Open-source atomic malware analysis

Analyze another

mmalmi/nostr-vpn

UNKNOWN
Verdict: BENIGN

Referenced by 1 sample

Well-known

suspicious severity, 90% confident.
malware/botnet Firewall disable commands

Objectives

suspicious severity, 85% confident.
collection/stealer Search extracted app bundle
suspicious severity, 92% confident.
command-and-control/dns C# writes refreshed configuration
suspicious severity, 92% confident.
exfiltration/stealer/host-profile Rust host profile commands
suspicious severity, 90% confident.
impact/degrade Firewall rules cleared and opened
suspicious severity, 90% confident.
persistence/system/surface PrivilegedHelperTools persistence path
notable severity, 96% confident.
collection/screenshot PowerShell uses GDI+ CopyFromScreen

Micro-behaviors

notable severity, 100% confident.
os/service References a systemd ExecStart directive

20 of 133 traits shown

Identity

SHA-256 74d1ed3443a0c62df8b2dfd8458d047a0e574185cf340776aad2132b0ddd9954
Canonical SHA-256 002aad252274cef50ec67c0b754df7352f242f02b27bf6ac56ac78a4305b3210
Filename HEAD
Package mmalmi/nostr-vpn
PURL pkg:github/mmalmi/nostr-vpn

Origin

Source upload
Ecosystem github
Domain github.com
URL https://codeload.github.com/mmalmi/nostr-vpn/tar.gz/HEAD

Timeline

First seen 2 Aug 2026 23:43 UTC
First analyzed 2 Aug 2026 23:45 UTC
Last analyzed 2 Aug 2026 23:45 UTC
Last updated 2 Aug 2026 23:43 UTC

Labeling

Label unknown
Label source upload
Traits version d9759