Open-source atomic malware analysis

Analyze another

jgraph/drawio-desktop

PE
Verdict: SUSPICIOUS
AI Legitimate JGraph draw.io installer
Mal-ecule
O₃(CAsI)H₅(DbF₈Os₇Po₄U)Md₅(Bi₆BkPa)
Size 125.2 MB download
First seen 18 days ago
Analyzed 13 days ago
Ecosystem github
Source github.com
Elevated NSIS loader with reboot and clipboard access: jgraph-drawio-desktop-v31.1.5-draw.io-ia32-31.1.5-windows-32bit-installer.exe:0x7ce2
Elevated NSIS overlay loader with reboot and clipboard access: jgraph-drawio-desktop-v31.1.5-draw.io-ia32-31.1.5-windows-32bit-installer.exe:0x7ce2
jgraph-drawio-desktop-v31.1.5-draw.io-ia32-31.1.5-windows-32bit-installer.exe pe
0x0 4d5a90000300000004000000ffff0000 MZ..............
0x10 b8000000000000004000000000000000 ........@.......
0x20 00000000000000000000000000000000 ................
0x30 000000000000000000000000d8000000 ................
0x40 0e1fba0e00b409cd21b8014ccd215468 ........!..L.!Th
0x50 69732070726f6772616d2063616e6e6f is program canno
0x60 742062652072756e20696e20444f5320 t be run in DOS
0x70 6d6f64652e0d0d0a2400000000000000 mode....$.......
0x80 ad310881e95066d2e95066d2e95066d2 .1...Pf..Pf..Pf.
0x90 2a5f39d2eb5066d2e95067d24c5066d2 *_9..Pf..Pg.LPf.
0xa0 2a5f3bd2e65066d2bd7356d2e35066d2 *_;..Pf..sV..Pf.
0xb0 2e5660d2e85066d252696368e95066d2 .V`..Pf.Rich.Pf.
0xc0 00000000000000000000000000 .............
0x4f9 ffffff837e58ff7465ff7634ff155480 ....~X.te.v4..T.
0x509 400085c089451474558b7d0c6a0157c7 @....E.tU.}.j.W.
0x519 45e410000000c745e808000000ff1550 E......E.......P
0x529 804000ff765857ff1558804000ff7514 .@..vXW..X.@..u.
0x539 8b354c80400057ffd689450c8d45e468 .5L.@.W...E..E.h
0x549 20080000506aff68e02e470057ff152c ...Pj.h..G.W..,
0x559 824000ff750c57ffd6ff7514ffd38d45 .@..u.W...u....E
0x569 a450ff7508ff15848240005f5e33c05b .P.u.....@._^3.[
0x579 c9c210008b4c2404a128af47008bd153 .....L$..(.G...S
0x589 69d21840000056578b540208f6c20274 i..@..VW.T.....t
0x599 4f8d710133ff3b352caf470073428bce O.q.3.;5,.G.sB..
0x5a9 69c9184000008d4401088b08f6c10274 i..@...D.......t
0x5b9 0347eb1ef6c10474098bcf .G.....t...
0x7c62 536574437572736f7200bd014c6f6164 SetCursor...Load
0x7c72 437572736f7257003800436865636b44 CursorW.8.CheckD
0x7c82 6c67427574746f6e00003c014765744d lgButton..<.GetM
0x7c92 657373616765506f7300b9014c6f6164 essagePos...Load
0x7ca2 4269746d617057001c0043616c6c5769 BitmapW...CallWi
0x7cb2 6e646f7750726f635700b10149735769 ndowProcW...IsWi
0x7cc2 6e646f7756697369626c65004200436c ndowVisible.B.Cl
0x7cd2 6f7365436c6970626f61726400004a02 oseClipboard..J.
0x7ce2 536574436c6970626f61726444617461 SetClipboardDataElevated NSIS overlay loader with reboot and clipboard access
0x7cf2 0000c100456d707479436c6970626f61 ....EmptyClipboaElevated NSIS loader with reboot and clipboard access
0x7d02 72640000f6014f70656e436c6970626f rd....OpenClipbo
0x7d12 61726400a402547261636b506f707570 ard...TrackPopup
0x7d22 4d656e7500000900417070656e644d65 Menu....AppendMe
0x7d32 6e7557005e00437265617465506f7075 nuW.^.CreatePopu
0x7d42 704d656e75005d014765745379737465 pMenu.].GetSyste
0x7d52 6d4d6574726963730000540253657444 mMetrics..T.SetD
0x7d62 6c674974656d54657874570014014765 lgItemTextW...Ge
0x7d72 74446c674974656d546578745700e301 tDlgItemTextW...
