Open-source atomic malware analysis

Analyze another

raw.py

PYTHON
Verdict: SUSPICIOUS
Mal-ecule
O₆(S₂C₂ErAs₃CaI)H₂(Cm₃Po)Md(Pt)
Size 583 B download
First seen 117 days ago
Analyzed 117 days ago
Ecosystem malcontent-samples

Objectives

hostile severity, 92% confident.
supply-chain/install-hook Downloads and executes file
suspicious severity, 100% confident.
command-and-control/channel Discord CDN URL pointing to executable
notable severity, 75% confident.
evasion/process/hidden Process creation with custom flags
notable severity, 70% confident.
supply-chain subprocess with shell=True
component severity, 85% confident.
anti-static/obfuscation Low comment line count
component severity, 95% confident.
anti-static/obfuscation/payload Python source extension basename
component severity, 100% confident.
command-and-control/dropper open() function call
component severity, 100% confident.
credential-access/browser tempfile module import

Micro-behaviors

suspicious severity, 90% confident.
communications/http Discord CDN URL with executable extension
notable severity, 70% confident.
communications/http/lib requests.get call (Python)
notable severity, 75% confident.
process/create subprocess.Popen call (content)
baseline severity, 70% confident.
fs Reference to tempfile module
baseline severity, 90% confident.
fs/file Opens a file
baseline severity, 75% confident.
fs/temp Gets temp directory path

Metadata

baseline severity, 95% confident.
import imports requests
component severity, 95% confident.
lang Few generated table functions

Identity

SHA-256 e9f89885876c1958bc6eede3373e4f3c4d76a5bc35a247fb7531b757798cb032
Filename raw.py

Origin

Source harvest
Feed datasets
Ecosystem malcontent-samples

Timeline

First seen 24 Apr 2026 16:18 UTC
Last analyzed 24 Apr 2026 17:48 UTC
Last updated 30 Apr 2026 20:07 UTC

Labeling

Label bad
Label source harvest
Traits version 8bf61