Linux Analysis Report
SGNConnect_v5.0.20.deb

Overview

General Information

Sample name: SGNConnect_v5.0.20.deb
Analysis ID: 1655141
MD5: 8aa66ae2a690b14f05dcd0289714e99d
SHA1: 32a4113918a775b59bc2273fc11c48bc62272e89
SHA256: 7383858f6f991035ec2a43e70af6e103dc6bfc6e06c62e1d1474d638c8fb4867
Infos:

Detection

Score: 2
Range: 0 - 100

Signatures

Creates hidden files and/or directories
Executes the "rm" command used to delete files or directories
Sample tries to set the executable flag
Uses the "uname" system call to query kernel version information (possible evasion)
Writes shell script file to disk with an unusual file extension

Classification

RansomwareSpreadingPhishingBankerTrojan / BotAdwareSpywareExploiterEvaderMinercleansuspiciousmalicious
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global traffic DNS traffic detected: DNS query: daisy.ubuntu.com
Source: classification engine Classification label: clean2.linDEB@0/6@2/0
Source: /usr/bin/exo-open (PID: 5446) Directory: /root/.Xdefaults-galassia Jump to behavior
Source: /usr/bin/exo-open (PID: 5446) Directory: /root/.cache Jump to behavior
Source: /usr/bin/engrampa (PID: 5453) Directory: /root/.Xdefaults-galassia Jump to behavior
Source: /usr/bin/engrampa (PID: 5453) Directory: /usr/share/fonts/.uuid Jump to behavior
Source: /usr/bin/engrampa (PID: 5453) Directory: /usr/local/share/fonts/.uuid Jump to behavior
Source: /usr/bin/engrampa (PID: 5453) Directory: /root/.local/share/fonts/.uuid Jump to behavior
Source: /usr/bin/engrampa (PID: 5453) Directory: /root/.fonts/.uuid Jump to behavior
Source: /usr/bin/engrampa (PID: 5453) Directory: /usr/share/fonts/X11/.uuid Jump to behavior
Source: /usr/bin/engrampa (PID: 5453) Directory: /usr/share/fonts/cMap/.uuid Jump to behavior
Source: /usr/bin/engrampa (PID: 5453) Directory: /usr/share/fonts/cmap/.uuid Jump to behavior
Source: /usr/bin/engrampa (PID: 5453) Directory: /usr/share/fonts/opentype/.uuid Jump to behavior
Source: /usr/bin/engrampa (PID: 5453) Directory: /usr/share/fonts/truetype/.uuid Jump to behavior
Source: /usr/bin/engrampa (PID: 5453) Directory: /usr/share/fonts/type1/.uuid Jump to behavior
Source: /usr/bin/engrampa (PID: 5453) Directory: /usr/share/fonts/X11/Type1/.uuid Jump to behavior
Source: /usr/bin/engrampa (PID: 5453) Directory: /usr/share/fonts/X11/encodings/.uuid Jump to behavior
Source: /usr/bin/engrampa (PID: 5453) Directory: /usr/share/fonts/X11/misc/.uuid Jump to behavior
Source: /usr/bin/engrampa (PID: 5453) Directory: /usr/share/fonts/X11/util/.uuid Jump to behavior
Source: /usr/bin/engrampa (PID: 5453) Directory: /usr/share/fonts/cmap/adobe-cns1/.uuid Jump to behavior
Source: /usr/bin/engrampa (PID: 5453) Directory: /usr/share/fonts/cmap/adobe-gb1/.uuid Jump to behavior
Source: /usr/bin/engrampa (PID: 5453) Directory: /usr/share/fonts/cmap/adobe-japan1/.uuid Jump to behavior
Source: /usr/bin/engrampa (PID: 5453) Directory: /usr/share/fonts/cmap/adobe-japan2/.uuid Jump to behavior
Source: /usr/bin/engrampa (PID: 5453) Directory: /usr/share/fonts/cmap/adobe-korea1/.uuid Jump to behavior
Source: /usr/bin/engrampa (PID: 5453) Directory: /usr/share/fonts/opentype/malayalam/.uuid Jump to behavior
Source: /usr/bin/engrampa (PID: 5453) Directory: /usr/share/fonts/opentype/mathjax/.uuid Jump to behavior
Source: /usr/bin/engrampa (PID: 5453) Directory: /usr/share/fonts/opentype/noto/.uuid Jump to behavior
