Mal-ecule
O₆(LaAlAsCErXe)H₇(Cm₁₁CrDb₅DsF₆Os₂Po₄)
Objectives
suspicious severity, 90% confident.
impact/degrade
FPU scaling routine text
suspicious severity, 85% confident.
lateral-movement/exploit
Memory protection+injection exploitation pattern
notable severity, 90% confident.
anti-static/obfuscation/eval
Packed binary process execution
notable severity, 95% confident.
command-and-control/dropper/execution
LuaJIT runtime strings cluster
notable severity, 90% confident.
evasion/process/injection
W^X memory protection constants with VirtualProtect and CreateThread
Micro-behaviors
suspicious severity, 85% confident.
communications/ip
Hardcoded external IPv4 address
notable severity, 92% confident.
communications/http
uTLS dependency embedded
notable severity, 90% confident.
communications/http/lib
Creates a new HTTP request
notable severity, 90% confident.
communications/ipc
Pipe creation with handle redirect
notable severity, 90% confident.
communications/socket
Go crypto/tls client connection wrapper
notable severity, 88% confident.
crypto/asymmetric
X25519 key exchange marker
notable severity, 90% confident.
data/archive
Go zip.NewWriter usage
notable severity, 95% confident.
dylib
Extended dynamic library loading (ANSI)
notable severity, 95% confident.
dylib/load
Extended dynamic library loading (ANSI)
notable severity, 90% confident.
fs/file
Copy data via io.Copy
notable severity, 92% confident.
os/api-resolution
Custom API resolver logic (manual module/export resolution)
notable severity, 95% confident.
process/create
Create process (Unicode)
notable severity, 96% confident.
process/interpreter
Embedded Lua virtual machine
notable severity, 95% confident.
process/terminate
Process termination via TerminateProcess
Metadata
notable severity, 100% confident.
unsigned
Binary is not digitally signed
20 of 117 traits shown
Objectives
suspicious severity, 90% confident.
impact/degrade
FPU scaling routine text
suspicious severity, 85% confident.
lateral-movement/exploit
Memory protection+injection exploitation pattern
notable severity, 90% confident.
anti-static/obfuscation/eval
Packed binary process execution
notable severity, 95% confident.
command-and-control/dropper/execution
LuaJIT runtime strings cluster
notable severity, 90% confident.
evasion/process/injection
W^X memory protection constants with VirtualProtect and CreateThread
Micro-behaviors
suspicious severity, 85% confident.
communications/ip
Hardcoded external IPv4 address
notable severity, 92% confident.
communications/http
uTLS dependency embedded
notable severity, 90% confident.
communications/http/lib
Creates a new HTTP request
notable severity, 90% confident.
communications/ipc
Pipe creation with handle redirect
notable severity, 90% confident.
communications/socket
Go crypto/tls client connection wrapper
notable severity, 88% confident.
crypto/asymmetric
X25519 key exchange marker
notable severity, 90% confident.
data/archive
Go zip.NewWriter usage
notable severity, 95% confident.
dylib
Extended dynamic library loading (ANSI)
notable severity, 95% confident.
dylib/load
Extended dynamic library loading (ANSI)
notable severity, 90% confident.
fs/file
Copy data via io.Copy
notable severity, 92% confident.
os/api-resolution
Custom API resolver logic (manual module/export resolution)
notable severity, 95% confident.
process/create
Create process (Unicode)
notable severity, 96% confident.
process/interpreter
Embedded Lua virtual machine
notable severity, 95% confident.
process/terminate
Process termination via TerminateProcess
Metadata
notable severity, 100% confident.
unsigned
Binary is not digitally signed
20 of 117 traits shown
Identity
| SHA-256 | 6a48ef430e554a2826d0afcdf0c24a9ef7d3e0b76c39975c39181ffe2b18020b |
|---|---|
| Canonical SHA-256 | 010407830d1a94e71e6551ce60c6421ab9806b582cef0eb575a814dbfa668893 |
| Filename | github.com-mehdimin11-surf-v0.0.0-20260613092640-ad5ed84dc67c.zip |
| Package | github.com/mehdimin11/surf |
| Version | v0.0.0-20260613092640-ad5ed84dc67c |
Origin
| Source | forager |
|---|---|
| Feed | pkg.go.dev |
| Ecosystem | go |
| Domain | golang.org |
| URL | https://proxy.golang.org/github.com/mehdimin11/surf/@v/v0.0.0-20260613092640-ad5ed84dc67c.zip |
Timeline
| First seen | 13 Jun 2026 07:42 UTC |
|---|---|
| First analyzed | 13 Jun 2026 07:46 UTC |
| Last analyzed | 13 Jun 2026 07:46 UTC |
| Last updated | 13 Jun 2026 07:46 UTC |
Labeling
| Label | bad |
|---|---|
| Label source | harvest |
| Traits version | 40f6c |
Not seeing what you expected? Let us know