Open-source atomic malware analysis

Analyze another

VirusShare_bdea64f09814e3f0656506e21fc1e56f

PE
Verdict: BENIGN
Mal-ecule
H(Ti)
Size 276.0 KB download
First seen 91 days ago
Analyzed 78 days ago

Well-known

component severity, 99% confident.
malware/worm .text section present

Objectives

component severity, 80% confident.
anti-static/obfuscation Executable section with very low entropy
component severity, 99% confident.
anti-static/obfuscation/payload PE version resource text
component severity, 86% confident.
anti-static/obfuscation/string Long mixed-case identifiers cluster
component severity, 90% confident.
anti-static/pack PE has under ten imports
component severity, 100% confident.
command-and-control/infrastructure Binary has 4 or fewer sections
component severity, 95% confident.
evasion/indicator-removal Regex component marker
component severity, 95% confident.
evasion/masquerade/identity PE FileDescription is single-character placeholder
component severity, 92% confident.
evasion/process/injection Regex component marker

Micro-behaviors

notable severity, 85% confident.
time/timing KUSER_SHARED_DATA structure access (uptime)
component severity, 90% confident.
communications/proxy SOCKS5 client greeting bytes

Metadata

baseline severity, 100% confident.
binary PE first resource is RT_VERSION
baseline severity, 100% confident.
binary/metrics Binary has 1000 or more strings
baseline severity, 90% confident.
binary/section PE .reloc section presence
baseline severity, 100% confident.
dotnet .NET assembly detected via BSJB CLR metadata signature
baseline severity, 95% confident.
dylib::mscoree links mscoree (CorDllMain)
baseline severity, 100% confident.
hardening NO_SEH (SafeSEH not used)
baseline severity, 90% confident.
lang/compiler mscorlib reference
baseline severity, 70% confident.
package PE InternalName metadata field
component severity, 95% confident.
binary/anomaly PE version info numeric fields present

20 of 25 traits shown

Identity

SHA-256 7b4cfd65a0758ddd8e77f8ec5afb827d80d8053e028029fe5097e64b5f5e1322
Filename VirusShare_bdea64f09814e3f0656506e21fc1e56f

Origin

Source harvest

Timeline

First seen 12 May 2026 19:06 UTC
First analyzed 12 May 2026 22:54 UTC
Last analyzed 25 May 2026 20:48 UTC
Last updated 25 May 2026 20:48 UTC

Labeling

Label bad
Label source harvest
Traits version 7924e