Is "For Mainframe" on JetBrains Marketplace Safe to Install?

IBA Group a.s. · jetbrains · v2.1.0-242

THIS PLUGIN IS NO LONGER BEING ACTIVELY MAINTAINED. TO CONTINUE USING THE SAME FUNCTIONALITY, SUPPORTED BY A COMMUNITY, USE ZOWE® EXPLORER PLUGIN. FOR INDIVIDUAL...

Risk Assessment

Analyzed
100
out of 100
CRITICAL

217 security findings detected across all analyzers

JetBrains plugin analyzed via plugin.xml configuration and static code analysis

Severity Breakdown

0
Critical
43
High
148
Medium
0
Low
0
Info

Finding Categories

43
Malware Signatures
148
IoC Indicators

YARA Rules Matched

8 rules(43 hits)
postinstall file manipulation postinstall file download postinstall system command postinstall obfuscation postinstall network communication postinstall crypto operations postinstall persistence mechanism PM Zip with js

About This Extension

THIS PLUGIN IS NO LONGER BEING ACTIVELY MAINTAINED. TO CONTINUE USING THE SAME FUNCTIONALITY, SUPPORTED BY A COMMUNITY, USE ZOWE® EXPLORER PLUGIN. FOR INDIVIDUAL...

Detailed Findings

69 total

YARA Rule Matches

8 rules

Indicators of Compromise

Network indicators, suspicious strings, and potential IoCs extracted during analysis

