Open-source atomic malware analysis

Analyze another

llama_cpp_bin-9660.0.0.tar.gz

TAR.GZ
Verdict: BENIGN
AI Legitimate llama.cpp source code distribution
Mal-ecule
K(Li)O₈(AlCEu₂SAsCoDy₂Er₃)H₆(Cm₁₄Db₄Ds₂F₆Os₅Po₁₀)Md₃(BkPt)
Size 4.1 MB download
First seen 1 day ago
Analyzed 1 day ago
Ecosystem python

Well-known

notable severity, 95% confident.
lib nlohmann::json single-header source library

Objectives

suspicious severity, 95% confident.
anti-analysis/debugger-detect Unix TracerPid debugger check
suspicious severity, 92% confident.
command-and-control/backdoor/tasking Native exec read task tokens
suspicious severity, 92% confident.
exfiltration/stealer Native environ harvest loop
suspicious severity, 85% confident.
supply-chain/metadata-anomaly setup.py with abnormally high version number
notable severity, 90% confident.
evasion/file-hiding Quoted hidden-dotfile path literal
notable severity, 100% confident.
evasion/kernel-hide/lkm Derived ast condition

Micro-behaviors

notable severity, 90% confident.
communications/http/request Performs HTTP request (urllib, requests, httpx)
notable severity, 100% confident.
communications/socket Raw socket send call
notable severity, 90% confident.
data/compress ZSTD_CCtx type
notable severity, 90% confident.
data/serialize Python json.loads call
notable severity, 90% confident.
data/text/llm LLM edit_file tool reference
notable severity, 95% confident.
dylib/load LoadLibraryA call in source
notable severity, 92% confident.
os/msdos DOS read file call
notable severity, 95% confident.
process/create Create process (ANSI)
notable severity, 90% confident.
process/create/shell system() function call
notable severity, 90% confident.
process/info Get module handle

Metadata

notable severity, 92% confident.
build actions/checkout workflow step
notable severity, 90% confident.
encoded-payload Encoded payload detected: xor → base64
notable severity, 95% confident.
lang Source imports subprocess module

20 of 52 traits shown

Identity

SHA-256 2382c9aeba8782c5ed071ede52f48c089f67152c7461e3e0cd56cdc24ab77286
Canonical SHA-256 0029616465e6d641c1e75a0e0e6e132f3ea6177593735d7f16c89e7edfbbe9a8
Filename llama_cpp_bin-9660.0.0.tar.gz
Package llama-cpp-bin
Version 9660.0.0

Timeline

First seen 15 Jun 2026 23:31 UTC
First analyzed 16 Jun 2026 16:12 UTC
Last analyzed 16 Jun 2026 16:12 UTC
Last updated 16 Jun 2026 16:12 UTC

Labeling

Label unknown
Label source forager
Traits version 061e3