Open-source atomic malware analysis

Analyze another

github.com-golang-go-src-cmd-v0.0.0-20251013211441-28622c19591d.zip

ZIP
Verdict: BENIGN
AI Official Go source code
Mal-ecule
O₇(CAs₄Ca₂ErIPrS)H₆(Db₇Cm₆Ds₂F₁₃Os₃Po₇)Md₂
Size 7.2 MB download
First seen 2 days ago
Analyzed 15 hours ago
Ecosystem go
notable severity cross-file finding. Shell command execution capability
notable severity cross-file finding. Shell execution symbols
github.com-golang-go-src-cmd-v0.0.0-20251013211441-28622c19591d.zip zip
0 PK�������������������M���github.com/golang/go/src/[email protected]/READMGo testing package
608 ��X vpu�����v����t>��?��m�'�����Vo�;0T�}PӰhu6 �j�File content manipulation (read/write/seek)

Objectives

hostile severity, 98% confident.
command-and-control/dropper/staging Raw Base64 encoded PE stage
suspicious severity, 92% confident.
anti-static/obfuscation/string Go rolling-key XOR decode loop
suspicious severity, 95% confident.
credential-access/cloud/token Git credential helper extraction
suspicious severity, 92% confident.
credential-access/files Go reads user secret dotfiles
suspicious severity, 80% confident.
privilege-escalation/elevation-control/uac-bypass setuid() to change process UID
suspicious severity, 95% confident.
supply-chain/trojanized Disables Go module sum verification

Micro-behaviors

suspicious severity, 95% confident.
data Raw Base64 PE header blob
notable severity, 90% confident.
communications/http/lib Creates a new HTTP request
notable severity, 90% confident.
communications/socket Go net.Listen call
notable severity, 90% confident.
data/archive Go zip.OpenReader usage
notable severity, 90% confident.
fs/directory Create directory tree via os.MkdirAll
notable severity, 98% confident.
process/create Direct execution via syscall.Exec

Metadata

notable severity, 90% confident.
encoded-payload Encoded payload detected: xor

20 of 47 traits shown

Identity

SHA-256 fc674f6428a97ef1a3666af94326133586d4ca906875ddf9de5be2dd4dd8f312
Canonical SHA-256 00035c2e3224d4d5a9c5a8aac1230ae5462b9f55b3002c6607dfae7190fa281d
Filename github.com-golang-go-src-cmd-v0.0.0-20251013211441-28622c19591d.zip
Package github.com/golang/go/src/cmd
Version v0.0.0-20251013211441-28622c19591d

Origin

Source forager
Feed pkg.go.dev
Ecosystem go
Domain golang.org
URL https://proxy.golang.org/github.com/golang/go/src/cmd/@v/v0.0.0-20251013211441-28622c19591d.zip

Timeline

First seen 15 Jun 2026 12:41 UTC
First analyzed 16 Jun 2026 23:58 UTC
Last analyzed 16 Jun 2026 23:58 UTC
Last updated 16 Jun 2026 23:58 UTC

Labeling

Label unknown
Label source forager
Traits version 27202