IP Addresses
20
Domains
128
Strings
148

All Indicators · 148

Domain
detected Domain: 8.tz

XIOC detected Domain: 8.tz

extracted_from_files

Domain
detected Domain: x.zm

XIOC detected Domain: x.zm

extracted_from_files

Domain
detected Domain: 8e.gn

XIOC detected Domain: 8e.gn

extracted_from_files

Domain
detected Domain: i.sk

XIOC detected Domain: i.sk

extracted_from_files

Domain
detected Domain: 6.ax

XIOC detected Domain: 6.ax

extracted_from_files

Domain
detected Domain: c.kg

XIOC detected Domain: c.kg

extracted_from_files

IP
detected IP: ::2

XIOC detected IP: ::2

extracted_from_files

Domain
detected Domain: ƈ.iq

XIOC detected Domain: ƈ.iq

extracted_from_files

Domain
detected Domain: ք.es

XIOC detected Domain: ք.es

extracted_from_files

Domain
detected Domain: q.tȱc.cd

XIOC detected Domain: q.tȱc.cd

extracted_from_files

Domain
detected Domain: y5.ir

XIOC detected Domain: y5.ir

extracted_from_files

Domain
detected Domain: t.fi

XIOC detected Domain: t.fi

extracted_from_files

Domain
detected Domain: rw.dj

XIOC detected Domain: rw.dj

extracted_from_files

Domain
detected Domain: 5.kz

XIOC detected Domain: 5.kz

extracted_from_files

Domain
detected Domain: ck.ua

XIOC detected Domain: ck.ua

extracted_from_files

Domain
detected Domain: w.dk

XIOC detected Domain: w.dk

extracted_from_files

Domain
detected Domain: v.ni

XIOC detected Domain: v.ni

extracted_from_files

Domain
detected Domain: r.sd

XIOC detected Domain: r.sd

extracted_from_files

Domain
detected Domain: jx.mu

XIOC detected Domain: jx.mu

extracted_from_files

Domain
detected Domain: b.ws

XIOC detected Domain: b.ws

extracted_from_files

Domain
detected Domain: o.sc

XIOC detected Domain: o.sc

extracted_from_files

Domain
detected Domain: p.mw

XIOC detected Domain: p.mw

extracted_from_files

Domain
detected Domain: pt.uz

XIOC detected Domain: pt.uz

extracted_from_files

Domain
detected Domain: r.ir

XIOC detected Domain: r.ir

extracted_from_files

Domain
detected Domain: retrofit2.pro

XIOC detected Domain: retrofit2.pro

extracted_from_files

Domain
detected Domain: n.gq

XIOC detected Domain: n.gq

extracted_from_files

Domain
detected Domain: o.jcb

XIOC detected Domain: o.jcb

extracted_from_files

Domain
detected Domain: d.p.ug

XIOC detected Domain: d.p.ug

extracted_from_files

Domain
detected Domain: a.ro

XIOC detected Domain: a.ro

extracted_from_files

Domain
detected Domain: v.sn

XIOC detected Domain: v.sn

extracted_from_files

Domain
detected Domain: x.ky

XIOC detected Domain: x.ky

extracted_from_files

Domain
detected Domain: r8.cu

XIOC detected Domain: r8.cu

extracted_from_files

Domain
detected Domain: lz.sh

XIOC detected Domain: lz.sh

extracted_from_files

Domain
detected Domain: k.lv

XIOC detected Domain: k.lv

extracted_from_files

Domain
detected Domain: c.mc

XIOC detected Domain: c.mc

extracted_from_files

Domain
detected Domain: e.sd

XIOC detected Domain: e.sd

extracted_from_files

Domain
detected Domain: r.is

XIOC detected Domain: r.is

extracted_from_files

IP
detected IP: ::f

XIOC detected IP: ::f

extracted_from_files

Domain
detected Domain: x.cx

XIOC detected Domain: x.cx

extracted_from_files

Domain
detected Domain: f.bm

XIOC detected Domain: f.bm

extracted_from_files

Domain
detected Domain: em.tm

XIOC detected Domain: em.tm

extracted_from_files

Domain
detected Domain: ũ.vn

XIOC detected Domain: ũ.vn

extracted_from_files

Domain
detected Domain: q7ɖ.lv

XIOC detected Domain: q7ɖ.lv

extracted_from_files

Domain
detected Domain: wrx.gf

XIOC detected Domain: wrx.gf

extracted_from_files

Domain
detected Domain: 4.km

XIOC detected Domain: 4.km

extracted_from_files

Domain
detected Domain: e.kn

XIOC detected Domain: e.kn

extracted_from_files

Domain
detected Domain: m.ss

XIOC detected Domain: m.ss

extracted_from_files

Domain
detected Domain: g.rs

XIOC detected Domain: g.rs

extracted_from_files

Domain
detected Domain: eܩpȭ.re

XIOC detected Domain: eܩpȭ.re

extracted_from_files

Domain
detected Domain: i.kg

XIOC detected Domain: i.kg

extracted_from_files

Domain
detected Domain: 2ļ.ky

XIOC detected Domain: 2ļ.ky

extracted_from_files

Domain
detected Domain: ߩ.st

XIOC detected Domain: ߩ.st

extracted_from_files

Domain
detected Domain: 8.si

XIOC detected Domain: 8.si

extracted_from_files

Domain
detected Domain: 2.so

XIOC detected Domain: 2.so

extracted_from_files

Domain
detected Domain: zl0t.bm

XIOC detected Domain: zl0t.bm

extracted_from_files

Domain
detected Domain: 3u.id

XIOC detected Domain: 3u.id

extracted_from_files

Domain
detected Domain: t.ar

XIOC detected Domain: t.ar

extracted_from_files

Domain
detected Domain: t.nu

XIOC detected Domain: t.nu

