Local reference
Suspicious dependency
Inferred
Referenced by 1 sample
Well-known
suspicious severity, 90% confident.
malware/botnet
Firewall disable commands
Objectives
suspicious severity, 85% confident.
collection/stealer
Search extracted app bundle
suspicious severity, 92% confident.
command-and-control/dns
C# writes refreshed configuration
suspicious severity, 92% confident.
exfiltration/stealer/host-profile
Rust host profile commands
suspicious severity, 90% confident.
impact/degrade
Firewall rules cleared and opened
suspicious severity, 90% confident.
persistence/system/surface
PrivilegedHelperTools persistence path
notable severity, 96% confident.
collection/screenshot
PowerShell uses GDI+ CopyFromScreen
Micro-behaviors
notable severity, 100% confident.
os/service
References a systemd ExecStart directive
20 of 133 traits shown
Identity
| SHA-256 | 74d1ed3443a0c62df8b2dfd8458d047a0e574185cf340776aad2132b0ddd9954 |
|---|---|
| Canonical SHA-256 | 002aad252274cef50ec67c0b754df7352f242f02b27bf6ac56ac78a4305b3210 |
| Filename | HEAD |
| Package | mmalmi/nostr-vpn |
| PURL | pkg:github/mmalmi/nostr-vpn |
Origin
| Source | upload |
|---|---|
| Ecosystem | github |
| Domain | github.com |
| URL | https://codeload.github.com/mmalmi/nostr-vpn/tar.gz/HEAD |
Timeline
| First seen | 2 Aug 2026 23:43 UTC |
|---|---|
| First analyzed | 2 Aug 2026 23:45 UTC |
| Last analyzed | 2 Aug 2026 23:45 UTC |
| Last updated | 2 Aug 2026 23:43 UTC |
Labeling
| Label | unknown |
|---|---|
| Label source | upload |
| Traits version | d9759 |
Not seeing what you expected? Let us know