Open-source atomic malware analysis

Analyze another

freedownloadmanager_infected_postinst

SHELL
Verdict: SUSPICIOUS
Mal-ecule
O₅(SAs₂EuP₂I)H₃(Po₂FOs)Md₂(Pa)
Size 42.7 KB download
First seen 117 days ago
Analyzed 115 days ago
Ecosystem malcontent-samples

Objectives

suspicious severity, 80% confident.
supply-chain/install-hook/dropper Tests directory writability before malware
notable severity, 90% confident.
anti-static/obfuscation HTTP URL in decoded payload
notable severity, 70% confident.
exfiltration Base64-encoded HTTP protocol indicator
notable severity, 70% confident.
persistence/system/cron /etc/cron.d directory path (additional system
baseline severity, 70% confident.
anti-static/obfuscation/code-metrics Very low whitespace ratio (minified/compressed)
component severity, 100% confident.
impact/wipe/disk Android DCIM folder

Micro-behaviors

suspicious severity, 90% confident.
process/create Shell command with both null redirection and excessive pipes
notable severity, 75% confident.
fs/chmod chmod +x (make executable)
notable severity, 80% confident.
os/package-manager Adds a trusted key via apt-key
baseline severity, 80% confident.
crypto/certificate X.509 certificate handling (legitimate)
baseline severity, 70% confident.
fs/path Unix /tmp/ path reference
component severity, 100% confident.
process Redirects output to /dev/null

Metadata

notable severity, 90% confident.
encoded-payload Encoded payload detected: base64
component severity, 90% confident.
package File has 30 or more lines

Identity

SHA-256 eafa976d315cca0ffe0e8571379acef00673e95c1709355a30ff4c376b2527ec
Filename freedownloadmanager_infected_postinst

Origin

Source harvest
Feed datasets
Ecosystem malcontent-samples

Timeline

First seen 24 Apr 2026 16:18 UTC
Last analyzed 26 Apr 2026 13:06 UTC
Last updated 26 Apr 2026 13:06 UTC

Labeling

Label bad
Label source harvest
Traits version bf48d