Open-source atomic malware analysis

Analyze another

d92d62de3dec5d93e178304fa957c0b5ba803167c535546c6040443562e4ea69.dll

PE
Verdict: BENIGN
Mal-ecule
O(As)H(Ds)
Size 208.0 KB download
First seen 89 days ago
Analyzed 59 days ago

Objectives

suspicious severity, 75% confident.
anti-static/obfuscation/payload Minimal PE imports with dynamic loading
component severity, 95% confident.
anti-static/obfuscation Huge null run in executable (128+ bytes)
component severity, 100% confident.
anti-static/obfuscation/reflection LoadLibrary symbol
component severity, 86% confident.
anti-static/obfuscation/string Long mixed-case identifiers cluster
component severity, 90% confident.
anti-static/pack Reloc section mostly non-relocation bytes
component severity, 94% confident.
evasion/masquerade/identity Two dotted-quad version strings
component severity, 92% confident.
evasion/process/injection Regex component marker
component severity, 90% confident.
impact/destroy Preserves .exe .gho .bak files

Micro-behaviors

notable severity, 95% confident.
dylib/load Dynamic library loading via LoadLibraryA
baseline severity, 100% confident.
os/module Reference to USER32.dll
baseline severity, 90% confident.
process/create Close handle

Metadata

baseline severity, 100% confident.
binary PE has RT_GROUP_ICON in resources list
baseline severity, 100% confident.
binary/metrics Binary has 1000 or more strings
baseline severity, 90% confident.
binary/section PE .reloc section presence
baseline severity, 100% confident.
build requestedExecutionLevel is asInvoker
baseline severity, 100% confident.
file Windows DLL extension
baseline severity, 100% confident.
hardening ASLR enabled (DYNAMIC_BASE)
baseline severity, 90% confident.
package PE version resource metadata
component severity, 95% confident.
binary/anomaly PE version info numeric fields present
component severity, 95% confident.
binary/symbols Binary imports ADVAPI32.dll

20 of 28 traits shown

Identity

SHA-256 d92d62de3dec5d93e178304fa957c0b5ba803167c535546c6040443562e4ea69
Filename d92d62de3dec5d93e178304fa957c0b5ba803167c535546c6040443562e4ea69.dll

Origin

Source harvest

Timeline

First seen 12 May 2026 19:33 UTC
First analyzed 11 Jun 2026 21:57 UTC
Last analyzed 11 Jun 2026 21:57 UTC
Last updated 11 Jun 2026 21:57 UTC

Labeling

Label bad
Label source harvest
Traits version e31a3