Open-source atomic malware analysis

Analyze another

kokobeochat 1.0.12

ZIP
Verdict: BENIGN
Mal-ecule
O₃(C₃AsCa)H₃(CmDb₂F)Md(Pa)
Size 13.7 KB download
First seen 115 days ago
Analyzed 114 days ago
Ecosystem wordpress
Source wordpress.org

Objectives

notable severity, 70% confident.
command-and-control/backdoor AJAX request handler pattern
component severity, 90% confident.
anti-static/obfuscation JavaScript function keyword in non-code file
component severity, 70% confident.
command-and-control Domain tracking field
component severity, 100% confident.
command-and-control/dropper .js extension
component severity, 85% confident.
credential-access/phishing Cordova config allows external domain origin

Micro-behaviors

notable severity, 85% confident.
communications/http/request HTTP GET parameter access ($_GET)
notable severity, 100% confident.
data/db WordPress update_option function symbol
notable severity, 84% confident.
data/text AI agent target phrase
notable severity, 80% confident.
fs/read Self-reference via __FILE__
baseline severity, 80% confident.
process/create Command injection characters in config-like strings
baseline severity, 84% confident.
process/create/shell Right string trimming

Metadata

baseline severity, 70% confident.
package GPL license reference

Identity

SHA-256 924388f78d051fdba33731c379947b78ef49b7cf5c423ecbb7ac0939271c49b7
Canonical SHA-256 1d38cf346c523db5ac8a71bebf455373481462fd9303847c0999afe78f87d744
Filename kokobeochat-1.0.12.zip
Package kokobeochat
Version 1.0.12
PURL pkg:wordpress/[email protected]

Origin

Source harvest
Feed wordpress.org
Ecosystem wordpress
Domain wordpress.org

Timeline

First seen 30 Apr 2026 10:06 UTC
Last analyzed 1 May 2026 15:29 UTC
Last updated 1 May 2026 15:29 UTC

Labeling

Label unknown
Label source harvest
Traits version 2a0fe