Open-source atomic malware analysis

Analyze another

qairt_visualizer-0.11.0-py3-none-macosx_11_0_arm64.whl

WHL
Verdict: BENIGN

Objectives

hostile severity, 98% confident.
command-and-control/dropper Complete dropper lifecycle (Fetch + Write + Execute)
hostile severity, 95% confident.
evasion/process/injection Node-API addon with shellcode injection capability
hostile severity, 95% confident.
exfiltration Sensitive file read and exfiltration (JS)
hostile severity, 98% confident.
supply-chain/hidden-payload PyPI package fetches writes executes payload
suspicious severity, 100% confident.
anti-analysis/geofencing CIS region timezone offset checks
suspicious severity, 90% confident.
anti-static/obfuscation Instantiating an object via 'this' with bracket
suspicious severity, 100% confident.
anti-static/obfuscation/eval Generic Function constructor usage
suspicious severity, 90% confident.
anti-static/obfuscation/string Massive string concatenation operations
suspicious severity, 92% confident.
anti-static/pack Node imports payload decoder
suspicious severity, 90% confident.
command-and-control/backdoor/tasking Node C2 command response dispatch
suspicious severity, 90% confident.
command-and-control/remote-command WebSocket sends host environment context
suspicious severity, 90% confident.
credential-access/env/secrets process.env secret-name filter regex
suspicious severity, 94% confident.
evasion/quarantine-removal Rust xattr quarantine delete
suspicious severity, 92% confident.
evasion/security-bypass checkServerIdentity returns undefined/null
suspicious severity, 90% confident.
execution/interpreter/eval Global object assignment (root/self/global)
suspicious severity, 93% confident.
exfiltration/http Python raw socket stream
suspicious severity, 93% confident.
exfiltration/stealer/host-profile TS host profile fields
suspicious severity, 90% confident.
supply-chain/impersonation Suspicious npm package clone detected
suspicious severity, 96% confident.
supply-chain/recon-exfil/oast Node encodes host profile JSON as base64

Micro-behaviors

suspicious severity, 92% confident.
process/create/shell WScript Run hides launched process

20 of 191 traits shown

Identity

SHA-256 3cf5b4b45eca69e643cfd90bc9590952d18677b0fdf2a65829135f072c51c7fe
Canonical SHA-256 000877d1b0f3d96fa96340eacd5e83109ed2166e0698a934c1ed2bd2a5d78e51
Filename qairt_visualizer-0.11.0-py3-none-macosx_11_0_arm64.whl
Package qairt-visualizer
Version 0.11.0-py3-none-macosx_11_0_arm64

Origin

Source harvest
Feed pypi.org
Ecosystem python
Domain pythonhosted.org

Timeline

First seen 14 Jun 2026 16:43 UTC
First analyzed 14 Jun 2026 17:02 UTC
Last analyzed 14 Jun 2026 17:02 UTC
Last updated 14 Jun 2026 17:02 UTC

Labeling

Label unknown
Label source harvest
Traits version 061e3