Open-source atomic malware analysis

Analyze another

rsocket.rb

RUBY
Verdict: SUSPICIOUS
Mal-ecule
KO₃(C₂Ca₂S)H₂(Cm₂U)Md(Pa)
Size 180 B download
First seen 117 days ago
Analyzed 115 days ago
Ecosystem malcontent-samples

Well-known

notable severity, 70% confident.
tool/offensive GTFOBins Ruby pattern marker

Objectives

suspicious severity, 90% confident.
command-and-control Ruby TCPSocket with popen (reverse
suspicious severity, 90% confident.
command-and-control/backdoor/webshell Web shell command parameter
notable severity, 75% confident.
supply-chain/metadata-anomaly IO.popen execution

Micro-behaviors

notable severity, 90% confident.
communications/socket TCP socket connection

Metadata

component severity, 80% confident.
package Very short file (under 12 lines)

Identity

SHA-256 0b947405a6357ad9b469143d68b70ec57bdb8c04b0bff60a545fecdd819333ca
Filename rsocket.rb

Origin

Source harvest
Feed datasets
Ecosystem malcontent-samples

Timeline

First seen 24 Apr 2026 16:18 UTC
Last analyzed 26 Apr 2026 16:57 UTC
Last updated 26 Apr 2026 16:57 UTC

Labeling

Label bad
Label source harvest
Traits version bf48d