Open-source atomic malware analysis

Analyze another

copass_core-1.4.3-py3-none-any.whl

ZIP
Verdict: HOSTILE
Mal-ecule
O₃(CoCS)H₂(Cm₂Po)
Size 47.4 KB download
First seen 32 days ago
Analyzed 32 days ago
Ecosystem python
Source pythonhosted.org

Well-known

component severity, 100% confident.
malware/supply-chain Telco data usage record user id field

Objectives

hostile severity, 97% confident.
collection/stealer Python bearer session replay
suspicious severity, 85% confident.
command-and-control/dropper/delivery Config endpoint retrieved before stage-2 fetch
notable severity, 70% confident.
supply-chain/metadata-anomaly PKG-INFO missing Author-email field
baseline severity, 80% confident.
anti-static/obfuscation/code-metrics High ratio of embedded code in strings
component severity, 95% confident.
anti-static/obfuscation/payload Python source extension basename
component severity, 100% confident.
impact/ransom/encrypt signatures word
component severity, 100% confident.
supply-chain/metadata-anomaly/manifest Python PKG-INFO metadata file
component severity, 100% confident.
supply-chain/recon-exfil __init__.py file

Micro-behaviors

notable severity, 80% confident.
communications/http/lib httpx.AsyncClient usage
notable severity, 80% confident.
communications/ipc MCP tools/list JSON-RPC method
notable severity, 90% confident.
process/interpreter Python exec() built-in function
baseline severity, 90% confident.
communications/http HTTP protocol prefix
baseline severity, 100% confident.
process/create/shell shell script command substitution

Metadata

baseline severity, 95% confident.
import imports httpx
baseline severity, 95% confident.
import/python::copass_core imports copass_core.http
baseline severity, 95% confident.
import/python::copass_core/auth imports copass_core.auth.api_key
baseline severity, 95% confident.
import/python::copass_core/http imports copass_core.http.errors
baseline severity, 95% confident.
import/python::copass_core/resources imports copass_core.resources.users
baseline severity, 100% confident.
library Python standard library module group 1

20 of 44 traits shown

Well-known

component severity, 100% confident.
malware/supply-chain Telco data usage record user id field

Objectives

hostile severity, 97% confident.
collection/stealer Python bearer session replay
suspicious severity, 85% confident.
command-and-control/dropper/delivery Config endpoint retrieved before stage-2 fetch
notable severity, 70% confident.
supply-chain/metadata-anomaly PKG-INFO missing Author-email field
baseline severity, 80% confident.
anti-static/obfuscation/code-metrics High ratio of embedded code in strings
component severity, 95% confident.
anti-static/obfuscation/payload Python source extension basename
component severity, 100% confident.
impact/ransom/encrypt signatures word
component severity, 100% confident.
supply-chain/metadata-anomaly/manifest Python PKG-INFO metadata file
component severity, 100% confident.
supply-chain/recon-exfil __init__.py file

Micro-behaviors

notable severity, 80% confident.
communications/http/lib httpx.AsyncClient usage
notable severity, 80% confident.
communications/ipc MCP tools/list JSON-RPC method
notable severity, 90% confident.
process/interpreter Python exec() built-in function
baseline severity, 90% confident.
communications/http HTTP protocol prefix
baseline severity, 100% confident.
process/create/shell shell script command substitution

Metadata

baseline severity, 95% confident.
import imports httpx
baseline severity, 95% confident.
import/python::copass_core imports copass_core.http
baseline severity, 95% confident.
import/python::copass_core/auth imports copass_core.auth.api_key
baseline severity, 95% confident.
import/python::copass_core/http imports copass_core.http.errors
baseline severity, 95% confident.
import/python::copass_core/resources imports copass_core.resources.users
baseline severity, 100% confident.
library Python standard library module group 1

20 of 44 traits shown

Identity

SHA-256 382dc8d617f9139aa8a185373acd0e850bbb8400471e305a41d717b6a631a95d
Filename copass_core-1.4.3-py3-none-any.whl

Origin

Ecosystem python
Domain pythonhosted.org

Timeline

First seen 15 May 2026 19:26 UTC
Last analyzed 16 May 2026 07:28 UTC