Open-source atomic malware analysis

Analyze another

2b9cfdd264b3db3a7960ec45a6291270274b16c2d81cafa26e0082a59d50f238.exe

PE
Verdict: BENIGN
Mal-ecule
H(Os)Md(Bi)
Size 708.0 KB download
First seen 112 days ago
Analyzed 95 days ago

Objectives

component severity, 90% confident.
anti-analysis/debugger-detect PE TLS callback table present
component severity, 95% confident.
anti-static/obfuscation Huge null run in executable (128+ bytes)
component severity, 100% confident.
anti-static/obfuscation/binary-metrics Binary has normal code entropy (>5.5)
component severity, 86% confident.
anti-static/obfuscation/string Long mixed-case identifiers cluster
component severity, 90% confident.
anti-static/pack High plaintext string count
component severity, 85% confident.
command-and-control/dropper/staging Regex component marker
component severity, 95% confident.
evasion/indicator-removal Regex component marker
component severity, 85% confident.
evasion/masquerade PE lacks VS_VERSION_INFO resource
component severity, 95% confident.
evasion/masquerade/file Filename has EXE extension
component severity, 100% confident.
impact/infect scanner word

Micro-behaviors

notable severity, 70% confident.
os/privilege runas privilege elevation string
baseline severity, 100% confident.
data/text/malware Malware type word with malware suffix
baseline severity, 90% confident.
dylib/library GNU libstdc++ stdlib
baseline severity, 70% confident.
fs/path Windows Temp directory path
component severity, 90% confident.
communications/proxy SOCKS5 client greeting bytes

Metadata

suspicious severity, 92% confident.
binary/section Many slash-numeric PE sections (padding artifact)
baseline severity, 94% confident.
binary MinGW native wrapper for GCJ
baseline severity, 100% confident.
binary/metrics Binary has 1000 or more strings
baseline severity, 84% confident.
package Large binary with few DLL dependencies
component severity, 99% confident.
binary/anomaly CLAM COFF timestamp marker

20 of 22 traits shown

Identity

SHA-256 2b9cfdd264b3db3a7960ec45a6291270274b16c2d81cafa26e0082a59d50f238
Filename 2b9cfdd264b3db3a7960ec45a6291270274b16c2d81cafa26e0082a59d50f238.exe

Origin

Source harvest

Timeline

First seen 13 May 2026 19:15 UTC
First analyzed 31 May 2026 09:14 UTC
Last analyzed 31 May 2026 09:14 UTC
Last updated 31 May 2026 09:14 UTC

Labeling

Label bad
Label source harvest
Traits version 52045