Open-source atomic malware analysis

Analyze another

0f3476eaebfc4fd91d529dd3665a7b57e3b795da68aeea586698efb60d89babc.exe

PE
Verdict: HOSTILE
Mal-ecule
H(Cm)Md(Bi)
Size 30.5 KB download unavailable
First seen 78 days ago
Analyzed 60 days ago

Well-known

component severity, 99% confident.
malware/worm Exactly seven imports

Objectives

baseline severity, 75% confident.
anti-static/obfuscation/payload Minimal PE imports with dynamic loading
component severity, 100% confident.
anti-static/obfuscation/binary-metrics Binary has normal code entropy (>5.5)
component severity, 100% confident.
anti-static/obfuscation/reflection VirtualProtect symbol
component severity, 99% confident.
anti-static/pack UPX magic byte sequence
component severity, 96% confident.
command-and-control/dropper/execution Empty RWX UPX0 decoy section
component severity, 100% confident.
command-and-control/infrastructure Binary has 4 or fewer sections
component severity, 95% confident.
evasion/masquerade/file Filename has EXE extension

Micro-behaviors

notable severity, 70% confident.
communications/socket WS2_32 Winsock DLL import
baseline severity, 90% confident.
dylib Windows GetProcAddress API string
baseline severity, 95% confident.
mem/protect Modify memory page protection
baseline severity, 90% confident.
os/module Resolve exports with GetProcAddress
baseline severity, 90% confident.
process/terminate Exit current process

Metadata

notable severity, 85% confident.
binary/metrics High code section entropy
baseline severity, 100% confident.
binary Downgrade standalone UPX packer finding
baseline severity, 95% confident.
binary/section UPX packed section name
baseline severity, 95% confident.
dylib::kernel32 links kernel32 (LoadLibraryA, GetProcAddress, VirtualProtect, VirtualAlloc, VirtualFree, ... +1 more)
baseline severity, 95% confident.
dylib::ws2_32 links ws2_32 (ORDINAL 12)

anti-static

hostile severity, 100% confident.
packer/upx UPX decompression failed: IO error: No such file or directory (os error 2)
suspicious severity, 100% confident.
packer Binary contains a UPX packing marker

20 of 27 traits shown

Identity

SHA-256 0f3476eaebfc4fd91d529dd3665a7b57e3b795da68aeea586698efb60d89babc
Filename 0f3476eaebfc4fd91d529dd3665a7b57e3b795da68aeea586698efb60d89babc.exe

Origin

Source harvest

Timeline

First seen 13 May 2026 08:14 UTC
First analyzed 31 May 2026 01:35 UTC
Last analyzed 31 May 2026 01:35 UTC
Last updated 31 May 2026 01:35 UTC

Labeling

Label bad
Label source harvest
Traits version 52045