Open-source atomic malware analysis

Analyze another

5599b3c6b633d903c29de06459acba19fc1cf0615038c01771b0b5f1c4e5cb8b.exe

PE
Verdict: BENIGN
Mal-ecule
H(Cm)Md₂(Bk)
Size 186.0 KB download
First seen 108 days ago
Analyzed 90 days ago

Objectives

component severity, 100% confident.
anti-static/obfuscation/binary-metrics Binary has normal code entropy (>5.5)
component severity, 99% confident.
anti-static/obfuscation/payload PE version resource text
component severity, 100% confident.
command-and-control/infrastructure Binary has 4 or fewer sections
component severity, 95% confident.
evasion/indicator-removal Regex component marker
component severity, 95% confident.
evasion/masquerade/file Filename has EXE extension
component severity, 94% confident.
evasion/masquerade/identity Two dotted-quad version strings
component severity, 92% confident.
evasion/process/injection Regex component marker

Micro-behaviors

notable severity, 80% confident.
communications/http/client WebClient.DownloadString method
component severity, 100% confident.
communications/http/server Access to Headers getter

Metadata

notable severity, 90% confident.
build Manifest is MyApplication template name
notable severity, 90% confident.
encoded-payload Encoded payload detected: xor
baseline severity, 100% confident.
binary .NET Metadata Root (BSJB)
baseline severity, 100% confident.
binary/metrics Binary has 1000 or more strings
baseline severity, 90% confident.
binary/section PE .reloc section presence
baseline severity, 100% confident.
dotnet .NET assembly detected via BSJB CLR metadata signature
baseline severity, 95% confident.
dylib::mscoree links mscoree (CorExeMain)
baseline severity, 100% confident.
hardening NO_SEH (SafeSEH not used)
baseline severity, 90% confident.
lang/compiler mscorlib reference
baseline severity, 70% confident.
package PE CompanyName metadata field
component severity, 95% confident.
binary/anomaly PE version info numeric fields present

20 of 33 traits shown

Identity

SHA-256 5599b3c6b633d903c29de06459acba19fc1cf0615038c01771b0b5f1c4e5cb8b
Filename 5599b3c6b633d903c29de06459acba19fc1cf0615038c01771b0b5f1c4e5cb8b.exe

Origin

Source harvest

Timeline

First seen 12 May 2026 19:25 UTC
First analyzed 31 May 2026 03:51 UTC
Last analyzed 31 May 2026 03:51 UTC
Last updated 31 May 2026 03:51 UTC

Labeling

Label bad
Label source harvest
Traits version 52045