Open-source atomic malware analysis

Analyze another

mmalmi/nostr-vpn

UNKNOWN
Verdict: HOSTILE

Referenced by 3 samples

Well-known

suspicious severity, 90% confident.
malware/botnet Firewall disable commands
notable severity, 96% confident.
tool/detection Snort text marker

Objectives

suspicious severity, 85% confident.
collection/stealer Search extracted app bundle
suspicious severity, 88% confident.
discovery/network Local network enumeration
suspicious severity, 85% confident.
evasion/process/hidden Hidden window execution
suspicious severity, 95% confident.
evasion/security-bypass Ad-hoc codesign of dropped payload
suspicious severity, 92% confident.
exfiltration/stealer/host-profile Rust host profile commands
suspicious severity, 88% confident.
persistence/login/ssh Changes ownership on authorized_keys path
suspicious severity, 90% confident.
persistence/system/surface PrivilegedHelperTools persistence path
notable severity, 94% confident.
command-and-control/dropper/execution Rust sets file mode executable (chmod 0o755)
notable severity, 95% confident.
command-and-control/reverse-shell Rust libc::dup over a raw socket fd
notable severity, 95% confident.
execution/interpreter/script PowerShell execution policy bypass

Micro-behaviors

notable severity, 100% confident.
fs/file/write Node synchronously writes a file

Metadata

notable severity, 95% confident.
lang Imports subprocess module

20 of 116 traits shown

Identity

SHA-256 f1bc841a10be8f62332c3dd121a2a1553dbed9ddce304ff8c795748c0c4dae5c
Canonical SHA-256 001b49104ae621a0ab0c2a558767b3a37eb655a8bfb7fc8b834e9de88a900e22
Filename HEAD
Package mmalmi/nostr-vpn
PURL pkg:github/mmalmi/nostr-vpn

Origin

Source forager
Feed aur.archlinux.org
Ecosystem arch
URL https://codeload.github.com/mmalmi/nostr-vpn/tar.gz/HEAD

Timeline

First seen 10 Jul 2026 11:05 UTC
First analyzed 10 Jul 2026 11:06 UTC
Last analyzed 10 Jul 2026 17:40 UTC
Last updated 10 Jul 2026 17:39 UTC

Labeling

Label unknown
Traits version b8372