Open-source atomic malware analysis

Analyze another

0120dae09f9f6fa1074800fa2fb98ba67ecb4b6eca9f89e360e0a880e7202509

PE
Verdict: HOSTILE
AI Packed PE with clipboard access
Mal-ecule
O(As₂)H(Os)Md(Bi₅)
Size 2.9 MB download
First seen 11 hours ago
Analyzed 5 hours ago
Ecosystem windows
Source abuse.ch
Also detected by 2 sources
Empty-code PE with dominant packed loader section: file:0x0
Empty-text PE with nonstandard high-entropy packing: file:0x0
Opaque empty-text PE with near-total packed code: file:0x0
file pe
0x0 4d5a90000300000004000000ffff0000 MZ..............Empty-text PE with nonstandard high-entropy packing
0x10 b8000000000000004000000000000000 ........@.......
0x20 00000000000000000000000000000000 ................
0x30 00000000000000000000000080000000 ................
0x40 0e1fba0e00b409cd21b8014ccd215468 ........!..L.!ThOpaque empty-text PE with near-total packed code
0x50 69732070726f6772616d2063616e6e6f is program canno
0x60 742062652072756e20696e20444f5320 t be run in DOS
0x70 6d6f64652e0d0d0a2400000000000000 mode....$.......
0x80 504500006486070031d1376000000000 PE..d...1.7`....
0x90 00000000f00023000b020e1d005c0200 ......#......\..
0xa0 002c010000000000d00e2a0000100000 .,........*.....
0xb0 00000040010000000010000000020000 ...@............
0xc0 06000000000000000600000000000000 ................
0xd0 00104e0000040000fe562f0002002081 ..N......V/... .
0xe0 00001000000000000010000000000000 ................
0xf0 00001000000000000010000000000000 ................
0x100 00000000100000000000000000000000 ................
0x110 50b82b00640000000000000000000000 P.+.d...........
0x120 50b54d003c4b00000000000000000000 P.M.<K..........
0x130 0000000000 .....
0x1f5fd0 5084b6cd0df2e04a24ab68dc5264744e P......J$.h.RdtN
0x1f5fe0 3c67d40a4fde9229f7098dfbd17f4da8 <g..O..)......M.
0x1f5ff0 bc50c0d45965087107eb6851611d2767 .P..Ye.q..hQa.'g
0x1f6000 5f4d54bc1115d8b8fca64abf410fca5e _MT.......J.A..^
0x1f6010 27ff8f6133a8bf86d616db0267e15ee6 '..a3.......g.^.
0x1f6020 8f98687869697bc8fb0c3b5765119f79 ..hxii{...;We..y
0x1f6030 c4d0e29fdfc2489658fed6639f9e17e9 ......H.X..c....
0x1f6040 6fe4de1acd2054263d826db3a7fb3165 o.... T&=.m...1e
0x1f6050 60ef1999cfd637651e879260925e04bb `.....7e...`.^..
0x1f6060 31797d1aabffbdcb980c8652e2f886e7 1y}........R....
0x1f6070 bef95575f35f827df02d8bfa67b50283 ..Uu._.}.-..g...
0x1f6080 c679787b9f913f4ccbfe04691635a827 .yx{..?L...i.5.'
0x1f6090 ce18f58749976033f8c73994db492e80 ....I.`3..9..I..
0x1f60a0 e942d9e0d11829ca92d7 .B....)...

Objectives

Micro-behaviors

Metadata

notable severity, 95% confident.
binary PE has no signature record

Identity

SHA-256 0120dae09f9f6fa1074800fa2fb98ba67ecb4b6eca9f89e360e0a880e7202509
Filename file
Package 0120dae09f9f6fa1074800fa2fb98ba67ecb4b6eca9f89e360e0a880e7202509

Origin

Source harvest
Feed malwarebazaar
Ecosystem windows
Domain abuse.ch

Timeline

First seen 5 Aug 2026 17:31 UTC
First analyzed 5 Aug 2026 23:28 UTC
Last analyzed 5 Aug 2026 23:28 UTC
Last updated 5 Aug 2026 23:28 UTC

Labeling

Label bad
Label source harvest
Traits version b5ca8