Open-source atomic malware analysis

Analyze another

b38d50cc91670d6e8a26a5dc91f2a8810e00b392a76fd20de87e5260601e212d.exe

PE
Verdict: BENIGN
Mal-ecule
H₂(DbDs)Md(Bk)
Size 60.0 KB download
First seen 85 days ago
Analyzed 65 days ago

Objectives

component severity, 95% confident.
anti-static/obfuscation Huge null run in executable (128+ bytes)
component severity, 100% confident.
anti-static/obfuscation/binary-metrics Binary has normal code entropy (>5.5)
component severity, 99% confident.
anti-static/obfuscation/payload PE version resource text
component severity, 86% confident.
anti-static/obfuscation/string Long mixed-case identifiers cluster
component severity, 100% confident.
command-and-control/dropper VB6 runtime dispatch string cluster
component severity, 100% confident.
command-and-control/infrastructure Binary has 4 or fewer sections
component severity, 85% confident.
evasion/masquerade PE lacks VS_VERSION_INFO resource
component severity, 95% confident.
evasion/masquerade/file Filename has EXE extension
component severity, 85% confident.
lateral-movement/brute-force Service account redis

Micro-behaviors

notable severity, 80% confident.
data/embedded/payload Embedded PE/MZ binary
notable severity, 94% confident.
dylib VB6 DllFunctionCall thunk
baseline severity, 93% confident.
fs/file/write VB6 runtime file open helper
component severity, 90% confident.
mem/protect Hidden VirtualProtect string reference

Metadata

notable severity, 90% confident.
build PE carries bound import descriptors
baseline severity, 92% confident.
binary VB6 runtime helper import
baseline severity, 95% confident.
dylib::msvbvm60 links msvbvm60 (CIcos, adj_fptan, vbaVarMove, vbaFreeVar, vbaStrVarMove, ... +56 more)
baseline severity, 90% confident.
lang/compiler Microsoft Visual string
baseline severity, 70% confident.
package PE OriginalFilename metadata field
component severity, 100% confident.
binary/metrics Binary has 20+ imports
component severity, 90% confident.
binary/section PE resource section

20 of 23 traits shown

Identity

SHA-256 b38d50cc91670d6e8a26a5dc91f2a8810e00b392a76fd20de87e5260601e212d
Filename b38d50cc91670d6e8a26a5dc91f2a8810e00b392a76fd20de87e5260601e212d.exe

Origin

Source harvest

Timeline

First seen 12 May 2026 19:29 UTC
First analyzed 2 Jun 2026 02:59 UTC
Last analyzed 2 Jun 2026 02:59 UTC
Last updated 2 Jun 2026 02:59 UTC

Labeling

Label bad
Label source harvest
Traits version ed903