Open-source atomic malware analysis

Analyze another

onering-1.4.1/build.rs

UNKNOWN
Verdict: HOSTILE
Mal-ecule
O(S₂)H₄(CmFOsPo)
Size 2.3 KB download
First seen 6 days ago
Analyzed 6 days ago

Found in 2 archives

Objectives

hostile severity, 96% confident.
supply-chain/install-hook/build build.rs posts data to external endpoint
hostile severity, 100% confident.
supply-chain/recon-exfil Rust build.rs exfils source patch to Sentry
component severity, 85% confident.
command-and-control/dropper/execution Rust Command::new call

Micro-behaviors

notable severity, 82% confident.
communications/http/download Rust invokes curl or wget
notable severity, 85% confident.
fs/file/write Rust fs write call
notable severity, 86% confident.
os/env Rust environment variable lookup
notable severity, 92% confident.
process/create Captures child process output
baseline severity, 75% confident.
data/control-flow Rust while loop
component severity, 86% confident.
data/text/keywords curl/wget download client token

Metadata

component severity, 97% confident.
file/text Validation vocabulary string

Objectives

hostile severity, 96% confident.
supply-chain/install-hook/build build.rs posts data to external endpoint
hostile severity, 100% confident.
supply-chain/recon-exfil Rust build.rs exfils source patch to Sentry
component severity, 85% confident.
command-and-control/dropper/execution Rust Command::new call

Micro-behaviors

notable severity, 82% confident.
communications/http/download Rust invokes curl or wget
notable severity, 85% confident.
fs/file/write Rust fs write call
notable severity, 86% confident.
os/env Rust environment variable lookup
notable severity, 92% confident.
process/create Captures child process output
baseline severity, 75% confident.
data/control-flow Rust while loop
component severity, 86% confident.
data/text/keywords curl/wget download client token

Metadata

component severity, 97% confident.
file/text Validation vocabulary string

Identity

SHA-256 d46497217da839e05b88c745b655ccaa49e0bdd45e2b706d132711c79fb38c28
Filename onering-1.4.1/build.rs

Origin

Source harvest

Timeline

First seen 10 Jun 2026 15:46 UTC
First analyzed 10 Jun 2026 15:46 UTC
Last analyzed 10 Jun 2026 15:46 UTC
Last updated 10 Jun 2026 15:46 UTC

Labeling

Label bad
Label source harvest