extracted_from_files

Domain
detected Domain: b.gq

XIOC detected Domain: b.gq

extracted_from_files

Domain
detected Domain: 1.no

XIOC detected Domain: 1.no

extracted_from_files

Domain
detected Domain: z.vi

XIOC detected Domain: z.vi

extracted_from_files

Domain
detected Domain: i.lv

XIOC detected Domain: i.lv

extracted_from_files

Domain
detected Domain: zk.qa

XIOC detected Domain: zk.qa

extracted_from_files

Domain
detected Domain: n.ml

XIOC detected Domain: n.ml

extracted_from_files

Domain
detected Domain: 5.lu

XIOC detected Domain: 5.lu

extracted_from_files

Domain
detected Domain: y.sc

XIOC detected Domain: y.sc

extracted_from_files

Domain
detected Domain: d.nf

XIOC detected Domain: d.nf

extracted_from_files

Domain
detected Domain: w.tn

XIOC detected Domain: w.tn

extracted_from_files

Domain
detected Domain: ytݺ.mq

XIOC detected Domain: ytݺ.mq

extracted_from_files

Domain
detected Domain: a.kz

XIOC detected Domain: a.kz

extracted_from_files

Domain
detected Domain: q.aw

XIOC detected Domain: q.aw

extracted_from_files

Domain
detected Domain: n.si

XIOC detected Domain: n.si

extracted_from_files

Domain
detected Domain: v.bz

XIOC detected Domain: v.bz

extracted_from_files

Domain
detected Domain: 3ї.kp

XIOC detected Domain: 3ї.kp

extracted_from_files

Domain
detected Domain: e.gp

XIOC detected Domain: e.gp

extracted_from_files

IP
detected IP: ::b

XIOC detected IP: ::b

extracted_from_files

Domain
detected Domain: r.kg

XIOC detected Domain: r.kg

extracted_from_files

Domain
detected Domain: 2.ht

XIOC detected Domain: 2.ht

extracted_from_files

Domain
detected Domain: z.cu

XIOC detected Domain: z.cu

extracted_from_files

Domain
detected Domain: libkeytar-linux-x64.so

XIOC detected Domain: libkeytar-linux-x64.so

extracted_from_files

Domain
detected Domain: libkeytar-linux-i386.so

XIOC detected Domain: libkeytar-linux-i386.so

extracted_from_files

Domain
detected Domain: libkeytar-linux-arm64.so

XIOC detected Domain: libkeytar-linux-arm64.so

extracted_from_files

Domain
detected Domain: mgqo.cc

XIOC detected Domain: mgqo.cc

extracted_from_files

Domain
detected Domain: iھ.mh

XIOC detected Domain: iھ.mh

extracted_from_files

Domain
detected Domain: gson.pro

XIOC detected Domain: gson.pro

extracted_from_files

Domain
detected Domain: y.sd

XIOC detected Domain: y.sd

extracted_from_files

Domain
detected Domain: y.ge

XIOC detected Domain: y.ge

extracted_from_files

Domain
detected Domain: m.re

XIOC detected Domain: m.re

extracted_from_files

Domain
detected Domain: s8.ru

XIOC detected Domain: s8.ru

extracted_from_files

Domain
detected Domain: y.mw

XIOC detected Domain: y.mw

extracted_from_files

Domain
detected Domain: 2.ad

XIOC detected Domain: 2.ad

extracted_from_files

Domain
detected Domain: z.gr

XIOC detected Domain: z.gr

extracted_from_files

Domain
detected Domain: gj.is

XIOC detected Domain: gj.is

extracted_from_files

Domain
detected Domain: ttp.st

XIOC detected Domain: ttp.st

extracted_from_files

Domain
detected Domain: 1n.si

XIOC detected Domain: 1n.si

extracted_from_files

Domain
detected Domain: r.us

XIOC detected Domain: r.us

extracted_from_files

Domain
detected Domain: 9m.bv

XIOC detected Domain: 9m.bv

extracted_from_files

Domain
detected Domain: fmbundle.properties

XIOC detected Domain: fmbundle.properties

extracted_from_files

Domain
detected Domain: c.nf

XIOC detected Domain: c.nf

extracted_from_files

Domain
detected Domain: xcg.gs

XIOC detected Domain: xcg.gs

extracted_from_files

Domain
detected Domain: t.do

XIOC detected Domain: t.do

extracted_from_files

Domain
detected Domain: n.pe

XIOC detected Domain: n.pe

extracted_from_files

Domain
detected Domain: n.ng

XIOC detected Domain: n.ng

extracted_from_files

Domain
detected Domain: ڣ.cw

XIOC detected Domain: ڣ.cw

extracted_from_files

Domain
detected Domain: a.cv

XIOC detected Domain: a.cv

extracted_from_files

Domain
detected Domain: suی.uk

XIOC detected Domain: suی.uk

extracted_from_files

Domain
detected Domain: tc.hr

XIOC detected Domain: tc.hr

extracted_from_files

Domain
detected Domain: ڶ.de

XIOC detected Domain: ڶ.de

extracted_from_files

Domain
detected Domain: 6w.gm

XIOC detected Domain: 6w.gm

extracted_from_files

Domain
detected Domain: v.ie

XIOC detected Domain: v.ie

extracted_from_files

IP
detected IP: a::7

XIOC detected IP: a::7

extracted_from_files

IP
detected IP: 0::8

XIOC detected IP: 0::8

extracted_from_files

IP
detected IP: ::48

XIOC detected IP: ::48

extracted_from_files

Domain
detected Domain: olɖnn2.md

XIOC detected Domain: olɖnn2.md

extracted_from_files

IP
detected IP: 5::

XIOC detected IP: 5::

extracted_from_files

IP
detected IP: 2::

