Open-source atomic malware analysis

Analyze another

f7a110efa09467da041b7abbd4a0cbbe67e804e78630af22fa8564038576a856

PE
Verdict: HOSTILE
AI Masquerading Inno installer with fake service identity
Mal-ecule
O₂(CEr)H₇(Cr₂Db₄F₂Mg₂Os₇Po₅U)Md₂(Bi₅Pa)
Size 13.1 MB download
First seen 15 days ago
Analyzed 15 days ago
Ecosystem windows
Source abuse.ch
Also detected by 2 sources
Inno overlay stages payload behind a fake Windows service identity: 31159be01493eeb09cf3b299702a6369.exe:0x0
Unsigned Inno overlay claims the Windows contact service identity: 31159be01493eeb09cf3b299702a6369.exe:0x0
Large overlay with very low entropy: 31159be01493eeb09cf3b299702a6369.exe:0x0
31159be01493eeb09cf3b299702a6369.exe pe
0x0 4d5a50000200000004000f00ffff0000 MZP.............Unsigned Inno overlay claims the Windows contact service identity
0x10 b80000000000000040001a0000000000 ........@.......
0x20 00000000000000000000000000000000 ................
0x30 00000000000000000000000000010000 ................
0x40 ba10000e1fb409cd21b8014ccd219090 ........!..L.!..
0x50 546869732070726f6772616d206d7573 This program mus
0x60 742062652072756e20756e6465722057 t be run under W
0x70 696e33320d0a24370000000000000000 in32..$7........
0x80 00000000000000000000000000000000 ................
0x90 00000000000000000000000000000000 ................
0xa0 00000000000000000000000000000000 ................
0xb0 00000000000000000000000000000000 ................
0xc0 00000000000000000000000000000000 ................
0xd0 00000000000000000000000000000000 ................
0xe0 00000000000000000000000000000000 ................
0xf0 00000000000000000000000000000000 ................
0x100 504500004c010b00c23b8c6900000000 PE..L....;.i....
0x110 00000000e00002010b0102 ...........
0xb73c 61006c00650073000000000053006f00 a.l.e.s.....S.o.
0xb74c 6600740077006100720065005c004300 f.t.w.a.r.e.\.C.
0xb75c 6f006400650047006500610072005c00 o.d.e.G.e.a.r.\.
0xb76c 4c006f00630061006c00650073000000 L.o.c.a.l.e.s...
0xb77c 53006f00660074007700610072006500 S.o.f.t.w.a.r.e.Inno overlay stages payload behind a fake Windows service identity
0xb78c 5c0042006f0072006c0061006e006400 \.B.o.r.l.a.n.d.
0xb79c 5c004c006f00630061006c0065007300 \.L.o.c.a.l.e.s.
0xb7ac 0000000053006f006600740077006100 ....S.o.f.t.w.a.
0xb7bc 720065005c0042006f0072006c006100 r.e.\.B.o.r.l.a.
0xb7cc 6e0064005c00440065006c0070006800 n.d.\.D.e.l.p.h.
0xb7dc 69005c004c006f00630061006c006500 i.\.L.o.c.a.l.e.
0xb7ec 7300000000000000558bec6a0053568b s.......U..j.SV.
0xb7fc da8bf033c055684dc4400064ff306489 ...3.UhM.@.d.0d.
0xb80c 20833d102c4b0000 .=.,K..
0xae3bd 7374656d2e52544c436f6e7374730e57 stem.RTLConsts.W
0xae3cd 696e6170692e57696e646f7773185769 inapi.Windows.Wi
0xae3dd 6e6170692e57696e646f77732e506b67 napi.Windows.Pkg
0xae3ed 48656c7065720e53797374656d2e5549 Helper.System.UI
0xae3fd 54797065730c53797374656d2e547970 Types.System.Typ
0xae40d 65730c57696e6170692e50734150490f es.Winapi.PsAPI.
0xae41d 57696e6170692e5348466f6c6465720f Winapi.SHFolder.
0xae42d 57696e6170692e496d616765486c7006 Winapi.ImageHlp.
0xae43d 50424b4446320b53797374656d2e4d61 PBKDF2.System.MaInno overlay stages payload behind a fake Windows service identity
0xae44d 74680b53797374656d2e486173680e53 th.System.Hash.S
0xae45d 797374656d2e436c61737365731b5379 ystem.Classes.Sy
0xae46d 7374656d2e47656e65726963732e436f stem.Generics.Co
0xae47d 6c6c656374696f6e731853797374656d llections.System
0xae48d 2e47656e65726963732e44656661756c .Generics.Defaul
0xae49d 74731253797374656d2e446961676e6f ts.System.Diagno
