| URL: | https://url.emailprotection.link/?b9MxoLxiO71Hq-XJ3hARu7IKGQU43Y4k5RypD3nIQW6eEAZaMvF6ktTCT2QWTdNql-jP35WFg_56e2OumIrqJVlGDS9b7znhrFF7qCepd_6Z9WNA5fSC3VuJ3JL1A-l_AoY5L6e7rd4Wuv7TOytxMDQcTBOksYK-zlX6Fty0qpcY0KCQbO2ebn5bcWw3DrBZnzu0HyFDUjixm9x3hsx8ynwWcavQ8ArD5PhcRTrnq8y3Wa4S81psl1xcFwd9b8ilbdYKEVz8kGT1Wnp7MQMWqGY3UQi6Xs9SPm-9m3VegXpNMLA18VkTez69fIsmLkW6LMDnltNj39CDpbU_5BVvyBc13roGbs72HYcU_FySDUn84FjspBs0OQXu20DHBDMzsD7OQnbtzT0_kuR1fzNV19kTmay5wRzASCgNAjNXUQrZjQ-edEJTgCU61-E6nd-3zUawIrKx4OfHnsfJ1W0j_-uFWj8XvkqPdSd7M1fIqgJCAL4r5aEYeOFy9_iv0aY0EEH8Yslz8Oqpk3shlDNIxevPKO8hV7nAykVcLz7_49EvyybrBnb0-T8qHx7vMpBjnYOmGXdNcRdVDerukPWq9PJ0TRdKHXpB2Zr3nctfy2vk-f7dpAh26O-er-w90HmZhsVozJ3CGhCHUrjPZ4laa6qdupKcRUb7FFDH4rpQf6Q_6n9RCmhNAi0ZHPZ7SZPJJDZDwlLPWFC9Br6bvnZ3wij6VkK8KWnekYML1ivr15LFHoZ3LVzo82pZW8rMoqUTZOSWQwaF6iSB5Fma0zx1Ugo6IrMuCl0Vx4jde7cOWT7fMHEaACYCCdZGpKdRjHOyZUK7Bv3YhF9s95fCsWbng9A~~ |
| Full analysis: | https://app.any.run/tasks/a157cb63-65a9-4e03-997e-9657d6418681 |
| Verdict: | Malicious activity |
| Analysis date: | June 02, 2024, 11:27:53 |
| OS: | Ubuntu 22.04.2 |
| MD5: | 8B9B18C96BB22354F5CE240654F586A6 |
| SHA1: | 7769DA5A3C2A2957805BAF97894E9D6BD81A39A9 |
| SHA256: | CA2A277E5DCF722A4B2779E474F347EC0878EBD23182F670150AF2379E02E80B |
| SSDEEP: | 24:2Z1RsyJAMuK2lse2dkGUX2vnqkRzGpAFg3:g1RlJdOltMkhAm3 |
PID | CMD | Path | Indicators | Parent process |
|---|---|---|---|---|
| 11942 | /bin/sh -c "DISPLAY=:0 sudo -iu user google-chrome https://url\.emailprotection\.link/?b9MxoLxiO71Hq-XJ3hARu7IKGQU43Y4k5RypD3nIQW6eEAZaMvF6ktTCT2QWTdNql-jP35WFg_56e2OumIrqJVlGDS9b7znhrFF7qCepd_6Z9WNA5fSC3VuJ3JL1A-l_AoY5L6e7rd4Wuv7TOytxMDQcTBOksYK-zlX6Fty0qpcY0KCQbO2ebn5bcWw3DrBZnzu0HyFDUjixm9x3hsx8ynwWcavQ8ArD5PhcRTrnq8y3Wa4S81psl1xcFwd9b8ilbdYKEVz8kGT1Wnp7MQMWqGY3UQi6Xs9SPm-9m3VegXpNMLA18VkTez69fIsmLkW6LMDnltNj39CDpbU_5BVvyBc13roGbs72HYcU_FySDUn84FjspBs0OQXu20DHBDMzsD7OQnbtzT0_kuR1fzNV19kTmay5wRzASCgNAjNXUQrZjQ-edEJTgCU61-E6nd-3zUawIrKx4OfHnsfJ1W0j_-uFWj8XvkqPdSd7M1fIqgJCAL4r5aEYeOFy9_iv0aY0EEH8Yslz8Oqpk3shlDNIxevPKO8hV7nAykVcLz7_49EvyybrBnb0-T8qHx7vMpBjnYOmGXdNcRdVDerukPWq9PJ0TRdKHXpB2Zr3nctfy2vk-f7dpAh26O-er-w90HmZhsVozJ3CGhCHUrjPZ4laa6qdupKcRUb7FFDH4rpQf6Q_6n9RCmhNAi0ZHPZ7SZPJJDZDwlLPWFC9Br6bvnZ3wij6VkK8KWnekYML1ivr15LFHoZ3LVzo82pZW8rMoqUTZOSWQwaF6iSB5Fma0zx1Ugo6IrMuCl0Vx4jde7cOWT7fMHEaACYCCdZGpKdRjHOyZUK7Bv3YhF9s95fCsWbng9A~~ " | /bin/sh | — | any-guest-agent |
User: user Integrity Level: UNKNOWN | ||||
