Benign python Download

desphere-native 0.1.1

Legitimate Rust audio transcoder package

“Rust/pyo3 NIST SPHERE (and Shorten) to RIFF/WAV transcoder”

Ad-hoc SignatureHigh entropy __cstring section (>=4.5)

Evidence

High entropy __cstring section (>=4.5) desphere_native.abi3.so · 0xe08f8–0xe0928
0xe08f8ff9b09010420082c017f000000000000..... .,........
0xe09082f72757374632f616336386661613230/rustc/ac68faa20
0xe091863353863626363643031656537323038c58cbccd01ee7208
0xe09286266336236653933613764376639362fbf3b6e93a7d7f96/
Uses closedir desphere_native.abi3.so · 0x10191e–0x10195e
0x10191e794578635f547970654572726f72005fyExc_TypeError._
0x10192e6f70656e646972005f636c6f73656469opendir._closedi
0x10193e72005f5f524e764e744373614c4f6a45r.__RNvNtCsaLOjE
0x10194e39565974784b5f3373746433656e76319VYtxK_3std3env1
0x10195e31 1
Ad-hoc Signature desphere_native.abi3.so · 0x118ee0–0x118f10
0x118ee0383433373266322e300000000000000084372f2.0.......
0x118ef0fade0cc0000011b00000000100000000................
0x118f000000001800000000fade0c0200001198................
0x118f10000204000002000200000078000000 ...........x...
Identifier: libdesphere.dylib desphere_native.abi3.so · 0x118f50–0x118f90
0x118f5000000000000600000000000000000000................
0x118f606c696264657370686572652e64796c69libdesphere.dyli
0x118f7062000000000000000000000000000000b...............
0x118f808f9b5f67f550f06b631d38b7948d23ba.._g.P.kc.8...#.
0x118f90ff .
PyPI package has basic metadata METADATA · lines 1–11
1Metadata-Version: 2.4
2Name: desphere-native
3Version: 0.1.1
4Classifier: Programming Language :: Rust
5Classifier: Programming Language :: Python :: 3
6Classifier: License :: OSI Approved :: MIT License
7Classifier: Topic :: Multimedia :: Sound/Audio :: Conversion
8License-File: LICENSE
9Summary: Rust/pyo3 NIST SPHERE (and Shorten) to RIFF/WAV transcoder
10Keywords: sphere,nist,shorten,wav,audio,transcode
11Author: Uriel Cohen Priva

No evidence locations were recorded for this file. Raw result

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.