Source: /usr/bin/engrampa (PID: 5453) Directory: /usr/share/fonts/opentype/urw-base35/.uuid Jump to behavior
Source: /usr/bin/engrampa (PID: 5453) Directory: /usr/share/fonts/truetype/Gargi/.uuid Jump to behavior
Source: /usr/bin/engrampa (PID: 5453) Directory: /usr/share/fonts/truetype/Gubbi/.uuid Jump to behavior
Source: /usr/bin/engrampa (PID: 5453) Directory: /usr/share/fonts/truetype/Nakula/.uuid Jump to behavior
Source: /usr/bin/engrampa (PID: 5453) Directory: /usr/share/fonts/truetype/Navilu/.uuid Jump to behavior
Source: /usr/bin/engrampa (PID: 5453) Directory: /usr/share/fonts/truetype/Sahadeva/.uuid Jump to behavior
Source: /usr/bin/engrampa (PID: 5453) Directory: /usr/share/fonts/truetype/Sarai/.uuid Jump to behavior
Source: /usr/bin/engrampa (PID: 5453) Directory: /usr/share/fonts/truetype/abyssinica/.uuid Jump to behavior
Source: /usr/bin/engrampa (PID: 5453) Directory: /usr/share/fonts/truetype/ancient-scripts/.uuid Jump to behavior
Source: /usr/bin/engrampa (PID: 5453) Directory: /usr/share/fonts/truetype/dejavu/.uuid Jump to behavior
Source: /usr/bin/engrampa (PID: 5453) Directory: /usr/share/fonts/truetype/droid/.uuid Jump to behavior
Source: /usr/bin/engrampa (PID: 5453) Directory: /usr/share/fonts/truetype/fonts-beng-extra/.uuid Jump to behavior
Source: /usr/bin/engrampa (PID: 5453) Directory: /usr/share/fonts/truetype/fonts-deva-extra/.uuid Jump to behavior
Source: /usr/bin/engrampa (PID: 5453) Directory: /usr/share/fonts/truetype/fonts-gujr-extra/.uuid Jump to behavior
Source: /usr/bin/engrampa (PID: 5453) Directory: /usr/share/fonts/truetype/fonts-guru-extra/.uuid Jump to behavior
Source: /usr/bin/engrampa (PID: 5453) Directory: /usr/share/fonts/truetype/fonts-kalapi/.uuid Jump to behavior
Source: /usr/bin/engrampa (PID: 5453) Directory: /usr/share/fonts/truetype/fonts-orya-extra/.uuid Jump to behavior
Source: /usr/bin/engrampa (PID: 5453) Directory: /usr/share/fonts/truetype/fonts-telu-extra/.uuid Jump to behavior
Source: /usr/bin/engrampa (PID: 5453) Directory: /usr/share/fonts/truetype/fonts-yrsa-rasa/.uuid Jump to behavior
Source: /usr/bin/engrampa (PID: 5453) Directory: /usr/share/fonts/truetype/freefont/.uuid Jump to behavior
Source: /usr/bin/engrampa (PID: 5453) Directory: /usr/share/fonts/truetype/kacst/.uuid Jump to behavior
Source: /usr/bin/engrampa (PID: 5453) Directory: /usr/share/fonts/truetype/kacst-one/.uuid Jump to behavior
Source: /usr/bin/engrampa (PID: 5453) Directory: /usr/share/fonts/truetype/lao/.uuid Jump to behavior
Source: /usr/bin/engrampa (PID: 5453) Directory: /usr/share/fonts/truetype/lato/.uuid Jump to behavior
Source: /usr/bin/engrampa (PID: 5453) Directory: /usr/share/fonts/truetype/liberation/.uuid Jump to behavior
Source: /usr/bin/engrampa (PID: 5453) Directory: /usr/share/fonts/truetype/liberation2/.uuid Jump to behavior
Source: /usr/bin/engrampa (PID: 5453) Directory: /usr/share/fonts/truetype/lohit-assamese/.uuid Jump to behavior
Source: /usr/bin/engrampa (PID: 5453) Directory: /usr/share/fonts/truetype/lohit-bengali/.uuid Jump to behavior
Source: /usr/bin/engrampa (PID: 5453) Directory: /usr/share/fonts/truetype/lohit-devanagari/.uuid Jump to behavior
Source: /usr/bin/engrampa (PID: 5453) Directory: /usr/share/fonts/truetype/lohit-gujarati/.uuid Jump to behavior
Source: /usr/bin/engrampa (PID: 5453) Directory: /usr/share/fonts/truetype/lohit-kannada/.uuid Jump to behavior
Source: /usr/bin/engrampa (PID: 5453) Directory: /usr/share/fonts/truetype/lohit-malayalam/.uuid Jump to behavior
