Open-source atomic malware analysis

Analyze another

82b44e9772ffe5cc9c8daef9eaaa77528c2f677908c88f232c69d2726a22e559.exe

PE
Verdict: BENIGN
Mal-ecule
H(Os)Md(Bi)
Size 83.5 KB download
First seen 111 days ago
Analyzed 94 days ago

Well-known

baseline severity, 96% confident.
app Microsoft company metadata
baseline severity, 97% confident.
lib Microsoft ImageHlp company metadata

Objectives

baseline severity, 75% confident.
anti-static/obfuscation/payload Minimal PE imports with dynamic loading

Micro-behaviors

notable severity, 90% confident.
os/registry Recursively delete registry key tree
baseline severity, 90% confident.
dylib Windows GetProcAddress API string
baseline severity, 95% confident.
mem/protect Modify memory page protection
baseline severity, 100% confident.
os/module Reference to ADVAPI32.dll
baseline severity, 90% confident.
process/terminate Exit current process

Metadata

notable severity, 85% confident.
binary/metrics High code section entropy
baseline severity, 100% confident.
binary PE first resource is RT_VERSION
baseline severity, 95% confident.
binary/section UPX packed section name
baseline severity, 95% confident.
dylib::advapi32 links advapi32 (GetAce)
baseline severity, 95% confident.
dylib::kernel32 links kernel32 (LoadLibraryA, GetProcAddress, VirtualProtect, VirtualAlloc, VirtualFree, ... +1 more)
baseline severity, 95% confident.
dylib::msvcrt links msvcrt (exit)
baseline severity, 95% confident.
dylib::netapi32 links netapi32 (NetApiBufferFree)
baseline severity, 95% confident.
dylib::shlwapi links shlwapi (SHDeleteKeyA)
baseline severity, 95% confident.
dylib::user32 links user32 (wsprintfA)
baseline severity, 100% confident.
hardening Writable and executable section (W^X violation)

anti-static

hostile severity, 100% confident.
packer/upx UPX decompression failed: IO error: No such file or directory (os error 2)
suspicious severity, 100% confident.
packer Binary contains a UPX packing marker

20 of 37 traits shown

Identity

SHA-256 82b44e9772ffe5cc9c8daef9eaaa77528c2f677908c88f232c69d2726a22e559
Filename 82b44e9772ffe5cc9c8daef9eaaa77528c2f677908c88f232c69d2726a22e559.exe

Origin

Source harvest

Timeline

First seen 14 May 2026 06:37 UTC
First analyzed 31 May 2026 02:53 UTC
Last analyzed 31 May 2026 02:53 UTC
Last updated 31 May 2026 02:53 UTC

Labeling

Label bad
Label source harvest
Traits version 52045