The weakness tested: can a verdict be reached when there is almost nothing to look at?
The sample
Every preceding case gave the engine a substantial file. Case 01's implant was 10.84 MB across six sections. Case 03's encryptor carried 42 capabilities. Case 04's loader, 63.
This sample is 3.50 KB.
| Field | Value |
|---|---|
| Type | PE32 |
| Machine | x86 |
| File size | 3.50 KB |
| Sections | 3 |
| Subsystem | 2 (Windows GUI) |
| Entrypoint RVA | 0x1000 |
| Image base | 0x400000 |
| Compile timestamp (UTC) | 2023-10-26T14:42:18Z |
| Import Address Table | KERNEL32.dll — 1 import |
Analysis returned zero suspicious artefacts, zero behaviour indicators, and seven code capabilities.
Verdict: Malicious. Risk score 98.4%.
This is the inverse of Case Study 03. There, 42 capabilities outscored 98. Here, seven capabilities and a single import produce a higher score than either — on a file offering less static surface than anything else we have published.
SHA-256: 953a438fd6034f420b2ac591a4871b4e386aa907e2ed9ca9116aa1c37b17f513
Scanned: 2026-09-20T17:19:23Z
Subsequently identified as: vshell
What the engine found
Seven observations, each with its scope and match count:
| Capability | Scope | Matches |
|---|---|---|
| contain obfuscated stackstrings | basic block | 3 |
| delay execution | basic block | 2 |
| encode data using XOR | basic block | 1 |
| PEB access | basic block | 3 |
| access PEB ldr_data | basic block | 3 |
| resolve function by parsing PE exports | function | 3 |
| contain loop | function | 3 |
The analyst note read these as a set: PEB and loader-data access to enumerate loaded modules, export parsing to resolve API addresses without declaring them in the import table, XOR encoding, stack strings concealing data that would otherwise appear as readable content in the binary, and a delay consistent with evading automated analysis environments that execute samples for a fixed period.
Its functional call: loader or dropper — malware whose purpose is to deliver additional payloads onto a system.
Its stated limit: the specific malware family cannot be determined with certainty from the available data.
The empty panels are the finding
Zero artefacts and zero behaviour indicators would, in a signature or string-matching engine, be the end of the analysis. There is nothing to match. Fewer than four kilobytes, three sections, one imported function, no recognisable strings.
That emptiness is not an absence of evidence. It is evidence.
A 3.5 KB Windows GUI executable that imports exactly one function and resolves everything else by walking the PEB is not a small program. It is a program built to carry no visible structure. Legitimate software of that size links what it uses; the import table is the first thing a normal toolchain writes. A binary that has almost none, and contains export-parsing code instead, has replaced its import table with a runtime substitute — and the only reason to do that is to make the file's behaviour unreadable before execution.
The capability panels above are one part of what the classifier evaluates. File structure, section layout and import characteristics are assessed independently of them. On this sample the panels a human reads are nearly empty while the structural view is extreme. The score reflects the whole, not the visible part — which is why 98.4 is consistent with seven capabilities, and why an engine scoring by counting what it could display would have called this file uninteresting.
Ground truth
VirusTotal: 48 of 70 detections. Popular threat label trojan.jaik/mikey. Tagged spreader.
Its Code insights analysis describes the sample as a network stager and downloader that:
- resolves APIs dynamically via PEB traversal and ROR-13 export hashing
- loads
ws2_32.dllat runtime - opens a TCP socket to a hardcoded C2, assembled at runtime as 165.154.226.87 on port 8084
- sends initial beacon data
- allocates PAGE_EXECUTE_READWRITE memory
- downloads an encrypted secondary payload via
recv - decrypts it with a single-byte XOR key, 0x99
- executes the payload directly in memory
Every one of the seven capabilities corresponds to a component of that description:
| Capability reported | Component of the sample's behaviour |
|---|---|
| PEB access · access PEB ldr_data | PEB traversal for API resolution |
| resolve function by parsing PE exports | ROR-13 export hashing |
| contain obfuscated stackstrings | the C2 address assembled at runtime rather than stored |
| encode data using XOR | the 0x99 payload decryption |
| contain loop | hash comparison and decryption loops |
| delay execution | evasion of timed automated analysis |
Seven observations, seven components. Nothing reported that is not there; nothing there that was missed, within what the file exposes before it runs.
The functional classification is also correct. The sample delivers a secondary payload. The note said loader or dropper.
What the note did not say, and why that is the point
The note did not call this a backdoor, a C2 implant or a network tool. It stated that the family could not be determined with certainty.
The sample does, in fact, open a socket and beacon to a remote server.
It could not have been established statically. ws2_32.dll is never named in the import table — it is loaded at runtime through the same export-hashing mechanism the engine detected. The C2 address is not stored as a string; it is assembled on the stack, which is exactly what the obfuscated-stackstrings finding describes. The networking is structurally invisible until the file executes.
An engine that had asserted backdoor here would have been right. It would also have been guessing, and the same guess on a file without a socket would have been wrong. What the engine reported was the mechanism that hides the network behaviour — stack strings, runtime resolution — without claiming knowledge of what that mechanism conceals.
This matters more than a correct guess would have. In the preceding case, two vendors labelled a sample Backdoor whose import table contained no networking library at all. The discipline runs in both directions: state what the structure establishes, name the boundary, and leave the evidence at each address for the analyst to read.
What the industry returned
48 of 70 detected. 22 did not, including Malwarebytes, Palo Alto Networks, TrendMicro and TrendMicro-HouseCall, Trellix ENS, Tencent, Sangfor Engine Zero, Xcitium, Skyhigh (SWG), Panda, QuickHeal, Acronis (Static ML), Alibaba, CMC, Lionic, TACHYON, TEHTRIS, ViRobot, Yandex, Zillya and Zoner.
Four engines could not process the file at all: Avast-Mobile, BitDefenderFalx, Symantec Mobile Insight and Trustlook.
Among the detections, ZoneAlarm by Check Point returned Troj/Loader-IY — a correct functional label, and the same vendor engine that returned Undetected on the Silver Fox loader in Case Study 04. Coverage is per-sample. That is the nature of the mechanism, and it is why we report each file's result as it came back.
What this case does not show
One sample is one sample. This case demonstrates that a correct verdict, a correct functional classification and a correctly drawn confidence boundary were produced from a file with a nearly empty static surface, and that independent deeper analysis confirmed every structural observation. It is not a detection rate.
The comparison is also specific in scope. VirusTotal runs static analysis configurations, so what is compared here is static analysis against static analysis — the appropriate comparison, since that is what we perform. We make no claim about how these vendors' full products behave at runtime, having neither tested them nor any basis for an opinion.
Every capability we report carries a virtual address and its disassembly. The hash above is public. The free tier includes malware analysis at no cost.
DEKENEAS performs no actor attribution. Verdicts are computed from file structure and code capability: no signature set, no malware family database, and no reputation service in the verdict path.