Open-source atomic malware analysis

Analyze another

4d13ac9ebc7e0ab75339290eede50e016acf597af626bd3efbd4d7a65ddaced0.exe

PE
Verdict: BENIGN
Mal-ecule
H(Os)Md(Bi)
Size 1.3 MB download
First seen 109 days ago
Analyzed 94 days ago

Objectives

component severity, 85% confident.
anti-static/obfuscation/payload Registry value named "scode"
component severity, 72% confident.
anti-static/obfuscation/reflection Reflection GetFields reference
component severity, 86% confident.
anti-static/obfuscation/string Long mixed-case identifiers cluster
component severity, 85% confident.
command-and-control/dropper/staging Regex component marker
component severity, 95% confident.
evasion/indicator-removal Regex component marker
component severity, 85% confident.
evasion/masquerade PE lacks VS_VERSION_INFO resource
component severity, 95% confident.
evasion/masquerade/file Filename has EXE extension
component severity, 80% confident.
execution/interpreter/script SaveToFile string fragment (veTo)
component severity, 86% confident.
exfiltration/messaging Notification config wording
component severity, 88% confident.
persistence/login/scheduled-task Regex component marker

Micro-behaviors

notable severity, 90% confident.
os/sysinfo Query disk free space
component severity, 80% confident.
communications/http/client Regex component marker
component severity, 90% confident.
os/api-resolution Kernel32 DLL resolution string
component severity, 82% confident.
process/enumerate GetModuleFileNameExA dynamic resolve
component severity, 80% confident.
process/interpreter/powershell AddParameter method (PowerShell execution)

Metadata

notable severity, 85% confident.
binary/metrics PE with malformed section layout
baseline severity, 88% confident.
lang/compiler Native runtime binary is large
component severity, 100% confident.
binary File is a compiled binary
component severity, 80% confident.
binary/anomaly CompanyName field absent from PE version info
component severity, 90% confident.
binary/section Tiny C string section ratio

20 of 23 traits shown

Identity

SHA-256 4d13ac9ebc7e0ab75339290eede50e016acf597af626bd3efbd4d7a65ddaced0
Filename 4d13ac9ebc7e0ab75339290eede50e016acf597af626bd3efbd4d7a65ddaced0.exe

Origin

Source harvest

Timeline

First seen 15 May 2026 12:15 UTC
First analyzed 31 May 2026 02:24 UTC
Last analyzed 31 May 2026 02:24 UTC
Last updated 31 May 2026 02:24 UTC

Labeling

Label bad
Label source harvest
Traits version 52045