Local reference
Suspicious dependency
Inferred
Mal-ecule
H(Cm)Md(Bi)
Well-known
component severity, 99% confident.
malware/worm
Exactly seven imports
Objectives
baseline severity, 75% confident.
anti-static/obfuscation/payload
Minimal PE imports with dynamic loading
component severity, 100% confident.
anti-static/obfuscation/binary-metrics
Binary has normal code entropy (>5.5)
component severity, 100% confident.
anti-static/obfuscation/reflection
VirtualProtect symbol
component severity, 99% confident.
anti-static/pack
UPX magic byte sequence
component severity, 96% confident.
command-and-control/dropper/execution
Empty RWX UPX0 decoy section
component severity, 100% confident.
command-and-control/infrastructure
Binary has 4 or fewer sections
component severity, 95% confident.
evasion/masquerade/file
Filename has EXE extension
Micro-behaviors
notable severity, 70% confident.
communications/socket
WS2_32 Winsock DLL import
baseline severity, 90% confident.
dylib
Windows GetProcAddress API string
baseline severity, 95% confident.
mem/protect
Modify memory page protection
baseline severity, 90% confident.
os/module
Resolve exports with GetProcAddress
baseline severity, 90% confident.
process/terminate
Exit current process
Metadata
notable severity, 85% confident.
binary/metrics
High code section entropy
baseline severity, 100% confident.
binary
Downgrade standalone UPX packer finding
baseline severity, 95% confident.
binary/section
UPX packed section name
baseline severity, 95% confident.
dylib::kernel32
links kernel32 (LoadLibraryA, GetProcAddress, VirtualProtect, VirtualAlloc, VirtualFree, ... +1 more)
baseline severity, 95% confident.
dylib::ws2_32
links ws2_32 (ORDINAL 12)
anti-static
hostile severity, 100% confident.
packer/upx
UPX decompression failed: IO error: No such file or directory (os error 2)
suspicious severity, 100% confident.
packer
Binary contains a UPX packing marker
20 of 27 traits shown
Identity
| SHA-256 | 0f3476eaebfc4fd91d529dd3665a7b57e3b795da68aeea586698efb60d89babc |
|---|---|
| Filename | 0f3476eaebfc4fd91d529dd3665a7b57e3b795da68aeea586698efb60d89babc.exe |
Origin
| Source | harvest |
|---|
Timeline
| First seen | 13 May 2026 08:14 UTC |
|---|---|
| First analyzed | 31 May 2026 01:35 UTC |
| Last analyzed | 31 May 2026 01:35 UTC |
| Last updated | 31 May 2026 01:35 UTC |
Labeling
| Label | bad |
|---|---|
| Label source | harvest |
| Traits version | 52045 |
Not seeing what you expected? Let us know