Local reference
Suspicious dependency
Inferred
Mal-ecule
O₅(SAs₂EuP₂I)H₃(Po₂FOs)Md₂(Pa)
Objectives
suspicious severity, 80% confident.
supply-chain/install-hook/dropper
Tests directory writability before malware
notable severity, 90% confident.
anti-static/obfuscation
HTTP URL in decoded payload
notable severity, 70% confident.
exfiltration
Base64-encoded HTTP protocol indicator
notable severity, 70% confident.
persistence/system/cron
/etc/cron.d directory path (additional system
baseline severity, 70% confident.
anti-static/obfuscation/code-metrics
Very low whitespace ratio (minified/compressed)
component severity, 100% confident.
impact/wipe/disk
Android DCIM folder
Micro-behaviors
suspicious severity, 90% confident.
process/create
Shell command with both null redirection and excessive pipes
notable severity, 75% confident.
fs/chmod
chmod +x (make executable)
notable severity, 80% confident.
os/package-manager
Adds a trusted key via apt-key
baseline severity, 80% confident.
crypto/certificate
X.509 certificate handling (legitimate)
baseline severity, 70% confident.
fs/path
Unix /tmp/ path reference
component severity, 100% confident.
process
Redirects output to /dev/null
Metadata
notable severity, 90% confident.
encoded-payload
Encoded payload detected: base64
component severity, 90% confident.
package
File has 30 or more lines
Identity
| SHA-256 | eafa976d315cca0ffe0e8571379acef00673e95c1709355a30ff4c376b2527ec |
|---|---|
| Filename | freedownloadmanager_infected_postinst |
Origin
| Source | harvest |
|---|---|
| Feed | datasets |
| Ecosystem | malcontent-samples |
Timeline
| First seen | 24 Apr 2026 16:18 UTC |
|---|---|
| Last analyzed | 26 Apr 2026 13:06 UTC |
| Last updated | 26 Apr 2026 13:06 UTC |
Labeling
| Label | bad |
|---|---|
| Label source | harvest |
| Traits version | bf48d |
Not seeing what you expected? Let us know