Open-source atomic malware analysis

Analyze another

oreilly3.rb

RUBY
Verdict: SUSPICIOUS
Mal-ecule
K(Te)O(C₂)H₃(Cm₂DbPo₂)Md(Pa)
Size 110 B download
First seen 117 days ago
Analyzed 117 days ago
Ecosystem malcontent-samples

Well-known

suspicious severity, 85% confident.
tools/offensive GTFOBins shell execution via Ruby

Objectives

suspicious severity, 95% confident.
command-and-control/reverse-shell Ruby socket reverse shell (cli path)
notable severity, 75% confident.
command-and-control Timestamp validation check

Micro-behaviors

notable severity, 90% confident.
communications/socket TCP socket connection
notable severity, 76% confident.
data/text LLM path navigation request
notable severity, 90% confident.
process/create Interactive shell references (/bin/sh -i)
notable severity, 85% confident.
process/create/shell Shell execution via exec

Metadata

component severity, 80% confident.
package Very short file (under 12 lines)

Identity

SHA-256 9d9afacecfe6b34bc20ad6af7af236658ebf2a1c5a0ab3be22a0df9b3f72ead3
Filename oreilly3.rb

Origin

Source harvest
Feed datasets
Ecosystem malcontent-samples

Timeline

First seen 24 Apr 2026 16:18 UTC
Last analyzed 24 Apr 2026 18:48 UTC
Last updated 30 Apr 2026 21:12 UTC

Labeling

Label bad
Label source harvest
Traits version 8bf61