Open-source atomic malware analysis

Analyze another

usniper.py

PYTHON
Verdict: BENIGN
Mal-ecule
O(C)H(F)
Size 7.0 KB download
First seen 74 days ago
Analyzed 71 days ago

Objectives

suspicious severity, 85% confident.
command-and-control/backdoor/rat /proc filesystem walk reading cmdline and stat
component severity, 90% confident.
anti-analysis/sandbox-detect Python os.path.exists artifact check

Micro-behaviors

notable severity, 66% confident.
fs/proc/info Access /proc for arbitrary PIDs
baseline severity, 70% confident.
data/control-flow/locking Python threading lock usage
baseline severity, 70% confident.
data/decode Hex decoding via int(x, 16)
baseline severity, 90% confident.
fs/file Opens a file
baseline severity, 78% confident.
fs/file/write Python write() call
baseline severity, 80% confident.
os/random/prng Python random module import
baseline severity, 100% confident.
process/create/shell cmd command name
component severity, 85% confident.
data/control-flow Silent exception suppression via try-except-pass
component severity, 80% confident.
data/text Python import-from statement

Metadata

baseline severity, 90% confident.
encoded-payload Decoded unicode-escape content
baseline severity, 100% confident.
file Python file extension
component severity, 90% confident.
file/text File has 30 or more lines

Identity

SHA-256 fb97b2e6373b9c48987ab8a1e6abcb63b069e1720ddd696a516bba2db9c0bab8
Filename usniper.py

Origin

Source harvest

Timeline

First seen 4 Jun 2026 23:17 UTC
First analyzed 7 Jun 2026 22:20 UTC
Last analyzed 7 Jun 2026 22:20 UTC
Last updated 7 Jun 2026 22:20 UTC

Labeling

Label bad
Label source harvest
Traits version 8e9ac