Open-source atomic malware analysis

Analyze another

HEUR-Trojan-PSW.Win32.Convagent.gen-105707e77e4156ee47c2eb95cfe2bf7b7cf13713fa2d348c6eee607a08b56bbe

PE
Verdict: SUSPICIOUS
AI Heuristic Trojan detection and UPX packing
Mal-ecule
O₂(AsC)H(Db)Md(Bi)
Size 3.1 MB download
First seen 85 days ago
Analyzed 34 days ago
Ecosystem MalwareBazaar
HEUR-Trojan-PSW.Win32.Convagent.gen-105707e77e4156ee47c2eb95cfe2bf7b7cf13713fa2d348c6eee607a08b56bbe pe
0x0 4d5a90000300000004000000ffff0000 MZ..............Entry point in writable scrambled UPX section
0x10 8b000000000000004000000000000000 ........@.......
0x20 00000000000000000000000000000000 ................
0x30 00000000000000000000000080000000 ................
0x40 0e1fba0e00b409cd21b8014ccd215468 ........!..L.!Th
0x50 69732070726f6772616d2063616e6e6f is program canno
0x60 742062652072756e20696e20444f5320 t be run in DOS
0x70 6d6f64652e0d0d0a2400000000000000 mode....$.......
0x80 50450000 PE..
0x168 00000000000000000000000000000000 ................
0x178 55505830000000000060860000100000 UPX0.....`......
0x188 00000000000200000000000000000000 ................
0x198 00000000800000e05550583100000000 ........UPX1....
0x1a8 0040320000708600003a320000020000 .@2..p...:2.....
0x1b8 000000000000000000000000 ............
0x1f0 352e303200555058210d090e0a605ec3 5.02.UPX!....`^.
0x200 98933c1806df7bb800e22b320000f8b1 ..<...{...+2....Entry point in writable scrambled UPX section
0x210 00269300141a030045810067d4e53538 .&......E..g..58
0x220 1879eaf33c5d377b3d8620d493d100f2 .y..<]7{=. .....
0x230 91d190dc51452a40163145f2e3caf43d ....QE*@.1E....=
0x240 c979ff1bc1ade3920213595a718e81 .y........YZq..
0x323bf0 00000000000000000000000000000000 ................
0x323c00 0000000000000000000000003cb0b800 ............<...Entry point in writable scrambled UPX section
0x323c10 28b0b800000000000000000000000000 (...............
0x323c20 00000000 ....

Objectives

Micro-behaviors

Metadata

anti-static

hostile severity, 100% confident.
packer/upx UPX decompression failed: IO error: No such file or directory (os error 2)
suspicious severity, 100% confident.
packer Binary contains a UPX packing marker

Identity

SHA-256 105707e77e4156ee47c2eb95cfe2bf7b7cf13713fa2d348c6eee607a08b56bbe
Filename HEUR-Trojan-PSW.Win32.Convagent.gen-105707e77e4156ee47c2eb95cfe2bf7b7cf13713fa2d348c6eee607a08b56bbe

Origin

Source harvest
Feed datasets
Ecosystem MalwareBazaar

Timeline

First seen 1 May 2026 14:08 UTC
First analyzed 12 May 2026 10:57 UTC
Last analyzed 21 Jun 2026 23:42 UTC
Last updated 21 Jun 2026 23:42 UTC

Labeling

Label bad
Label source harvest
Traits version 1f35f