Open-source atomic malware analysis

Analyze another

9a59f072a34bd7b6254c69710bafed27752e2fac1a292eb5a9cba1a52c55c316

PE
Verdict: SUSPICIOUS
AI Unsigned binary with mismatched metadata
Mal-ecule
O(As)H₂(MgOs)Md₂(Bi₃Pa)
Size 3.2 MB download
First seen 11 hours ago
Analyzed 5 hours ago
Ecosystem windows
Source abuse.ch
Also detected by 2 sources
wyhrytj.exe pe
0x0 4d5a7800010000000400000000000000 MZx.............
0x10 00000000000000004000000000000000 ........@.......
0x20 00000000000000000000000000000000 ................
0x30 00000000000000000000000078000000 ............x...
0x40 0e1fba0e00b409cd21b8014ccd215468 ........!..L.!Th
0x50 69732070726f6772616d2063616e6e6f is program canno
0x60 742062652072756e20696e20444f5320 t be run in DOS
0x70 6d6f64652e2400005045000064860700 mode.$..PE..d...
0x80 9b0c726a0000000000000000f0002200 ..rj..........".
0x90 0b020e0000622f000024030000000000 .....b/..$......
0xa0 00100000001000000000004001000000 ...........@....
0xb0 00100000000200000600000000000000 ................
0xc0 060000000000000000e0320000040000 ..........2.....
0xd0 00000000 ....
0x2f6bfa 0000ecfeffff0bffffff27ffffff8fff ..........'.....
0x2f6c0a ffff6cffffff47ffffff0000000034df ..l...G.......4.
0x2f6c1a ffff51dfffff42dfffff4cdfffff2020 ..Q...B...L...
0x2f6c2a 556e6b6e6f776e2070736575646f2072 Unknown pseudo r
0x2f6c3a 656c6f636174696f6e2070726f746f63 elocation protoc
0x2f6c4a 6f6c2076657273696f6e2025642e0a00 ol version %d...
0x2f6c5a 2020556e6b6e6f776e2070736575646f Unknown pseudo
0x2f6c6a 2072656c6f636174696f6e2062697420 relocation bit
0x2f6c7a 73697a652025642e0a00256420626974 size %d...%d bit
0x2f6c8a 2070736575646f2072656c6f63617469 pseudo relocati
0x2f6c9a 6f6e206174202570206f7574206f6620 on at %p out of
0x2f6caa 72616e67652c20746172 range, tar
0x2f8be8 04220000010401000422000001040100 ."......."......
0x2f8bf8 04220000010401000422000001040100 ."......."......
0x2f8c08 04220000010401000422000001040100 ."......."......
0x2f8c18 04220000010401000422000001040100 ."......."......
0x2f8c28 04220000010401000422000001040100 ."......."......
0x2f8c38 04220000010401000422000001040100 ."......."......Resolve exports with GetProcAddress
0x2f8c48 04220000010401000422000001040100 ."......."......
0x2f8c58 04220000010401000422000001040100 ."......."......
0x2f8c68 04220000010401000422000001040100 ."......."......
0x2f8c78 04220000010401000422000001040100 ."......."......Imports virtual-memory allocation and protection APIs
0x2f8c88 04220000010401000422000001040100 ."......."......Modify memory page protection
0x2f8c98 04220000010401000422000001040100 ."......."......
0x2f8ca8 04220000010401000422000001040100 ."......."......
0x2f8cb8 04220000010401000422000001040100 ."......."......
0x2f8cc8 04220000010401000422000001040100 ."......."......
0x2f8cd8 04220000010401000422000001040100 ."......."......
0x2f8ce8 04220000010401000422000001040100 ."......."......
0x2f8cf8 04220000010401000422000001040100 ."......."......
0x2f8d08 04220000010401000422000001040100 ."......."......
0x2f8d18 04220000010401000422000001040100 ."......."......
0x2f8d28 04220000010401000422000001040100 ."......."......
0x2f8d38 04220000010401000422000001040100 ."......."......
0x2f8d48 04220000010401000422000001040100 ."......."......
0x2f8d58 04220000010401000422000001040100 ."......."......
0x2f8d68 04220000010401000422000001040100 ."......."......
0x2f8d78 04220000010401000422000001040100 ."......."......
0x2f8d88 04220000010401000422000001040100 ."......."......
0x2f8d98 04220000010401000422000001040100 ."......."......
0x2f8da8 04220000010401000422000001040100 ."......."......
0x2f8db8 04220000010401000422000001040100 ."......."......
