Open-source atomic malware analysis

Analyze another

php-extended-php-api-fr-insee-sirene-object-9.0.6.zip

ZIP
Verdict: BENIGN
Mal-ecule
O(As₃)H₂(CmF₂)
Size 116.5 KB download
First seen 32 days ago
Analyzed 29 days ago
Ecosystem php
Source packagist.org

Well-known

baseline severity, 100% confident.
tool/sysadmin Uses jq for JSON processing

Objectives

notable severity, 75% confident.
anti-static/obfuscation Mixed encoding indicators
notable severity, 90% confident.
anti-static/obfuscation/code-metrics Many random-looking source identifier names
baseline severity, 100% confident.
command-and-control/dropper/execution Benign platform bootstrap curl domain
component severity, 94% confident.
command-and-control/backdoor/webshell file_get_contents (raw POST body reader)
component severity, 100% confident.
impact/infect find target pattern
component severity, 100% confident.
supply-chain/install-hook/dropper mtime string reference
component severity, 98% confident.
supply-chain/trojanized Regex component marker

Micro-behaviors

notable severity, 80% confident.
communications/http/download curl silent flags
notable severity, 82% confident.
fs/directory find enumerates regular files
notable severity, 80% confident.
fs/read Self-reference via __FILE__
baseline severity, 90% confident.
communications/http HTTPS protocol prefix
baseline severity, 66% confident.
fs/link Resolve symbolic links to canonical
baseline severity, 70% confident.
fs/path Unix /tmp/ path reference
baseline severity, 70% confident.
fs/temp Literal /tmp/ path string
baseline severity, 80% confident.
process/create shell script heredoc
component severity, 100% confident.
process/daemonize Redirects output to /dev/null

Metadata

baseline severity, 75% confident.
file/text Many no-param functions
baseline severity, 100% confident.
lang Bash shell shebang line
baseline severity, 97% confident.
package/testing/harness Extends PHPUnit TestCase class

20 of 31 traits shown

Identity

SHA-256 ef2b1d097211166f34ad9108e98ad5db957d878bcb42947323fc64c1304055a8
Canonical SHA-256 096606d76186eda332a1c823a363c8c933eedc36e3d502987e1c2fa9d7aff54c
Filename php-extended-php-api-fr-insee-sirene-object-9.0.6.zip
Package php-extended
Version 9.0.6

Origin

Source harvest
Feed packagist.org
Ecosystem php
Domain packagist.org

Timeline

First seen 20 May 2026 19:32 UTC
First analyzed 24 May 2026 00:41 UTC
Last analyzed 24 May 2026 00:41 UTC
Last updated 24 May 2026 00:41 UTC

Labeling

Label unknown
Label source harvest
Traits version 9ea7c