Open-source atomic malware analysis

Analyze another

8ce33ed9a7227d43520970b4e7e7afe683f4fcc8dbd210f3373e899a39e1fd2d.exe

PE
Verdict: BENIGN
Mal-ecule
H₃(CmFPo)Md(Bk)
Size 808.0 KB download
First seen 95 days ago
Analyzed 77 days ago

Objectives

component severity, 100% confident.
anti-static/obfuscation/binary-metrics Binary has normal code entropy (>5.5)
component severity, 99% confident.
anti-static/obfuscation/payload PE version resource text
component severity, 100% confident.
command-and-control/infrastructure Binary has 4 or fewer sections
component severity, 95% confident.
evasion/indicator-removal Regex component marker
component severity, 95% confident.
evasion/masquerade/file Filename has EXE extension
component severity, 94% confident.
evasion/masquerade/identity Two dotted-quad version strings

Micro-behaviors

suspicious severity, 85% confident.
communications/http Stack-built WinInet library reference
notable severity, 88% confident.
fs/traversal .NET drive enumeration via DriveInfo API
notable severity, 90% confident.
process/user Query current username via .NET
component severity, 100% confident.
data/embedded/payload LZMA header nonzero size pos 1

Metadata

notable severity, 90% confident.
build Manifest is MyApplication template name
baseline severity, 100% confident.
binary PE has RT_ICON in resources list
baseline severity, 100% confident.
binary/metrics Binary has 1000 or more strings
baseline severity, 90% confident.
binary/section PE .reloc section presence
baseline severity, 100% confident.
dotnet .NET assembly detected via BSJB CLR metadata signature
baseline severity, 95% confident.
dylib::mscoree links mscoree (CorExeMain)
baseline severity, 100% confident.
hardening ASLR enabled (DYNAMIC_BASE)
baseline severity, 90% confident.
lang/compiler mscorlib reference
baseline severity, 84% confident.
package Large binary with few DLL dependencies
component severity, 95% confident.
binary/anomaly PE version info numeric fields present

20 of 42 traits shown

Identity

SHA-256 8ce33ed9a7227d43520970b4e7e7afe683f4fcc8dbd210f3373e899a39e1fd2d
Filename 8ce33ed9a7227d43520970b4e7e7afe683f4fcc8dbd210f3373e899a39e1fd2d.exe

Origin

Source harvest

Timeline

First seen 12 May 2026 19:22 UTC
First analyzed 30 May 2026 13:06 UTC
Last analyzed 30 May 2026 13:06 UTC
Last updated 30 May 2026 13:06 UTC

Labeling

Label bad
Label source harvest
Traits version ca5ef