Open-source atomic malware analysis

Analyze another

78b592a2710d81fa91235b445f674ee804db39c8cc34f7e894b4e7b7f6eacaff.exe

PE
Verdict: BENIGN
Mal-ecule
O(As)H(Ds)
Size 119.5 KB download
First seen 89 days ago
Analyzed 71 days ago

Well-known

component severity, 95% confident.
malware/trojan/elex Resource dominant compact loader
component severity, 99% confident.
malware/worm Exactly four sections

Objectives

suspicious severity, 75% confident.
anti-static/obfuscation/payload Minimal PE imports with dynamic loading
component severity, 100% confident.
anti-static/obfuscation/binary-metrics Binary has normal code entropy (>5.5)
component severity, 100% confident.
anti-static/obfuscation/reflection LoadLibrary symbol
component severity, 100% confident.
command-and-control/infrastructure Binary has 4 or fewer sections
component severity, 95% confident.
evasion/masquerade/file Filename has EXE extension
component severity, 92% confident.
evasion/process/injection Regex component marker

Micro-behaviors

notable severity, 95% confident.
dylib/load Dynamic library loading via LoadLibraryA
baseline severity, 90% confident.
dylib Windows GetProcAddress API string
baseline severity, 80% confident.
os/api-resolution PEB access via FS segment (x86)
baseline severity, 92% confident.
os/module Dynamically resolve own modules and exports
baseline severity, 85% confident.
os/syscall Direct NT API access
baseline severity, 90% confident.
process/info Get current process ID
baseline severity, 90% confident.
process/terminate Exit current process

Metadata

baseline severity, 70% confident.
binary PE has many readable strings
baseline severity, 100% confident.
binary/metrics Binary has 1000 or more strings
baseline severity, 90% confident.
binary/section PE .reloc section presence
baseline severity, 95% confident.
dylib::kernel32 links kernel32 (GetCommandLineA, ExitProcess, LoadLibraryA, GetProcAddress, GetCurrentProcessId, ... +1 more)
baseline severity, 100% confident.
hardening DEP / NX enabled (NX_COMPAT)

20 of 28 traits shown

Identity

SHA-256 78b592a2710d81fa91235b445f674ee804db39c8cc34f7e894b4e7b7f6eacaff
Filename 78b592a2710d81fa91235b445f674ee804db39c8cc34f7e894b4e7b7f6eacaff.exe

Origin

Source harvest

Timeline

First seen 13 May 2026 08:16 UTC
First analyzed 31 May 2026 08:32 UTC
Last analyzed 31 May 2026 08:32 UTC
Last updated 31 May 2026 08:32 UTC

Labeling

Label bad
Label source harvest
Traits version 52045