Objectives
hostile severity, 95% confident.
credential-access/browser
Python Chromium DPAPI decryption
suspicious severity, 92% confident.
anti-analysis/debugger-detect
Python Frida tool name
suspicious severity, 90% confident.
anti-static/obfuscation/control-flow
Large integer array assignment
suspicious severity, 92% confident.
anti-static/obfuscation/string
Reverse-slice adjacent to base64/hex decode
suspicious severity, 80% confident.
command-and-control/channel/tunnel
SOCKS proxy server implementation
suspicious severity, 88% confident.
command-and-control/dropper/staging
Direct ctypes BCrypt CNG bypass
suspicious severity, 92% confident.
evasion/security-bypass
Python pycurl SSL_VERIFYHOST disabled
suspicious severity, 75% confident.
exfiltration/dns
Long encoded-looking DNS subdomain label
suspicious severity, 93% confident.
exfiltration/http
Python raw socket stream
suspicious severity, 90% confident.
persistence/login/account
RouterOS full admin group
Micro-behaviors
20 of 86 traits shown
Identity
| SHA-256 | 467810235f10a2b45607c112b874e876c8c167ba129bbc85aa160f78b12222b3 |
|---|---|
| Canonical SHA-256 | 0037463de05d4bb8ccc06007e5130a7982f052fd2fd91d6853ac615ebf0bd2f6 |
| Filename | yt_dlp-2026.6.16.235352.dev0-py3-none-any.whl |
| Package | yt-dlp |
| Version | 2026.6.16.235352.dev0-py3-none-any |
Origin
| Source | harvest |
|---|---|
| Feed | pypi.org |
| Ecosystem | python |
| Domain | pythonhosted.org |
Timeline
| First seen | 16 Jun 2026 21:22 UTC |
|---|---|
| First analyzed | 16 Jun 2026 23:33 UTC |
| Last analyzed | 16 Jun 2026 23:33 UTC |
| Last updated | 16 Jun 2026 23:33 UTC |
Labeling
| Label | unknown |
|---|---|
| Label source | harvest |
| Traits version | 27202 |
Not seeing what you expected? Let us know