Well-known
hostile severity, 100% confident.
malware/trojan/elex
Storm DDoS Active Setup loader
Objectives
suspicious severity, 94% confident.
evasion/self-delete
COMSPEC CreateProcess self-delete
suspicious severity, 93% confident.
persistence/login/startup
Active Setup StubPath persistence
suspicious severity, 94% confident.
persistence/system/service
Persists DLL through Windows service
notable severity, 90% confident.
anti-static/obfuscation
Unusual PE section alignment
Micro-behaviors
notable severity, 95% confident.
data/embedded
Complete PE resource extraction with data access
notable severity, 66% confident.
fs/file
Copy files (Windows API ANSI)
notable severity, 92% confident.
os/registry
Registry open create and write APIs
notable severity, 95% confident.
os/service
Full Windows service dispatch triplet
notable severity, 98% confident.
process/inject
CreateRemoteThread API reference
Metadata
notable severity, 92% confident.
binary
Overlay exceeds one-third
notable severity, 100% confident.
unsigned
Binary is not digitally signed
baseline severity, 95% confident.
dylib::advapi32
links ADVAPI32.dll (CloseServiceHandle, RegOpenKeyExA, RegQueryValueExA, StartServiceCtrlDispatcherA, RegCreateKeyA, ... +10 more)
baseline severity, 95% confident.
dylib::comdlg32
links comdlg32.dll (GetFileTitleA)
baseline severity, 95% confident.
dylib::kernel32
links KERNEL32.dll (lstrcatA, lstrcpyA, GetEnvironmentVariableA, GetShortPathNameA, GetModuleFileNameA, ... +28 more)
baseline severity, 95% confident.
dylib::mfc42
links MFC42.DLL (ORDINAL 924, ORDINAL 800, ORDINAL 941, ORDINAL 535, ORDINAL 537)
baseline severity, 95% confident.
dylib::msvcp60
links MSVCP60.dll (??0_Winit@std@@QAE@XZ, ??1_Winit@std@@QAE@XZ, ??1Init@ios_base@std@@QAE@XZ, ??0Init@ios_base@std@@QAE@XZ)
baseline severity, 100% confident.
hardening::no-pie
Binary is not position-independent (fixed load address)
baseline severity, 100% confident.
signed::unsigned
Binary is not digitally signed
Third-party
notable severity, 90% confident.
SigBase/SUSP/Imphash
Detects imphash often found in malware samples (Zero hits with with search for 'imphash:x p:0' on Virustotal)
20 of 56 traits shown
Identity
| SHA-256 | 7a59052dde463dd7a545695446e5c6fddd2c1166e626c947b594b0666b28d8fb |
|---|---|
| Filename | 2026-02-07_c1bf45620b0c9ed2aac6d73365a76045_elex_wannacry |
Origin
| Source | harvest |
|---|---|
| Feed | vxug |
| Ecosystem | _unknown |
Timeline
| First seen | 24 Apr 2026 16:15 UTC |
|---|---|
| Last analyzed | 24 Apr 2026 19:09 UTC |
| Last updated | 24 Apr 2026 19:09 UTC |
Labeling
| Label | bad |
|---|---|
| Label source | harvest |
| Traits version | 8bf61 |
Not seeing what you expected? Let us know