Open-source atomic malware analysis

Analyze another

kube-diag-full-linux-amd64

ELF
Verdict: HOSTILE
Mal-ecule
KO₁₁(C₁₃Er₅As₂I₄LaCaCoDyEuPrS)H₅(Cm₁₈CrDb₃F₃Po₃)Md₄(Bi₂BkPa)
Size 13.4 MB download unavailable
First seen 113 days ago
Analyzed 113 days ago
Ecosystem elf_linux

Objectives

hostile severity, 95% confident.
command-and-control/channel Hidden encrypted config with LLM proxy tunnel
hostile severity, 96% confident.
command-and-control/channel/tunnel Encrypted hidden Go tunnel config
hostile severity, 97% confident.
command-and-control/remote-command Go HTTP encrypted command output
suspicious severity, 90% confident.
command-and-control/infrastructure Hidden encrypted runtime config
suspicious severity, 90% confident.
evasion/file-hiding Hidden file in staging directory
suspicious severity, 92% confident.
evasion/masquerade Go stealth procname package
notable severity, 80% confident.
anti-static/obfuscation/control-flow Abnormally low logic density for binary size
notable severity, 85% confident.
command-and-control/backdoor/binary WebSocket protocol headers
notable severity, 85% confident.
impact/ransom Ransomware file extension markers (enc/crypted/cry)
notable severity, 85% confident.
lateral-movement/brute-force SSH authentication credential spraying

Micro-behaviors

suspicious severity, 86% confident.
communications/http OAuth client credential fields
suspicious severity, 86% confident.
communications/ssh Permissive Go SSH server auth
notable severity, 75% confident.
communications Reverse proxy implementation reference
notable severity, 90% confident.
communications/proxy Uses github.com/armon/go-socks5 library
notable severity, 80% confident.
communications/socket Bind to all network interfaces (0.0.0.0)
notable severity, 75% confident.
communications/websocket Gorilla WebSocket library (Go)
notable severity, 90% confident.
crypto/symmetric AES cipher constructor symbol
notable severity, 75% confident.
fs/path Hidden file path in /tmp directory
notable severity, 85% confident.
process/create Go binary uses os/exec

Metadata

notable severity, 90% confident.
encoded-payload Encoded payload detected: url

20 of 69 traits shown

Identity

SHA-256 ead1beea49eecc1d20ab439eed61fa195cbf085a6b952728bea7ae6aebfea0f6
Filename kube-diag-full-linux-amd64

Origin

Source harvest
Feed dissect-malware
Ecosystem elf_linux

Timeline

First seen 24 Apr 2026 16:11 UTC
Last analyzed 24 Apr 2026 18:27 UTC
Last updated 24 Apr 2026 18:27 UTC

Labeling

Label bad
Label source harvest
Traits version 8bf61