Open-source atomic malware analysis

Analyze another

decoded.py

PYTHON
Verdict: HOSTILE
Mal-ecule
KO₁₃(Co₅Eu₃AlAs₇C₉Ca₉Er₃LaDy₅S₅I₅PXe)H₇(FCm₈CrOs₃Po₃TiDb₃)Md₂(Pa)
Size 106.8 KB download
First seen 118 days ago
Analyzed 117 days ago
Ecosystem malcontent-samples

Well-known

suspicious severity, 95% confident.
malware/stealer AiBot browser wallet extension path

Objectives

hostile severity, 95% confident.
collection/file-targeting Comprehensive extension targeting
hostile severity, 96% confident.
exfiltration/messaging Archive exfiltration via Telegram
suspicious severity, 93% confident.
anti-analysis/geofencing Execution gated on FQDN substring
suspicious severity, 90% confident.
anti-static/obfuscation Python subprocess redirects DEVNULL
suspicious severity, 85% confident.
collection/stealer UUID upload header
suspicious severity, 95% confident.
command-and-control Telegram Bot sendDocument endpoint (file exfiltration)
suspicious severity, 80% confident.
command-and-control/infrastructure Free webhosting domain
suspicious severity, 95% confident.
credential-access/browser Chromium Login Data SQL query
suspicious severity, 98% confident.
credential-access/discord Discord token dQw4w9WgXcQ payload separator
suspicious severity, 95% confident.
credential-access/messaging Telegram session stealer detected
suspicious severity, 95% confident.
credential-access/wallet Multiple crypto wallet extensions targeted
suspicious severity, 90% confident.
evasion/security-bypass Python aiohttp SSL bypass
suspicious severity, 90% confident.
exfiltration Posts key-like material over HTTP
suspicious severity, 80% confident.
lateral-movement/social-engineering Mention of password-protected archive in instructions
notable severity, 90% confident.
credential-access/gaming Steam loginusers.vdf file access
notable severity, 90% confident.
discovery Windows systeminfo command string literal
notable severity, 90% confident.
discovery/host Targets profile data for 3+ browsers

Micro-behaviors

suspicious severity, 80% confident.
fs/path/sensitive Reference to browser Login Data (credentials)

Metadata

notable severity, 90% confident.
encoded-payload Encoded payload detected: url

20 of 64 traits shown

Identity

SHA-256 cd6e6bb14ba331d722668f7c5c72199523d9bc5aa07d9b49beecf50bca80db0d
Filename decoded.py

Origin

Source harvest
Feed datasets
Ecosystem malcontent-samples

Timeline

First seen 24 Apr 2026 16:18 UTC
Last analyzed 26 Apr 2026 04:55 UTC
Last updated 26 Apr 2026 04:55 UTC

Labeling

Label bad
Label source harvest
Traits version bf48d