Open-source atomic malware analysis

Analyze another

43231

PE
Verdict: BENIGN
Mal-ecule
H(Cm)Md₂(Bi₂Si)
Size 441.0 KB download
First seen 51 days ago
Analyzed 40 days ago

Objectives

baseline severity, 100% confident.
anti-static/obfuscation WININET.DLL absent from PE import table
baseline severity, 90% confident.
evasion/indicator-removal Export timestamp is absent
component severity, 95% confident.
anti-analysis/debugger-detect Minimal PE import DLL count (<= 3)
component severity, 100% confident.
anti-static/obfuscation/binary-metrics Binary has normal code entropy (>5.5)
component severity, 95% confident.
anti-static/obfuscation/payload Regex component marker
component severity, 100% confident.
anti-static/pack Near-maximum entropy in .text section
component severity, 100% confident.
command-and-control/dropper/staging Binary contains high-entropy data regions
component severity, 100% confident.
command-and-control/infrastructure Binary has 4 or fewer sections
component severity, 97% confident.
evasion/masquerade/version-resource PE has no Authenticode signature
component severity, 100% confident.
evasion/process/injection Lacks substantial resources

Micro-behaviors

notable severity, 100% confident.
communications/ipc Uses named pipe IPC APIs
baseline severity, 70% confident.
os/module Get current process handle

Metadata

notable severity, 85% confident.
binary/metrics High code section entropy
notable severity, 85% confident.
binary/section High entropy executable section
notable severity, 100% confident.
signed Binary is not digitally signed
baseline severity, 100% confident.
binary PE has exactly two resource entries
baseline severity, 95% confident.
dylib::kernel32 links kernel32.dll (CreateNamedPipeW, GetCurrentProcess, GetUserDefaultLangID)
baseline severity, 95% confident.
dylib::ole32 links ole32.dll (CoRegisterInitializeSpy)
baseline severity, 95% confident.
dylib::user32 links user32.dll (GetMessageExtraInfo)
baseline severity, 90% confident.
lang/compiler Native runtime has huge functions

20 of 29 traits shown

Identity

SHA-256 2b52bcf15c4854d049cf3826d6d2f65e76c7cf66740f8c3b4a2f2aa377e619b6
Filename 43231

Origin

Ecosystem pe-machine-learning-dataset

Timeline

First seen 1 May 2026 09:47 UTC
Last analyzed 12 May 2026 10:05 UTC