Open-source atomic malware analysis

Analyze another

Azure.Security.KeyVault.Secrets.4.11.0.nupkg

ZIP
Verdict: SUSPICIOUS
Mal-ecule
O(Dy)H₂(Cm₃Db₃)Md₃(BiHeSi)
Size 372.0 KB download
First seen 42 days ago
Analyzed 36 days ago
Ecosystem dotnet
Source nuget.org

Objectives

notable severity, 85% confident.
anti-static/obfuscation/payload mscoree.dll text reference
notable severity, 82% confident.
discovery/network/scan Public cloud range providers
baseline severity, 100% confident.
anti-static/obfuscation WININET.DLL absent from PE import table
baseline severity, 90% confident.
evasion/anti-av/edr-detect Security product displayName field

Micro-behaviors

notable severity, 82% confident.
communications/http WebSocket async send method
notable severity, 72% confident.
communications/http/client Async HTTP response retrieval
notable severity, 100% confident.
communications/http/server Access to ASP.NET Request object
notable severity, 70% confident.
data/db LINQ query operations
notable severity, 90% confident.
data/decode .NET FromBase64String reference
notable severity, 85% confident.
data/serialize System.Text.Json library reference
baseline severity, 95% confident.
data/embedded Microsoft timestamp certificate chain

Metadata

notable severity, 97% confident.
binary/anomaly Reproducible PE has future timestamp
notable severity, 100% confident.
hardening Modern PE without ASLR enabled
notable severity, 100% confident.
signed Signed by Microsoft Corporation
baseline severity, 100% confident.
binary .NET Assembly (mscoree.dll)
baseline severity, 100% confident.
binary/metrics Binary has 1000 or more strings
baseline severity, 90% confident.
binary/section PE .reloc section presence
baseline severity, 100% confident.
build Built with /Brepro (deterministic)
baseline severity, 100% confident.
dotnet .NET assembly detected via BSJB CLR metadata signature
baseline severity, 95% confident.
dylib::mscoree links mscoree.dll (CorDllMain)

20 of 61 traits shown

Identity

SHA-256 25aaca1abbdd820ed26355ec0e4a00f37197513aa4a235624d21ac6bee018500
Filename Azure.Security.KeyVault.Secrets.4.11.0.nupkg

Origin

Ecosystem dotnet
Domain nuget.org

Timeline

First seen 5 May 2026 20:22 UTC
Last analyzed 12 May 2026 12:34 UTC