service/usr/bin/systemctlsnapd
User:
root
Integrity Level:
UNKNOWN
Exit code:
0
12936systemctl --user --global is-enabled snap.snapd-desktop-integration.snapd-desktop-integration.service/usr/bin/systemctlsnapd
User:
root
Integrity Level:
UNKNOWN
Exit code:
0
12937systemctl --user --global is-enabled snap.snapd-desktop-integration.snapd-desktop-integration.service/usr/bin/systemctlsnapd
User:
root
Integrity Level:
UNKNOWN
Exit code:
1195
12938systemctl --user --global is-enabled snap.snapd-desktop-integration.snapd-desktop-integration.service/usr/bin/systemctlsnapd
User:
root
Integrity Level:
UNKNOWN
Exit code:
1195
12939/usr/lib/thunderbird/thunderbird/usr/lib/thunderbird/thunderbird
gnome-shell
User:
user
Integrity Level:
UNKNOWN
12942/bin/sh /usr/bin/which /usr/bin/thunderbird/usr/bin/whichthunderbird
User:
user
Integrity Level:
UNKNOWN
Exit code:
1195
Executable files
1
Suspicious files
100
Text files
15
Unknown types
0

Dropped files

PID
Process
Filename
Type
12950glxtest/home/user/.cache/mesa_shader_cache/indexbinary
MD5:
SHA256:
12939thunderbird/home/user/.thunderbird/Crash Reports/InstallTime20231024181440text
MD5:
SHA256:
12939thunderbird/home/user/.thunderbird/3rhlg0uf.default-release/times.jsonbinary
MD5:
SHA256:
12939thunderbird/home/user/.thunderbird/rd28jmyl.default/times.jsonbinary
MD5:
SHA256:
12939thunderbird/home/user/.thunderbird/installs.initext
MD5:
SHA256:
12939thunderbird/home/user/.thunderbird/profiles.initext
MD5:
SHA256:
12939thunderbird/home/user/.thunderbird/3rhlg0uf.default-release/compatibility.iniini
MD5:
SHA256:
12939thunderbird/home/user/.thunderbird/3rhlg0uf.default-release/cookies.sqlite-journal (deleted)binary
MD5:
SHA256:
12939thunderbird/home/user/.thunderbird/3rhlg0uf.default-release/pkcs11.txttext
MD5:
SHA256:
12939thunderbird/home/user/.thunderbird/3rhlg0uf.default-release/cert9.db-journal (deleted)binary
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
34
DNS requests
37
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
204
91.189.91.48:80
http://connectivity-check.ubuntu.com/
unknown
unknown
12939
thunderbird
POST
200
95.101.54.202:80
http://r11.o.lencr.org/
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
185.125.190.18:80
connectivity-check.ubuntu.com
Canonical Group Limited
GB
unknown
470
avahi-daemon
224.0.0.251:5353
unknown
91.189.91.48:80
connectivity-check.ubuntu.com
Canonical Group Limited
US
unknown
156.146.33.141:443
odrs.gnome.org
Datacamp Limited
DE
unknown
485
snapd
185.125.188.59:443
api.snapcraft.io
Canonical Group Limited
GB
unknown
485
snapd
185.125.188.55:443
api.snapcraft.io
Canonical Group Limited
GB
malicious
485
snapd
185.125.188.54:443
api.snapcraft.io
Canonical Group Limited
GB
unknown
485
snapd
185.125.188.58:443
api.snapcraft.io
Canonical Group Limited
GB
unknown
12939
thunderbird
99.86.159.3:443
services.addons.thunderbird.net
AMAZON-02
US
unknown
12939
thunderbird
35.190.72.216:443
location.services.mozilla.com
GOOGLE
US
unknown

DNS requests

Domain
IP
Reputation
connectivity-check.ubuntu.com
  • 185.125.190.18
  • 91.189.91.97
  • 91.189.91.98
  • 185.125.190.98
  • 185.125.190.49
  • 185.125.190.96
  • 185.125.190.17
  • 91.189.91.96
  • 91.189.91.48
  • 185.125.190.97
  • 91.189.91.49
  • 185.125.190.48
  • 2620:2d:4002:1::197
  • 2620:2d:4000:1::22
  • 2620:2d:4000:1::2a
  • 2620:2d:4000:1::96
  • 2620:2d:4002:1::196
  • 2001:67c:1562::23
  • 2620:2d:4000:1::97
  • 2620:2d:4000:1::2b
  • 2620:2d:4002:1::198
  • 2620:2d:4000:1::23
  • 2620:2d:4000:1::98
  • 2001:67c:1562::24
unknown
google.com
  • 172.217.18.14
  • 2a00:1450:4001:80e::200e
whitelisted
odrs.gnome.org
  • 156.146.33.141
  • 156.146.33.15
  • 195.181.175.16
  • 212.102.56.181
  • 156.146.33.138
  • 212.102.56.179
  • 195.181.175.41
  • 2a02:6ea0:c700::17
  • 2a02:6ea0:c700::21
  • 2a02:6ea0:c700::11
  • 2a02:6ea0:c700::22
  • 2a02:6ea0:c700::10
  • 2a02:6ea0:c700::18
  • 2a02:6ea0:c700::101
unknown
api.snapcraft.io
  • 185.125.188.59
  • 185.125.188.54
  • 185.125.188.55
  • 185.125.188.58
unknown
205.100.168.192.in-addr.arpa
unknown
services.addons.thunderbird.net
  • 99.86.159.3
  • 99.86.159.118
  • 99.86.159.2
  • 99.86.159.80
  • 2600:9000:20eb:ca00:c:19e4:9800:93a1
  • 2600:9000:20eb:7200:c:19e4:9800:93a1
  • 2600:9000:20eb:4a00:c:19e4:9800:93a1
  • 2600:9000:20eb:5a00:c:19e4:9800:93a1
  • 2600:9000:20eb:6e00:c:19e4:9800:93a1
  • 2600:9000:20eb:8600:c:19e4:9800:93a1
  • 2600:9000:20eb:d000:c:19e4:9800:93a1
  • 2600:9000:20eb:9200:c:19e4:9800:93a1
whitelisted
location.services.mozilla.com
  • 35.190.72.216
whitelisted
prod.classify-client.prod.webservices.mozgcp.net
unknown
r11.o.lencr.org
  • 95.101.54.202
  • 2.16.202.120
  • 95.101.54.122
  • 2.16.202.112
  • 95.101.54.137
  • 95.101.54.139
  • 2.16.202.121
  • 95.101.54.200
  • 95.101.54.208
  • 2a02:26f0:480:e::210:f10f
  • 2a02:26f0:480:e::210:f108
unknown
live.thunderbird.net
  • 172.67.74.82
  • 104.26.3.27
  • 104.26.2.27
  • 2606:4700:20::681a:21b
  • 2606:4700:20::681a:31b
  • 2606:4700:20::ac43:4a52
whitelisted

Threats

No threats detected
No debug info