valkyrie logo
valkyrie logo
  • Download Threat Hunter Assessment Tool
DASHBOARD
  • Unknown File Hunter Scans
STATISTICS
SETTINGS
  • Summary
  • Static Analysis
  • Dynamic Analysis
  • Precise Detectors
  • Human Expert Analysis
  • File Details
Analyzing...
File Name:   046fc9f92ac2bb066805121cc137d718f1b830eb17d1c892bd99318427a0d7db.exe
SHA1:   d315accf779dfb2f7657746f1f93f27291672e80
MD5:   5fef9324d989c502a58bb092fb5a17e8
First Seen Date:  2023-07-03 21:06:09.985120 ( 2023-07-03 21:06:09.985120 )
Number of Clients Seen:   2
Last Analysis Date:  2023-07-04 11:53:37.018069 ( 2023-07-04 11:53:37.018069 )
Human Expert Analysis Date:  2023-07-04 11:52:09.617904 ( 2023-07-04 11:52:09.617904 )
Human Expert Analysis Result:   Clean

Analysis Summary

Analysis Type Date Verdict
Signature Based Detection 2023-07-04 11:53:37.018069 Clean
Static Analysis Overall Verdict 2023-07-04 11:53:37.018069 No Threat Found help
Dynamic Analysis Overall Verdict 2023-07-04 11:53:37.018069 No Threat Found help
Precise Detectors Overall Verdict 2023-07-04 11:53:37.018069 No Match help
Human Expert Analysis Overall Verdict 2023-07-04 11:52:09.617904 Clean

Static Analysis

Static Analysis Overall Verdict Result
No Threat Found help
Detector Result
Optional Header LoaderFlags field is valued illegal Clean
Non-ascii or empty section names detected Clean
Illegal size of optional Header Clean
Packer detection on signature database Unknown help
Based on the sections entropy check! file is possibly packed Clean
Timestamp value suspicious Clean
Header Checksum is zero! Clean
Enrty point is outside the 1st(.code) section! Binary is possibly packed Clean
Optional Header NumberOfRvaAndSizes field is valued illegal Clean
Anti-vm present Clean
The Size Of Raw data is valued illegal! Binary might crash your disassembler/debugger Suspicious
TLS callback functions array detected Clean

Dynamic Analysis

Dynamic Analysis Overall Verdict Result
No Threat Found help
Suspicious Behaviors
Opens a file in a system directory
Creates a child process
Has no visible windows
Reads memory of another process

046fc9f92ac2bb066805121cc137d718f1b830eb17d1c892bd99318427a0d7db.exe tried to connect to some addresses pinned on the map below (click pins for more details):

Behavioral Information

LoadLibrary

ADVAPI32.dll

C:\Windows\system32\ole32.dll

C:\Windows\syswow64\MSCTF.dll

OLEAUT32.DLL

SHELL32.dll

ole32.dll

propsys.dll

comctl32.dll

C:\Windows\SysWOW64\ieframe.dll

kernel32.dll

api-ms-win-downlevel-ole32-l1-1-0.dll

urlmon.dll

api-ms-win-downlevel-shlwapi-l2-1-0.dll

PROPSYS.dll

OLEAUT32.dll

iertutil.dll

USER32.dll

API-MS-Win-Core-LocalRegistry-L1-1-0.dll

CreateMutex

<NULL>

ReadFile

C:\Windows\Fonts\staticcache.dat

OpenMutex

Local\MSCTF.Asm.MutexDefault1

CreateProcess

"C:\Program Files\Internet Explorer\iexplore.exe" https://bell-sw.com/pages/downloads/?version=java-8-lts&os=Windows&package=jre-full

QueryFilePath

C:\[u046fc9f92ac2bb066805121cc137d718f1b830eb17d1c892bd99318427a0d7db.exe]

C:\Windows\syswow64\MSCTF.dll

C:\Windows\syswow64\USER32.dll

C:\Windows\SysWOW64\ieframe.dll

OpenRegistryKey

\REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings

\REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings

\REGISTRY\USER\S-1-5-21-3979321414-2393373014-2172761192-1000\Software\Microsoft\Internet Explorer\TabbedBrowsing

\REGISTRY\MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\MAIN\FeatureControl

Precise Detectors Analysis Results

Detector Name Date Verdict Reason
Static Precise PUA Detector 1 2023-07-03 21:05:36.203796 No Match help NotDetected
Static Precise PUA Detector 4 2023-07-03 21:05:36.247525 No Match help NotDetected
Static Precise NI Detector 3 2023-07-03 21:05:36.281255 No Match help NotDetected
Static Precise PUA Detector 5 2023-07-03 21:05:36.326778 No Match help NotDetected
Static Precise Trojan Detector 1 2023-07-03 21:05:36.336788 No Match help NotDetected
Static Precise Trojan Detector 3 2023-07-03 21:05:36.328804 No Match help NotDetected
Static Precise PUA Detector 6 2023-07-03 21:05:36.364303 No Match help NotDetected
Static Precise Trojan Detector 12 2023-07-03 21:05:36.408028 No Match help NotDetected
Static Precise Virus Detector 1 2023-07-03 21:05:36.444273 No Match help NotDetected
Static Precise Virus Detector 2 2023-07-03 21:05:36.445461 No Match help NotDetected
Static Precise Trojan Detector 13 2023-07-03 21:05:36.499010 No Match help NotDetected
Static Precise PUA Detector 2 2023-07-03 21:05:36.499344 No Match help NotDetected

Advance Heuristics

No Advanced Heuristic Analysis Result Received

Detector Result

Human Expert Analysis Results

Analysis Start Date:   2023-07-04 05:21:00.047065 ( 2023-07-04 05:21:00.047065 )
Analysis End Date:  2023-07-04 11:52:09.617904 ( 2023-07-04 11:52:09.617904 )
File Upload Date:  2023-07-03 21:05:26.932523 ( 2023-07-03 21:05:26.932523 )
Update Date:  2023-07-04 11:53:36.447740 ( 2023-07-04 11:53:36.447740 )
Human Expert Analyst Feedback:   None
Verdict:   Clean

Additional File Information

Vendor Validation

Certificate Validation

PE Headers

Property Value

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy MD5

PE Imports

PE Exports

PE Resources

© Verdict Cloud, Xcitium, Inc. 2025. All rights reserved. v1.49.0-72-ENT
 
 
 
 
Loading...