Open-source atomic malware analysis

Analyze another

ps1_oneliner.py

PYTHON
Verdict: SUSPICIOUS
Mal-ecule
O(C)H₃(Cm₂Db₂Po)
Size 6.9 KB download
First seen 75 days ago
Analyzed 66 days ago

Objectives

notable severity, 90% confident.
command-and-control/reverse-shell any language socket dial primitive
baseline severity, 100% confident.
anti-analysis/sandbox-detect VirtualBox driver file existence check
baseline severity, 90% confident.
anti-static/obfuscation/code-metrics Extremely high embedded code count
component severity, 94% confident.
anti-static/obfuscation/payload TARGET config key marker
component severity, 90% confident.
command-and-control/channel/tunnel Base64 encode call marker
component severity, 90% confident.
command-and-control/dropper Python variable assigned PowerShell command
component severity, 84% confident.
credential-access/vpn Tailscale debug subcommand literal
component severity, 90% confident.
supply-chain/install-hook/dropper PowerShell download source marker

Micro-behaviors

notable severity, 70% confident.
communications/socket socket.recv() call
notable severity, 95% confident.
data/decode Base64 decoding behavior
notable severity, 90% confident.
data/encode Imports Python base64 module
notable severity, 70% confident.
process/create/shell powershell keyword
baseline severity, 80% confident.
data/text English language detection

Metadata

baseline severity, 100% confident.
file Python file extension
component severity, 90% confident.
file/text File has 30 or more lines

Identity

SHA-256 f01556065e17734a8100d4b74e06001da0fd850244e739de4a851c045d5a071b
Filename ps1_oneliner.py

Origin

Source harvest

Timeline

First seen 4 Jun 2026 23:17 UTC
First analyzed 7 Jun 2026 10:23 UTC
Last analyzed 14 Jun 2026 10:57 UTC
Last updated 14 Jun 2026 10:57 UTC

Labeling

Label bad
Label source harvest
Traits version c7b65