Open-source atomic malware analysis

Analyze another

07448a01829d8d916d2b7bcf91e1fb4731ea51febdb71af48d594639f4cb1cde

PE
Verdict: HOSTILE
AI Valorant cheat loader tampering with Vanguard
Mal-ecule
K₂(GaLi)O(Pr)H₇(Cm₅CrF₃Hf₂Os₆Po₅U₂)Md(Bi₄)
Size 1.5 MB download
First seen 5 days ago
Analyzed 3 days ago
Source virussign.com
Also detected by 1 source
Valorant cheat loader tampering with Vanguard: virussign.com_295198a1ac16f495efba7bdb7e28d950.vir:0xf4010
Adjusts token privileges then launches a process: virussign.com_295198a1ac16f495efba7bdb7e28d950.vir:0xf4008
virussign.com_295198a1ac16f495efba7bdb7e28d950.vir pe
0xf3ff0 20e2b18400f0908cb220f0908cb620f0 ........ .... .
0xf4000 908d8020f0908d8420f0908cb420f090 ... .... .... ..Adjusts token privileges then launches a process
0xf4010 8d8320f0908d8820f0908cbe00f0908c .. .... ........Valorant cheat loader tampering with Vanguard
0xf4020 b620f0908cb420f0908d8320f0908d88 . .... .... ....
0xf4030 00ce9320ce9220ce9520ce9620ce9820 ... .. .. .. ..
0xf4040 ce9f20cea900ce9220ce9420ce9620ce .. ..... .. .. .
0xf4050 9e20ce9820ce9f00ceb220ceb820ceb4 . .. ..... .. ..
0xf4060 20ceb620cebb20cebe00ceb120ceb520 .. .. ..... ..
0xf4070 ceb920cebf20cf8020cf8320cf8420cf .. .. .. .. .. .
0xf4080 8900ceb220ceb320ceb720cebc20cf81 .... .. .. .. ..
0xf4090 20cf8620 ..
0xf4640 b620f096b9be00f096b9a020f096b9a1 . ......... ....
0xf4650 20f096b9a220f096b9b920f096b9b320 .... .... .... Adjusts token privileges then launches a process
0xf4660 f096b9ae00f096b9a020f096b9a120f0 ......... .... .
0xf4670 96b9a220f096b9b320f096b9ad20f096 ... .... .... ..
0xf4680 b9bd00f096b9a520f096b9a820f096b9 ....... .... ...
0xf4690 a900f096ba8020f096ba8520f096ba88 ...... .... ....
0xf46a0 20f096ba8420f096ba8d00e1a0b320e1 .... ........ .
0xf46b0 a0b420e1a0b620e1a0bd20e1a18220e1 .. ... ... ... .
0xf46c0 a18a20e2808de1a1a1e2808d20e2808d .. ......... ...
0xf46d0 e1a1b3e2808d00e1a18300e1808120e1 .............. .
0xf46e0 808220e1808420e1809220e1809d20e1 .. ... ... ... .
0xf46f0 81a520e1818a20e1818b00e1808420e1 .. ... ....... .
0xf4700 808e20e1809220e1809520e1809720e1 .. ... ... ... .
0xf4710 809d20e1818a20e1818b00e180a920e1 .. ... ....... .
0xf4720 80bc20e1818d20e1818f20e1818620e1 .. ... ... ... .
0xf4730 80ab20e180ad00e1808920e1808a20e1 .. ....... ... .
0xf4740 80a520e180a920e180a820e1818220e1 .. ... ... ... .
0xf4750 818520e1818900df9020df8920df9220 .. ...... .. ..
0xf4760 df9f20df9620df9c20dfa020dfa500df .. .. .. .. ....
0xf4770 8020df9820dfa120dfa020dfa500df8f . .. .. .. .....
0xf4780 20df9b20df8b00df8e20df8f20df9b20 .. ..... .. ..
0xf4790 df8b00e1b19b20e1b19c20e1b19d20e1 ...... ... ... .
0xf47a0 b1a120e1b1a220e1b1a500f090b09720 .. ... ........
