| URL: | https://screenshare.pics/03LFO7.png |
| Full analysis: | https://app.any.run/tasks/d660f404-9cfc-45f0-b352-08c9dda6cb17 |
| Verdict: | Malicious activity |
| Analysis date: | June 10, 2024, 17:39:19 |
| OS: | Ubuntu 22.04.2 |
| Indicators: | |
| MD5: | 8660DEC04ED4D42F83014D1FE8FCA244 |
| SHA1: | 0963DE1A0B81CC1E760348B58177F3BFEE590FD8 |
| SHA256: | EEA937D6DAE1ED4B7A104CE8F6645199DE899A4D457A6DC174CF27E345FDD62C |
| SSDEEP: | 3:N8Lo+aM1PLCn:2lH1PLC |
PID | CMD | Path | Indicators | Parent process |
|---|---|---|---|---|
| 12451 | systemctl --user --global is-enabled snap.snapd-desktop-integration.snapd-desktop-integration.service | /usr/bin/systemctl | — | snapd |
User: root Integrity Level: UNKNOWN Exit code: 0 | ||||
| 12452 | systemctl --user --global is-enabled snap.snapd-desktop-integration.snapd-desktop-integration.service | /usr/bin/systemctl | — | snapd |
User: root Integrity Level: UNKNOWN Exit code: 0 | ||||
| 12453 | systemctl --user --global is-enabled snap.snapd-desktop-integration.snapd-desktop-integration.service | /usr/bin/systemctl | — | snapd |
User: root Integrity Level: UNKNOWN Exit code: 0 | ||||
| 12454 | systemctl --user --global is-enabled snap.snapd-desktop-integration.snapd-desktop-integration.service | /usr/bin/systemctl | — | snapd |
User: root Integrity Level: UNKNOWN Exit code: 0 | ||||
| 12455 | systemctl --user --global is-enabled snap.snapd-desktop-integration.snapd-desktop-integration.service | /usr/bin/systemctl | — | snapd |
User: root Integrity Level: UNKNOWN Exit code: 0 | ||||
| 12456 | systemctl --user --global is-enabled snap.snapd-desktop-integration.snapd-desktop-integration.service | /usr/bin/systemctl | — | snapd |
User: root Integrity Level: UNKNOWN Exit code: 0 | ||||
| 12457 | /bin/sh -c "DISPLAY=:0 sudo -iu user google-chrome https://screenshare\.pics/03LFO7\.png " | /bin/sh | — | any-guest-agent |
User: root Integrity Level: UNKNOWN | ||||
| 12458 | sudo -iu user google-chrome https://screenshare.pics/03LFO7.png | /usr/bin/sudo | — | sh |
User: root Integrity Level: UNKNOWN | ||||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 185.125.188.58:443 | api.snapcraft.io | Canonical Group Limited | GB | unknown |
— | — | 185.125.188.55:443 | api.snapcraft.io | Canonical Group Limited | GB | unknown |
— | — | 185.125.188.54:443 | api.snapcraft.io | Canonical Group Limited | GB | unknown |
— | — | 185.125.188.59:443 | api.snapcraft.io | Canonical Group Limited | GB | unknown |
470 | avahi-daemon | 224.0.0.251:5353 | — | — | — | unknown |
485 | snapd | 185.125.188.55:443 | api.snapcraft.io | Canonical Group Limited | GB | malicious |
485 | snapd | 185.125.188.54:443 | api.snapcraft.io | Canonical Group Limited | GB | unknown |
485 | snapd | 185.125.188.59:443 | api.snapcraft.io | Canonical Group Limited | GB | unknown |
— | — | 239.255.255.250:1900 | — | — | — | unknown |
— | — | 74.125.133.84:443 | accounts.google.com | — | — | unknown |
Domain | IP | Reputation |
|---|---|---|
api.snapcraft.io |
| unknown |
49.100.168.192.in-addr.arpa |
| unknown |
clientservices.googleapis.com |
| whitelisted |
safebrowsingohttpgateway.googleapis.com |
| unknown |
screenshare.pics |
| unknown |
google-ohttp-relay-safebrowsing.fastly-edge.com |
| unknown |
accounts.google.com |
| shared |
grabify.world |
| unknown |
grabify.link |
| unknown |
static.cloudflareinsights.com |
| whitelisted |