Open-source atomic malware analysis

Analyze another

e4d64982d9848a9c10560b310e2e2d9f11b4e9f0b56630158fd7828a879b8734.exe

PE
Verdict: BENIGN
Mal-ecule
H(Cm)Md(Bi)
Size 29.0 KB download
First seen 71 days ago
Analyzed 65 days ago

Well-known

baseline severity, 97% confident.
lib Microsoft ImageHlp company metadata

Objectives

baseline severity, 75% confident.
anti-static/obfuscation/payload Minimal PE imports with dynamic loading
component severity, 100% confident.
anti-static/obfuscation/binary-metrics Binary has normal code entropy (>5.5)

Micro-behaviors

notable severity, 90% confident.
communications/socket Winsock bind import
baseline severity, 90% confident.
dylib Windows GetProcAddress API string
baseline severity, 82% confident.
fs Resolve special folder path ANSI
baseline severity, 95% confident.
mem/protect Modify memory page protection
baseline severity, 100% confident.
os/module Reference to ADVAPI32.dll
baseline severity, 90% confident.
os/random Generate cryptographic random bytes
baseline severity, 90% confident.
process/terminate Exit current process

Metadata

notable severity, 85% confident.
binary/metrics High code section entropy
baseline severity, 100% confident.
binary PE first resource is RT_VERSION
baseline severity, 95% confident.
binary/section UPX packed section name
baseline severity, 95% confident.
dylib::advapi32 links advapi32 (CryptGenRandom)
baseline severity, 95% confident.
dylib::kernel32 links kernel32 (LoadLibraryA, ExitProcess, GetProcAddress, VirtualProtect)
baseline severity, 95% confident.
dylib::msvcrt links msvcrt (atoi)
baseline severity, 95% confident.
dylib::shell32 links shell32 (SHGetSpecialFolderPathA)
baseline severity, 95% confident.
dylib::ws2_32 links ws2_32 (bind)
baseline severity, 100% confident.
hardening High-entropy ASLR (64-bit)
baseline severity, 70% confident.
package PE ProductName metadata field

20 of 38 traits shown

Identity

SHA-256 e4d64982d9848a9c10560b310e2e2d9f11b4e9f0b56630158fd7828a879b8734
Filename e4d64982d9848a9c10560b310e2e2d9f11b4e9f0b56630158fd7828a879b8734.exe

Origin

Source harvest

Timeline

First seen 18 May 2026 10:56 UTC
First analyzed 23 May 2026 23:58 UTC
Last analyzed 23 May 2026 23:58 UTC
Last updated 26 May 2026 01:40 UTC

Labeling

Label bad
Label source harvest
Traits version 9ea7c