Open-source atomic malware analysis

Analyze another

36f6531d59c061d5b25f792b88b53fd54c810b9680a37947d8c25e81c6148fd5.exe

PE
Verdict: SUSPICIOUS
Mal-ecule
H(Cm)Md(Bi)
Size 46.0 KB download unavailable
First seen 77 days ago
Analyzed 59 days ago

Objectives

baseline severity, 75% confident.
anti-static/obfuscation/payload Minimal PE imports with dynamic loading
component severity, 100% confident.
anti-static/obfuscation/binary-metrics Binary has normal code entropy (>5.5)
component severity, 100% confident.
anti-static/obfuscation/reflection VirtualProtect symbol

Micro-behaviors

notable severity, 72% confident.
communications/socket WSOCK32 Winsock DLL import
baseline severity, 90% confident.
dylib Windows GetProcAddress API string
baseline severity, 95% confident.
mem/protect Modify memory page protection
baseline severity, 100% confident.
os/module Reference to ADVAPI32.dll
baseline severity, 90% confident.
process/terminate Exit current process

Metadata

notable severity, 85% confident.
binary/metrics High code section entropy
baseline severity, 100% confident.
binary PE first resource is RT_VERSION
baseline severity, 95% confident.
binary/section UPX packed section name
baseline severity, 95% confident.
dylib::advapi32 links advapi32 (FreeSid)
baseline severity, 95% confident.
dylib::kernel32 links kernel32 (LoadLibraryA, ExitProcess, GetProcAddress, VirtualProtect)
baseline severity, 95% confident.
dylib::msvcrt links msvcrt (iob)
baseline severity, 95% confident.
dylib::ws2_32 links ws2_32 (WSARecv)
baseline severity, 95% confident.
dylib::wsock32 links wsock32 (ORDINAL 111)
baseline severity, 100% confident.
hardening Writable and executable section (W^X violation)
baseline severity, 80% confident.
package Apache License text

anti-static

hostile severity, 100% confident.
packer/upx UPX decompression failed: IO error: No such file or directory (os error 2)
suspicious severity, 100% confident.
packer Binary contains a UPX packing marker

20 of 31 traits shown

Identity

SHA-256 36f6531d59c061d5b25f792b88b53fd54c810b9680a37947d8c25e81c6148fd5
Filename 36f6531d59c061d5b25f792b88b53fd54c810b9680a37947d8c25e81c6148fd5.exe

Origin

Source harvest

Timeline

First seen 12 May 2026 19:31 UTC
First analyzed 31 May 2026 13:29 UTC
Last analyzed 31 May 2026 13:29 UTC
Last updated 31 May 2026 13:29 UTC

Labeling

Label bad
Label source harvest
Traits version 176d6