Open-source atomic malware analysis

Analyze another

docker.io_pihole_pihole_experimental.tar.xz

TAR.XZ
Verdict: BENIGN
AI Legitimate Pi-hole Docker image

Objectives

suspicious severity, 92% confident.
anti-analysis/environment-detect iOS mobile analysis tool check
suspicious severity, 85% confident.
anti-static/obfuscation/control-flow Small C++ binary with exception-obfuscated execution
suspicious severity, 90% confident.
anti-static/obfuscation/string Massive string concatenation operations
suspicious severity, 95% confident.
collection/stealer Greps for CTF flags
suspicious severity, 85% confident.
command-and-control/dropper/execution Selects curl or wget dynamically
suspicious severity, 90% confident.
credential-access/dump Access to system shadow password
suspicious severity, 92% confident.
discovery/account Shell enumerates passwd and group files
suspicious severity, 88% confident.
discovery/network Local network enumeration
suspicious severity, 85% confident.
discovery/system Multiple architecture strings in runtime shell logic
suspicious severity, 90% confident.
discovery/system/fingerprint Compact binary with comprehensive system fingerprinting
suspicious severity, 100% confident.
evasion/anti-av/platform SELinux policy file references
suspicious severity, 100% confident.
evasion/kernel-hide/lkm Fileless kernel module loading (memfd_create
suspicious severity, 94% confident.
exfiltration/stealer/credential C PAN-OS curl binary POST
suspicious severity, 95% confident.
impact/infect ELF file infector pattern
suspicious severity, 94% confident.
lateral-movement/pass-the-hash NTLMSSP negotiate marker
suspicious severity, 90% confident.
persistence/system/service Solaris SMF service FMRI
suspicious severity, 90% confident.
privilege-escalation Systemd service modification and reload
suspicious severity, 96% confident.
supply-chain/recon-exfil/oast Raw lifecycle content posts working directory

Micro-behaviors

suspicious severity, 95% confident.
fs/path/sensitive Container/orchestration credential paths

anti-analysis

suspicious severity, 90% confident.
archive Archive contains symlink that may escape extraction directory

20 of 207 traits shown

Identity

SHA-256 1fb129e23cee9391b1eea4af34177cd973fab88b739205d89e149e3ebceb032e
Canonical SHA-256 000e3aa248a427d4f417a2a00376c473103d7efe294a0fe689990412c382640e
Filename docker.io_pihole_pihole_experimental.tar.xz
Package docker.io/pihole/pihole
Version experimental

Origin

Source forager
Feed hub.docker.com
Ecosystem container
Domain docker.io
URL oci://docker.io/pihole/pihole:experimental

Timeline

First seen 15 Jun 2026 16:01 UTC
First analyzed 15 Jun 2026 21:52 UTC
Last analyzed 15 Jun 2026 21:52 UTC
Last updated 15 Jun 2026 21:52 UTC

Labeling

Label good
Label source forager
Traits version 061e3