File name:

3b378846bc429fdf9bec08b9635885267d8d269f6d941ab1d6e526a03304331b.zip

Full analysis: https://app.any.run/tasks/f9572025-d76c-4362-a713-861882e6a28a
Verdict: Malicious activity
Analysis date: August 08, 2024, 22:51:50
OS: Ubuntu 22.04.2
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=deflate
MD5:

D555810D2F12F185E5B3DB9B520BC2E7

SHA1:

48A21C2BC00FBE9A05E35962636C51CAFBC5F347

SHA256:

E355A07EDE9425A275EFC1EE0205E5BB63A67F2357A2BFB082AE0DF50A6E7FC9

SSDEEP:

384:GGRdeYK2VJErPo1ouXf3RCAcGRdeYK2VJErPo1ouXf3RCA/:GGRbxJErw6mfkXGRbxJErw6mfkU

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Checks DMI information (probably VM detection)

      • systemd-hostnamed (PID: 12996)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2021:01:23 10:12:38
ZipCRC: 0x5e1be22c
ZipCompressedSize: 8918
ZipUncompressedSize: 24576
ZipFileName: 3b378846bc429fdf9bec08b9635885267d8d269f6d941ab1d6e526a03304331b.o
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
231
Monitored processes
17
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
sh no specs file no specs sh no specs sudo no specs file-roller no specs locale-check no specs systemctl no specs systemctl no specs systemctl no specs systemctl no specs systemctl no specs 7z no specs 7z no specs tracker-extract-3 no specs dbus-daemon no specs nautilus no specs systemd-hostnamed no specs

Process information

PID
CMD
Path
Indicators
Parent process
12934sh -c "file --mime-type /home/user/Desktop/3b378846bc429fdf9bec08b9635885267d8d269f6d941ab1d6e526a03304331b\.zip"/bin/shany-guest-agent
User:
root
Integrity Level:
UNKNOWN
Exit code:
0
12935file --mime-type /home/user/Desktop/3b378846bc429fdf9bec08b9635885267d8d269f6d941ab1d6e526a03304331b.zip/usr/bin/filesh
User:
root
Integrity Level:
UNKNOWN
Exit code:
0
12936/bin/sh -c "DISPLAY=:0 sudo -iu user file-roller /home/user/Desktop/3b378846bc429fdf9bec08b9635885267d8d269f6d941ab1d6e526a03304331b\.zip "/bin/shany-guest-agent
User:
root
Integrity Level:
UNKNOWN
12937sudo -iu user file-roller /home/user/Desktop/3b378846bc429fdf9bec08b9635885267d8d269f6d941ab1d6e526a03304331b.zip/usr/bin/sudosh
User:
root
Integrity Level:
UNKNOWN
12938file-roller /home/user/Desktop/3b378846bc429fdf9bec08b9635885267d8d269f6d941ab1d6e526a03304331b.zip/usr/bin/file-rollersudo
User:
user
Integrity Level:
UNKNOWN
12939/usr/bin/locale-check C.UTF-8/usr/bin/locale-checkfile-roller
User:
user
Integrity Level:
UNKNOWN
Exit code:
0
12954systemctl --user --global is-enabled snap.snapd-desktop-integration.snapd-desktop-integration.service/usr/bin/systemctlsnapd
User:
root
Integrity Level:
UNKNOWN
Exit code:
482
12955systemctl --user --global is-enabled snap.snapd-desktop-integration.snapd-desktop-integration.service/usr/bin/systemctlsnapd
User:
root
Integrity Level:
UNKNOWN
Exit code:
482
12956systemctl --user --global is-enabled snap.snapd-desktop-integration.snapd-desktop-integration.service/usr/bin/systemctlsnapd
User:
root
Integrity Level:
UNKNOWN
Exit code:
482
12957systemctl --user --global is-enabled snap.snapd-desktop-integration.snapd-desktop-integration.service/usr/bin/systemctlsnapd
User:
root
Integrity Level:
UNKNOWN
Exit code:
482
Executable files
0
Suspicious files
0
Text files
2
Unknown types
1

Dropped files

PID
Process
Filename
Type
12938file-roller/home/user/.local/share/recently-used.xbelxml
MD5:
SHA256:
129717z/home/user/Desktop/3b378846bc429fdf9bec08b9635885267d8d269f6d941ab1d6e526a03304331b.elfo
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
8
DNS requests
10
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
204
185.125.190.97:80
http://connectivity-check.ubuntu.com/
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
185.125.190.18:80
connectivity-check.ubuntu.com
Canonical Group Limited
GB
unknown
470
avahi-daemon
224.0.0.251:5353
unknown
185.125.190.49:80
connectivity-check.ubuntu.com
Canonical Group Limited
GB
unknown
185.125.190.97:80
connectivity-check.ubuntu.com
Canonical Group Limited
GB
unknown
1195
snap-store
195.181.170.19:443
odrs.gnome.org
Datacamp Limited
DE
unknown
485
snapd
185.125.188.55:443
api.snapcraft.io
Canonical Group Limited
GB
malicious

DNS requests

Domain
IP
Reputation
connectivity-check.ubuntu.com
  • 185.125.190.18
  • 185.125.190.96
  • 185.125.190.49
  • 91.189.91.48
  • 91.189.91.98
  • 185.125.190.17
  • 91.189.91.49
  • 91.189.91.97
  • 185.125.190.98
  • 185.125.190.97
  • 91.189.91.96
  • 185.125.190.48
  • 2001:67c:1562::23
  • 2001:67c:1562::24
  • 2620:2d:4000:1::98
  • 2620:2d:4000:1::22
  • 2620:2d:4002:1::196
  • 2620:2d:4000:1::2b
  • 2620:2d:4000:1::97
  • 2620:2d:4000:1::2a
  • 2620:2d:4000:1::23
  • 2620:2d:4002:1::197
  • 2620:2d:4000:1::96
  • 2620:2d:4002:1::198
whitelisted
google.com
  • 142.250.186.110
  • 2a00:1450:4001:829::200e
whitelisted
odrs.gnome.org
  • 195.181.170.19
  • 138.199.37.37
  • 138.199.37.40
  • 212.102.56.178
  • 156.146.33.15
  • 195.181.175.41
  • 138.199.37.25
  • 2a02:6ea0:c700::107
  • 2a02:6ea0:c700::19
  • 2a02:6ea0:c700::21
  • 2a02:6ea0:c700::101
  • 2a02:6ea0:c700::18
  • 2a02:6ea0:c700::11
  • 2a02:6ea0:c700::112
whitelisted
api.snapcraft.io
  • 185.125.188.55
  • 185.125.188.59
  • 185.125.188.58
  • 185.125.188.54
whitelisted
73.100.168.192.in-addr.arpa
unknown

Threats

No threats detected
No debug info