AI
Legitimate Pi-hole Docker image
Objectives
suspicious severity, 92% confident.
anti-analysis/environment-detect
iOS mobile analysis tool check
suspicious severity, 85% confident.
anti-static/obfuscation/control-flow
Small C++ binary with exception-obfuscated execution
suspicious severity, 90% confident.
anti-static/obfuscation/string
Massive string concatenation operations
suspicious severity, 95% confident.
collection/stealer
Greps for CTF flags
suspicious severity, 85% confident.
command-and-control/dropper/execution
Selects curl or wget dynamically
suspicious severity, 90% confident.
credential-access/dump
Access to system shadow password
suspicious severity, 92% confident.
discovery/account
Shell enumerates passwd and group files
suspicious severity, 88% confident.
discovery/network
Local network enumeration
suspicious severity, 85% confident.
discovery/system
Multiple architecture strings in runtime shell logic
suspicious severity, 90% confident.
discovery/system/fingerprint
Compact binary with comprehensive system fingerprinting
suspicious severity, 100% confident.
evasion/anti-av/platform
SELinux policy file references
suspicious severity, 100% confident.
evasion/kernel-hide/lkm
Fileless kernel module loading (memfd_create
suspicious severity, 94% confident.
exfiltration/stealer/credential
C PAN-OS curl binary POST
suspicious severity, 95% confident.
impact/infect
ELF file infector pattern
suspicious severity, 94% confident.
lateral-movement/pass-the-hash
NTLMSSP negotiate marker
suspicious severity, 90% confident.
persistence/system/service
Solaris SMF service FMRI
suspicious severity, 90% confident.
privilege-escalation
Systemd service modification and reload
suspicious severity, 96% confident.
supply-chain/recon-exfil/oast
Raw lifecycle content posts working directory
Micro-behaviors
suspicious severity, 95% confident.
fs/path/sensitive
Container/orchestration credential paths
anti-analysis
suspicious severity, 90% confident.
archive
Archive contains symlink that may escape extraction directory
20 of 207 traits shown
Identity
| SHA-256 | 1fb129e23cee9391b1eea4af34177cd973fab88b739205d89e149e3ebceb032e |
|---|---|
| Canonical SHA-256 | 000e3aa248a427d4f417a2a00376c473103d7efe294a0fe689990412c382640e |
| Filename | docker.io_pihole_pihole_experimental.tar.xz |
| Package | docker.io/pihole/pihole |
| Version | experimental |
Origin
| Source | forager |
|---|---|
| Feed | hub.docker.com |
| Ecosystem | container |
| Domain | docker.io |
| URL | oci://docker.io/pihole/pihole:experimental |
Timeline
| First seen | 15 Jun 2026 16:01 UTC |
|---|---|
| First analyzed | 15 Jun 2026 21:52 UTC |
| Last analyzed | 15 Jun 2026 21:52 UTC |
| Last updated | 15 Jun 2026 21:52 UTC |
Labeling
| Label | good |
|---|---|
| Label source | forager |
| Traits version | 061e3 |
Not seeing what you expected? Let us know