Mal-ecule
O(Dy)H₂(Cm₃Db₃)Md₃(BiHeSi)
Objectives
notable severity, 85% confident.
anti-static/obfuscation/payload
mscoree.dll text reference
notable severity, 82% confident.
discovery/network/scan
Public cloud range providers
baseline severity, 100% confident.
anti-static/obfuscation
WININET.DLL absent from PE import table
baseline severity, 90% confident.
evasion/anti-av/edr-detect
Security product displayName field
Micro-behaviors
notable severity, 82% confident.
communications/http
WebSocket async send method
notable severity, 72% confident.
communications/http/client
Async HTTP response retrieval
notable severity, 100% confident.
communications/http/server
Access to ASP.NET Request object
notable severity, 70% confident.
data/db
LINQ query operations
notable severity, 90% confident.
data/decode
.NET FromBase64String reference
notable severity, 85% confident.
data/serialize
System.Text.Json library reference
baseline severity, 95% confident.
data/embedded
Microsoft timestamp certificate chain
Metadata
notable severity, 97% confident.
binary/anomaly
Reproducible PE has future timestamp
notable severity, 100% confident.
hardening
Modern PE without ASLR enabled
notable severity, 100% confident.
signed
Signed by Microsoft Corporation
baseline severity, 100% confident.
binary
.NET Assembly (mscoree.dll)
baseline severity, 100% confident.
binary/metrics
Binary has 1000 or more strings
baseline severity, 90% confident.
binary/section
PE .reloc section presence
baseline severity, 100% confident.
build
Built with /Brepro (deterministic)
baseline severity, 100% confident.
dotnet
.NET assembly detected via BSJB CLR metadata signature
baseline severity, 95% confident.
dylib::mscoree
links mscoree.dll (CorDllMain)
20 of 61 traits shown
Identity
| SHA-256 | 25aaca1abbdd820ed26355ec0e4a00f37197513aa4a235624d21ac6bee018500 |
|---|---|
| Filename | Azure.Security.KeyVault.Secrets.4.11.0.nupkg |
Origin
| Ecosystem | dotnet |
|---|---|
| Domain | nuget.org |
Timeline
| First seen | 5 May 2026 20:22 UTC |
|---|---|
| Last analyzed | 12 May 2026 12:34 UTC |
Not seeing what you expected? Let us know