Open-source atomic malware analysis

Analyze another

0b5e7a1a0f8624deaae8f3f83a0187ed6827b6851435377bd38992790939250e.exe

PE
Verdict: HOSTILE
Mal-ecule
H(Cm)Md(Bi)
Size 146.5 KB download unavailable
First seen 76 days ago
Analyzed 59 days ago

Micro-behaviors

notable severity, 90% confident.
communications/socket Winsock send import
baseline severity, 90% confident.
dylib Windows GetProcAddress API string
baseline severity, 95% confident.
mem/protect Modify memory page protection
baseline severity, 90% confident.
os/module Resolve exports with GetProcAddress
baseline severity, 90% confident.
os/registry Close registry key
baseline severity, 90% confident.
process/terminate Exit current process

Metadata

notable severity, 85% confident.
binary/metrics High code section entropy
baseline severity, 100% confident.
binary PE has RT_ICON in resources list
baseline severity, 95% confident.
binary/section UPX packed section name
baseline severity, 95% confident.
dylib::advapi32 links advapi32 (RegCloseKey)
baseline severity, 95% confident.
dylib::kernel32 links kernel32 (LoadLibraryA, GetProcAddress, VirtualProtect, VirtualAlloc, VirtualFree, ... +1 more)
baseline severity, 95% confident.
dylib::ole32 links ole32 (CoCreateGuid)
baseline severity, 95% confident.
dylib::oleaut32 links oleaut32 (VarNot)
baseline severity, 95% confident.
dylib::user32 links user32 (SetTimer)
baseline severity, 95% confident.
dylib::winmm links winmm (timeGetTime)
baseline severity, 95% confident.
dylib::ws2_32 links ws2_32 (WSAIoctl)
baseline severity, 95% confident.
dylib::wsock32 links wsock32 (send)
baseline severity, 100% confident.
hardening Writable and executable section (W^X violation)

anti-static

hostile severity, 100% confident.
packer/upx UPX decompression failed: IO error: No such file or directory (os error 2)
suspicious severity, 100% confident.
packer Binary contains a UPX packing marker

20 of 36 traits shown

Identity

SHA-256 0b5e7a1a0f8624deaae8f3f83a0187ed6827b6851435377bd38992790939250e
Filename 0b5e7a1a0f8624deaae8f3f83a0187ed6827b6851435377bd38992790939250e.exe

Origin

Source harvest

Timeline

First seen 13 May 2026 22:20 UTC
First analyzed 31 May 2026 00:52 UTC
Last analyzed 31 May 2026 00:52 UTC
Last updated 31 May 2026 00:52 UTC

Labeling

Label bad
Label source harvest
Traits version 52045