Open-source atomic malware analysis

Analyze another

a4adbba0e5a436c5820413938dabd7b3cefc15b57719bc76a6ea69c0fc71cef2.exe

PE
Verdict: BENIGN
Mal-ecule
H(Cm)Md(Bi)
Size 424.1 KB download unavailable
First seen 77 days ago
Analyzed 57 days ago

Micro-behaviors

notable severity, 92% confident.
communications/ip Hardcoded external IPv4 address with port
baseline severity, 90% confident.
dylib Windows GetProcAddress API string
baseline severity, 90% confident.
fs/file Get standard I/O handle
baseline severity, 90% confident.
mem/alloc Get process heap handle
baseline severity, 90% confident.
mem/c-runtime Memory compare
baseline severity, 100% confident.
os/module Reference to USER32.dll
baseline severity, 90% confident.
process/create Close handle
baseline severity, 90% confident.
process/sync CreateMutex API call
baseline severity, 90% confident.
process/terminate Exit current process
baseline severity, 95% confident.
process/thread Create thread in current process
baseline severity, 90% confident.
time Get tick count

Metadata

notable severity, 100% confident.
binary PE binary has trailing overlay data
baseline severity, 100% confident.
binary/metrics Binary has 1000 or more strings
baseline severity, 100% confident.
build PE carries side-by-side assembly manifest
baseline severity, 95% confident.
dylib::kernel32 links kernel32 (GetModuleHandleW, InterlockedDecrement, GetProcAddress, GetModuleHandleA, GetEnvironmentStringsW, ... +23 more)
baseline severity, 95% confident.
dylib::msvcrt links msvcrt (XcptFilter, adjust_fdiv, setusermatherr, initterm, onexit, ... +12 more)
baseline severity, 95% confident.
dylib::ole32 links ole32 (OleQueryLinkFromData, OleInitialize, CLSIDFromProgID, CoUninitialize)
baseline severity, 95% confident.
dylib::setupapi links setupapi (SetupRemoveFromSourceListA)
baseline severity, 95% confident.
dylib::user32 links user32 (LoadBitmapA, LoadCursorFromFileA, GetWindow, ShowWindow)
baseline severity, 95% confident.
dylib::winscard links winscard (SCardConnectA)

20 of 44 traits shown

Identity

SHA-256 a4adbba0e5a436c5820413938dabd7b3cefc15b57719bc76a6ea69c0fc71cef2
Filename a4adbba0e5a436c5820413938dabd7b3cefc15b57719bc76a6ea69c0fc71cef2.exe

Origin

Source harvest

Timeline

First seen 12 May 2026 19:23 UTC
First analyzed 2 Jun 2026 01:41 UTC
Last analyzed 2 Jun 2026 01:41 UTC
Last updated 2 Jun 2026 01:41 UTC

Labeling

Label bad
Label source harvest
Traits version ed903