| URL: | iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com |
| Full analysis: | https://app.any.run/tasks/851e9bf5-8e2b-4465-8703-2bfb953cc14d |
| Verdict: | Malicious activity |
| Threats: | Ransomware is a type of malicious software that locks users out of their system or data using different methods to force them to pay a ransom. Most often, such programs encrypt files on an infected machine and demand a fee to be paid in exchange for the decryption key. Additionally, such programs can be used to steal sensitive information from the compromised computer and even conduct DDoS attacks against affected organizations to pressure them into paying. |
| Analysis date: | April 29, 2024, 09:47:12 |
| OS: | Ubuntu 22.04.2 |
| Tags: | |
| MD5: | B3E1DACE0A87E48734F1F6322D120AB2 |
| SHA1: | 2E196DF7A0D6FC2CAC492AFB5162C22FFFF98F57 |
| SHA256: | C707E3CC1762EDF1BAF4BEDE54FF468D2167024F279AE6DF9044CFBBBEFD2D2A |
| SSDEEP: | 3:RZXDiCP8NBBC3ADyKI:TPyBBeT |
PID | CMD | Path | Indicators | Parent process |
|---|---|---|---|---|
| 9262 | /bin/sh -c "DISPLAY=:0 sudo -iu user google-chrome iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea\.com " | /bin/sh | — | any-guest-agent |
User: root Integrity Level: UNKNOWN | ||||
| 9263 | sudo -iu user google-chrome iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com | /usr/bin/sudo | — | sh |
User: root Integrity Level: UNKNOWN | ||||
| 9264 | /usr/bin/google-chrome iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com | /opt/google/chrome/chrome | — | sudo |
User: user Integrity Level: UNKNOWN | ||||
| 9265 | /usr/bin/locale-check C.UTF-8 | /usr/bin/locale-check | — | chrome |
User: user Integrity Level: UNKNOWN Exit code: 0 | ||||
| 9266 | readlink -f /usr/bin/google-chrome | /usr/bin/readlink | — | chrome |
User: user Integrity Level: UNKNOWN Exit code: 0 | ||||
| 9267 | dirname /opt/google/chrome/google-chrome | /usr/bin/dirname | — | chrome |
User: user Integrity Level: UNKNOWN Exit code: 0 | ||||
| 9268 | mkdir -p /home/user/.local/share/applications | /usr/bin/mkdir | — | chrome |
User: user Integrity Level: UNKNOWN Exit code: 0 | ||||
| 9269 | cat | /usr/bin/cat | — | chrome |
User: user Integrity Level: UNKNOWN | ||||
| 9270 | cat | /usr/bin/cat | — | chrome |
User: user Integrity Level: UNKNOWN | ||||
| 9271 | /opt/google/chrome/chrome | — | chrome | |
User: user Integrity Level: UNKNOWN Exit code: 0 | ||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 9264 | chrome | /9264/fd/63 | — | |
MD5:— | SHA256:— | |||
| 9264 | chrome | /home/user/.config/google-chrome/BrowserMetrics/BrowserMetrics-662F6CA7-2430.pma | — | |
MD5:— | SHA256:— | |||
| 9264 | chrome | /home/user/.config/google-chrome/Default/Session Storage/LOG | — | |
MD5:— | SHA256:— | |||
| 9264 | chrome | /home/user/.config/google-chrome/Default/shared_proto_db/metadata/LOG | — | |
MD5:— | SHA256:— | |||
| 9264 | chrome | /home/user/.config/google-chrome/Default/shared_proto_db/LOG | — | |
MD5:— | SHA256:— | |||
| 9264 | chrome | /home/user/.config/google-chrome/WidevineCdm/.com.google.Chrome.2PPpjN | — | |
MD5:— | SHA256:— | |||
| 9264 | chrome | /.com.google.Chrome.gkSnAE | — | |
MD5:— | SHA256:— | |||
| 9264 | chrome | /.com.google.Chrome.I2OPMC | — | |
MD5:— | SHA256:— | |||
| 9264 | chrome | /.com.google.Chrome.kqhBnO | — | |
MD5:— | SHA256:— | |||
| 9264 | chrome | /.com.google.Chrome.RjX83r | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 204 | 185.125.190.96:80 | http://connectivity-check.ubuntu.com/ | unknown | — | — | unknown |
— | — | GET | 200 | 2.16.202.123:80 | http://apps.identrust.com/roots/dstrootcax3.p7c | unknown | — | — | unknown |
— | — | GET | 200 | 92.123.17.153:80 | http://cert.int-x3.letsencrypt.org/ | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 224.0.0.251:5353 | — | — | — | unknown |
— | — | 185.125.190.96:80 | — | Canonical Group Limited | GB | unknown |
— | — | 91.189.91.49:80 | — | Canonical Group Limited | US | unknown |
— | — | 185.125.188.58:443 | api.snapcraft.io | Canonical Group Limited | GB | unknown |
— | — | 185.125.188.59:443 | api.snapcraft.io | Canonical Group Limited | GB | unknown |
— | — | 239.255.255.250:1900 | — | — | — | unknown |
— | — | 142.250.185.163:443 | clientservices.googleapis.com | GOOGLE | US | unknown |
— | — | 74.125.71.84:443 | accounts.google.com | GOOGLE | US | unknown |
— | — | 104.16.166.228:443 | iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com | CLOUDFLARENET | — | unknown |
— | — | 35.237.128.253:443 | static.kryptoslogicsinkhole.com | GOOGLE-CLOUD-PLATFORM | US | unknown |
Domain | IP | Reputation |
|---|---|---|
api.snapcraft.io |
| unknown |
clientservices.googleapis.com |
| whitelisted |
accounts.google.com |
| shared |
iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com |
| whitelisted |
static.kryptoslogicsinkhole.com |
| whitelisted |
apps.identrust.com |
| shared |
a1952.dscq.akamai.net |
| unknown |
cert.int-x3.letsencrypt.org |
| whitelisted |
e8652.dscx.akamaiedge.net |
| unknown |
update.googleapis.com |
| unknown |
PID | Process | Class | Message |
|---|---|---|---|
— | — | A Network Trojan was detected | AV TROJAN Observed DNS Query to Suspicious Domain (iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea[.]com) |
— | — | A Network Trojan was detected | AV TROJAN Observed DNS Query to Suspicious Domain (iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea[.]com) |
— | — | A Network Trojan was detected | ET MALWARE Possible WannaCry DNS Lookup 1 |
— | — | A Network Trojan was detected | ET MALWARE Possible WannaCry DNS Lookup 1 |
— | — | Not Suspicious Traffic | INFO [ANY.RUN] Cloudflare Network Error Logging (NEL) |