Open-source atomic malware analysis

Analyze another

dd52dd9975e9416fd24d4230c84fa82e1edbdfee75670486d5a38ef9cc042960.zip

ZIP
Verdict: HOSTILE
Mal-ecule
H(Cm)Md₂(Bi₂Si)
Size 3.5 KB download
First seen 49 days ago
Analyzed 38 days ago
Ecosystem APTMalware

Objectives

baseline severity, 100% confident.
anti-static/obfuscation WININET.DLL absent from PE import table
baseline severity, 90% confident.
evasion/indicator-removal Export timestamp is absent
component severity, 100% confident.
anti-static/obfuscation/binary-metrics Binary has normal code entropy (>5.5)
component severity, 100% confident.
command-and-control/backdoor/shell oleaut32 ordinal 2
component severity, 100% confident.
command-and-control/infrastructure Binary has 4 or fewer sections
component severity, 97% confident.
evasion/masquerade/version-resource Console subsystem on dw20 claim
component severity, 100% confident.
evasion/process/injection Lacks substantial resources

Micro-behaviors

notable severity, 88% confident.
communications/socket Winsock socket creation import
baseline severity, 90% confident.
data/string Limited string copy
baseline severity, 82% confident.
fs/path sprintf string formatting API
baseline severity, 90% confident.
os Formatted console output
baseline severity, 90% confident.
os/signal Install signal handler
baseline severity, 70% confident.
process/threading CreateThread API name reference
baseline severity, 70% confident.
time/timing Delay execution

Metadata

notable severity, 100% confident.
binary/metrics Tiny PE by file size
notable severity, 100% confident.
signed Binary is not digitally signed
baseline severity, 90% confident.
binary PE Rich header present (MSVC toolchain)
baseline severity, 95% confident.
dylib::kernel32 links KERNEL32.dll (Sleep)
baseline severity, 95% confident.
dylib::msvcrt links MSVCRT.dll (controlfp, except_handler3, set_app_type, p__fmode, p__commode, ... +17 more)
baseline severity, 95% confident.
dylib::ws2_32 links WS2_32.dll (ORDINAL 52, ORDINAL 4, ORDINAL 9, ORDINAL 8, ORDINAL 21, ... +13 more)

20 of 30 traits shown

Identity

SHA-256 074a842be7620a86cca7b394170ae38e4429b15fb831d545fa44595b51893bf5
Filename dd52dd9975e9416fd24d4230c84fa82e1edbdfee75670486d5a38ef9cc042960.zip

Origin

Source harvest
Feed datasets
Ecosystem APTMalware

Timeline

First seen 1 May 2026 09:36 UTC
First analyzed 12 May 2026 09:56 UTC
Last analyzed 12 May 2026 09:56 UTC
Last updated 2 Jun 2026 20:34 UTC

Labeling

Label bad
Label source harvest
Traits version 46790