Local reference
Suspicious dependency
Inferred
Mal-ecule
O(Ca)H(U)
Objectives
notable severity, 90% confident.
credential-access/email/webmail
Reads DOM credential field values
component severity, 75% confident.
lateral-movement/social-engineering
Inline password token in lure
component severity, 75% confident.
supply-chain/recon-exfil
HTTP upload request call token
Micro-behaviors
notable severity, 82% confident.
ui/window/manage
Password input form field
baseline severity, 90% confident.
communications/http
HTTP protocol prefix
baseline severity, 80% confident.
os/service
CI/CD pipeline HTTP usage
component severity, 82% confident.
crypto/symmetric/aes
JavaScript static key string assignment
component severity, 84% confident.
data/text/keywords
password/token/api_key field keyword
component severity, 84% confident.
fs/path
Hidden directory path literal
Metadata
baseline severity, 100% confident.
lang
javascript code embedded in string
component severity, 90% confident.
file/text
File has 30 or more lines
Identity
| SHA-256 | 92c4cdddc15b702b9ecd4b5363d7462ae876f035d6a55008a4b80f2af863466c |
|---|---|
| Filename | VirusShare_7050b03866e9f41ecd1e227d89a517f1 |
Origin
| Source | harvest |
|---|
Timeline
| First seen | 31 May 2026 22:44 UTC |
|---|---|
| First analyzed | 1 Jun 2026 06:58 UTC |
| Last analyzed | 1 Jun 2026 06:58 UTC |
| Last updated | 1 Jun 2026 06:58 UTC |
Labeling
| Label | bad |
|---|---|
| Label source | harvest |
| Traits version | 961ce |
Not seeing what you expected? Let us know