Open-source atomic malware analysis

Analyze another

af504337b51f5fb5bcc3c779afc95bf5b167431660ebd8b71fcfdff1ec9e227a.exe

PE
Verdict: BENIGN
Mal-ecule
H₂(DbDs)Md(Bk)
Size 536.0 KB download
First seen 85 days ago
Analyzed 66 days ago

Objectives

component severity, 95% confident.
anti-static/obfuscation Huge null run in executable (128+ bytes)
component severity, 99% confident.
anti-static/obfuscation/payload PE version resource text
component severity, 100% confident.
command-and-control/dropper VB6 runtime dispatch string cluster
component severity, 100% confident.
command-and-control/infrastructure Binary has 4 or fewer sections
component severity, 95% confident.
evasion/masquerade/file Filename has EXE extension
component severity, 90% confident.
impact/destroy Preserves .exe .gho .bak files
component severity, 90% confident.
persistence/login/scheduled-task Regex component marker
component severity, 95% confident.
persistence/system/registry Executable path in TypeLib redirection

Micro-behaviors

notable severity, 80% confident.
data/encode Large hexadecimal encoded blob
notable severity, 94% confident.
dylib VB6 DllFunctionCall thunk
baseline severity, 93% confident.
fs/file/write VB6 runtime file open helper
component severity, 90% confident.
communications/proxy SOCKS5 client greeting bytes
component severity, 92% confident.
data/string VB6 __vbaVarCat string concatenation

Metadata

notable severity, 90% confident.
build PE carries bound import descriptors
baseline severity, 100% confident.
binary PE has RT_ICON in resources list
baseline severity, 80% confident.
binary/metrics High number of imported symbols (>80)
baseline severity, 95% confident.
dylib::msvbvm60 links msvbvm60 (EVENT_SINK_GetIDsOfNames, CIcos, adj_fptan, vbaVarMove, vbaStrI4, ... +77 more)
baseline severity, 84% confident.
package Large binary with few DLL dependencies
component severity, 95% confident.
binary/anomaly PE version info numeric fields present
component severity, 90% confident.
binary/section PE standard code/data section

20 of 26 traits shown

Identity

SHA-256 af504337b51f5fb5bcc3c779afc95bf5b167431660ebd8b71fcfdff1ec9e227a
Filename af504337b51f5fb5bcc3c779afc95bf5b167431660ebd8b71fcfdff1ec9e227a.exe

Origin

Source harvest

Timeline

First seen 12 May 2026 19:30 UTC
First analyzed 31 May 2026 14:19 UTC
Last analyzed 31 May 2026 14:19 UTC
Last updated 31 May 2026 14:19 UTC

Labeling

Label bad
Label source harvest
Traits version 176d6