Open-source atomic malware analysis

Analyze another

2026-02-08_7db863d7066f5d284f504d7e85c79f69_elex_wannacry

PE
Verdict: HOSTILE
Mal-ecule
KO₇(Er₃P₂As₇AlC₃IS)H₅(DbFOs₃Po₃Ds)Md₂(Bi₈)Th
Size 96.0 KB download
First seen 54 days ago
Analyzed 52 days ago
Ecosystem _unknown

Well-known

hostile severity, 100% confident.
malware/trojan/elex Storm DDoS Active Setup loader

Objectives

suspicious severity, 94% confident.
evasion/self-delete COMSPEC CreateProcess self-delete
suspicious severity, 93% confident.
persistence/login/startup Active Setup StubPath persistence
suspicious severity, 94% confident.
persistence/system/service Persists DLL through Windows service
notable severity, 90% confident.
anti-static/obfuscation Unusual PE section alignment

Micro-behaviors

notable severity, 95% confident.
data/embedded Complete PE resource extraction with data access
notable severity, 66% confident.
fs/file Copy files (Windows API ANSI)
notable severity, 92% confident.
os/registry Registry open create and write APIs
notable severity, 95% confident.
os/service Windows service admin import cluster
notable severity, 98% confident.
process/inject CreateRemoteThread API reference

Metadata

notable severity, 92% confident.
binary Overlay exceeds one-third
notable severity, 100% confident.
unsigned Binary is not digitally signed
baseline severity, 95% confident.
dylib::advapi32 links ADVAPI32.dll (CloseServiceHandle, RegOpenKeyExA, RegQueryValueExA, StartServiceCtrlDispatcherA, RegCreateKeyA, ... +10 more)
baseline severity, 95% confident.
dylib::comdlg32 links comdlg32.dll (GetFileTitleA)
baseline severity, 95% confident.
dylib::kernel32 links KERNEL32.dll (lstrcatA, lstrcpyA, GetEnvironmentVariableA, GetShortPathNameA, GetModuleFileNameA, ... +28 more)
baseline severity, 95% confident.
dylib::mfc42 links MFC42.DLL (ORDINAL 924, ORDINAL 800, ORDINAL 941, ORDINAL 535, ORDINAL 537)
baseline severity, 95% confident.
dylib::msvcp60 links MSVCP60.dll (??0_Winit@std@@QAE@XZ, ??1_Winit@std@@QAE@XZ, ??1Init@ios_base@std@@QAE@XZ, ??0Init@ios_base@std@@QAE@XZ)
baseline severity, 100% confident.
hardening::no-pie Binary is not position-independent (fixed load address)
baseline severity, 100% confident.
signed::unsigned Binary is not digitally signed

Third-party

notable severity, 90% confident.
SigBase/SUSP/Imphash Detects imphash often found in malware samples (Zero hits with with search for 'imphash:x p:0' on Virustotal)

20 of 56 traits shown

Identity

SHA-256 ffc684c8dd10478ba980494de3f37d066337c0ea671778b865c7410b04301282
Filename 2026-02-08_7db863d7066f5d284f504d7e85c79f69_elex_wannacry

Origin

Source harvest
Feed vxug
Ecosystem _unknown

Timeline

First seen 24 Apr 2026 16:15 UTC
Last analyzed 26 Apr 2026 09:41 UTC
Last updated 26 Apr 2026 09:41 UTC

Labeling

Label bad
Label source harvest
Traits version bf48d