Open-source atomic malware analysis

Analyze another

tabby-1.0.234-portable-arm64.zip

ZIP
Verdict: SUSPICIOUS

Objectives

hostile severity, 99% confident.
command-and-control/backdoor/dispatch Profile exfiltration with remote execution
hostile severity, 95% confident.
supply-chain/recon-exfil npm supply chain attack with CI/CD targeting
suspicious severity, 93% confident.
anti-analysis/self-modify TS reads own script
suspicious severity, 90% confident.
anti-analysis/vm-detect Node VM vendor string set
suspicious severity, 92% confident.
anti-static/obfuscation Generic PEB+PE walk with multiplicative hash resolver (x64)
suspicious severity, 93% confident.
anti-static/obfuscation/encoding Encoded file download pattern
suspicious severity, 100% confident.
anti-static/obfuscation/eval Generic Function constructor usage
suspicious severity, 90% confident.
anti-static/obfuscation/string Python rolling-key XOR loop
suspicious severity, 94% confident.
command-and-control/backdoor/tasking JS execSync command call
suspicious severity, 92% confident.
command-and-control/trigger JS import-time / first-touch C2 hook installation
suspicious severity, 94% confident.
evasion/hijack-execution-flow Node hidden module inject
suspicious severity, 94% confident.
impact/wipe QNX Node process kill loop
suspicious severity, 100% confident.
lateral-movement/brute-force SSH authentication methods
suspicious severity, 100% confident.
supply-chain/hidden-payload Executes npm owner add command
suspicious severity, 94% confident.
supply-chain/install-hook Node writes npm preinstall hook
suspicious severity, 92% confident.
supply-chain/install-hook/scripts npm install with --save flag from code
suspicious severity, 96% confident.
supply-chain/recon-exfil/oast Node encodes host profile JSON as base64

Micro-behaviors

suspicious severity, 90% confident.
communications/http/url Encoded URL targets .php endpoint
suspicious severity, 92% confident.
process/control NtSuspendProcess and NtResumeProcess runtime resolution

Metadata

suspicious severity, 90% confident.
binary Metasploit related PDB path

20 of 370 traits shown

Identity

SHA-256 a3353ab91c8eca2c56948488c9785651541fa1211955eba07502b73ecf94f033
Canonical SHA-256 0001bb02621131da25449520dcc7da954e247cca6d1c6b08894d01a01643ef40
Filename tabby-1.0.234-portable-arm64.zip
Package tabby

Timeline

First seen 30 May 2026 00:25 UTC
First analyzed 14 Jun 2026 11:19 UTC
Last analyzed 14 Jun 2026 11:19 UTC
Last updated 20 Jun 2026 11:25 UTC

Labeling

Label good
Label source forager
Traits version c7b65