Open-source atomic malware analysis

Analyze another

b36620e04d1a6b44ce8cc2dfbbcd2d326cc9f6a842da5991f98d58c921c729c9.exe

PE
Verdict: HOSTILE
Mal-ecule
H(Cm)Md(Bi)
Size 3.4 MB download unavailable
First seen 79 days ago
Analyzed 61 days ago

Objectives

baseline severity, 70% confident.
anti-static/obfuscation/binary-metrics Large overlay relative to file
component severity, 90% confident.
anti-static/obfuscation/control-flow Regex component marker
component severity, 86% confident.
anti-static/obfuscation/string Long mixed-case identifiers cluster
component severity, 99% confident.
anti-static/pack UPX magic byte sequence
component severity, 96% confident.
command-and-control/dropper/execution Large overlay bundle component
component severity, 100% confident.
command-and-control/infrastructure Binary has 4 or fewer sections
component severity, 95% confident.
evasion/masquerade/file Filename has EXE extension

Micro-behaviors

notable severity, 70% confident.
communications/socket WS2_32 Winsock DLL import
baseline severity, 90% confident.
dylib Windows GetProcAddress API string
baseline severity, 100% confident.
os/module Reference to USER32.dll
component severity, 90% confident.
dylib/load Hidden LoadLibraryA string reference
component severity, 90% confident.
mem/protect Hidden VirtualProtect string reference

Metadata

suspicious severity, 92% confident.
binary Large overlay with very low entropy
baseline severity, 100% confident.
binary/metrics Binary has 1000 or more strings
baseline severity, 95% confident.
binary/section UPX packed section name
baseline severity, 100% confident.
hardening Writable and executable section (W^X violation)
baseline severity, 88% confident.
lang/compiler Native runtime binary is large
baseline severity, 84% confident.
package Large binary with few DLL dependencies

anti-static

hostile severity, 100% confident.
packer/upx UPX decompression failed (possibly tampered): upx: /tmp/hopper-litmus-2704093702/.tmpOB25o9: Exception: checksum error
suspicious severity, 100% confident.
packer Binary contains a UPX packing marker

20 of 25 traits shown

Identity

SHA-256 b36620e04d1a6b44ce8cc2dfbbcd2d326cc9f6a842da5991f98d58c921c729c9
Filename b36620e04d1a6b44ce8cc2dfbbcd2d326cc9f6a842da5991f98d58c921c729c9.exe

Origin

Source harvest

Timeline

First seen 12 May 2026 19:21 UTC
First analyzed 30 May 2026 12:03 UTC
Last analyzed 30 May 2026 12:03 UTC
Last updated 30 May 2026 12:03 UTC

Labeling

Label bad
Label source harvest
Traits version ca5ef