Open-source atomic malware analysis

Analyze another

GHIElectronics.TinyCLR.Drivers.BasicNet.3.0.0.2000-prerelease.nupkg

NUPKG
Verdict: BENIGN
Mal-ecule
H(Cm)Md₂(Bi₂Si)
Size 34.7 KB download
First seen 9 days ago
Analyzed 9 days ago
Ecosystem dotnet
Source nuget.org

Objectives

component severity, 100% confident.
anti-static/obfuscation/binary-metrics Binary has normal code entropy (>5.5)
component severity, 99% confident.
anti-static/obfuscation/payload PE version resource text
component severity, 90% confident.
anti-static/pack PE has under ten imports
component severity, 95% confident.
command-and-control/backdoor/loader Staged loader six file archive
component severity, 100% confident.
command-and-control/infrastructure Binary has 4 or fewer sections
component severity, 95% confident.
evasion/indicator-removal Regex component marker
component severity, 92% confident.
evasion/process/injection Regex component marker
component severity, 98% confident.
supply-chain/metadata-anomaly/manifest NuGet nuspec manifest file

Micro-behaviors

notable severity, 86% confident.
communications/ip Hardcoded external IPv4 address
component severity, 100% confident.
communications/http/server Modification of HTTP context items
component severity, 92% confident.
crypto/asymmetric Regex component marker
component severity, 92% confident.
os/sysinfo References GetAddressBytes method

Metadata

notable severity, 100% confident.
binary PE binary has trailing overlay data
notable severity, 100% confident.
signed Signed by GHI Electronics LLC
baseline severity, 90% confident.
binary/section PE .reloc section presence
baseline severity, 100% confident.
file Windows DLL extension
baseline severity, 100% confident.
hardening NO_SEH (SafeSEH not used)
baseline severity, 90% confident.
lang/compiler mscorlib reference
baseline severity, 90% confident.
package PE version resource metadata
component severity, 95% confident.
binary/anomaly PE version info numeric fields present

20 of 33 traits shown

Identity

SHA-256 9f3cdd943ce6e0aed3866c617589ccee0b8bc55e11b44b4cafc08eb98904a322
Canonical SHA-256 39e361a5d389714f365721455223f72dfb7f67e80c82af80c7033636862d1ee0
Filename GHIElectronics.TinyCLR.Drivers.BasicNet.3.0.0.2000-prerelease.nupkg
Package GHIElectronics.TinyCLR.Drivers.BasicNet
Version 3.0.0.2000-prerelease

Origin

Source harvest
Feed nuget.org
Ecosystem dotnet
Domain nuget.org

Timeline

First seen 12 Jun 2026 09:36 UTC
First analyzed 12 Jun 2026 12:11 UTC
Last analyzed 12 Jun 2026 12:11 UTC
Last updated 12 Jun 2026 12:11 UTC

Labeling

Label unknown
Label source harvest
Traits version e31a3