Open-source atomic malware analysis

Analyze another

vim.vim

PYTHON
Verdict: BENIGN
Mal-ecule
O(As)H(Po₃)
Size 77.8 KB download unavailable
First seen 82 days ago
Analyzed 82 days ago

Objectives

notable severity, 80% confident.
anti-static/obfuscation/code-metrics Excessive sequential identifiers (a, b, c, >25%)
component severity, 93% confident.
anti-analysis/geofencing host identifier substring marker
component severity, 90% confident.
command-and-control/beacon/network Command/result field word
component severity, 95% confident.
command-and-control/dropper/staging Exception-handled crypto fallback marker
component severity, 82% confident.
discovery/system Hostname profile field
component severity, 82% confident.
discovery/system/ics-environment Regex component marker
component severity, 80% confident.
exfiltration/http system field marker in posted system data
component severity, 80% confident.
supply-chain/impersonation Python with-block file operation marker

Micro-behaviors

notable severity, 70% confident.
process/create/shell bash shell keyword (beyond shebang)
notable severity, 84% confident.
process/interpreter Ruby interpreter launched by another runtime
baseline severity, 90% confident.
os/msdos DOS dispatcher check op
component severity, 100% confident.
data/text/keywords "Environment" keyword
component severity, 84% confident.
data/text/llm clipboard keyword (doc-context)

Metadata

baseline severity, 80% confident.
file/text Sequential source identifier names

Identity

SHA-256 385864dc7e9c5db96ec77d73734c12becffb37e178addc38e5dd1e89633d54ea
Filename vim.vim

Origin

Source cyclotron

Timeline

First seen 25 May 2026 21:41 UTC
First analyzed 26 May 2026 00:16 UTC
Last analyzed 26 May 2026 00:16 UTC
Last updated 2 Jun 2026 22:18 UTC

Labeling

Label good
Label source cyclotron
Traits version 60d49