File name:

DEL.txt

Full analysis: https://app.any.run/tasks/d93f103c-2427-4d62-b1ab-5a3a51b86c3a
Verdict: Malicious activity
Analysis date: May 22, 2024, 05:42:11
OS: Ubuntu 22.04.2
MIME: text/plain
File info: ASCII text, with CRLF line terminators
MD5:

43B0C96498AF1C336100F48F916C5CAA

SHA1:

9298854D67D642E98B1973EF534A59C0EED9845A

SHA256:

FA66504708C2D3A2A05D7FFC4D733BD4AB0CCF4E88FE320B30C7CF60BD2087A9

SSDEEP:

3:3Jy43MfPYlv6hC5XKF28FrzyrAuAoAXON3yMoqZUVHYDMWz:3JFcfPi6WXfUrehAoAeMMoX6DMM

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executes commands using command-line interpreter

      • apt (PID: 6356)
      • apt (PID: 6280)
      • gnome-terminal-server (PID: 6235)
      • apt (PID: 6429)
      • apt (PID: 6460)
      • dpkg-preconfigure (PID: 6508)
      • apt (PID: 6584)
    • Executes the "rm" command to delete files or directories

      • dpkg (PID: 6523)
      • update-motd-updates-available (PID: 6590)
    • Checks the user who created the process

      • ftp (PID: 6452)
    • Connects to FTP

      • ftp (PID: 6452)
    • Creates or rewrites file in the "bin" folder

      • dpkg (PID: 6523)
    • Uses base64 (probably to encode stolen data or decode malicious payload)

      • nmap-common.postinst (PID: 6573)
    • Changes time attribute to hide new files or make changes to the existing one

      • sh (PID: 6588)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.pic | Bio-Rad Image(s) bitmap (100)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
555
Monitored processes
333
Malicious processes
0
Suspicious processes
1

Behavior graph

Click at the process to see the details
start sh no specs sudo no specs gnome-text-editor no specs locale-check no specs systemctl no specs gnome-terminal no specs gnome-terminal.real no specs gnome-terminal-server no specs bash no specs lesspipe no specs basename no specs dash no specs dircolors no specs dirname no specs bash no specs command-not-found no specs snap no specs apt no specs dpkg no specs sudo no specs sudo no specs apt no specs dpkg no specs dpkg no specs sh no specs snap no specs http no specs sh no specs snap no specs sh no specs snap no specs http sh no specs snap no specs bash no specs bash no specs bash no specs apt-cache no specs dpkg no specs bash no specs bash no specs apt-cache no specs dpkg no specs bash no specs bash no specs apt-cache no specs dpkg no specs sudo no specs sudo no specs apt no specs dpkg no specs dpkg no specs sh no specs snap no specs http no specs sh no specs snap no specs sh no specs snap no specs http sh no specs snap no specs sudo no specs sudo no specs apt no specs dpkg no specs dpkg no specs sh no specs snap no specs dig grep no specs ftp telnet telnet sudo no specs sudo no specs apt no specs dpkg no specs dpkg no specs sh no specs snap no specs http no specs sh no specs snap no specs sh no specs snap no specs http sh no specs dpkg-preconfigure no specs locale no specs sh no specs sh no specs stty no specs stty no specs sh no specs whiptail no specs perl no specs apt-extracttemplates no specs dpkg no specs dpkg no specs dpkg no specs dpkg no specs dpkg no specs dpkg no specs dpkg-split no specs dpkg-deb no specs dpkg-deb no specs dpkg-deb no specs tar no specs preinst no specs dpkg-deb no specs dpkg-deb no specs dpkg-deb no specs rm no specs dpkg-split no specs dpkg-deb no specs dpkg-deb no specs dpkg-deb no specs tar no specs dpkg-deb no specs dpkg-deb no specs dpkg-deb no specs rm no specs dpkg-split no specs dpkg-deb no specs dpkg-deb no specs dpkg-deb no specs tar no specs dpkg-deb no specs dpkg-deb no specs dpkg-deb no specs rm no specs dpkg-split no specs dpkg-deb no specs dpkg-deb no specs dpkg-deb no specs tar no specs dpkg-deb no specs dpkg-deb no specs dpkg-deb no specs rm no specs dpkg-split no specs dpkg-deb no specs dpkg-deb no specs dpkg-deb no specs tar no specs dpkg-deb no specs dpkg-deb no specs dpkg-deb no specs rm no specs dpkg no specs libblas3:amd64.postinst no specs update-alternatives no specs nmap-common.postinst no specs tac no specs base64 no specs gzip no specs man-db.postinst no specs mandb no specs libc-bin.postinst no specs ldconfig.real no specs dpkg no specs dpkg no specs dpkg no specs apt no specs sh no specs sh no specs test no specs echo no specs touch no specs update-motd-updates-available no specs apt-config no specs apt-config no specs apt-config no specs apt-config no specs apt-config no specs find no specs mktemp no specs apt-check no specs dirname no specs dpkg no specs dpkg no specs ischroot no specs dpkg no specs dpkg no specs dpkg no specs dpkg no specs dpkg no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs rm no specs sh no specs snap no specs nmap dpkg no specs dpkg no specs ischroot no specs dpkg no specs dpkg no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs lsb_release no specs

