Open-source atomic malware analysis

Analyze another

4d791660290aba28cb764af2e97cb07f4f987732e28376f259307d4f7a1aa33d.exe

PE
Verdict: BENIGN
Mal-ecule
H(Os)Md(Bi)
Size 7.2 MB download
First seen 107 days ago
Analyzed 94 days ago

Objectives

component severity, 95% confident.
anti-analysis/vm-detect Regex component marker
component severity, 95% confident.
anti-static/obfuscation Direct PEB access (GS segment)
component severity, 100% confident.
anti-static/obfuscation/binary-metrics Binary has normal code entropy (>5.5)
component severity, 95% confident.
anti-static/obfuscation/payload mscoree DLL string reference
component severity, 95% confident.
anti-static/pack Code section entropy above 7.4
component severity, 95% confident.
evasion/anti-av/platform ETW event write blinding patch bytes

Micro-behaviors

notable severity, 90% confident.
os/random RtlGenRandom export-ordinal alias (SystemFunction036)
baseline severity, 85% confident.
os/syscall Direct NT API access
baseline severity, 84% confident.
os/sysinfo/platform Enumerate installed system locales
baseline severity, 80% confident.
process/inject/runtime CorExitProcess CLR termination reference
component severity, 98% confident.
process/terminate Regex component marker

Metadata

notable severity, 85% confident.
binary/metrics High code section entropy
baseline severity, 95% confident.
binary mscoree name reference
baseline severity, 90% confident.
binary/linking ext-ms Windows API-set cluster
baseline severity, 90% confident.
binary/section PE .reloc section presence
baseline severity, 95% confident.
dylib::kernel32 links kernel32 (AcquireSRWLockExclusive)
baseline severity, 100% confident.
hardening High-entropy ASLR (64-bit)
baseline severity, 88% confident.
lang/compiler Native runtime binary is large
baseline severity, 84% confident.
package Large binary with few DLL dependencies
component severity, 95% confident.
binary/symbols COM registration export

20 of 41 traits shown

Identity

SHA-256 4d791660290aba28cb764af2e97cb07f4f987732e28376f259307d4f7a1aa33d
Filename 4d791660290aba28cb764af2e97cb07f4f987732e28376f259307d4f7a1aa33d.exe

Origin

Source harvest

Timeline

First seen 17 May 2026 15:10 UTC
First analyzed 30 May 2026 22:59 UTC
Last analyzed 30 May 2026 22:59 UTC
Last updated 30 May 2026 22:59 UTC

Labeling

Label bad
Label source harvest
Traits version 52045