valkyrie logo
valkyrie logo
  • Download Threat Hunter Assessment Tool
DASHBOARD
  • Unknown File Hunter Scans
STATISTICS
SETTINGS
  • Summary
  • Static Analysis
  • Dynamic Analysis
  • Precise Detectors
  • Human Expert Analysis
  • File Details
Analyzing...
File Name:   2023-03-01_8efccd45c79b053ace1c9691a3add9da_mafia
SHA1:   40f40a99ea7be53397a801921abbd77a1f9abc64
MD5:   8efccd45c79b053ace1c9691a3add9da
First Seen Date:  2023-03-15 13:27:27.798331 ( 2023-03-15 13:27:27.798331 )
Number of Clients Seen:   3
Last Analysis Date:  2023-03-15 18:42:41.950891 ( 2023-03-15 18:42:41.950891 )
Human Expert Analysis Date:  2023-03-15 18:42:34.626964 ( 2023-03-15 18:42:34.626964 )
Human Expert Analysis Result:   PUA

Analysis Summary

Analysis Type Date Verdict
Signature Based Detection 2023-03-15 17:18:41.172589 Malware
Static Analysis Overall Verdict 2023-03-15 18:42:41.950891 No Threat Found help
Dynamic Analysis Overall Verdict 2023-03-15 18:42:41.950891 Highly Suspicious
Precise Detectors Overall Verdict 2023-03-15 18:42:41.950891 No Match help
Human Expert Analysis Overall Verdict 2023-03-15 18:42:34.626964 PUA

Static Analysis

Static Analysis Overall Verdict Result
No Threat Found help
Detector Result
Optional Header LoaderFlags field is valued illegal Clean
Non-ascii or empty section names detected Clean
Illegal size of optional Header Clean
Packer detection on signature database Unknown help
Based on the sections entropy check! file is possibly packed Clean
Timestamp value suspicious Clean
Header Checksum is zero! Clean
Enrty point is outside the 1st(.code) section! Binary is possibly packed Clean
Optional Header NumberOfRvaAndSizes field is valued illegal Clean
Anti-vm present Suspicious
The Size Of Raw data is valued illegal! Binary might crash your disassembler/debugger Clean
TLS callback functions array detected Clean

Dynamic Analysis

Dynamic Analysis Overall Verdict Result
Highly Suspicious
Suspicious Behaviors
Installs a driver
Installs a kernel/file system driver
Modifies Windows Service Keys
Has no visible windows

2023-03-01_8efccd45c79b053ace1c9691a3add9da_mafia tried to connect to some addresses pinned on the map below (click pins for more details):

Behavioral Information

CreateService

OpenService

LoadLibrary

Wtsapi32.dll

QueryFilePath

C:\2023-03-01_8efccd45c79b053ace1c9691a3add9da_mafia

OpenRegistryKey

\REGISTRY\MACHINE\SYSTEM\ControlSet001\services\TCPIP6\P

\REGISTRY\MACHINE\SYSTEM\ControlSet001\Control\GroupOrderLis

\REGISTRY\MACHINE\SYSTEM\ControlSet001\services\tdx

\REGISTRY\MACHINE\SYSTEM\ControlSet001\services

Precise Detectors Analysis Results

Detector Name Date Verdict Reason
Static Precise PUA Detector 1 2023-03-15 13:27:21.802992 No Match help NotDetected
Static Precise PUA Detector 4 2023-03-15 13:27:21.845099 No Match help NotDetected
Static Precise NI Detector 3 2023-03-15 13:27:21.947481 No Match help NotDetected
Static Precise PUA Detector 5 2023-03-15 13:27:21.974965 No Match help NotDetected
Static Precise Trojan Detector 1 2023-03-15 13:27:21.984045 No Match help NotDetected
Static Precise Trojan Detector 3 2023-03-15 13:27:21.998786 No Match help NotDetected
Static Precise PUA Detector 6 2023-03-15 13:27:22.063332 No Match help NotDetected
Static Precise Trojan Detector 12 2023-03-15 13:27:22.080137 No Match help NotDetected
Static Precise Virus Detector 1 2023-03-15 13:27:22.133924 No Match help NotDetected
Static Precise Virus Detector 2 2023-03-15 13:27:22.127211 No Match help NotDetected
Static Precise Trojan Detector 13 2023-03-15 13:27:22.189002 No Match help NotDetected
Static Precise PUA Detector 2 2023-03-15 13:27:22.197116 No Match help NotDetected

Advance Heuristics

No Advanced Heuristic Analysis Result Received

Detector Result

Human Expert Analysis Results

Analysis Start Date:   2023-03-15 14:40:42.719888 ( 2023-03-15 14:40:42.719888 )
Analysis End Date:  2023-03-15 18:42:34.626964 ( 2023-03-15 18:42:34.626964 )
File Upload Date:  2023-03-15 13:26:46.549302 ( 2023-03-15 13:26:46.549302 )
Update Date:  2023-03-15 18:42:41.746684 ( 2023-03-15 18:42:41.746684 )
Human Expert Analyst Feedback:  
Verdict:   PUA
Malware Family:  
Malware Type:   Pua

Additional File Information

Vendor Validation

Certificate Validation

PE Headers

Property Value

File Paths

File Path on Client Seen Count
40f40a99ea7be53397a801921abbd77a1f9abc64 1

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy MD5

PE Imports

PE Exports

PE Resources

© Verdict Cloud, Xcitium, Inc. 2025. All rights reserved. v1.49.0-72-ENT
 
 
 
 
Loading...