Local reference
Suspicious dependency
Inferred
Mal-ecule
O(As)H(Ds)
Well-known
component severity, 95% confident.
malware/trojan/elex
Resource dominant compact loader
component severity, 99% confident.
malware/worm
Exactly four sections
Objectives
suspicious severity, 75% confident.
anti-static/obfuscation/payload
Minimal PE imports with dynamic loading
component severity, 100% confident.
anti-static/obfuscation/binary-metrics
Binary has normal code entropy (>5.5)
component severity, 100% confident.
anti-static/obfuscation/reflection
LoadLibrary symbol
component severity, 100% confident.
command-and-control/infrastructure
Binary has 4 or fewer sections
component severity, 95% confident.
evasion/masquerade/file
Filename has EXE extension
component severity, 92% confident.
evasion/process/injection
Regex component marker
Micro-behaviors
notable severity, 95% confident.
dylib/load
Dynamic library loading via LoadLibraryA
baseline severity, 90% confident.
dylib
Windows GetProcAddress API string
baseline severity, 80% confident.
os/api-resolution
PEB access via FS segment (x86)
baseline severity, 92% confident.
os/module
Dynamically resolve own modules and exports
baseline severity, 85% confident.
os/syscall
Direct NT API access
baseline severity, 90% confident.
process/info
Get current process ID
baseline severity, 90% confident.
process/terminate
Exit current process
Metadata
baseline severity, 70% confident.
binary
PE has many readable strings
baseline severity, 100% confident.
binary/metrics
Binary has 1000 or more strings
baseline severity, 90% confident.
binary/section
PE .reloc section presence
baseline severity, 95% confident.
dylib::kernel32
links kernel32 (GetCommandLineA, ExitProcess, LoadLibraryA, GetProcAddress, GetCurrentProcessId, ... +1 more)
baseline severity, 100% confident.
hardening
DEP / NX enabled (NX_COMPAT)
20 of 28 traits shown
Identity
| SHA-256 | 78b592a2710d81fa91235b445f674ee804db39c8cc34f7e894b4e7b7f6eacaff |
|---|---|
| Filename | 78b592a2710d81fa91235b445f674ee804db39c8cc34f7e894b4e7b7f6eacaff.exe |
Origin
| Source | harvest |
|---|
Timeline
| First seen | 13 May 2026 08:16 UTC |
|---|---|
| First analyzed | 31 May 2026 08:32 UTC |
| Last analyzed | 31 May 2026 08:32 UTC |
| Last updated | 31 May 2026 08:32 UTC |
Labeling
| Label | bad |
|---|---|
| Label source | harvest |
| Traits version | 52045 |
Not seeing what you expected? Let us know