Open-source atomic malware analysis

Analyze another

k8s.io-kubernetes-v0.0.0-20260616171728-41b7f6da7dfa.zip

ZIP
Verdict: BENIGN
AI Legitimate Kubernetes source code archive
hostile severity cross-file finding. PowerShell script detecting emulator or sandbox environment
suspicious severity cross-file finding. PowerShell downloads archive then executes
suspicious severity cross-file finding. Go portForward/tunnelForward module
suspicious severity cross-file finding. Orchestration credential paths
suspicious severity cross-file finding. Systemd service modification and reload
notable severity cross-file finding. Invoke-WebRequest cmdlet (iwr/wget/curl alias)
notable severity cross-file finding. Restart=always directive
notable severity cross-file finding. Systemd service file path reference
notable severity cross-file finding. unzip extracts archive to directory
notable severity cross-file finding. WantedBy autostart-enrollment directive
notable severity cross-file finding. checking for firewall tool availability
k8s.io-kubernetes-v0.0.0-20260616171728-41b7f6da7dfa.zip zip
0 PK�������������������E���k8s.io/kube[email protected]/.geneUser information fingerprinting

Objectives

hostile severity, 95% confident.
command-and-control/channel/deaddrop URL dead drop / indirection pattern
hostile severity, 95% confident.
command-and-control/trigger Go package init() runs network I/O on import
suspicious severity, 90% confident.
command-and-control/backdoor/proxy Go portForward/tunnelForward module
suspicious severity, 95% confident.
command-and-control/dropper/execution Hidden PowerShell Get-Content IEX
suspicious severity, 92% confident.
credential-access/files Go reads SSH private key paths
suspicious severity, 94% confident.
credential-access/vpn Go PAN-OS OpenVPN client key
suspicious severity, 98% confident.
evasion/anti-av/platform Embedded Defender exclusion cmdlet
suspicious severity, 94% confident.
exfiltration/stealer/credential Go system secret path list
suspicious severity, 94% confident.
impact/dos NetScaler dd zero source
suspicious severity, 96% confident.
supply-chain/recon-exfil curl queries cloud metadata service

Micro-behaviors

suspicious severity, 95% confident.
fs/delete lu4p/shred secure deletion library

20 of 141 traits shown

Identity

SHA-256 70ef7bfede2ffcf941be57023cad73f537ef6f017253c80df3e273454910a799
Canonical SHA-256 0028c2f78748af07c3b652fb76d15f8d0a47e2dbd902d4eea710bb55657def27
Filename k8s.io-kubernetes-v0.0.0-20260616171728-41b7f6da7dfa.zip
Package k8s.io/kubernetes
Version v0.0.0-20260616171728-41b7f6da7dfa

Origin

Source forager
Feed pkg.go.dev
Ecosystem go
Domain golang.org
URL https://proxy.golang.org/k8s.io/kubernetes/@v/v0.0.0-20260616171728-41b7f6da7dfa.zip

Timeline

First seen 16 Jun 2026 14:37 UTC
First analyzed 17 Jun 2026 00:14 UTC
Last analyzed 17 Jun 2026 00:14 UTC
Last updated 17 Jun 2026 00:14 UTC

Labeling

Label unknown
Label source forager
Traits version 27202