0x7d82 4d657373616765426f78496e64697265 MessageBoxIndire
0x7d92 637457002f0043686172507265765700 ctW./.CharPrevW.
0x7da2 2a00436861724e6578744100d7027773 *.CharNextA...ws
0x7db2 7072696e74664100a200446973706174 printfA...Dispat
0x7dc2 63684d65737361676557000001025065 chMessageW....Pe
0x7dd2 656b4d65737361676557000055534552 ekMessageW..USER
0x7de2 33322e646c6c00000e0253656c656374 32.dll....Select
0x7df2 4f626a65637400003c02536574546578 Object..<.SetTex
0x7e02 74436f6c6f7200001602536574426b4d tColor....SetBkM
0x7e12 6f6465003d00437265617465466f6e74 ode.=.CreateFont
0x7e22 496e6469726563745700290043726561 IndirectW.).Crea
0x7e32 74654272757368496e64697265637400 teBrushIndirect.
0x7e42 8f0044656c6574654f626a6563740000 ..DeleteObject..
0x7e52 6b014765744465766963654361707300 k.GetDeviceCaps.
0x7e62 1502536574426b436f6c6f7200004744 ..SetBkColor..GD
0x7e72 4933322e646c6c009b00534846696c65 I32.dll...SHFile
0x7e82 4f7065726174696f6e570000ad005348 OperationW....SH
0x7e92 47657446696c65496e666f5700007a00 GetFileInfoW..z.
0x7ea2 534842726f777365466f72466f6c6465 SHBrowseForFolde
0x7eb2 72570000bd0053484765745061746846 rW....SHGetPathF
0x7ec2 726f6d49444c6973745700000a015368 romIDListW....Sh
0x7ed2 656c6c4578656375746545785700c300 ellExecuteExW...
0x7ee2 53484765745370656369616c466f6c64 SHGetSpecialFold
0x7ef2 65724c6f636174696f6e00005348454c erLocation..SHEL
0x7f02 4c33322e646c6c00e201526567456e75 L32.dll...RegEnu
0x7f12 6d56616c75655700e001526567456e75 mValueW...RegEnu
0x7f22 6d4b65795700f8015265675175657279 mKeyW...RegQuery
0x7f32 56616c75654578570000050252656753 ValueExW....RegS
0x7f42 657456616c75654578570000cb015265 etValueExW....Re
0x7f52 67436c6f73654b657900d90152656744 gCloseKey...RegD
0x83f0 720020006c00610075006e0063006800 r. .l.a.u.n.c.h.
0x8400 69006e006700200069006e0073007400 i.n.g. .i.n.s.t.
0x8410 61006c006c006500720000002e002e00 a.l.l.e.r.......
0x8420 2e002000250064002500250000000000 .. .%.d.%.%.....
0x8430 53006500530068007500740064006f00 S.e.S.h.u.t.d.o.Elevated NSIS overlay loader with reboot and clipboard access
0x8440 77006e00500072006900760069006c00 w.n.P.r.i.v.i.l.
0x8450 65006700650000004100000000000000 e.g.e...A.......
0x8460 2e0074006d0070000000000041000000 ..t.m.p.....A...
0x8470 7e006e00730075000000000020005f00 ~.n.s.u..... ._.
0x8480 3f003d000000000054004d0050000000 ?.=.....T.M.P...
0x8490 540045004d005000000000004c006f00 T.E.M.P.....L.o.
0x84a0 770000005c00540065006d0070000000 w...\.T.e.m.p...
0x84b0 20002f0044003d00000000004e004300 ./.D.=.....N.C.
0x84c0 52004300000000004e00530049005300 R.C.....N.S.I.S.
0x84d0 20004500720072006f00720000000000 .E.r.r.o.r.....
0x84e0 4500720072006f007200200077007200 E.r.r.o.r. .w.r.
0x84f0 6900740069006e006700200074006500 i.t.i.n.g. .t.e.
0x8500 6d0070006f0072006100720079002000 m.p.o.r.a.r.y. .
0x8510 6600 f.
0x24f0e 20002842000002008080000001002000 .(B.......... .
0x24f1e 2808010001000000000001002000a31d (........... ...
0x24f2e 000004000000000000004c0234000000 ..........L.4...
0x24f3e 560053005f0056004500520053004900 V.S._.V.E.R.S.I.
0x24f4e 4f004e005f0049004e0046004f000000 O.N._.I.N.F.O...
0x24f5e 0000bd04effe0000000001001f000000 ................
0x24f6e 050001001f0000000500000000000000 ................
