valkyrie logo
valkyrie logo
  • Download Threat Hunter Assessment Tool
DASHBOARD
  • Unknown File Hunter Scans
STATISTICS
SETTINGS
  • Summary
  • Static Analysis
  • Dynamic Analysis
  • Precise Detectors
  • Human Expert Analysis
  • File Details
Analyzing...
File Name:   d7443e8971985f4cbd75219edfdedde221be125432c421d6b0d1537f7d8b36d5.exe
SHA1:   6e8b3b6064269f4d8c98375380232e736842eb7b
MD5:   5fae1fc204f85528336f435f2af78c5b
First Seen Date:  2023-08-04 18:47:23.586037 ( 2023-08-04 18:47:23.586037 )
Number of Clients Seen:   4
Last Analysis Date:  2023-08-07 08:26:21.092134 ( 2023-08-07 08:26:21.092134 )
Human Expert Analysis Date:  2023-08-07 08:25:59.136575 ( 2023-08-07 08:25:59.136575 )
Human Expert Analysis Result:   Malware

Analysis Summary

Analysis Type Date Verdict
Signature Based Detection 2023-08-04 19:16:20.226362 Malware
Static Analysis Overall Verdict 2023-08-07 08:26:21.092134 No Threat Found help
Dynamic Analysis Overall Verdict 2023-08-07 08:26:21.092134 No Threat Found help
Precise Detectors Overall Verdict 2023-08-07 08:26:21.092134 No Match help
Human Expert Analysis Overall Verdict 2023-08-07 08:25:59.136575 Malware

Static Analysis

Static Analysis Overall Verdict Result
No Threat Found help
Detector Result
Optional Header LoaderFlags field is valued illegal Clean
Non-ascii or empty section names detected Clean
Illegal size of optional Header Clean
Packer detection on signature database Unknown help
Based on the sections entropy check! file is possibly packed Clean
Timestamp value suspicious Clean
Header Checksum is zero! Suspicious
Enrty point is outside the 1st(.code) section! Binary is possibly packed Clean
Optional Header NumberOfRvaAndSizes field is valued illegal Clean
Anti-vm present Clean
The Size Of Raw data is valued illegal! Binary might crash your disassembler/debugger Clean
TLS callback functions array detected Clean

Packer detection on signature database

Microsoft Visual C# / Basic .NET

.NET executable

Dynamic Analysis

Dynamic Analysis Overall Verdict Result
No Threat Found help
Suspicious Behaviors
Opens a file in a system directory
Logs user key strokes
Has no visible windows
Uses a function clandestinely

d7443e8971985f4cbd75219edfdedde221be125432c421d6b0d1537f7d8b36d5.exe tried to connect to some addresses pinned on the map below (click pins for more details):

Behavioral Information

QueryFilePath

C:\Windows\SYSTEM32\MSCOREE.DLL

C:\d7443e8971985f4cbd75219edfdedde221be125432c421d6b0d1537f7d8b36d5.exe

C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc\MSVCR80.dll

C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll

LowerChar

file

RegSetValue

HKEY_CURRENT_USERdi

CreateMutex

<NULL>

55b565ac97f14798

Global\.net clr networking

OpenMutex

Global\CLR_CASOFF_MUTEX

Global\.net clr networking

ReadFile

C:\Windows\Microsoft.NET\Framework\v2.0.50727\config\machine.config

C:\Windows\Microsoft.NET\Framework\v2.0.50727\Config\machine.config

LoadLibrary

ADVAPI32.dll

SHLWAPI.dll

C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll

mscoree.dll

ntdll

advapi32.dll

shell32.dll

C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\38bf604432e1a30c954b2ee40d6a2d1c\mscorlib.ni.dll

C:\Windows\Microsoft.NET\Framework\v2.0.50727\ole32.dll

ole32.dll

kernel32.dll

AdvApi32.dll

C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll

C:\Windows\assembly\NativeImages_v2.0.50727_32\System\908ba9e296e92b4e14bdc2437edac603\System.ni.dll

C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\5a401fd2a7689ff13fb54182953f9c40\System.Drawing.ni.dll

C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\6949c4470a81970ec3de0a575d93babc\System.Windows.Forms.ni.dll

C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\12dc10e5c0e8d176cf21a16a6fc5fc3b\Microsoft.VisualBasic.ni.dll

user32.dll

gdi32.dll

C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\007fc007edc388d9806dff94ee04f129\System.Configuration.ni.dll

user32

C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\d49908aa93a23c84847b1f8b1b667860\System.Xml.ni.dll

C:\Windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\ws2_32.dll

ws2_32.dll

OpenRegistryKey

\REGISTRY\MACHINE\SOFTWARE\Wow6432Node\M

\REGISTRY\MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\NI\61e7e666\c991064

\REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Micro

\REGISTRY\MACHINE\SOFTWARE\Microsoft\Fusion\NativeImagesIndex\v2.0.50727_32\index1c2

\REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFra

\REGISTRY\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options

\REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets

\REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NETFramework\Security\Policy\Extensions\NamedPermissionSets\Internet

\REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\.NE

QueryProcessAddress

GetAsyncKeyState

OpenProcess

OpenProcessW

Precise Detectors Analysis Results

Detector Name Date Verdict Reason
Static Precise PUA Detector 1 2023-08-04 18:47:18.884245 No Match help NotDetected
Static Precise PUA Detector 4 2023-08-04 18:47:18.911203 No Match help NotDetected
Static Precise NI Detector 3 2023-08-04 18:47:18.956296 No Match help NotDetected
Static Precise PUA Detector 5 2023-08-04 18:47:18.969678 No Match help NotDetected
Static Precise Trojan Detector 1 2023-08-04 18:47:19.035649 No Match help NotDetected
Static Precise Trojan Detector 3 2023-08-04 18:47:19.035745 No Match help NotDetected
Static Precise PUA Detector 6 2023-08-04 18:47:19.039287 No Match help NotDetected
Static Precise Trojan Detector 12 2023-08-04 18:47:19.074818 No Match help NotDetected
Static Precise Virus Detector 1 2023-08-04 18:47:19.125209 No Match help NotDetected
Static Precise Virus Detector 2 2023-08-04 18:47:19.124102 No Match help NotDetected
Static Precise Trojan Detector 13 2023-08-04 18:47:19.202006 No Match help NotDetected
Static Precise PUA Detector 2 2023-08-04 18:47:19.189026 No Match help NotDetected

Advance Heuristics

No Advanced Heuristic Analysis Result Received

Detector Result

Human Expert Analysis Results

Analysis Start Date:   2023-08-07 06:32:34.624336 ( 2023-08-07 06:32:34.624336 )
Analysis End Date:  2023-08-07 08:25:59.136575 ( 2023-08-07 08:25:59.136575 )
File Upload Date:  2023-08-04 18:47:13.967357 ( 2023-08-04 18:47:13.967357 )
Update Date:  2023-08-07 08:26:20.878429 ( 2023-08-07 08:26:20.878429 )
Human Expert Analyst Feedback:  
Verdict:   Malware
Malware Family:  
Malware Type:   Trojan Generic

Additional File Information

Vendor Validation

Certificate Validation

PE Headers

Property Value

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy MD5

PE Imports

PE Exports

PE Resources

© Verdict Cloud, Xcitium, Inc. 2025. All rights reserved. v1.49.0-72-ENT
 
 
 
 
Loading...