Open-source atomic malware analysis

Analyze another

oreilly1.rb

RUBY
Verdict: SUSPICIOUS
Mal-ecule
KO₂(C₂S)H₂(Cm₂U)Md(Pa)
Size 131 B download
First seen 117 days ago
Analyzed 115 days ago
Ecosystem malcontent-samples

Well-known

notable severity, 70% confident.
tool/offensive GTFOBins Ruby pattern marker

Objectives

suspicious severity, 90% confident.
command-and-control Ruby TCPSocket with popen (reverse
suspicious severity, 90% confident.
command-and-control/backdoor/webshell Web shell command parameter
notable severity, 75% confident.
supply-chain/metadata-anomaly IO.popen execution

Micro-behaviors

notable severity, 90% confident.
communications/socket TCP socket connection

Metadata

component severity, 80% confident.
package Very short file (under 12 lines)

Identity

SHA-256 ea84b7b18ba62ab9cd18ce5bc2660408953fae9969977052bcbc9213aff72370
Filename oreilly1.rb

Origin

Source harvest
Feed datasets
Ecosystem malcontent-samples

Timeline

First seen 24 Apr 2026 16:18 UTC
Last analyzed 26 Apr 2026 21:56 UTC
Last updated 26 Apr 2026 21:56 UTC

Labeling

Label bad
Label source harvest
Traits version bf48d