XIOC detected IP: 2::

extracted_from_files

IP
detected IP: c::

XIOC detected IP: c::

extracted_from_files

Domain
detected Domain: ٲ䞱ο.so

XIOC detected Domain: ٲ䞱ο.so

extracted_from_files

Domain
detected Domain: q.km

XIOC detected Domain: q.km

extracted_from_files

Domain
detected Domain: 7.la

XIOC detected Domain: 7.la

extracted_from_files

Domain
detected Domain: 8.bg

XIOC detected Domain: 8.bg

extracted_from_files

Domain
detected Domain: 9.mn

XIOC detected Domain: 9.mn

extracted_from_files

Domain
detected Domain: 7.cw

XIOC detected Domain: 7.cw

extracted_from_files

Domain
detected Domain: ņ0.al

XIOC detected Domain: ņ0.al

extracted_from_files

Domain
detected Domain: æ37.mp

XIOC detected Domain: æ37.mp

extracted_from_files

Domain
detected Domain: 8.py

XIOC detected Domain: 8.py

extracted_from_files

Domain
detected Domain: pom.properties

XIOC detected Domain: pom.properties

extracted_from_files

Domain
detected Domain: ߏ.dj

XIOC detected Domain: ߏ.dj

extracted_from_files

Domain
detected Domain: q.nr

XIOC detected Domain: q.nr

extracted_from_files

Domain
detected Domain: ri.lr

XIOC detected Domain: ri.lr

extracted_from_files

Domain
detected Domain: k.id

XIOC detected Domain: k.id

extracted_from_files

Domain
detected Domain: analytics.properties

XIOC detected Domain: analytics.properties

extracted_from_files

Domain
detected Domain: 6.sj

XIOC detected Domain: 6.sj

extracted_from_files

IP
detected IP: ::5c

XIOC detected IP: ::5c

extracted_from_files

IP
detected IP: 2c3::

XIOC detected IP: 2c3::

extracted_from_files

IP
detected IP: ::4

XIOC detected IP: ::4

extracted_from_files

IP
detected IP: 8::

XIOC detected IP: 8::

extracted_from_files

IP
detected IP: ::d

XIOC detected IP: ::d

extracted_from_files

Domain
detected Domain: r.jm

XIOC detected Domain: r.jm

extracted_from_files

Domain
detected Domain: com.segment.analytics.java

XIOC detected Domain: com.segment.analytics.java

extracted_from_files

IP
detected IP: f::

XIOC detected IP: f::

extracted_from_files

IP
detected IP: ::cf

XIOC detected IP: ::cf

extracted_from_files

IP
detected IP: ::0

XIOC detected IP: ::0

extracted_from_files

IP
detected IP: ::9

XIOC detected IP: ::9

extracted_from_files

IP
detected IP: ::c

XIOC detected IP: ::c

extracted_from_files

Domain
detected Domain: ɩl.gb

XIOC detected Domain: ɩl.gb

extracted_from_files

Domain
detected Domain: 8h.ml

XIOC detected Domain: 8h.ml

extracted_from_files

IP
detected IP: b::

XIOC detected IP: b::

extracted_from_files

Security Analysis Summary

Security Analysis Overview

For Mainframe is a jetbrains extension published by IBA Group a.s.. Version 2.1.0-242 has been analyzed by the Risky Plugins security platform, receiving a risk score of 100/100 (CRITICAL risk) based on 217 security findings.

Risk Assessment

This extension presents critical security risk. Severe issues were detected, potentially including malware indicators, exposed secrets, or dangerous behaviors. Installation is strongly discouraged until these issues are addressed.

Findings Breakdown

  • High: 43 finding(s)
  • Medium: 148 finding(s)

What Was Analyzed

The security assessment covers multiple analysis categories:

  • Malware Detection: YARA rule matching against 2,400+ malware signatures
  • Secret Detection: Scanning for exposed API keys, tokens, and credentials
  • Static Analysis: Code-level security analysis for common vulnerability patterns
  • Network Analysis: Detection of suspicious network communications and endpoints
  • Obfuscation Detection: Identification of code obfuscation techniques

Developer Information

For Mainframe is published by IBA Group a.s. on the jetbrains marketplace. The extension has approximately 5K users.

Recommendation

This extension is not recommended for installation without thorough manual review. Consider alternatives with lower risk scores, or contact the developer to address the identified security concerns.

Frequently Asked Questions