Open-source atomic malware analysis

Analyze another

v3.0.0.6

UNKNOWN
Verdict: HOSTILE

Referenced by 1 sample

Well-known

notable severity, 100% confident.
lib Imports the Python urllib3 library

Objectives

hostile severity, 99% confident.
command-and-control/dropper/execution Hidden PowerShell downloads and launches an executable
suspicious severity, 96% confident.
anti-analysis/fingerprinting Host-derived payload key material
suspicious severity, 95% confident.
anti-analysis/timing CI check followed by requests
suspicious severity, 85% confident.
anti-static/obfuscation/code-metrics Multiple long padded Base64 string literals
suspicious severity, 98% confident.
execution/interpreter/eval Jinja traversal reaches shell command
suspicious severity, 94% confident.
impact/degrade/edr Multiple kernel-driver image options
suspicious severity, 94% confident.
persistence/system/init Shell enables FreeBSD rc.conf service

Micro-behaviors

notable severity, 100% confident.
communications/http/services GitHub issue management
notable severity, 100% confident.
communications/socket Python outbound socket connection

20 of 183 traits shown

Identity

SHA-256 60ced7cf1a0683451206295e47620bbbb8eac85fbb9b5da7e84789bee83f0691
Canonical SHA-256 005292293e26fa8768288f3ed7f643f747b7bc7ecc1a2737cfa0bcdcfa148b54
Filename v3.0.0.6

Timeline

First seen 1 Aug 2026 20:22 UTC
First analyzed 1 Aug 2026 20:24 UTC
Last analyzed 1 Aug 2026 20:24 UTC
Last updated 1 Aug 2026 20:23 UTC

Labeling

Label unknown
Label source upload
Traits version 9cc7c