Open-source atomic malware analysis

Analyze another

e7280cbccf49363aabe6572cf67b20f3c8d8c4fb32b1ed71e77be389e9201f13.dll

PE
Verdict: BENIGN
Mal-ecule
O(As)H₂(CmDb)Md(Pt)
Size 60.5 KB download
First seen 95 days ago
Analyzed 80 days ago

Objectives

suspicious severity, 88% confident.
anti-static/obfuscation/reflection Delegate invocation execution chain
baseline severity, 85% confident.
evasion/masquerade/dll DLL filename extension present
component severity, 100% confident.
anti-static/obfuscation/binary-metrics Binary has normal code entropy (>5.5)
component severity, 99% confident.
anti-static/obfuscation/payload PE version resource text
component severity, 92% confident.
command-and-control/dropper/staging VB NewLateBinding dispatch helper
component severity, 100% confident.
command-and-control/infrastructure Binary has 4 or fewer sections
component severity, 95% confident.
evasion/indicator-removal Regex component marker
component severity, 94% confident.
evasion/masquerade/identity Two dotted-quad version strings
component severity, 92% confident.
evasion/process/injection Regex component marker

Micro-behaviors

notable severity, 78% confident.
communications/http/client .NET SOAP HTTP client class
notable severity, 95% confident.
data/embedded/payload AssemblyResolve event registration
component severity, 100% confident.
communications/http/server Modification of HTTP context items

Metadata

notable severity, 85% confident.
lang/compiler Reflection.Emit usage (dynamic code)
baseline severity, 100% confident.
binary .NET Metadata Root (BSJB)
baseline severity, 90% confident.
binary/section PE .reloc section presence
baseline severity, 100% confident.
dotnet .NET assembly detected via BSJB CLR metadata signature
baseline severity, 95% confident.
dylib::mscoree links mscoree (CorDllMain)
baseline severity, 100% confident.
hardening ASLR enabled (DYNAMIC_BASE)
baseline severity, 70% confident.
package PE FileDescription metadata field
component severity, 95% confident.
binary/anomaly PE version info numeric fields present

20 of 30 traits shown

Identity

SHA-256 e7280cbccf49363aabe6572cf67b20f3c8d8c4fb32b1ed71e77be389e9201f13
Filename e7280cbccf49363aabe6572cf67b20f3c8d8c4fb32b1ed71e77be389e9201f13.dll

Origin

Source harvest

Timeline

First seen 14 May 2026 13:20 UTC
First analyzed 29 May 2026 22:08 UTC
Last analyzed 29 May 2026 22:08 UTC
Last updated 29 May 2026 22:08 UTC

Labeling

Label bad
Label source harvest
Traits version ca5ef