Open-source atomic malware analysis

Analyze another

488dacac0fd2eecf309f6334f064a2cab2978cd458b1c98a9c40e5d7b3bc08ba.7z

RAR
Verdict: HOSTILE
Mal-ecule
O(Er₂)Md₃(BiBk)
Size 465.8 KB download
First seen 36 days ago
Analyzed 19 days ago

Objectives

suspicious severity, 96% confident.
evasion/masquerade/file Document double-extension executable
notable severity, 85% confident.
evasion/masquerade PE stem disagrees with embedded PDB stem
component severity, 100% confident.
anti-static/obfuscation/binary-metrics Binary has normal code entropy (>5.5)
component severity, 99% confident.
anti-static/obfuscation/payload PE version resource text
component severity, 100% confident.
command-and-control/infrastructure Binary has 4 or fewer sections
component severity, 95% confident.
evasion/indicator-removal Regex component marker
component severity, 94% confident.
evasion/masquerade/identity Two dotted-quad version strings
component severity, 100% confident.
impact/wipe/disk Gutmann pattern 49 24 92

Micro-behaviors

component severity, 100% confident.
communications/http/server Modification of HTTP context items

Metadata

suspicious severity, 100% confident.
file-extension-mismatch File extension claims SevenZ but content is Rar
notable severity, 92% confident.
binary/section Large high-entropy random executable section
notable severity, 90% confident.
build Manifest is MyApplication template name
baseline severity, 100% confident.
binary .NET Metadata Root (BSJB)
baseline severity, 100% confident.
binary/metrics Binary has 1000 or more strings
baseline severity, 100% confident.
dotnet .NET assembly detected via BSJB CLR metadata signature
baseline severity, 95% confident.
dylib::mscoree links mscoree (CorExeMain)
baseline severity, 100% confident.
hardening NO_SEH (SafeSEH not used)
baseline severity, 90% confident.
lang/compiler mscorlib reference
baseline severity, 84% confident.
package Large binary with few DLL dependencies
component severity, 95% confident.
binary/anomaly PE version info numeric fields present

20 of 41 traits shown

Identity

SHA-256 488dacac0fd2eecf309f6334f064a2cab2978cd458b1c98a9c40e5d7b3bc08ba
Filename 488dacac0fd2eecf309f6334f064a2cab2978cd458b1c98a9c40e5d7b3bc08ba.7z

Origin

Source harvest

Timeline

First seen 13 May 2026 09:30 UTC
First analyzed 31 May 2026 03:49 UTC
Last analyzed 31 May 2026 03:49 UTC
Last updated 18 Jun 2026 16:59 UTC

Labeling

Label bad
Label source harvest
Traits version 52045