0xae4ad 73746963730f53797374656d2e54696d stics.System.Tim
0xae4bd 655370616e0f53797374656d2e566172 eSpan.System.Var
0xae4cd 69616e74730f53797374656d2e566172 iants.System.Var
0xae4dd 5574696c730b53797374656d2e527474 Utils.System.Rtt
0xae4ed 690e53797374656d2e547970496e666f i.System.TypInfo
0xae4fd 0f53797374656d2e53796e634f626a73 .System.SyncObjs
0xae50d 0f57696e6170692e4d65737361676573 .Winapi.Messages
0xae51d 0e57696e6170692e4163746976655808 .Winapi.ActiveX.
0xae52d 4368614368613230155368617265642e ChaCha20.Shared.
0xae53d 456e63727970 Encryp
0xb3c8c 00000000000000000000000000000000 ................
0xb3c9c 00000000000000000000000000000000 ................
0xb3cac 0000000000000000f1fffffffeffffff ................
0xb3cbc ffffffff000000000100000002000000 ................
0xb3ccc 0f000000708449000000000000050000 ....p.I.........
0xb3cdc 0000008000000040000000c000000000 .......@........
0xb3cec 01000000020000000300000002000000 ................
0xb3cfc 01000000030000000400000005000000 ................
0xb3d0c 496e6e6f205365747570205365747570 Inno Setup SetupUnsigned Inno overlay claims the Windows contact service identity
0xb3d1c 20446174612028362e372e3029000000 Data (6.7.0)...
0xb3d2c 00000000000000000000000000000000 ................
0xb3d3c 00000000000000000000000000000000 ................
0xb3d4c 496e6e6f205365747570204d65737361 Inno Setup Messa
0xb3d5c 6765732028362e352e30292028752900 ges (6.5.0) (u).
0xb3d6c 00000000000000000000000000000000 ................
0xb3d7c 00000000000000000000000000000000 ................
0xb3d8c 00000000ffffffffffffffff01000000 ................
0xb3d9c 000000000000000050fe400038fd4000 ........P.@.8.@.
0xb3dac 00204b0098fd400078fc4000a0fe4000 . K...@.x.@...@.
0xb3dbc e0fe400048ff4000e401410070fe4000 ..@.H.@...A.p.@.
0xb3dcc a40141006c014100ec0141003c604b00 ..A.l.A...A.<`K.
0xb3ddc d0fd4000b400410010204b0058ff4000 ..@...A.. K.X.@.
0xb3dec 7c014100d400410010604b00dc004100 |.A...A..`K...A.
0xb3dfc 70ff400030ff4000e400410058fe4000 p.@.0.@...A.X.@.
0xb3e0c 9c01410020204b0024014100c4014100 ..A. K.$.A...A.
0xb3e1c 0c5b4b00c8fd4000a8fd400054 .[K...@...@.T
0xb57e0 00000000000000000000000000000000 ................
0xb57f0 00000000000000000000000000000000 ................
0xb5800 00204c0018204c00142c4b0010304c00 . L.. L..,K..0L.
0xb5810 0000000000000000456d626172636164 ........EmbarcadUnsigned Inno overlay claims the Windows contact service identity
0xb5820 65726f2044656c70686920666f722057 ero Delphi for W
0xb5830 696e333220636f6d70696c6572207665 in32 compiler ve
0xb5840 7273696f6e2033362e30202832392e30 rsion 36.0 (29.0
0xb5850 2e35353336322e323031372900000000 .55362.2017)....
0xb5860 00000000000000000000000000000000 ................
0xb5870 00000000000000000000000000000000 ................
0xb5880 00000000000000000000000000000000 ................
0xb5890 00000000000000000000000000000000 ................
0xb58a0 0000000000 .....

Objectives

Micro-behaviors

Metadata

file

notable severity, 95% confident.
sfx/inno-setup/extraction Innoextract could not determine setup data version

20 of 34 traits shown

Identity

SHA-256 f7a110efa09467da041b7abbd4a0cbbe67e804e78630af22fa8564038576a856
Filename 31159be01493eeb09cf3b299702a6369.exe
Package f7a110efa09467da041b7abbd4a0cbbe67e804e78630af22fa8564038576a856

Origin

Source harvest
Feed malwarebazaar
Ecosystem windows
Domain abuse.ch

Timeline

First seen 10 Aug 2026 06:18 UTC
First analyzed 10 Aug 2026 08:08 UTC
Last analyzed 10 Aug 2026 09:33 UTC
Last updated 10 Aug 2026 09:33 UTC

Labeling

Label bad
Label source harvest
Traits version 73866