-= Per source details. Do not edit below this line.=-
Obfuscated code starts a multi-stage infection
Category: MALICIOUS - The campaign has clearly malicious intent, like infostealers.
Campaign: 2025-03-tlsclient3
Reasons (based on the campaign):
Downloads and executes a remote executable.
obfuscation
malware
{
"iocs": {
"ips": [
"185.196.8.88"
],
"urls": [
"https://files.whined.org/i386",
"https://files.whined.org/t1t1t1t1t1.exe",
"https://x.0.feedback/uh_uh+uh"
],
"domains": [
"whined.org",
"0.feedback"
]
},
"malicious-packages-origins": [
{
"id": "RLMA-2025-02007",
"sha256": "114da211bb86bb267b90de07629442507b6dc330a5a4104e6b1d50510382c9f6",
"modified_time": "2025-03-28T13:06:24Z",
"import_time": "2025-03-31T07:07:07.049660454Z",
"source": "reversing-labs",
"versions": [
"1.0.1",
"1.0.2"
]
},
{
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
}
]
}
],
"id": "pypi/2025-03-tlsclient3/tlsclient3",
"sha256": "6b18b3332078d66ca6c5318aae4fb7722fd4612a618359566ed01adcf351ee6a",
"modified_time": "2025-03-08T08:42:32Z",
"import_time": "2025-12-02T22:30:55.653617882Z",
"source": "kam193"
},
{
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
}
]
}
],
"id": "pypi/2025-03-tlsclient3/tlsclient3",
"sha256": "612e1a598a61304a9ae3550acb835ef5962f596bb74e857c2a035ba090e57dc4",
"modified_time": "2025-03-08T08:42:32Z",
"import_time": "2025-12-02T23:07:18.696455843Z",
"source": "kam193"
},
{
"id": "pypi/2025-03-tlsclient3/tlsclient3",
"sha256": "115ca597f26fa503ca5ed7936f3efd9f0b2168367d0bf4963877908c996673c5",
"modified_time": "2025-03-08T08:42:32Z",
"import_time": "2025-12-10T21:38:57.881840859Z",
"source": "kam193",
"versions": [
"1.0.1",
"1.0.2"
]
},
{
"id": "RLUA-2026-00828",
"sha256": "f479ef03995f033fd9f9ad2ecd6483b3dfdd65113541734c42b4c5e3e42e7250",
"modified_time": "2026-03-18T12:19:33Z",
"import_time": "2026-03-19T12:20:34.437879709Z",
"source": "reversing-labs"
}
]
}