valkyrie logo
valkyrie logo
  • Download Threat Hunter Assessment Tool
DASHBOARD
  • Unknown File Hunter Scans
STATISTICS
SETTINGS
  • Summary
  • Static Analysis
  • Dynamic Analysis
  • Precise Detectors
  • Human Expert Analysis
  • File Details
Analyzing...
File Name:   Odeme_Onay_Kopyas.exe
SHA1:   b2965a7783b66b66618be73bf8115e92dab29b57
MD5:   706aa6e6ec6c73d221f82bd4ab0d12c8
First Seen Date:  2024-10-17 07:57:47.342496 ( 2024-10-17 07:57:47.342496 )
Number of Clients Seen:   4
Last Analysis Date:  2024-10-18 15:44:56.789521 ( 2024-10-18 15:44:56.789521 )
Human Expert Analysis Date:  2024-10-18 15:44:21.312619 ( 2024-10-18 15:44:21.312619 )
Human Expert Analysis Result:   Malware

Analysis Summary

Analysis Type Date Verdict
Signature Based Detection 2024-10-18 15:44:56.789521 Malware
Static Analysis Overall Verdict 2024-10-18 15:44:56.789521 No Threat Found help
Dynamic Analysis Overall Verdict 2024-10-18 15:44:56.789521 No Threat Found help
Precise Detectors Overall Verdict 2024-10-18 15:44:56.789521 No Match help
Human Expert Analysis Overall Verdict 2024-10-18 15:44:21.312619 Malware

Static Analysis

Static Analysis Overall Verdict Result
No Threat Found help
Detector Result
Optional Header LoaderFlags field is valued illegal Clean
Non-ascii or empty section names detected Clean
Illegal size of optional Header Clean
Packer detection on signature database Unknown help
Based on the sections entropy check! file is possibly packed Clean
Timestamp value suspicious Clean
Header Checksum is zero! Clean
Enrty point is outside the 1st(.code) section! Binary is possibly packed Clean
Optional Header NumberOfRvaAndSizes field is valued illegal Clean
Anti-vm present Suspicious
The Size Of Raw data is valued illegal! Binary might crash your disassembler/debugger Clean
TLS callback functions array detected Clean

Dynamic Analysis

Dynamic Analysis Overall Verdict Result
No Threat Found help
Suspicious Behaviors
Has no visible windows

Odeme_Onay_Kopyas.exe tried to connect to some addresses pinned on the map below (click pins for more details):

Behavioral Information

LoadLibrary

kernel32.dll

uxtheme.dll

comctl32.dll

ole32.dll

API-MS-Win-Core-LocalRegistry-L1-1-0.dll

UxTheme.dll

IMM32.dll

user32.dll

advapi32.dll

shell32.dll

shlwapi.dll

CreateMutex

<NULL>

WriteFile

C:\Users\win7\AppData\Local\Temp\Countee

ReadFile

C:\Odeme_Onay_Kopyas.exe

QueryFilePath

C:\Odeme_Onay_Kopyas.exe

OpenRegistryKey

\REGISTRY\USER\.DEFAULT\Control Panel\Mouse

Precise Detectors Analysis Results

Detector Name Date Verdict Reason
Static Precise PUA Detector 1 2024-10-17 07:57:14.112201 No Match help NotDetected
Static Precise PUA Detector 4 2024-10-17 07:57:14.099277 No Match help NotDetected
Static Precise NI Detector 3 2024-10-17 07:57:14.145954 No Match help NotDetected
Static Precise PUA Detector 5 2024-10-17 07:57:14.149106 No Match help NotDetected
Static Precise Trojan Detector 1 2024-10-17 07:57:14.158018 No Match help NotDetected
Static Precise Trojan Detector 3 2024-10-17 07:57:14.213082 No Match help NotDetected
Static Precise PUA Detector 6 2024-10-17 07:57:14.226437 No Match help NotDetected
Static Precise Trojan Detector 12 2024-10-17 07:57:14.269286 No Match help NotDetected
Static Precise Virus Detector 1 2024-10-17 07:57:14.313322 No Match help NotDetected
Static Precise Virus Detector 2 2024-10-17 07:57:14.314403 No Match help NotDetected
Static Precise Trojan Detector 13 2024-10-17 07:57:14.368626 No Match help NotDetected
Static Precise PUA Detector 2 2024-10-17 07:57:14.367071 No Match help NotDetected

Advance Heuristics

No Advanced Heuristic Analysis Result Received

Detector Result

Human Expert Analysis Results

Analysis Start Date:   2024-10-18 05:26:15.440313 ( 2024-10-18 05:26:15.440313 )
Analysis End Date:  2024-10-18 15:44:21.312619 ( 2024-10-18 15:44:21.312619 )
File Upload Date:  2024-10-17 07:57:06.800677 ( 2024-10-17 07:57:06.800677 )
Update Date:  2024-10-18 15:44:56.078201 ( 2024-10-18 15:44:56.078201 )
Human Expert Analyst Feedback:   Trojware
Verdict:   Malware
Malware Family:   Generic
Malware Type:   Trojan Generic

Additional File Information

Vendor Validation

Certificate Validation

PE Headers

Property Value

File Paths

File Path on Client Seen Count
C:\Users\fatma.yilmaz\AppData\Local\Temp\Rar$EXa0.991\Ɩdeme Onay Kopyası.exe 3
C:\Users\fatma.yilmaz\AppData\Local\Temp\Rar$EXa0.991\ļæ½deme Onay Kopyasļæ½.exe 3
C:\Users\neslihan.demir\AppData\Local\Temp\Rar$EXa9196.31305\Ɩdeme Onay Kopyası.exe 3

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy MD5

PE Imports

PE Exports

PE Resources

© Verdict Cloud, Xcitium, Inc. 2025. All rights reserved. v1.49.0-72-ENT
 
 
 
 
Loading...