Open-source atomic malware analysis

Analyze another

yt_dlp-2026.6.16.235352.dev0-py3-none-any.whl

WHL
Verdict: BENIGN
Mal-ecule
K(Li)O₁₃(Ca₄AlAs₁₃C₁₄CoEr₂Eu₃PDyILaS₃Xe₂)H₆(Cm₂₄Cr₆Db₁₁F₉Os₃Po₇)Md₄(Pa₂Pt)
Size 3.0 MB download
First seen 4 days ago
Analyzed 4 days ago
Ecosystem python
Source pythonhosted.org

Objectives

hostile severity, 95% confident.
credential-access/browser Python Chromium DPAPI decryption
suspicious severity, 92% confident.
anti-analysis/debugger-detect Python Frida tool name
suspicious severity, 90% confident.
anti-static/obfuscation/control-flow Large integer array assignment
suspicious severity, 92% confident.
anti-static/obfuscation/string Reverse-slice adjacent to base64/hex decode
suspicious severity, 80% confident.
command-and-control/channel/tunnel SOCKS proxy server implementation
suspicious severity, 88% confident.
command-and-control/dropper/staging Direct ctypes BCrypt CNG bypass
suspicious severity, 92% confident.
evasion/security-bypass Python pycurl SSL_VERIFYHOST disabled
suspicious severity, 75% confident.
exfiltration/dns Long encoded-looking DNS subdomain label
suspicious severity, 93% confident.
exfiltration/http Python raw socket stream
suspicious severity, 90% confident.
persistence/login/account RouterOS full admin group

Micro-behaviors

20 of 86 traits shown

Identity

SHA-256 467810235f10a2b45607c112b874e876c8c167ba129bbc85aa160f78b12222b3
Canonical SHA-256 0037463de05d4bb8ccc06007e5130a7982f052fd2fd91d6853ac615ebf0bd2f6
Filename yt_dlp-2026.6.16.235352.dev0-py3-none-any.whl
Package yt-dlp
Version 2026.6.16.235352.dev0-py3-none-any

Origin

Source harvest
Feed pypi.org
Ecosystem python
Domain pythonhosted.org

Timeline

First seen 16 Jun 2026 21:22 UTC
First analyzed 16 Jun 2026 23:33 UTC
Last analyzed 16 Jun 2026 23:33 UTC
Last updated 16 Jun 2026 23:33 UTC

Labeling

Label unknown
Label source harvest
Traits version 27202