Process information

PID
CMD
Path
Indicators
Parent process
6169/bin/sh -c "DISPLAY=:0 sudo -iu user gnome-text-editor /tmp/DEL\.txt "/bin/shany-guest-agent
User:
user
Integrity Level:
UNKNOWN
6170sudo -iu user gnome-text-editor /tmp/DEL.txt/usr/bin/sudosh
User:
user
Integrity Level:
UNKNOWN
6171gnome-text-editor /tmp/DEL.txt/usr/bin/gnome-text-editorsudo
User:
user
Integrity Level:
UNKNOWN
6172/usr/bin/locale-check C.UTF-8/usr/bin/locale-checkgnome-text-editor
User:
user
Integrity Level:
UNKNOWN
Exit code:
0
6218systemctl --user --global is-enabled snap.snapd-desktop-integration.snapd-desktop-integration.service/usr/bin/systemctlsnapd
User:
root
Integrity Level:
UNKNOWN
Exit code:
6171
6228/usr/bin/python3 /usr/bin/gnome-terminal/usr/bin/gnome-terminalgnome-shell
User:
user
Integrity Level:
UNKNOWN
Exit code:
1464
6230/usr/bin/gnome-terminal.real/usr/bin/gnome-terminal.realgnome-terminal
User:
user
Integrity Level:
UNKNOWN
Exit code:
6171
6235/usr/libexec/gnome-terminal-server/usr/libexec/gnome-terminal-serversystemd
User:
user
Integrity Level:
UNKNOWN
6253bash/bin/bashgnome-terminal-server
User:
user
Integrity Level:
UNKNOWN
6254/bin/sh /usr/bin/lesspipe/usr/bin/lesspipebash
User:
user
Integrity Level:
UNKNOWN
Exit code:
6171
Executable files
0
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
6171gnome-text-editor/home/user/.local/share/org.gnome.TextEditor/recently-used.xbel.CDG0N2
MD5:
SHA256:
6171gnome-text-editor/home/user/.config/enchant/en_IE.dic
MD5:
SHA256:
6171gnome-text-editor/home/user/.config/enchant/en_IE.exc
MD5:
SHA256:
6171gnome-text-editor/home/user/.cache/mesa_shader_cache/07/a5ca34ded861cac74dd87c9367c0531ebaf63d.tmp
MD5:
SHA256:
6171gnome-text-editor/home/user/.cache/mesa_shader_cache/ab/bb62a84ebd8c6f699de6da1f95cf51d1deb40a.tmp
MD5:
SHA256:
6171gnome-text-editor/home/user/.cache/mesa_shader_cache/d2/ea27fa2c8972e4719271e6ea166eb60cb88796.tmp
MD5:
SHA256:
6171gnome-text-editor/home/user/.cache/mesa_shader_cache/74/0feed80fcc6c9ed6fbc025c5e0aa962968fa40.tmp
MD5:
SHA256:
6171gnome-text-editor/home/user/.local/share/org.gnome.TextEditor/.goutputstream-9IN5N2
MD5:
SHA256:
6171gnome-text-editor/home/user/.local/share/org.gnome.TextEditor/recently-used.xbel.FXC4N2
MD5:
SHA256:
6171gnome-text-editor/home/user/.cache/mesa_shader_cache/92/143bd47bc036b374d409d26257fa05426c8ece.tmp
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
9
TCP/UDP connections
27
DNS requests
20
Threats
7