0xf47b0 f090b09820f090b0a700f090b08920f0 .... ......... .
0xf47c0 90b09720f090b0a620f090b0a700f090 ... .... .......
0xf47d0 92be20f090938d20f090939220f09093 .. .... .... ...
0xf47e0 9320f09092bb20f090938220f09092b5 . .... .... ....
0xf47f0 20f090938600f09092b020f090938d20 ......... ....
0xf4800 f090938220f09092bf20f090938e20f0 .... .... .... .
0xf4810 9092b900f09092bc20f09092bd20f090 ........ .... ..
0xf4820 92be00f09093b520f09093b620f09093 ....... .... ...
0xf4830 ba20f09093bb . ....
0x14b498 2e007000680070000000000000000000 ..p.h.p.........
0x14b4a8 50004f00530054000000000022007d00 P.O.S.T.....".}.
0x14b4b8 00000000000000007b00220061006300 ........{.".a.c.
0x14b4c8 740069006f006e0022003a0022006800 t.i.o.n.".:.".h.Valorant cheat loader tampering with Vanguard
0x14b4d8 65006100720074006200650061007400 e.a.r.t.b.e.a.t.
0x14b4e8 22002c002200670061006d0065002200 ".,.".g.a.m.e.".
0x14b4f8 3a002200760061006c006f :.".v.a.l.o
0x14b580 7500740066002d0038000d000a000000 u.t.f.-.8.......
0x14b590 2f00760061006e006700750061007200 /.v.a.n.g.u.a.r.Valorant cheat loader tampering with Vanguard
0x14b5a0 64002f00760031002f00670061007400 d./.v.1./.g.a.t.
0x14b5b0 65007700610079000000000000000000 e.w.a.y.........
0x14b5c0 43006f006e00740065006e0074002d00 C.o.n.t.e.n.t.-.
0x14b5d0 54007900700065003a00200061007000 T.y.p.e.:. .a.p.
0x14b5e0 70006c00690063006100740069006f00 p.l.i.c.a.t.i.o.
0x14b5f0 6e002f0078002d00700072006f007400 n./.x.-.p.r.o.t.
0x14b600 6f006200750066000d000a0000000000 o.b.u.f.........
0x14b610 5b004800650061007200740062006500 [.H.e.a.r.t.b.e.
0x14b620 610074005d0020004200610063006b00 a.t.]. .B.a.c.k.
0x14b630 670072006f0075006e00640020007700 g.r.o.u.n.d. .w.
0x14b640 6f0072006b0065007200200074006800 o.r.k.e.r. .t.h.
0x14b650 720065006100640020007300 r.e.a.d. .s.
0x14bca8 726f6365737320746f6b656e2e000000 rocess token....
0x14bcb8 53006500440065006200750067005000 S.e.D.e.b.u.g.P.Adjusts token privileges then launches a process
0x14bcc8 72006900760069006c00650067006500 r.i.v.i.l.e.g.e.
0x14bcd8 00000000000000004661696c65642074 ........Failed t

Loading traits…

Identity

SHA-256 07448a01829d8d916d2b7bcf91e1fb4731ea51febdb71af48d594639f4cb1cde
Canonical SHA-256 02cf5f2f661ed3b0f9eeb001cb96f8ca50f79dd58924296fe68d4b22c707f6be
Filename virussign.com_295198a1ac16f495efba7bdb7e28d950.vir
Package 07448a01829d8d916d2b7bcf91e1fb4731ea51febdb71af48d594639f4cb1cde

Origin

Source harvest
Feed virussign
Domain virussign.com

Timeline

First seen 21 Jul 2026 13:49 UTC
First analyzed 23 Jul 2026 22:34 UTC
Last analyzed 23 Jul 2026 23:28 UTC
Last updated 23 Jul 2026 23:28 UTC

Labeling

Label bad
Label source harvest
Traits version 4c34e