-= Per source details. Do not edit below this line.=-
File is designed to download, hide under system-like name, and run a remote executable, widely identified as malicious.
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2025-05-pyiniter
Reasons (based on the campaign):
infostealer
Downloads and executes a remote executable.
{
"malicious-packages-origins": [
{
"sha256": "8ddb7a7d0116fa67908d4496e52654e39ac6cc0f187df4dfd8a57b0ae9f092dd",
"modified_time": "2025-05-22T12:33:42Z",
"versions": [
"0.1.0"
],
"source": "reversing-labs",
"id": "RLMA-2025-02588",
"import_time": "2025-05-22T14:06:36.888928696Z"
},
{
"source": "kam193",
"modified_time": "2025-05-09T20:14:13Z",
"ranges": [
{
"events": [
{
"introduced": "0"
}
],
"type": "ECOSYSTEM"
}
],
"sha256": "aae1c71f553a591485f1f936a908bacbb5443253e92364e1092163d80a40333b",
"id": "pypi/2025-05-pyiniter/pyiniter",
"import_time": "2025-12-02T22:30:55.470563912Z"
},
{
"source": "kam193",
"modified_time": "2025-05-09T20:14:13Z",
"ranges": [
{
"events": [
{
"introduced": "0"
}
],
"type": "ECOSYSTEM"
}
],
"sha256": "9f926429e9f976b0e3fe7deca152e047fef9ff22705a9e59cf492dab0397389d",
"id": "pypi/2025-05-pyiniter/pyiniter",
"import_time": "2025-12-02T23:07:18.495420397Z"
},
{
"sha256": "76141c8b8089db40c02d9c86db17572414dcaf7d02c1a5872245e3a9a15c7d92",
"modified_time": "2025-05-09T20:14:13Z",
"versions": [
"0.1.0"
],
"source": "kam193",
"id": "pypi/2025-05-pyiniter/pyiniter",
"import_time": "2025-12-10T21:38:57.709546305Z"
},
{
"modified_time": "2026-03-18T12:17:29Z",
"sha256": "f104c7e7387c2f00fd71cedc0d1e78494e85c877cebf319362be7ac58dd84c57",
"source": "reversing-labs",
"id": "RLUA-2026-00636",
"import_time": "2026-03-19T12:20:15.915543793Z"
}
],
"iocs": {
"urls": [
"https://raw.githubusercontent.com/Sierftgddfgrth/win32dll/main/win32dll.exe"
]
}
}