Open-source atomic malware analysis

Analyze another

9a45cc89dc9c741fb0573372ff47fef5bd8092a2afe856b2d0cacf88a933517a.dll

PE
Verdict: BENIGN
Mal-ecule
O(As)H(Ds)
Size 208.0 KB download
First seen 89 days ago
Analyzed 69 days ago

Objectives

suspicious severity, 75% confident.
anti-static/obfuscation/payload Minimal PE imports with dynamic loading
baseline severity, 85% confident.
evasion/masquerade/dll DLL filename extension present
component severity, 95% confident.
anti-static/obfuscation Huge null run in executable (128+ bytes)
component severity, 100% confident.
anti-static/obfuscation/reflection LoadLibrary symbol
component severity, 100% confident.
command-and-control/dropper/staging Binary has high overall entropy
component severity, 94% confident.
evasion/masquerade/identity Two dotted-quad version strings

Micro-behaviors

notable severity, 95% confident.
dylib/load Dynamic library loading via LoadLibraryA
baseline severity, 100% confident.
os/module Reference to USER32.dll
baseline severity, 90% confident.
process/create Close handle

Metadata

baseline severity, 100% confident.
binary PE has RT_ICON in resources list
baseline severity, 100% confident.
binary/metrics Binary has 1000 or more strings
baseline severity, 90% confident.
binary/section PE .reloc section presence
baseline severity, 100% confident.
build requestedExecutionLevel is asInvoker
baseline severity, 95% confident.
dylib::advapi32 links advapi32 (RegLoadAppKeyW)
baseline severity, 95% confident.
dylib::kernel32 links kernel32 (CloseHandle, LoadLibraryA, OutputDebugStringA, GenerateConsoleCtrlEvent, IsBadStringPtrA)
baseline severity, 95% confident.
dylib::user32 links user32 (TranslateMessage, RegisterDeviceNotificationW)
baseline severity, 100% confident.
hardening DEP / NX enabled (NX_COMPAT)
baseline severity, 70% confident.
package PE OriginalFilename metadata field
component severity, 95% confident.
binary/anomaly PE version info numeric fields present
component severity, 95% confident.
binary/symbols Binary imports ADVAPI32.dll

20 of 31 traits shown

Identity

SHA-256 9a45cc89dc9c741fb0573372ff47fef5bd8092a2afe856b2d0cacf88a933517a
Filename 9a45cc89dc9c741fb0573372ff47fef5bd8092a2afe856b2d0cacf88a933517a.dll

Origin

Source harvest

Timeline

First seen 12 May 2026 19:33 UTC
First analyzed 2 Jun 2026 04:04 UTC
Last analyzed 2 Jun 2026 04:04 UTC
Last updated 2 Jun 2026 04:04 UTC

Labeling

Label bad
Label source harvest
Traits version ed903