| 11943 | sudo -iu user google-chrome https://url.emailprotection.link/?b9MxoLxiO71Hq-XJ3hARu7IKGQU43Y4k5RypD3nIQW6eEAZaMvF6ktTCT2QWTdNql-jP35WFg_56e2OumIrqJVlGDS9b7znhrFF7qCepd_6Z9WNA5fSC3VuJ3JL1A-l_AoY5L6e7rd4Wuv7TOytxMDQcTBOksYK-zlX6Fty0qpcY0KCQbO2ebn5bcWw3DrBZnzu0HyFDUjixm9x3hsx8ynwWcavQ8ArD5PhcRTrnq8y3Wa4S81psl1xcFwd9b8ilbdYKEVz8kGT1Wnp7MQMWqGY3UQi6Xs9SPm-9m3VegXpNMLA18VkTez69fIsmLkW6LMDnltNj39CDpbU_5BVvyBc13roGbs72HYcU_FySDUn84FjspBs0OQXu20DHBDMzsD7OQnbtzT0_kuR1fzNV19kTmay5wRzASCgNAjNXUQrZjQ-edEJTgCU61-E6nd-3zUawIrKx4OfHnsfJ1W0j_-uFWj8XvkqPdSd7M1fIqgJCAL4r5aEYeOFy9_iv0aY0EEH8Yslz8Oqpk3shlDNIxevPKO8hV7nAykVcLz7_49EvyybrBnb0-T8qHx7vMpBjnYOmGXdNcRdVDerukPWq9PJ0TRdKHXpB2Zr3nctfy2vk-f7dpAh26O-er-w90HmZhsVozJ3CGhCHUrjPZ4laa6qdupKcRUb7FFDH4rpQf6Q_6n9RCmhNAi0ZHPZ7SZPJJDZDwlLPWFC9Br6bvnZ3wij6VkK8KWnekYML1ivr15LFHoZ3LVzo82pZW8rMoqUTZOSWQwaF6iSB5Fma0zx1Ugo6IrMuCl0Vx4jde7cOWT7fMHEaACYCCdZGpKdRjHOyZUK7Bv3YhF9s95fCsWbng9A~~ | /usr/bin/sudo | — | sh |
User: user Integrity Level: UNKNOWN | ||||
| 11944 | systemctl --user --global is-enabled snap.snapd-desktop-integration.snapd-desktop-integration.service | /usr/bin/systemctl | — | snapd |
User: root Integrity Level: UNKNOWN Exit code: 0 | ||||
| 11945 | systemctl --user --global is-enabled snap.snapd-desktop-integration.snapd-desktop-integration.service | /usr/bin/systemctl | — | snapd |
User: root Integrity Level: UNKNOWN Exit code: 0 | ||||
| 11946 | /usr/bin/google-chrome https://url.emailprotection.link/?b9MxoLxiO71Hq-XJ3hARu7IKGQU43Y4k5RypD3nIQW6eEAZaMvF6ktTCT2QWTdNql-jP35WFg_56e2OumIrqJVlGDS9b7znhrFF7qCepd_6Z9WNA5fSC3VuJ3JL1A-l_AoY5L6e7rd4Wuv7TOytxMDQcTBOksYK-zlX6Fty0qpcY0KCQbO2ebn5bcWw3DrBZnzu0HyFDUjixm9x3hsx8ynwWcavQ8ArD5PhcRTrnq8y3Wa4S81psl1xcFwd9b8ilbdYKEVz8kGT1Wnp7MQMWqGY3UQi6Xs9SPm-9m3VegXpNMLA18VkTez69fIsmLkW6LMDnltNj39CDpbU_5BVvyBc13roGbs72HYcU_FySDUn84FjspBs0OQXu20DHBDMzsD7OQnbtzT0_kuR1fzNV19kTmay5wRzASCgNAjNXUQrZjQ-edEJTgCU61-E6nd-3zUawIrKx4OfHnsfJ1W0j_-uFWj8XvkqPdSd7M1fIqgJCAL4r5aEYeOFy9_iv0aY0EEH8Yslz8Oqpk3shlDNIxevPKO8hV7nAykVcLz7_49EvyybrBnb0-T8qHx7vMpBjnYOmGXdNcRdVDerukPWq9PJ0TRdKHXpB2Zr3nctfy2vk-f7dpAh26O-er-w90HmZhsVozJ3CGhCHUrjPZ4laa6qdupKcRUb7FFDH4rpQf6Q_6n9RCmhNAi0ZHPZ7SZPJJDZDwlLPWFC9Br6bvnZ3wij6VkK8KWnekYML1ivr15LFHoZ3LVzo82pZW8rMoqUTZOSWQwaF6iSB5Fma0zx1Ugo6IrMuCl0Vx4jde7cOWT7fMHEaACYCCdZGpKdRjHOyZUK7Bv3YhF9s95fCsWbng9A~~ | /opt/google/chrome/chrome | sudo | |
User: user Integrity Level: UNKNOWN | ||||
| 11947 | /usr/bin/locale-check C.UTF-8 | /usr/bin/locale-check | — | chrome |
User: user Integrity Level: UNKNOWN Exit code: 0 | ||||
| 11948 | readlink -f /usr/bin/google-chrome | /usr/bin/readlink | — | chrome |
User: user Integrity Level: UNKNOWN Exit code: 0 | ||||
| 11949 | dirname /opt/google/chrome/google-chrome | /usr/bin/dirname | — | chrome |
User: user Integrity Level: UNKNOWN Exit code: 0 | ||||
| 11950 | mkdir -p /home/user/.local/share/applications | /usr/bin/mkdir | — | chrome |
User: user Integrity Level: UNKNOWN Exit code: 0 | ||||
| 11951 | cat | /usr/bin/cat | — | chrome |
User: user Integrity Level: UNKNOWN | ||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 11946 | chrome | /proc/11946/fd/63 | — | |
