Open-source atomic malware analysis

Analyze another

__min__c.xz

XZ
Verdict: SUSPICIOUS
Mal-ecule
O₅(As₃AlCErEu)Md₂(Bi₃He)
Size 1.6 MB download
First seen 117 days ago
Analyzed 115 days ago
Ecosystem malcontent-samples

Objectives

suspicious severity, 100% confident.
anti-static/pack UPX executable packer signature string
notable severity, 95% confident.
anti-static/obfuscation Very high entropy (strongly indicates
component severity, 70% confident.
anti-static/obfuscation/payload Zero recovered functions
component severity, 100% confident.
command-and-control/infrastructure Binary has 4 or fewer sections

Micro-behaviors

baseline severity, 70% confident.
crypto/symmetric Detects loop/jump control transfer in assembly
baseline severity, 66% confident.
fs/path Reference to /etc configuration files

Metadata

suspicious severity, 95% confident.
binary ELF binary without section headers
notable severity, 75% confident.
hardening::static-linked-heuristic ELF lacks dynamic linker sections
baseline severity, 100% confident.
binary::binary-format-checked Binary format is identified
baseline severity, 100% confident.
hardening::no-pie Binary is not position-independent (fixed load address)
baseline severity, 90% confident.
hardening::no-relro No RELRO (GOT writable after load)
baseline severity, 90% confident.
hardening::no-stack-canary No stack canary (stack smashing protection absent)
baseline severity, 92% confident.
package Very few recovered functions in large PE
baseline severity, 100% confident.
unsigned Binary is not digitally signed

Identity

SHA-256 c374cc51abd9303faf62e44cb523f49b899ac7e3761b11ada9b902f80176666c
Canonical SHA-256 58fa45ce3665fd665bde9589297a5a34c8df403e8732eb7bdc77d00c669fac29
Filename __min__c.xz

Origin

Source harvest
Feed datasets
Ecosystem malcontent-samples

Timeline

First seen 24 Apr 2026 16:18 UTC
Last analyzed 26 Apr 2026 23:34 UTC
Last updated 26 Apr 2026 23:34 UTC

Labeling

Label bad
Label source harvest
Traits version bf48d