0x2f8dc8 04220000010401000422000001040100 ."......."......
0x2f8dd8 04220000010401000422000001040100 ."......."......
0x2f8de8 04220000010401000422000001040100 ."......."......
0x2f8df8 04220000010401000422000001040100 ."......."......
0x2f8e08 042200000104010004220000010401 .".......".....
0x327e9e 00000000000000000000000000000000 ................
0x327eae 000000000100010000aa000001002000 .............. .
0x327ebe 68bd02000100000000006c0334000000 h.........l.4...
0x327ece 560053005f0056004500520053004900 V.S._.V.E.R.S.I.
0x327ede 4f004e005f0049004e0046004f000000 O.N._.I.N.F.O...
0x327eee 0000bd04effe0000010016001500491e ..............I.
0x327efe 340200000200bf2306003f0000000000 4......#..?.....
0x327f0e 00000400000001000000000000000000 ................
0x327f1e 000000000000ca020000010053007400 ............S.t.
0x327f2e 720069006e006700460069006c006500 r.i.n.g.F.i.l.e.
0x327f3e 49006e0066006f000000a60200000100 I.n.f.o.........
0x327f4e 30006300300039003000340062003000 0.c.0.9.0.4.b.0.
0x327f5e 000044001200010043006f006d007000 ..D.....C.o.m.p.
0x327f6e 61006e0079004e0061006d0065000000 a.n.y.N.a.m.e...
0x327f7e 000053006300680065006d0061002000 ..S.c.h.e.m.a. .
0x327f8e 4100730073006f006300690061007400 A.s.s.o.c.i.a.t.
0x327f9e 65007300000068002000010046006900 e.s...h. ...F.i.
0x327fae 6c006500440065007300630072006900 l.e.D.e.s.c.r.i.
0x327fbe 7000740069006f006e00000000004100 p.t.i.o.n.....A.
0x327fce 6400760061006e006300650064002000 d.v.a.n.c.e.d. .
0x327fde 4d006900670072006100740069006f00 M.i.g.r.a.t.i.o.
0x327fee 6e0020004200750069006c0064006500 n. .B.u.i.l.d.e.
0x327ffe 7200200054006f006f006c0000003e00 r. .T.o.o.l...>.
0x32800e 0f000100460069006c00650056006500 ....F.i.l.e.V.e.
0x32801e 7200730069006f006e00000000003200 r.s.i.o.n.....2.
0x32802e 31002e00320032002e00350036003400 1...2.2...5.6.4.
0x32803e 2e003700370035003300000000003c00 ..7.7.5.3.....<.
0x32804e 0e00010049006e007400650072006e00 ....I.n.t.e.r.n.
0x32805e 61006c004e0061006d00650000007300 a.l.N.a.m.e...s.
0x32806e 6300680065006d006100620075006900 c.h.e.m.a.b.u.i.
0x32807e 6c0064006500720000009c003c000100 l.d.e.r.....<...
0x32808e 4c006500670061006c0043006f007000 L.e.g.a.l.C.o.p.
0x32809e 79007200690067006800740000004300 y.r.i.g.h.t...C.
0x3280ae 6f007000790072006900670068007400 o.p.y.r.i.g.h.t.
0x3280be 20002800430029002000320030003200 .(.C.). .2.0.2.
0x3280ce 36002c00200053006300680065006d00 6.,. .S.c.h.e.m.
0x3280de 610020004100730073006f0063006900 a. .A.s.s.o.c.i.
0x3280ee 61007400650073002e00200041006c00 a.t.e.s... .A.l.
0x3280fe 6c002000520069006700680074007300 l. .R.i.g.h.t.s.
0x32810e 20005200650073006500720076006500 .R.e.s.e.r.v.e.
0x32811e 64002e00000044000e0001004f007200 d.....D.....O.r.
0x32812e 6900670069006e0061006c0046006900 i.g.i.n.a.l.F.i.
0x32813e 6c0065006e0061006d00650000007300 l.e.n.a.m.e...s.
0x32814e 6300680065006d006100620075006900 c.h.e.m.a.b.u.i.
0x32815e 6c0064006500720000004c0016000100 l.d.e.r...L.....
0x32816e 500072006f0064007500630074004e00 P.r.o.d.u.c.t.N.
0x32817e 61006d00650000000000530063006800 a.m.e.....S.c.h.
0x32818e 65006d0061004200750069006c006400 e.m.a.B.u.i.l.d.

Objectives

Micro-behaviors

Metadata

notable severity, 90% confident.
binary/anomaly PE mismatch beyond architecture suffix

Identity

SHA-256 9a59f072a34bd7b6254c69710bafed27752e2fac1a292eb5a9cba1a52c55c316
Filename wyhrytj.exe
Package 9a59f072a34bd7b6254c69710bafed27752e2fac1a292eb5a9cba1a52c55c316

Origin

Source harvest
Feed malwarebazaar
Ecosystem windows
Domain abuse.ch

Timeline

First seen 5 Aug 2026 17:31 UTC
First analyzed 5 Aug 2026 23:33 UTC
Last analyzed 5 Aug 2026 23:33 UTC
Last updated 5 Aug 2026 23:33 UTC

Labeling

Label bad
Label source harvest
Traits version b5ca8