valkyrie logo
valkyrie logo
  • Download Threat Hunter Assessment Tool
DASHBOARD
  • Unknown File Hunter Scans
STATISTICS
SETTINGS
  • Summary
  • Static Analysis
  • Dynamic Analysis
  • Precise Detectors
  • Human Expert Analysis
  • File Details
Analyzing...
File Name:   HEUR.Trojan.Win32.Generic-a3543a25e839c4b2ef7fa68f923c174aa73f79cbdcafc701bfd9577ed20fbc9e
SHA1:   e25fc8b1d8a1880d3f194df90646c9032f2d76ab
MD5:   88a45f1c930af04c295f7a89f8983fe5
First Seen Date:  2024-12-08 17:17:14.855782 ( 2024-12-08 17:17:14.855782 )
Number of Clients Seen:   2
Last Analysis Date:  2024-12-09 07:57:36.183947 ( 2024-12-09 07:57:36.183947 )
Human Expert Analysis Date:  2024-12-09 07:57:32.766371 ( 2024-12-09 07:57:32.766371 )
Human Expert Analysis Result:   Malware

Analysis Summary

Analysis Type Date Verdict
Signature Based Detection 2024-12-08 19:05:58.828358 Malware
Static Analysis Overall Verdict 2024-12-09 07:57:36.183947 No Threat Found help
Dynamic Analysis Overall Verdict 2024-12-09 07:57:36.183947 No Threat Found help
Precise Detectors Overall Verdict 2024-12-09 07:57:36.183947 No Match help
Human Expert Analysis Overall Verdict 2024-12-09 07:57:32.766371 Malware

Static Analysis

Static Analysis Overall Verdict Result
No Threat Found help
Detector Result
Optional Header LoaderFlags field is valued illegal Clean
Non-ascii or empty section names detected Clean
Illegal size of optional Header Clean
Packer detection on signature database Unknown help
Based on the sections entropy check! file is possibly packed Suspicious
Timestamp value suspicious Clean
Header Checksum is zero! Suspicious
Enrty point is outside the 1st(.code) section! Binary is possibly packed Suspicious
Optional Header NumberOfRvaAndSizes field is valued illegal Clean
Anti-vm present Clean
The Size Of Raw data is valued illegal! Binary might crash your disassembler/debugger Clean
TLS callback functions array detected Clean

Packer detection on signature database

UPX v0.89.6 - v1.02 / v1.05 -v1.24 -> Markus & Laszlo [overlay]

Dynamic Analysis

Dynamic Analysis Overall Verdict Result
No Threat Found help
Suspicious Behaviors
Has no visible windows

HEUR.Trojan.Win32.Generic-a3543a25e839c4b2ef7fa68f923c174aa73f79cbdcafc701bfd9577ed20fbc9e tried to connect to some addresses pinned on the map below (click pins for more details):

Behavioral Information

LoadLibrary

KERNEL32.DLL

GDI32.dll

mscms.dll

msvcrt.dll

ole32.dll

WINMM.dll

Precise Detectors Analysis Results

Detector Name Date Verdict Reason
Static Precise PUA Detector 1 2024-12-08 17:17:10.446983 No Match help NotDetected
Static Precise PUA Detector 4 2024-12-08 17:17:10.517781 No Match help NotDetected
Static Precise NI Detector 3 2024-12-08 17:17:10.650230 No Match help NotDetected
Static Precise PUA Detector 5 2024-12-08 17:17:10.675914 No Match help NotDetected
Static Precise Trojan Detector 1 2024-12-08 17:17:10.671777 No Match help NotDetected
Static Precise Trojan Detector 3 2024-12-08 17:17:10.669030 No Match help NotDetected
Static Precise PUA Detector 6 2024-12-08 17:17:10.716829 No Match help NotDetected
Static Precise Trojan Detector 12 2024-12-08 17:17:10.758221 No Match help NotDetected
Static Precise Virus Detector 1 2024-12-08 17:17:10.817784 No Match help NotDetected
Static Precise Virus Detector 2 2024-12-08 17:17:10.818207 No Match help NotDetected
Static Precise Trojan Detector 13 2024-12-08 17:17:10.865178 No Match help NotDetected
Static Precise PUA Detector 2 2024-12-08 17:17:10.875168 No Match help NotDetected

Advance Heuristics

No Advanced Heuristic Analysis Result Received

Detector Result

Human Expert Analysis Results

Analysis Start Date:   2024-12-09 06:45:20.308038 ( 2024-12-09 06:45:20.308038 )
Analysis End Date:  2024-12-09 07:57:32.766371 ( 2024-12-09 07:57:32.766371 )
File Upload Date:  2024-12-08 17:17:05.335192 ( 2024-12-08 17:17:05.335192 )
Update Date:  2024-12-09 07:57:35.841453 ( 2024-12-09 07:57:35.841453 )
Human Expert Analyst Feedback:  
Verdict:   Malware
Malware Family:  
Malware Type:   Trojan Generic

Additional File Information

Vendor Validation

Certificate Validation

PE Headers

Property Value

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy MD5

PE Imports

PE Exports

PE Resources

© Verdict Cloud, Xcitium, Inc. 2025. All rights reserved. v1.49.0-72-ENT
 
 
 
 
Loading...