Open-source atomic malware analysis

Analyze another

__init__.py

PYTHON
Verdict: SUSPICIOUS
Mal-ecule
O₅(S₃XeC₂As₃I)H(Po)Md₂(PaPt)
Size 461 B download
First seen 117 days ago
Analyzed 115 days ago
Ecosystem malcontent-samples

Objectives

suspicious severity, 95% confident.
execution/autoinstall pip install using sys.executable
suspicious severity, 100% confident.
supply-chain Detects the typosquatted domain files.pypihosted.org (mimics files.pythonhosted.org)
notable severity, 90% confident.
command-and-control/dropper/delivery pip install from remote URL
notable severity, 70% confident.
supply-chain/install-hook pip module reference string
component severity, 85% confident.
anti-static/obfuscation Low comment line count
component severity, 95% confident.
anti-static/obfuscation/payload Python source extension basename
component severity, 100% confident.
command-and-control/dropper .tar.gz extension

Micro-behaviors

notable severity, 95% confident.
process/create Executes shell commands via Python
baseline severity, 70% confident.
os/package-manager pip install command

Metadata

baseline severity, 95% confident.
import imports .ansi
component severity, 95% confident.
lang Few generated table functions
component severity, 80% confident.
package Very short file (under 12 lines)

Identity

SHA-256 fb2f152797a936feea9c7b7ec4d8df73ab76cd5669599da0fc2498e5442d87a9
Filename __init__.py

Origin

Source harvest
Feed datasets
Ecosystem malcontent-samples

Timeline

First seen 24 Apr 2026 16:18 UTC
Last analyzed 26 Apr 2026 03:54 UTC
Last updated 26 Apr 2026 03:54 UTC

Labeling

Label bad
Label source harvest
Traits version bf48d