Open-source atomic malware analysis

Analyze another

64f18b6b7769bec3096d56c3772f6f89380a2e989e778a2d0a3634ee79160ce3.exe

PE
Verdict: BENIGN
Mal-ecule
H₂(Db₂Os)Md
Size 370.0 KB download
First seen 113 days ago
Analyzed 95 days ago

Objectives

component severity, 99% confident.
anti-static/obfuscation/payload PE version resource text
component severity, 90% confident.
anti-static/pack PE has under ten imports
component severity, 100% confident.
command-and-control/infrastructure Binary has 4 or fewer sections
component severity, 95% confident.
evasion/indicator-removal Regex component marker
component severity, 95% confident.
evasion/masquerade/file Filename has EXE extension
component severity, 95% confident.
evasion/masquerade/identity PE FileDescription is single-character placeholder
component severity, 92% confident.
evasion/process/injection Regex component marker

Micro-behaviors

notable severity, 70% confident.
data/db SqlCommand class
notable severity, 90% confident.
data/decode .NET FromBase64String reference
baseline severity, 90% confident.
dylib Windows GetProcAddress API string
component severity, 100% confident.
communications/ipc References WCF EndpointAddress

Metadata

notable severity, 100% confident.
file PE with many long base64/hex-like strings
baseline severity, 100% confident.
binary .NET Metadata Root (BSJB)
baseline severity, 90% confident.
binary/section PE .reloc section presence
baseline severity, 100% confident.
dotnet .NET assembly detected via BSJB CLR metadata signature
baseline severity, 95% confident.
dylib::mscoree links mscoree (CorExeMain)
baseline severity, 100% confident.
hardening ASLR enabled (DYNAMIC_BASE)
baseline severity, 90% confident.
lang/compiler mscorlib reference
baseline severity, 70% confident.
package PE FileDescription metadata field
component severity, 95% confident.
binary/anomaly PE version info numeric fields present

20 of 35 traits shown

Identity

SHA-256 64f18b6b7769bec3096d56c3772f6f89380a2e989e778a2d0a3634ee79160ce3
Filename 64f18b6b7769bec3096d56c3772f6f89380a2e989e778a2d0a3634ee79160ce3.exe

Origin

Source harvest

Timeline

First seen 12 May 2026 19:31 UTC
First analyzed 30 May 2026 13:16 UTC
Last analyzed 30 May 2026 13:16 UTC
Last updated 30 May 2026 13:16 UTC

Labeling

Label bad
Label source harvest
Traits version ca5ef