Local reference
Suspicious dependency
Inferred
Referenced by 1 sample
Well-known
notable severity, 97% confident.
lib/format
Uses the goblin binary-parsing Rust crate
Objectives
hostile severity, 97% confident.
anti-analysis/sandbox-detect
Future-dated random PE with host checks
hostile severity, 97% confident.
anti-static/obfuscation
Random PE layout with VirtualProtect
suspicious severity, 90% confident.
credential-access/credential-manager
Windows Credential Vault access
suspicious severity, 94% confident.
persistence/login/winlogon
LogonUI picture password registry path
notable severity, 99% confident.
impact/system
NtRaiseHardError reference with ntdll context
notable severity, 95% confident.
lateral-movement/pass-the-hash
LocalAccountTokenFilterPolicy registry value
Micro-behaviors
notable severity, 95% confident.
fs/traversal
Enumerates drive types and walks file trees
notable severity, 95% confident.
mem/protect
Modify memory page protection
notable severity, 95% confident.
os/kernel
Imports the native Windows driver-unloading API
notable severity, 100% confident.
os/service
Exported ServiceMain func (Win Service)
Metadata
notable severity, 95% confident.
build
Step environment references an Actions secret
notable severity, 95% confident.
file/policy
System policies registry path
notable severity, 100% confident.
signed
Authenticode chain CN: Microsoft Windows Publisher
20 of 107 traits shown
Identity
| SHA-256 | 87a186db904e8dbf437db134e759e52482bdb39998a32c560f12fda986ed1ea2 |
|---|---|
| Filename | pkg:cargo/[email protected] |
Origin
| Source | x |
|---|---|
| Feed | pkg.go.dev |
| Ecosystem | go |
Timeline
| First seen | 21 Aug 2026 01:52 UTC |
|---|---|
| First analyzed | 21 Aug 2026 01:52 UTC |
| Last analyzed | 21 Aug 2026 02:05 UTC |
| Last updated | 21 Aug 2026 02:06 UTC |
Labeling
| Label | unknown |
|---|
Not seeing what you expected? Let us know