The weakness tested: can a verdict be reached when there is almost nothing to look at?

The sample

Every preceding case gave the engine a substantial file. Case 01's implant was 10.84 MB across six sections. Case 03's encryptor carried 42 capabilities. Case 04's loader, 63.

This sample is 3.50 KB.

FieldValue
TypePE32
Machinex86
File size3.50 KB
Sections3
Subsystem2 (Windows GUI)
Entrypoint RVA0x1000
Image base0x400000
Compile timestamp (UTC)2023-10-26T14:42:18Z
Import Address TableKERNEL32.dll — 1 import

Analysis returned zero suspicious artefacts, zero behaviour indicators, and seven code capabilities.

Verdict: Malicious. Risk score 98.4%.

This is the inverse of Case Study 03. There, 42 capabilities outscored 98. Here, seven capabilities and a single import produce a higher score than either — on a file offering less static surface than anything else we have published.

SHA-256: 953a438fd6034f420b2ac591a4871b4e386aa907e2ed9ca9116aa1c37b17f513
Scanned: 2026-09-20T17:19:23Z
Subsequently identified as: vshell

Verdict: Malicious — risk score 98.4% — with the sample's SHA-256 and PE metadata: PE32, x86, 3.50 KB, 3 sections, subsystem 2, entrypoint 0x1000, image base 0x400000, compile timestamp 2023-10-26T14:42:18Z
Figure 1 — Verdict and PE metadata. Three sections and a 3.50 KB file size on a Windows GUI executable

What the engine found

Seven observations, each with its scope and match count:

CapabilityScopeMatches
contain obfuscated stackstringsbasic block3
delay executionbasic block2
encode data using XORbasic block1
PEB accessbasic block3
access PEB ldr_databasic block3
resolve function by parsing PE exportsfunction3
contain loopfunction3
Suspicious Artefacts (0) — No matches. Behavior Indicators (0) — No capabilities found. Suspicious code (7) listing the seven capabilities with their scope and match counts. Import Address Table: KERNEL32.dll (1 import)
Figure 2 — Both evidence panels empty, seven code capabilities, and an import table with a single entry

The analyst note read these as a set: PEB and loader-data access to enumerate loaded modules, export parsing to resolve API addresses without declaring them in the import table, XOR encoding, stack strings concealing data that would otherwise appear as readable content in the binary, and a delay consistent with evading automated analysis environments that execute samples for a fixed period.

Its functional call: loader or dropper — malware whose purpose is to deliver additional payloads onto a system.

Its stated limit: the specific malware family cannot be determined with certainty from the available data.

AI Malware Analyst Note: Behavior, Possible Family Type, MITRE Techniques and Possible Risks sections. The family section concludes loader or dropper and states the specific family cannot be determined with certainty
Figure 3 — The analyst note. Definitive on the verdict, explicit about the boundary on family

The empty panels are the finding

Zero artefacts and zero behaviour indicators would, in a signature or string-matching engine, be the end of the analysis. There is nothing to match. Fewer than four kilobytes, three sections, one imported function, no recognisable strings.

That emptiness is not an absence of evidence. It is evidence.

A 3.5 KB Windows GUI executable that imports exactly one function and resolves everything else by walking the PEB is not a small program. It is a program built to carry no visible structure. Legitimate software of that size links what it uses; the import table is the first thing a normal toolchain writes. A binary that has almost none, and contains export-parsing code instead, has replaced its import table with a runtime substitute — and the only reason to do that is to make the file's behaviour unreadable before execution.

The capability panels above are one part of what the classifier evaluates. File structure, section layout and import characteristics are assessed independently of them. On this sample the panels a human reads are nearly empty while the structural view is extreme. The score reflects the whole, not the visible part — which is why 98.4 is consistent with seven capabilities, and why an engine scoring by counting what it could display would have called this file uninteresting.


Ground truth

VirusTotal: 48 of 70 detections. Popular threat label trojan.jaik/mikey. Tagged spreader.

