Mal-ecule
H(Cm)Md₂(Bi₂Si)
Objectives
baseline severity, 100% confident.
anti-static/obfuscation
WININET.DLL absent from PE import table
baseline severity, 75% confident.
anti-static/obfuscation/payload
Minimal PE imports with dynamic loading
baseline severity, 100% confident.
evasion/decoy
High complexity but very few functions
baseline severity, 90% confident.
evasion/indicator-removal
Export timestamp is absent
Micro-behaviors
notable severity, 85% confident.
communications/http/client
Read WinHTTP response body
baseline severity, 95% confident.
mem/protect
Modify memory page protection
baseline severity, 100% confident.
os/module
Reference to USER32.dll
baseline severity, 90% confident.
process/terminate
Exit current process
Metadata
suspicious severity, 85% confident.
binary/anomaly
High complexity but very few functions
notable severity, 70% confident.
binary/metrics
Single function with high complexity (monolithic stub)
notable severity, 100% confident.
signed
Binary is not digitally signed
baseline severity, 100% confident.
binary
PE has RT_GROUP_ICON in resources list
baseline severity, 95% confident.
binary/section
UPX packed section name
baseline severity, 95% confident.
dylib::advapi32
links ADVAPI32.dll (FreeSid)
baseline severity, 95% confident.
dylib::gdi32
links GDI32.dll (StartDocW)
baseline severity, 95% confident.
dylib::kernel32
links KERNEL32.DLL (LoadLibraryA, ExitProcess, GetProcAddress, VirtualProtect)
baseline severity, 95% confident.
dylib::ole32
links ole32.dll (OleCreate)
baseline severity, 95% confident.
dylib::user32
links USER32.dll (EndMenu)
baseline severity, 95% confident.
dylib::winhttp
links WINHTTP.dll (WinHttpReadData)
baseline severity, 100% confident.
hardening
DEP / NX enabled (NX_COMPAT)
20 of 37 traits shown
Identity
| SHA-256 | 54a9f1c82416fe7bd940f50781cb16b0d63d3713c0ec13c47a470c33cc3084fd |
|---|---|
| Filename | 499044 |
Origin
| Ecosystem | pe-machine-learning-dataset |
|---|
Timeline
| First seen | 1 May 2026 09:47 UTC |
|---|---|
| Last analyzed | 12 May 2026 11:03 UTC |
Not seeing what you expected? Let us know