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6406
http
GET
404
185.125.190.39:80
http://ie.archive.ubuntu.com/ubuntu/pool/main/c/curl/curl_7.81.0-1ubuntu1.15_amd64.deb
unknown
unknown
GET
204
185.125.190.96:80
http://connectivity-check.ubuntu.com/
unknown
unknown
6506
http
GET
185.125.190.36:80
http://ie.archive.ubuntu.com/ubuntu/pool/universe/libl/liblinear/liblinear4_2.3.0%2bdfsg-5_amd64.deb
unknown
unknown
6326
http
GET
404
91.189.91.82:80
http://ie.archive.ubuntu.com/ubuntu/pool/main/c/curl/curl_7.81.0-1ubuntu1.15_amd64.deb
unknown
unknown
6506
http
GET
185.125.190.36:80
http://ie.archive.ubuntu.com/ubuntu/pool/universe/l/lua-lpeg/lua-lpeg_1.0.2-1_amd64.deb
unknown
unknown
6506
http
GET
185.125.190.36:80
http://ie.archive.ubuntu.com/ubuntu/pool/universe/n/nmap/nmap-common_7.91%2bdfsg1%2breally7.80%2bdfsg1-2ubuntu0.1_all.deb
unknown
unknown
6506
http
GET
200
185.125.190.36:80
http://ie.archive.ubuntu.com/ubuntu/pool/main/l/lapack/libblas3_3.10.0-2ubuntu1_amd64.deb
unknown
unknown
473
NetworkManager
GET
204
91.189.91.48:80
http://connectivity-check.ubuntu.com/
unknown
unknown
6506
http
GET
200
185.125.190.36:80
http://ie.archive.ubuntu.com/ubuntu/pool/universe/n/nmap/nmap_7.91%2bdfsg1%2breally7.80%2bdfsg1-2ubuntu0.1_amd64.deb
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
185.125.190.96:80
connectivity-check.ubuntu.com
Canonical Group Limited
GB
unknown
195.181.170.19:443
Datacamp Limited
DE
unknown
470
avahi-daemon
224.0.0.251:5353
unknown
1195
snap-store
212.102.56.181:443
Datacamp Limited
DE
unknown
485
snapd
185.125.188.55:443
api.snapcraft.io
Canonical Group Limited
GB
malicious
6326
http
91.189.91.82:80
ie.archive.ubuntu.com
Canonical Group Limited
US
unknown
6406
http
185.125.190.39:80
ie.archive.ubuntu.com
Canonical Group Limited
GB
unknown
6452
ftp
213.192.90.102:21
Technical University of Gdansk, Academic Computer Center TASK
PL
unknown
6454
telnet
213.192.90.102:23
Technical University of Gdansk, Academic Computer Center TASK
PL
unknown
6455
telnet
213.192.90.102:443
Technical University of Gdansk, Academic Computer Center TASK
PL
unknown

DNS requests

Domain
IP
Reputation
163.100.168.192.in-addr.arpa
unknown
api.snapcraft.io
  • 185.125.188.54
  • 185.125.188.59
  • 185.125.188.58
  • 185.125.188.55
unknown
_http._tcp.ie.archive.ubuntu.com
unknown
ie.archive.ubuntu.com
  • 91.189.91.82
  • 91.189.91.83
  • 185.125.190.36
  • 185.125.190.39
  • 91.189.91.81
  • 2620:2d:4000:1::16
  • 2620:2d:4002:1::103
  • 2620:2d:4002:1::102
  • 2620:2d:4000:1::19
  • 2620:2d:4002:1::101
unknown
connectivity-check.ubuntu.com
  • 2620:2d:4000:1::98
  • 2001:67c:1562::23
  • 2620:2d:4002:1::197
  • 2620:2d:4000:1::2b
  • 2620:2d:4000:1::2a
  • 2620:2d:4000:1::22
  • 2001:67c:1562::24
  • 2620:2d:4000:1::23
  • 2620:2d:4000:1::96
  • 2620:2d:4002:1::198
  • 2620:2d:4000:1::97
  • 2620:2d:4002:1::196
  • 91.189.91.48
  • 91.189.91.97
  • 185.125.190.49
  • 185.125.190.18
  • 91.189.91.96
  • 185.125.190.97
  • 91.189.91.49
  • 91.189.91.98
  • 185.125.190.48
  • 185.125.190.96
  • 185.125.190.17
  • 185.125.190.98
unknown
213.192.90.102
  • 49.13.77.253
unknown
102.90.192.213.in-addr.arpa
unknown

Threats

PID
Process
Class
Message
6326
http
Not Suspicious Traffic
ET POLICY GNU/Linux APT User-Agent Outbound likely related to package management
6406
http
Not Suspicious Traffic
ET POLICY GNU/Linux APT User-Agent Outbound likely related to package management
6506
http
Not Suspicious Traffic
ET POLICY GNU/Linux APT User-Agent Outbound likely related to package management
6506
http
Not Suspicious Traffic
ET POLICY GNU/Linux APT User-Agent Outbound likely related to package management
6506
http
Not Suspicious Traffic
ET POLICY GNU/Linux APT User-Agent Outbound likely related to package management
6506
http
Not Suspicious Traffic
ET POLICY GNU/Linux APT User-Agent Outbound likely related to package management
6506
http
Not Suspicious Traffic
ET POLICY GNU/Linux APT User-Agent Outbound likely related to package management
No debug info