Open-source atomic malware analysis

Analyze another

Rakefile.rb

RUBY
Verdict: SUSPICIOUS
Mal-ecule
O₄(EuAsC₂S)H₂(Cm₃Os₃)Md(Pa)
Size 382 B download
First seen 117 days ago
Analyzed 115 days ago
Ecosystem malcontent-samples

Objectives

hostile severity, 95% confident.
exfiltration/stealer System info stealer with HTTP exfil
notable severity, 88% confident.
anti-static/obfuscation Base64 encode
notable severity, 75% confident.
command-and-control/infrastructure Direct IP address in URL

Micro-behaviors

suspicious severity, 95% confident.
communications HTTP URL with IP address
notable severity, 80% confident.
communications/http URL info parameter with Base64 encoding
notable severity, 90% confident.
communications/http/lib Hardcoded IP address in URL
notable severity, 80% confident.
os/env/vars Ruby Socket.gethostname call
notable severity, 75% confident.
os/network Socket IP address discovery
baseline severity, 75% confident.
data/serialize Ruby JSON serialization call
baseline severity, 100% confident.
data/source/quality Uses Base64 module

Metadata

component severity, 80% confident.
package Very short file (under 12 lines)

Identity

SHA-256 6fca6296d3ec565385d97208fc449886296c4c8cce6b6f3b454dd3adade1ab0a
Filename Rakefile.rb

Origin

Source harvest
Feed datasets
Ecosystem malcontent-samples

Timeline

First seen 24 Apr 2026 16:18 UTC
Last analyzed 26 Apr 2026 11:29 UTC
Last updated 26 Apr 2026 11:29 UTC

Labeling

Label bad
Label source harvest
Traits version bf48d