Open-source atomic malware analysis

Analyze another

client_5346.py

PYTHON
Verdict: SUSPICIOUS
Mal-ecule
O₅(ErAs₅C₂CaS)H₃(CmPoDb)Md₂(PaPt)Th
Size 1.9 KB download
First seen 117 days ago
Analyzed 115 days ago
Ecosystem malcontent-samples

Objectives

suspicious severity, 90% confident.
evasion/process/hidden Multiple process creation flags combined
notable severity, 78% confident.
anti-static/obfuscation Near-zero comment ratio in small Python file
component severity, 95% confident.
anti-static/obfuscation/payload Python source extension basename
component severity, 70% confident.
command-and-control Python os.remove call to delete
component severity, 100% confident.
command-and-control/dropper open() function call
component severity, 100% confident.
credential-access/browser base64 module import

Micro-behaviors

notable severity, 70% confident.
communications/http/lib requests.get call (Python)
notable severity, 90% confident.
process/create subprocess.Popen with sys.executable list
baseline severity, 90% confident.
communications/http HTTP protocol prefix
baseline severity, 85% confident.
fs/directory File deletion operation (Node.js/Python)
baseline severity, 90% confident.
fs/file Opens a file
baseline severity, 80% confident.
fs/path Expand user home directory

Metadata

baseline severity, 95% confident.
import imports requests
component severity, 95% confident.
lang Few generated table functions
component severity, 90% confident.
package File has 30 or more lines

Third-party

suspicious severity, 90% confident.
JPCERT/lazarus Python downloader for Lazarus

Identity

SHA-256 75f6305755c53f636b6e7428df3fec92c93074f0203fd644f922a559399e27ff
Filename client_5346.py

Origin

Source harvest
Feed datasets
Ecosystem malcontent-samples

Timeline

First seen 24 Apr 2026 16:18 UTC
Last analyzed 26 Apr 2026 15:19 UTC
Last updated 26 Apr 2026 15:19 UTC

Labeling

Label bad
Label source harvest
Traits version bf48d