Its Code insights analysis describes the sample as a network stager and downloader that:

  • resolves APIs dynamically via PEB traversal and ROR-13 export hashing
  • loads ws2_32.dll at runtime
  • opens a TCP socket to a hardcoded C2, assembled at runtime as 165.154.226.87 on port 8084
  • sends initial beacon data
  • allocates PAGE_EXECUTE_READWRITE memory
  • downloads an encrypted secondary payload via recv
  • decrypts it with a single-byte XOR key, 0x99
  • executes the payload directly in memory
VirusTotal Code insights marked Malicious, describing a network stager and downloader using PEB traversal and ROR-13 export hashing, loading ws2_32.dll at runtime, connecting to 165.154.226.87 on port 8084, allocating PAGE_EXECUTE_READWRITE memory, and decrypting a downloaded payload with a single-byte XOR key of 0x99
Figure 4 — Independent deeper analysis of the same file, against which the seven capabilities can be checked

Every one of the seven capabilities corresponds to a component of that description:

Capability reportedComponent of the sample's behaviour
PEB access · access PEB ldr_dataPEB traversal for API resolution
resolve function by parsing PE exportsROR-13 export hashing
contain obfuscated stackstringsthe C2 address assembled at runtime rather than stored
encode data using XORthe 0x99 payload decryption
contain loophash comparison and decryption loops
delay executionevasion of timed automated analysis

Seven observations, seven components. Nothing reported that is not there; nothing there that was missed, within what the file exposes before it runs.

The functional classification is also correct. The sample delivers a secondary payload. The note said loader or dropper.


What the note did not say, and why that is the point

The note did not call this a backdoor, a C2 implant or a network tool. It stated that the family could not be determined with certainty.

The sample does, in fact, open a socket and beacon to a remote server.

It could not have been established statically. ws2_32.dll is never named in the import table — it is loaded at runtime through the same export-hashing mechanism the engine detected. The C2 address is not stored as a string; it is assembled on the stack, which is exactly what the obfuscated-stackstrings finding describes. The networking is structurally invisible until the file executes.

An engine that had asserted backdoor here would have been right. It would also have been guessing, and the same guess on a file without a socket would have been wrong. What the engine reported was the mechanism that hides the network behaviour — stack strings, runtime resolution — without claiming knowledge of what that mechanism conceals.

This matters more than a correct guess would have. In the preceding case, two vendors labelled a sample Backdoor whose import table contained no networking library at all. The discipline runs in both directions: state what the structure establishes, name the boundary, and leave the evidence at each address for the analyst to read.


What the industry returned

VirusTotal summary: 48 of 70 security vendors flagged this file as malicious. Size 3.50 KB. Tags: peexe, spreader
Figure 5 — The VirusTotal summary for the same hash

48 of 70 detected. 22 did not, including Malwarebytes, Palo Alto Networks, TrendMicro and TrendMicro-HouseCall, Trellix ENS, Tencent, Sangfor Engine Zero, Xcitium, Skyhigh (SWG), Panda, QuickHeal, Acronis (Static ML), Alibaba, CMC, Lionic, TACHYON, TEHTRIS, ViRobot, Yandex, Zillya and Zoner.

Four engines could not process the file at all: Avast-Mobile, BitDefenderFalx, Symantec Mobile Insight and Trustlook.

VirusTotal security vendors' analysis showing ZoneAlarm by Check Point detecting the file as Troj/Loader-IY, followed by the Undetected verdicts from Malwarebytes, Palo Alto Networks, TrendMicro, Trellix ENS, Tencent, Sangfor Engine Zero, Xcitium and others, and four engines unable to process the file
Figure 6 — Detections, non-detections, and the four engines that could not process a 3.5 KB file

Among the detections, ZoneAlarm by Check Point returned Troj/Loader-IY — a correct functional label, and the same vendor engine that returned Undetected on the Silver Fox loader in Case Study 04. Coverage is per-sample. That is the nature of the mechanism, and it is why we report each file's result as it came back.


What this case does not show

One sample is one sample. This case demonstrates that a correct verdict, a correct functional classification and a correctly drawn confidence boundary were produced from a file with a nearly empty static surface, and that independent deeper analysis confirmed every structural observation. It is not a detection rate.

The comparison is also specific in scope. VirusTotal runs static analysis configurations, so what is compared here is static analysis against static analysis — the appropriate comparison, since that is what we perform. We make no claim about how these vendors' full products behave at runtime, having neither tested them nor any basis for an opinion.

Every capability we report carries a virtual address and its disassembly. The hash above is public. The free tier includes malware analysis at no cost.

DEKENEAS performs no actor attribution. Verdicts are computed from file structure and code capability: no signature set, no malware family database, and no reputation service in the verdict path.

Analyse a sample →