Source: /usr/bin/engrampa (PID: 5453) Directory: /usr/share/fonts/truetype/lohit-oriya/.uuid Jump to behavior
Source: /usr/bin/engrampa (PID: 5453) Directory: /usr/share/fonts/truetype/lohit-punjabi/.uuid Jump to behavior
Source: /usr/bin/engrampa (PID: 5453) Directory: /usr/share/fonts/truetype/lohit-tamil/.uuid Jump to behavior
Source: /usr/bin/engrampa (PID: 5453) Directory: /usr/share/fonts/truetype/lohit-tamil-classical/.uuid Jump to behavior
Source: /usr/bin/engrampa (PID: 5453) Directory: /usr/share/fonts/truetype/lohit-telugu/.uuid Jump to behavior
Source: /usr/bin/engrampa (PID: 5453) Directory: /usr/share/fonts/truetype/malayalam/.uuid Jump to behavior
Source: /usr/bin/engrampa (PID: 5453) Directory: /usr/share/fonts/truetype/noto/.uuid Jump to behavior
Source: /usr/bin/engrampa (PID: 5453) Directory: /usr/share/fonts/truetype/openoffice/.uuid Jump to behavior
Source: /usr/bin/engrampa (PID: 5453) Directory: /usr/share/fonts/truetype/padauk/.uuid Jump to behavior
Source: /usr/bin/engrampa (PID: 5453) Directory: /usr/share/fonts/truetype/pagul/.uuid Jump to behavior
Source: /usr/bin/engrampa (PID: 5453) Directory: /usr/share/fonts/truetype/samyak/.uuid Jump to behavior
Source: /usr/bin/engrampa (PID: 5453) Directory: /usr/share/fonts/truetype/samyak-fonts/.uuid Jump to behavior
Source: /usr/bin/engrampa (PID: 5453) Directory: /usr/share/fonts/truetype/sinhala/.uuid Jump to behavior
Source: /usr/bin/engrampa (PID: 5453) Directory: /usr/share/fonts/truetype/tibetan-machine/.uuid Jump to behavior
Source: /usr/bin/engrampa (PID: 5453) Directory: /usr/share/fonts/truetype/tlwg/.uuid Jump to behavior
Source: /usr/bin/engrampa (PID: 5453) Directory: /usr/share/fonts/truetype/ttf-khmeros-core/.uuid Jump to behavior
Source: /usr/bin/engrampa (PID: 5453) Directory: /usr/share/fonts/truetype/ubuntu/.uuid Jump to behavior
Source: /usr/bin/engrampa (PID: 5453) Directory: /usr/share/fonts/type1/urw-base35/.uuid Jump to behavior
Source: /usr/bin/engrampa (PID: 5453) Directory: /usr/share/fonts/X11/encodings/large/.uuid Jump to behavior
Source: /usr/bin/engrampa (PID: 5453) Directory: /root/.cache Jump to behavior
Source: /usr/bin/tar (PID: 5467) Directory: /tmp/dpkg-deb.7lBi6l/. Jump to behavior
Source: /usr/bin/dpkg-deb (PID: 5468) Rm executable: /usr/bin/rm -> rm -rf -- /tmp/dpkg-deb.7lBi6l Jump to behavior
Source: /usr/bin/tar (PID: 5467) File: /tmp/dpkg-deb.7lBi6l/postinst (bits: - usr: rx grp: rx all: rwx) Jump to behavior
Source: /usr/bin/tar (PID: 5467) File: /tmp/dpkg-deb.7lBi6l/prerm (bits: - usr: rx grp: rx all: rwx) Jump to behavior
Source: /usr/bin/tar (PID: 5467) File: /tmp/dpkg-deb.7lBi6l/. (bits: - usr: rx grp: rx all: rwx) Jump to behavior
Source: /usr/bin/tar (PID: 5467) Writes shell script file to disk with an unusual file extension: /tmp/dpkg-deb.7lBi6l/postinst Jump to dropped file
Source: /usr/bin/tar (PID: 5467) Writes shell script file to disk with an unusual file extension: /tmp/dpkg-deb.7lBi6l/prerm Jump to dropped file
Source: /usr/bin/exo-open (PID: 5446) Queries kernel information via 'uname': Jump to behavior
Source: /usr/bin/dbus-launch (PID: 5450) Queries kernel information via 'uname': Jump to behavior
Source: /usr/bin/engrampa (PID: 5453) Queries kernel information via 'uname': Jump to behavior
Source: /usr/bin/dbus-launch (PID: 5456) Queries kernel information via 'uname': Jump to behavior
No contacted IP infos