download: | /2025/07/22/P4XLO.jpeg |
Full analysis: | https://app.any.run/tasks/0be923e0-2514-4918-9678-b1bb5d5efae2 |
Verdict: | Malicious activity |
Threats: | Crypto mining malware is a resource-intensive threat that infiltrates computers with the purpose of mining cryptocurrencies. This type of threat can be deployed either on an infected machine or a compromised website. In both cases the miner will utilize the computing power of the device and its network bandwidth. |
Analysis date: | July 25, 2025, 19:56:40 |
OS: | Ubuntu 22.04.2 |
Tags: | |
Indicators: | |
MIME: | image/jpeg |
File info: | JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 640x640, components 3 |
MD5: | 65C2498D7393BF1141578F4CEB3F348E |
SHA1: | 0D418AED57749A1829B7D497EBF44F68272F4E07 |
SHA256: | F8C6C873E8289EBBD52D3FC5B6552129D7E20F8A3466ACA2D6F1DD2CDD578780 |
SSDEEP: | 6144:wngxqIQ/jyOOqJV9H8cXLiS7JSZlb5Y/iLkiUNH9V9MO:wng8IYJOq/18giOvNH9V9MO |
.jpg | | | JFIF JPEG bitmap (50) |
---|---|---|
.jpg | | | JPEG bitmap (37.4) |
.mp3 | | | MP3 audio (12.4) |
JFIFVersion: | 1.01 |
---|---|
ResolutionUnit: | None |
XResolution: | 1 |
YResolution: | 1 |
ImageSize: | 640x640 |
---|---|
Megapixels: | 0.41 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
41408 | /bin/sh -c "DISPLAY=:0 sudo -iu user eog /home/user/Desktop/P4XLO\.jpeg " | /usr/bin/dash | — | UbvyYXL4x2mYa65Q | |||||||||||
User: root Integrity Level: UNKNOWN Exit code: 0 Modules
| |||||||||||||||
41409 | sudo -iu user eog /home/user/Desktop/P4XLO.jpeg | /usr/bin/sudo | — | dash | |||||||||||
User: root Integrity Level: UNKNOWN Exit code: 0 Modules
| |||||||||||||||
41410 | eog /home/user/Desktop/P4XLO.jpeg | /usr/bin/eog | — | sudo | |||||||||||
User: user Integrity Level: UNKNOWN Exit code: 0 Modules
| |||||||||||||||
41411 | /usr/bin/locale-check C.UTF-8 | /usr/bin/locale-check | — | eog | |||||||||||
User: user Integrity Level: UNKNOWN Exit code: 0 Modules
| |||||||||||||||
41430 | /usr/bin/python3 /usr/bin/gnome-terminal | /usr/bin/python3.10 | — | gnome-shell | |||||||||||
User: user Integrity Level: UNKNOWN Exit code: 0 Modules
| |||||||||||||||
41432 | /usr/bin/gnome-terminal.real | /usr/bin/gnome-terminal.real | — | python3.10 | |||||||||||
User: user Integrity Level: UNKNOWN Exit code: 0 Modules
| |||||||||||||||
41437 | /usr/libexec/gnome-terminal-server | /usr/libexec/gnome-terminal-server | — | systemd | |||||||||||
User: user Integrity Level: UNKNOWN Exit code: 0 Modules
| |||||||||||||||
41455 | bash | /usr/bin/bash | — | gnome-terminal-server | |||||||||||
User: user Integrity Level: UNKNOWN Exit code: 0 Modules
| |||||||||||||||
41456 | /bin/sh /usr/bin/lesspipe | /usr/bin/dash | — | bash | |||||||||||
User: user Integrity Level: UNKNOWN Exit code: 0 Modules
| |||||||||||||||
41457 | basename /usr/bin/lesspipe | /usr/bin/basename | — | dash | |||||||||||
User: user Integrity Level: UNKNOWN Exit code: 0 Modules
|
PID | Process | Filename | Type | |
---|---|---|---|---|
41410 | eog | /home/user/.cache/thumbnails/normal/695ae0065f5ae46fba0a275a1711af44.png | image | |
MD5:— | SHA256:— | |||
41410 | eog | /home/user/.local/share/recently-used.xbel | xml | |
MD5:— | SHA256:— | |||
41497 | dd | /home/user/Desktop/panda-v14.sh | text | |
MD5:— | SHA256:— | |||
41515 | less | /home/user/.lesshsQ | text | |
MD5:— | SHA256:— | |||
41569 | apt-get | /tmp/#6029335 (deleted) | text | |
MD5:— | SHA256:— | |||
41569 | apt-get | /tmp/#6029338 (deleted) | text | |
MD5:— | SHA256:— | |||
41569 | apt-get | /tmp/#6029339 (deleted) | text | |
MD5:— | SHA256:— | |||
41569 | apt-get | /tmp/#6029359 (deleted) | text | |
MD5:— | SHA256:— | |||
41569 | apt-get | /tmp/#6029358 (deleted) | text | |
MD5:— | SHA256:— | |||
41569 | apt-get | /tmp/#6029364 (deleted) | text | |
MD5:— | SHA256:— |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
— | — | GET | 204 | 185.125.190.98:80 | http://connectivity-check.ubuntu.com/ | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
— | — | 91.189.91.97:80 | connectivity-check.ubuntu.com | Canonical Group Limited | US | whitelisted |
484 | avahi-daemon | 224.0.0.251:5353 | — | — | — | unknown |
— | — | 37.19.194.80:443 | odrs.gnome.org | Datacamp Limited | DE | whitelisted |
— | — | 185.125.190.98:80 | connectivity-check.ubuntu.com | Canonical Group Limited | GB | whitelisted |
— | — | 185.125.188.59:443 | api.snapcraft.io | Canonical Group Limited | GB | whitelisted |
— | — | 185.125.188.58:443 | api.snapcraft.io | Canonical Group Limited | GB | whitelisted |
— | — | 185.125.188.54:443 | api.snapcraft.io | Canonical Group Limited | GB | whitelisted |
41531 | curl | 140.82.121.4:443 | github.com | GITHUB | US | whitelisted |
41630 | bash | 51.79.215.200:7022 | stratum-asia.rplant.xyz | OVH SAS | SG | unknown |
41646 | curl | 140.82.121.4:443 | github.com | GITHUB | US | whitelisted |
Domain | IP | Reputation |
---|---|---|
connectivity-check.ubuntu.com |
| whitelisted |
google.com |
| whitelisted |
odrs.gnome.org |
| whitelisted |
api.snapcraft.io |
| whitelisted |
12.100.168.192.in-addr.arpa |
| unknown |
github.com |
| whitelisted |
stratum-asia.rplant.xyz |
| unknown |
release-assets.githubusercontent.com |
| unknown |
PID | Process | Class | Message |
---|---|---|---|
— | — | Not Suspicious Traffic | INFO [ANY.RUN] Attempting to access release user assets on GitHub |
— | — | Potential Corporate Privacy Violation | AV POLICY NiceHash Miner Subscribing To Pool |
— | — | Crypto Currency Mining Activity Detected | ET COINMINER W32/BitCoinMiner.MultiThreat Subscribe/Authorize Stratum Protocol Message |
— | — | Crypto Currency Mining Activity Detected | ET COINMINER W32/BitCoinMiner.MultiThreat Subscribe/Authorize Stratum Protocol Message |
— | — | Potential Corporate Privacy Violation | AV POLICY NiceHash Miner Subscribing To Pool |
— | — | Crypto Currency Mining Activity Detected | ET COINMINER W32/BitCoinMiner.MultiThreat Subscribe/Authorize Stratum Protocol Message |