Suspicious 54% windows Download

pulumi

Legitimate Pulumi infrastructure tool

Detects Base64 Encoding and Decoding patterns in Golang binariesDetects suspicious PowerShell code that downloads from web sites

Evidence

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.