Open-source atomic malware analysis

Analyze another

github.com-mehdimin11-surf-v0.0.0-20260613092640-ad5ed84dc67c.zip

ZIP
Verdict: HOSTILE
Mal-ecule
O₆(LaAlAsCErXe)H₇(Cm₁₁CrDb₅DsF₆Os₂Po₄)
Size 715.9 KB download
First seen 3 days ago
Analyzed 3 days ago
Ecosystem go

Objectives

suspicious severity, 90% confident.
impact/degrade FPU scaling routine text
suspicious severity, 85% confident.
lateral-movement/exploit Memory protection+injection exploitation pattern
notable severity, 90% confident.
anti-static/obfuscation/eval Packed binary process execution
notable severity, 95% confident.
command-and-control/dropper/execution LuaJIT runtime strings cluster
notable severity, 90% confident.
evasion/process/injection W^X memory protection constants with VirtualProtect and CreateThread

Micro-behaviors

suspicious severity, 85% confident.
communications/ip Hardcoded external IPv4 address
notable severity, 92% confident.
communications/http uTLS dependency embedded
notable severity, 90% confident.
communications/http/lib Creates a new HTTP request
notable severity, 90% confident.
communications/ipc Pipe creation with handle redirect
notable severity, 90% confident.
communications/socket Go crypto/tls client connection wrapper
notable severity, 88% confident.
crypto/asymmetric X25519 key exchange marker
notable severity, 90% confident.
data/archive Go zip.NewWriter usage
notable severity, 95% confident.
dylib Extended dynamic library loading (ANSI)
notable severity, 95% confident.
dylib/load Extended dynamic library loading (ANSI)
notable severity, 90% confident.
fs/file Copy data via io.Copy
notable severity, 92% confident.
os/api-resolution Custom API resolver logic (manual module/export resolution)
notable severity, 95% confident.
process/create Create process (Unicode)
notable severity, 96% confident.
process/interpreter Embedded Lua virtual machine
notable severity, 95% confident.
process/terminate Process termination via TerminateProcess

Metadata

notable severity, 100% confident.
unsigned Binary is not digitally signed

20 of 117 traits shown

Objectives

suspicious severity, 90% confident.
impact/degrade FPU scaling routine text
suspicious severity, 85% confident.
lateral-movement/exploit Memory protection+injection exploitation pattern
notable severity, 90% confident.
anti-static/obfuscation/eval Packed binary process execution
notable severity, 95% confident.
command-and-control/dropper/execution LuaJIT runtime strings cluster
notable severity, 90% confident.
evasion/process/injection W^X memory protection constants with VirtualProtect and CreateThread

Micro-behaviors

suspicious severity, 85% confident.
communications/ip Hardcoded external IPv4 address
notable severity, 92% confident.
communications/http uTLS dependency embedded
notable severity, 90% confident.
communications/http/lib Creates a new HTTP request
notable severity, 90% confident.
communications/ipc Pipe creation with handle redirect
notable severity, 90% confident.
communications/socket Go crypto/tls client connection wrapper
notable severity, 88% confident.
crypto/asymmetric X25519 key exchange marker
notable severity, 90% confident.
data/archive Go zip.NewWriter usage
notable severity, 95% confident.
dylib Extended dynamic library loading (ANSI)
notable severity, 95% confident.
dylib/load Extended dynamic library loading (ANSI)
notable severity, 90% confident.
fs/file Copy data via io.Copy
notable severity, 92% confident.
os/api-resolution Custom API resolver logic (manual module/export resolution)
notable severity, 95% confident.
process/create Create process (Unicode)
notable severity, 96% confident.
process/interpreter Embedded Lua virtual machine
notable severity, 95% confident.
process/terminate Process termination via TerminateProcess

Metadata

notable severity, 100% confident.
unsigned Binary is not digitally signed

20 of 117 traits shown

Identity

SHA-256 6a48ef430e554a2826d0afcdf0c24a9ef7d3e0b76c39975c39181ffe2b18020b
Canonical SHA-256 010407830d1a94e71e6551ce60c6421ab9806b582cef0eb575a814dbfa668893
Filename github.com-mehdimin11-surf-v0.0.0-20260613092640-ad5ed84dc67c.zip
Package github.com/mehdimin11/surf
Version v0.0.0-20260613092640-ad5ed84dc67c

Origin

Source forager
Feed pkg.go.dev
Ecosystem go
Domain golang.org
URL https://proxy.golang.org/github.com/mehdimin11/surf/@v/v0.0.0-20260613092640-ad5ed84dc67c.zip

Timeline

First seen 13 Jun 2026 07:42 UTC
First analyzed 13 Jun 2026 07:46 UTC
Last analyzed 13 Jun 2026 07:46 UTC
Last updated 13 Jun 2026 07:46 UTC

Labeling

Label bad
Label source harvest
Traits version 40f6c