Open-source atomic malware analysis

Analyze another

CW.Assistant.Extensions.Assistant.26.8.0-alpha.14.nupkg

NUPKG
Verdict: BENIGN
Mal-ecule
H(Cm)Md₂(Bi₂Si)
Size 35.0 KB download
First seen 10 days ago
Analyzed 10 days ago
Ecosystem dotnet
Source nuget.org

Objectives

component severity, 90% confident.
anti-static/obfuscation/control-flow Regex component marker
component severity, 99% confident.
anti-static/obfuscation/payload PE version resource text
component severity, 90% confident.
anti-static/pack Reloc section mostly non-relocation bytes
component severity, 80% confident.
command-and-control/dropper/delivery Compact PE import table
component severity, 100% confident.
command-and-control/infrastructure Binary has 4 or fewer sections
component severity, 92% confident.
evasion/process/injection Regex component marker
component severity, 98% confident.
supply-chain/metadata-anomaly/manifest NuGet nuspec manifest file

Micro-behaviors

notable severity, 86% confident.
communications/ip Hardcoded external IPv4 address
component severity, 80% confident.
communications/http/client Regex component marker
component severity, 90% confident.
communications/proxy SOCKS5 client greeting bytes
component severity, 88% confident.
data/text/keywords Codebase deletion target

Metadata

notable severity, 100% confident.
binary PE binary has trailing overlay data
notable severity, 100% confident.
signed Signed by AEC Advanced Engineering Computation Aktiebolag
baseline severity, 90% confident.
binary/section PE .reloc section presence
baseline severity, 100% confident.
file DLL filename extension present
baseline severity, 100% confident.
hardening DEP / NX enabled (NX_COMPAT)
baseline severity, 90% confident.
package PE version resource metadata
component severity, 95% confident.
binary/anomaly PE version info numeric fields present
component severity, 90% confident.
binary/metrics Binary has high overall entropy (packed/encrypted)
component severity, 86% confident.
build Cargo archive contains Windows native binary

20 of 25 traits shown

Identity

SHA-256 0c5e932e68d7a9316fc2d96e3dca87afdbe0a2e7c8cd888d9f242c51de1037c7
Canonical SHA-256 031c9dac8c951bcb4dc0e05a8d1b5fa1d0a98ca6601012f044250eab4349dfb3
Filename CW.Assistant.Extensions.Assistant.26.8.0-alpha.14.nupkg
Package CW.Assistant.Extensions.Assistant
Version 26.8.0-alpha.14

Origin

Source harvest
Feed nuget.org
Ecosystem dotnet
Domain nuget.org

Timeline

First seen 11 Jun 2026 19:39 UTC
First analyzed 12 Jun 2026 02:08 UTC
Last analyzed 12 Jun 2026 02:08 UTC
Last updated 12 Jun 2026 02:08 UTC

Labeling

Label unknown
Label source harvest
Traits version e31a3