-= Per source details. Do not edit below this line.=-
Collects basic information about the system, most probably a pentest or bug bounty.
Category: PROBABLY_PENTEST - Packages looking like typical pentest packages, but also anything that looks like testing, exploring pre-prepared kits, research & co, with clearly low-harm possibilities.
Campaign: 2024-08-byted-22.ax
Reasons (based on the campaign):
{
"malicious-packages-origins": [
{
"modified_time": "2024-08-22T22:25:03Z",
"ranges": [
{
"events": [
{
"introduced": "0"
}
],
"type": "ECOSYSTEM"
}
],
"sha256": "84e21627e718bc7d043fcf4ed50ec712682f95eb4531ea6c06f80fd0c296aa7a",
"id": "pypi/2024-08-byted-22.ax/ttat-api-test",
"source": "kam193",
"import_time": "2025-12-02T22:30:56.473446119Z"
},
{
"modified_time": "2024-08-22T22:25:03Z",
"ranges": [
{
"events": [
{
"introduced": "0"
}
],
"type": "ECOSYSTEM"
}
],
"sha256": "d20a1138316e89f4d0fa408c74d2aadafbb6d6c62a1bfb5fdececb77409aadd4",
"id": "pypi/2024-08-byted-22.ax/ttat-api-test",
"source": "kam193",
"import_time": "2025-12-02T23:07:19.657352133Z"
},
{
"modified_time": "2024-08-22T22:25:03Z",
"versions": [
"0.1.0",
"0.2.0"
],
"sha256": "e9b981e99d90b9d5c30a1d65c02b5dc5f1d40b19145416fb8065a890c593e698",
"id": "pypi/2024-08-byted-22.ax/ttat-api-test",
"source": "kam193",
"import_time": "2025-12-10T21:38:58.754122411Z"
}
],
"iocs": {
"domains": [
"zkecscnceogkcofvfnoqhyc1gg3hf6aqe.22.ax"
]
}
}