Local reference
Suspicious dependency
Inferred
Mal-ecule
O(As)H(Ds)
Objectives
suspicious severity, 75% confident.
anti-static/obfuscation/payload
Minimal PE imports with dynamic loading
baseline severity, 85% confident.
evasion/masquerade/dll
DLL filename extension present
component severity, 95% confident.
anti-static/obfuscation
Huge null run in executable (128+ bytes)
component severity, 100% confident.
anti-static/obfuscation/reflection
LoadLibrary symbol
component severity, 94% confident.
evasion/masquerade/identity
Two dotted-quad version strings
component severity, 92% confident.
evasion/process/injection
Regex component marker
Micro-behaviors
notable severity, 95% confident.
dylib/load
Dynamic library loading via LoadLibraryA
baseline severity, 100% confident.
os/module
Reference to USER32.dll
baseline severity, 90% confident.
process/create
Close handle
Metadata
baseline severity, 100% confident.
binary
PE has RT_GROUP_ICON in resources list
baseline severity, 100% confident.
binary/metrics
Binary has 1000 or more strings
baseline severity, 90% confident.
binary/section
PE .reloc section presence
baseline severity, 100% confident.
build
PE carries side-by-side assembly manifest
baseline severity, 95% confident.
dylib::advapi32
links advapi32 (RegLoadAppKeyW)
baseline severity, 95% confident.
dylib::kernel32
links kernel32 (CloseHandle, LoadLibraryA, OutputDebugStringA, GenerateConsoleCtrlEvent, IsBadStringPtrA)
baseline severity, 95% confident.
dylib::user32
links user32 (TranslateMessage, RegisterDeviceNotificationW)
baseline severity, 100% confident.
hardening
DEP / NX enabled (NX_COMPAT)
baseline severity, 70% confident.
package
PE ProductName metadata field
component severity, 95% confident.
binary/anomaly
PE version info numeric fields present
component severity, 95% confident.
binary/symbols
Binary imports ADVAPI32.dll
20 of 30 traits shown
Identity
| SHA-256 | 924877ae861a2d0fc27c46b8be67a3ecdf950985522ba15a3fb25608a8a611ed |
|---|---|
| Filename | 924877ae861a2d0fc27c46b8be67a3ecdf950985522ba15a3fb25608a8a611ed.dll |
Origin
| Source | harvest |
|---|
Timeline
| First seen | 12 May 2026 19:32 UTC |
|---|---|
| First analyzed | 31 May 2026 01:58 UTC |
| Last analyzed | 31 May 2026 01:58 UTC |
| Last updated | 31 May 2026 01:58 UTC |
Labeling
| Label | bad |
|---|---|
| Label source | harvest |
| Traits version | 52045 |
Not seeing what you expected? Let us know