Local reference
Suspicious dependency
Inferred
Mal-ecule
H(Cm)Md(Bi)
Objectives
baseline severity, 75% confident.
anti-static/obfuscation/payload
Minimal PE imports with dynamic loading
component severity, 100% confident.
anti-static/obfuscation/binary-metrics
Binary has normal code entropy (>5.5)
component severity, 100% confident.
anti-static/obfuscation/reflection
VirtualProtect symbol
component severity, 99% confident.
anti-static/pack
UPX magic byte sequence
component severity, 99% confident.
command-and-control/dropper
WINHTTP.dll string
component severity, 100% confident.
command-and-control/infrastructure
Binary has 4 or fewer sections
Micro-behaviors
notable severity, 88% confident.
communications/http/client
Query WinHTTP response headers
baseline severity, 90% confident.
dylib
Windows GetProcAddress API string
baseline severity, 95% confident.
mem/protect
Modify memory page protection
baseline severity, 100% confident.
os/module
Reference to ADVAPI32.dll
baseline severity, 90% confident.
process/terminate
Exit current process
Metadata
notable severity, 85% confident.
binary/metrics
High code section entropy
baseline severity, 100% confident.
binary
PE has RT_ICON in resources list
baseline severity, 95% confident.
binary/section
UPX packed section name
baseline severity, 95% confident.
dylib::advapi32
links advapi32 (LockServiceDatabase)
baseline severity, 95% confident.
dylib::kernel32
links kernel32 (LoadLibraryA, ExitProcess, GetProcAddress, VirtualProtect)
baseline severity, 95% confident.
dylib::winhttp
links winhttp (WinHttpQueryHeaders)
baseline severity, 100% confident.
hardening
DEP / NX enabled (NX_COMPAT)
anti-static
hostile severity, 100% confident.
packer/upx
UPX decompression failed: IO error: No such file or directory (os error 2)
suspicious severity, 100% confident.
packer
Binary contains a UPX packing marker
20 of 30 traits shown
Identity
| SHA-256 | f4cf0f0987a9ede49bd9de65d7b30a72a232856e1cb7c47d287ca8ba980d43ce |
|---|---|
| Filename | f4cf0f0987a9ede49bd9de65d7b30a72a232856e1cb7c47d287ca8ba980d43ce.exe |
Origin
| Source | harvest |
|---|
Timeline
| First seen | 12 May 2026 19:21 UTC |
|---|---|
| First analyzed | 30 May 2026 23:56 UTC |
| Last analyzed | 30 May 2026 23:56 UTC |
| Last updated | 30 May 2026 23:56 UTC |
Labeling
| Label | bad |
|---|---|
| Label source | harvest |
| Traits version | 52045 |
Not seeing what you expected? Let us know