Open-source atomic malware analysis

Analyze another

extconf.rb

RUBY
Verdict: SUSPICIOUS
Mal-ecule
O₄(AsC₃S₂La)H₃(DbOsPo)Md(Bk)
Size 432 B download
First seen 117 days ago
Analyzed 117 days ago
Ecosystem malcontent-samples

Objectives

hostile severity, 95% confident.
anti-static/obfuscation system() + Base64.decode64 (Ruby command execution)
suspicious severity, 94% confident.
command-and-control/dropper Windows VBS payload dropper
suspicious severity, 100% confident.
supply-chain extconf.rb performs shell execution (suspicious in build scripts)
notable severity, 85% confident.
command-and-control/dropper/execution Check for Windows OS via regex
notable severity, 90% confident.
lateral-movement/infection Writing content to other files
notable severity, 100% confident.
supply-chain/metadata-anomaly Ruby native extension config

Micro-behaviors

notable severity, 90% confident.
data/decode Ruby Base64 decode
notable severity, 70% confident.
os/sysinfo Windows platform check branch
notable severity, 95% confident.
process/create/shell system() executes command
baseline severity, 100% confident.
data/source/quality Uses Base64 module

Metadata

notable severity, 100% confident.
build::filename-extconf File is named extconf.rb

Identity

SHA-256 d4afadaef65404e650b6902d7f858e456aef8845f39c0ebd35289fa035e2413c
Filename extconf.rb

Origin

Source harvest
Feed datasets
Ecosystem malcontent-samples

Timeline

First seen 24 Apr 2026 16:18 UTC
Last analyzed 24 Apr 2026 19:33 UTC
Last updated 30 Apr 2026 23:02 UTC

Labeling

Label bad
Label source harvest
Traits version 8bf61