Local reference
Suspicious dependency
Inferred
Mal-ecule
O(As)H(Ds)
Objectives
suspicious severity, 75% confident.
anti-static/obfuscation/payload
Minimal PE imports with dynamic loading
baseline severity, 85% confident.
evasion/masquerade/dll
DLL filename extension present
component severity, 95% confident.
anti-static/obfuscation
Huge null run in executable (128+ bytes)
component severity, 100% confident.
anti-static/obfuscation/reflection
LoadLibrary symbol
component severity, 94% confident.
evasion/masquerade/identity
Two dotted-quad version strings
component severity, 92% confident.
evasion/process/injection
Regex component marker
Micro-behaviors
notable severity, 95% confident.
dylib/load
Dynamic library loading via LoadLibraryA
baseline severity, 100% confident.
os/module
Reference to ADVAPI32.dll
baseline severity, 90% confident.
process/create
Close handle
Metadata
baseline severity, 100% confident.
binary
PE has RT_ICON in resources list
baseline severity, 100% confident.
binary/metrics
Binary has 1000 or more strings
baseline severity, 90% confident.
binary/section
PE .reloc section presence
baseline severity, 100% confident.
build
requestedExecutionLevel is asInvoker
baseline severity, 95% confident.
dylib::advapi32
links advapi32 (RegLoadAppKeyW)
baseline severity, 95% confident.
dylib::kernel32
links kernel32 (LoadLibraryExA, LoadLibraryA, OutputDebugStringA, GenerateConsoleCtrlEvent, IsBadStringPtrA, ... +2 more)
baseline severity, 95% confident.
dylib::user32
links user32 (RegisterDeviceNotificationW, TranslateMessage)
baseline severity, 100% confident.
hardening
DEP / NX enabled (NX_COMPAT)
baseline severity, 70% confident.
package
PE CompanyName metadata field
component severity, 95% confident.
binary/anomaly
PE version info numeric fields present
component severity, 95% confident.
binary/symbols
Binary imports ADVAPI32.dll
20 of 31 traits shown
Identity
| SHA-256 | 5b3978a06e60c5f966cea02a94b871a69c64a71e91d20a36f6361229641652d9 |
|---|---|
| Filename | 5b3978a06e60c5f966cea02a94b871a69c64a71e91d20a36f6361229641652d9.dll |
Origin
| Source | harvest |
|---|
Timeline
| First seen | 12 May 2026 19:32 UTC |
|---|---|
| First analyzed | 31 May 2026 11:22 UTC |
| Last analyzed | 31 May 2026 11:22 UTC |
| Last updated | 31 May 2026 11:22 UTC |
Labeling
| Label | bad |
|---|---|
| Label source | harvest |
| Traits version | 52045 |
Not seeing what you expected? Let us know