MD5:— | SHA256:— | |||
| 11946 | chrome | /dev/shm/.com.google.Chrome.N1MRzI | — | |
MD5:— | SHA256:— | |||
| 11946 | chrome | /dev/shm/.com.google.Chrome.OFMIsI | — | |
MD5:— | SHA256:— | |||
| 11946 | chrome | /dev/shm/.com.google.Chrome.NP65F7 | — | |
MD5:— | SHA256:— | |||
| 11946 | chrome | /home/user/.config/google-chrome/Default/Local Storage/leveldb/LOG | — | |
MD5:— | SHA256:— | |||
| 11946 | chrome | /home/user/.config/google-chrome/Default/discounts_db/LOG | — | |
MD5:— | SHA256:— | |||
| 11946 | chrome | /home/user/.config/google-chrome/Default/parcel_tracking_db/LOG | — | |
MD5:— | SHA256:— | |||
| 11946 | chrome | /home/user/.config/google-chrome/Default/chrome_cart_db/LOG | — | |
MD5:— | SHA256:— | |||
| 11946 | chrome | /home/user/.config/google-chrome/Default/coupon_db/LOG | — | |
MD5:— | SHA256:— | |||
| 11946 | chrome | /home/user/.config/google-chrome/Default/LOG | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 204 | 91.189.91.97:80 | http://connectivity-check.ubuntu.com/ | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 91.189.91.97:80 | — | Canonical Group Limited | US | unknown |
— | — | 185.125.190.98:80 | — | Canonical Group Limited | GB | unknown |
— | — | 195.181.170.19:443 | odrs.gnome.org | Datacamp Limited | DE | unknown |
470 | avahi-daemon | 224.0.0.251:5353 | — | — | — | unknown |
— | — | 185.125.188.58:443 | api.snapcraft.io | Canonical Group Limited | GB | unknown |
— | — | 185.125.188.55:443 | api.snapcraft.io | Canonical Group Limited | GB | unknown |
— | — | 142.250.186.35:443 | clientservices.googleapis.com | GOOGLE | US | unknown |
11946 | chrome | 239.255.255.250:1900 | — | — | — | unknown |
— | — | 64.233.166.84:443 | accounts.google.com | — | — | unknown |
— | — | 151.101.129.91:443 | google-ohttp-relay-safebrowsing.fastly-edge.com | FASTLY | US | unknown |
Domain | IP | Reputation |
|---|---|---|
odrs.gnome.org |
| unknown |
api.snapcraft.io |
| unknown |
clientservices.googleapis.com |
| whitelisted |
accounts.google.com |
| shared |
url.emailprotection.link |
| whitelisted |
google-ohttp-relay-safebrowsing.fastly-edge.com |
| unknown |
urlrs.gslb.serverdata.net |
| unknown |
link.mail.beehiiv.com |
| unknown |
challenges.cloudflare.com |
| whitelisted |
120.100.168.192.in-addr.arpa |
| unknown |
PID | Process | Class | Message |
|---|---|---|---|
— | — | Not Suspicious Traffic | INFO [ANY.RUN] Cloudflare Network Error Logging (NEL) |
— | — | Not Suspicious Traffic | INFO [ANY.RUN] jQuery JavaScript Library Code Loaded (code.jquery .com) |
— | — | Not Suspicious Traffic | INFO [ANY.RUN] A free CDN for open source projects (jsdelivr .net) |
— | — | Not Suspicious Traffic | INFO [ANY.RUN] A free CDN for open source projects (jsdelivr .net) |