| URL: | https://lc2.shengage03.com/mb/zBoDGZXQvzUHv1OlH1UQew~~.ekjLwYS-bPgrpK7_1y951PFa.YODSDkqysDHlObNH03WshQ~~?q=https%3A%2F%2Fcheckpoint-security.b-cdn.net |
| Full analysis: | https://app.any.run/tasks/66e547dd-9a95-4804-8183-c274f470185e |
| Verdict: | Malicious activity |
| Analysis date: | September 03, 2024, 01:05:31 |
| OS: | Ubuntu 22.04.2 |
| Tags: | |
| MD5: | 4310B04567C1F936E64E136054FE3F64 |
| SHA1: | 91D8B42FE08060FC2223AA8F26EC43FD4B8127EE |
| SHA256: | D9D97769F27D2218E9EF910221F9FB8AFCF4F8EE8E5E535E90A7E1B168847C34 |
| SSDEEP: | 3:N8GXi4CECjLRmT+oweAOFdUVuJF2ji8qHUcWN8wN4fgBWCXjy6KKUHXMRJn:2GyPXLYTImFG4F2+VCzy6qHXMRJn |
PID | CMD | Path | Indicators | Parent process |
|---|---|---|---|---|
| 425 | /lib/systemd/systemd-resolved | /usr/lib/systemd/systemd-resolved | systemd | |
User: systemd-resolve Integrity Level: UNKNOWN | ||||
| 13406 | /bin/sh -c "DISPLAY=:0 sudo -iu user google-chrome https://lc2\.shengage03\.com/mb/zBoDGZXQvzUHv1OlH1UQew~~\.ekjLwYS-bPgrpK7_1y951PFa\.YODSDkqysDHlObNH03WshQ~~?q=https%3A%2F%2Fcheckpoint-security\.b-cdn\.net " | /bin/sh | — | any-guest-agent |
User: root Integrity Level: UNKNOWN | ||||
| 13407 | sudo -iu user google-chrome https://lc2.shengage03.com/mb/zBoDGZXQvzUHv1OlH1UQew~~.ekjLwYS-bPgrpK7_1y951PFa.YODSDkqysDHlObNH03WshQ~~?q=https%3A%2F%2Fcheckpoint-security.b-cdn.net | /usr/bin/sudo | — | sh |
User: root Integrity Level: UNKNOWN | ||||
| 13408 | /usr/bin/google-chrome https://lc2.shengage03.com/mb/zBoDGZXQvzUHv1OlH1UQew~~.ekjLwYS-bPgrpK7_1y951PFa.YODSDkqysDHlObNH03WshQ~~?q=https%3A%2F%2Fcheckpoint-security.b-cdn.net | /opt/google/chrome/chrome | sudo | |
User: user Integrity Level: UNKNOWN | ||||
| 13409 | /usr/bin/locale-check C.UTF-8 | /usr/bin/locale-check | — | chrome |
User: user Integrity Level: UNKNOWN Exit code: 0 | ||||
| 13410 | readlink -f /usr/bin/google-chrome | /usr/bin/readlink | — | chrome |
User: user Integrity Level: UNKNOWN Exit code: 0 | ||||
| 13411 | dirname /opt/google/chrome/google-chrome | /usr/bin/dirname | — | chrome |
User: user Integrity Level: UNKNOWN Exit code: 0 | ||||
| 13412 | mkdir -p /home/user/.local/share/applications | /usr/bin/mkdir | — | chrome |
User: user Integrity Level: UNKNOWN Exit code: 0 | ||||
| 13413 | cat | /usr/bin/cat | — | chrome |
User: user Integrity Level: UNKNOWN | ||||
| 13414 | cat | /usr/bin/cat | — | chrome |
User: user Integrity Level: UNKNOWN | ||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 13408 | chrome | /home/user/.config/google-chrome/ShaderCache/data_3 | binary | |
MD5:— | SHA256:— | |||
| 13408 | chrome | /home/user/.config/google-chrome/ShaderCache/data_2 | binary | |
MD5:— | SHA256:— | |||
| 13408 | chrome | /home/user/.config/google-chrome/ShaderCache/data_0 | binary | |
MD5:— | SHA256:— | |||
| 13408 | chrome | /home/user/.config/google-chrome/Default/GPUCache/data_3 | vxd | |
MD5:— | SHA256:— | |||
| 13408 | chrome | /home/user/.config/google-chrome/Default/GPUCache/data_2 | vxd | |
MD5:— | SHA256:— | |||
| 13408 | chrome | /home/user/.config/google-chrome/Default/GPUCache/data_0 | vxd | |
MD5:— | SHA256:— | |||
| 13408 | chrome | /home/user/.config/google-chrome/Default/DawnCache/data_3 | vxd | |
MD5:— | SHA256:— | |||
| 13408 | chrome | /home/user/.config/google-chrome/Default/DawnCache/data_2 | vxd | |
MD5:— | SHA256:— | |||
| 13408 | chrome | /home/user/.config/google-chrome/Default/DawnCache/data_0 | vxd | |
MD5:— | SHA256:— | |||
| 13408 | chrome | /home/user/.config/google-chrome/Default/History | binary | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 204 | 185.125.190.98:80 | http://connectivity-check.ubuntu.com/ | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 91.189.91.98:80 | connectivity-check.ubuntu.com | Canonical Group Limited | US | whitelisted |
470 | avahi-daemon | 224.0.0.251:5353 | — | — | — | unknown |
— | — | 91.189.91.49:80 | connectivity-check.ubuntu.com | Canonical Group Limited | US | whitelisted |
— | — | 185.125.190.98:80 | connectivity-check.ubuntu.com | Canonical Group Limited | GB | whitelisted |
13408 | chrome | 239.255.255.250:1900 | — | — | — | whitelisted |
— | — | 142.250.184.195:443 | clientservices.googleapis.com | GOOGLE | US | whitelisted |
— | — | 151.101.193.91:443 | google-ohttp-relay-safebrowsing.fastly-edge.com | — | — | unknown |
— | — | 173.194.76.84:443 | accounts.google.com | GOOGLE | US | whitelisted |
— | — | 142.250.74.202:443 | safebrowsingohttpgateway.googleapis.com | GOOGLE | US | whitelisted |
— | — | 52.24.15.33:443 | lc2.shengage03.com | AMAZON-02 | US | unknown |
Domain | IP | Reputation |
|---|---|---|
connectivity-check.ubuntu.com |
| whitelisted |
google.com |
| whitelisted |
clientservices.googleapis.com |
| whitelisted |
accounts.google.com |
| whitelisted |
safebrowsingohttpgateway.googleapis.com |
| whitelisted |
lc2.shengage03.com |
| unknown |
leo-email-tracker.saleshandy.com |
| whitelisted |
google-ohttp-relay-safebrowsing.fastly-edge.com |
| unknown |
checkpoint-security.b-cdn.net |
| whitelisted |
0d814rf7.zone.investir-sur-mesure.fr |
| unknown |
PID | Process | Class | Message |
|---|---|---|---|
425 | systemd-resolved | Not Suspicious Traffic | INFO [ANY.RUN] Cloudflare Network Error Logging (NEL) |
425 | systemd-resolved | Not Suspicious Traffic | INFO [ANY.RUN] Cloudflare Network Error Logging (NEL) |
425 | systemd-resolved | Possible Social Engineering Attempted | PHISHING [ANY.RUN] Domain was identified as Phishing (.dultzman .ru) |
425 | systemd-resolved | Possible Social Engineering Attempted | PHISHING [ANY.RUN] Domain was identified as Phishing (.dultzman .ru) |