0x24f7e 00000400000001000000000000000000 ................
0x24f8e 000000000000aa010000000053007400 ............S.t.
0x24f9e 720069006e006700460069006c006500 r.i.n.g.F.i.l.e.
0x24fae 49006e0066006f000000860100000000 I.n.f.o.........
0x24fbe 30003400300039003000340065003400 0.4.0.9.0.4.e.4.
0x24fce 00002e000700010043006f006d007000 ........C.o.m.p.
0x24fde 61006e0079004e0061006d0065000000 a.n.y.N.a.m.e...
0x24fee 00004a00470072006100700068000000 ..J.G.r.a.p.h...
0x24ffe 0000480010000100460069006c006500 ..H.....F.i.l.e.
0x2500e 44006500730063007200690070007400 D.e.s.c.r.i.p.t.
0x2501e 69006f006e0000000000640072006100 i.o.n.....d.r.a.
0x2502e 77002e0069006f002000640065007300 w...i.o. .d.e.s.
0x2503e 6b0074006f00700000002e0007000100 k.t.o.p.........
0x2504e 460069006c0065005600650072007300 F.i.l.e.V.e.r.s.
0x2505e 69006f006e0000000000330031002e00 i.o.n.....3.1...
0x2506e 31002e00350000000000640020000100 1...5.....d. ...
0x2507e 4c006500670061006c0043006f007000 L.e.g.a.l.C.o.p.
0x2508e 79007200690067006800740000004300 y.r.i.g.h.t...C.
0x2509e 6f007000790072006900670068007400 o.p.y.r.i.g.h.t.
0x250ae 200032003000310037002d0032003000 .2.0.1.7.-.2.0.
0x250be 32003600200064007200610077002e00 2.6. .d.r.a.w...
0x250ce 69006f0020004c007400640000003000 i.o. .L.t.d...0.
0x250de 08000100500072006f00640075006300 ....P.r.o.d.u.c.
0x250ee 74004e0061006d006500000000006400 t.N.a.m.e.....d.
0x250fe 7200610077002e0069006f0000003200 r.a.w...i.o...2.
0x2510e 07000100500072006f00640075006300 ....P.r.o.d.u.c.
0x2511e 7400560065007200730069006f006e00 t.V.e.r.s.i.o.n.
0x2512e 0000330031002e0031002e0035000000 ..3.1...1...5...
0x2513e 00004400000000005600610072004600 ..D.....V.a.r.F.
0x2514e 69006c00650049006e0066006f000000 i.l.e.I.n.f.o...
0x2515e 00002400040000005400720061006e00 ..$.....T.r.a.n.
0x2516e 73006c006100740069006f006e000000 s.l.a.t.i.o.n...
0x2517e 00000904e404000000003c3f786d6c20 ..........<?xml Elevated NSIS overlay loader with reboot and clipboard access
0x2518e 76657273696f6e3d22312e302220656e version="1.0" en
0x2519e 636f64696e673d225554462d38222073 coding="UTF-8" s
0x251ae 74616e64616c6f6e653d22796573223f tandalone="yes"?
0x251be 3e3c617373656d626c7920786d6c6e73 ><assembly xmlns
0x251ce 3d2275726e3a736368656d61732d6d69 ="urn:schemas-mi
0x251de 63726f736f66742d636f6d3a61736d2e crosoft-com:asm.
0x251ee 763122206d616e696665737456657273 v1" manifestVers
0x251fe 696f6e3d22312e30223e3c617373656d ion="1.0"><assem

Objectives

Micro-behaviors

Metadata

notable severity, 100% confident.
build PE manifest requests admin
notable severity, 100% confident.
strings-truncated String extraction truncated due to limits (count: 100000, total bytes: 50 MB)

file

20 of 27 traits shown

Identity

SHA-256 bccdfd5331e92a4526ff4e7ee0b03cd9c5cd63be3752947ffc4f50962dfb747e
Filename jgraph-drawio-desktop-v31.1.5-draw.io-ia32-31.1.5-windows-32bit-installer.exe
Package jgraph/drawio-desktop

Origin

Source harvest
Feed github.com
Ecosystem github
Domain github.com

Timeline

First seen 5 Aug 2026 17:30 UTC
First analyzed 10 Aug 2026 09:47 UTC
Last analyzed 10 Aug 2026 09:47 UTC
Last updated 10 Aug 2026 09:47 UTC

Labeling

Label unknown
Label source harvest
Traits version 73866