Open-source atomic malware analysis

Analyze another

HEUR-Trojan-PSW.Win32.Convagent.gen-43d178652432d3e7e9c5e673df3255440529309aaaeb5e0e0533080fd2c288a8

PE
Verdict: SUSPICIOUS
AI UPX packed PE with RWX section
Mal-ecule
O₂(AsC)H(Db)Md(Bi)
Size 3.1 MB download
First seen 85 days ago
Analyzed 34 days ago
Ecosystem MalwareBazaar
HEUR-Trojan-PSW.Win32.Convagent.gen-43d178652432d3e7e9c5e673df3255440529309aaaeb5e0e0533080fd2c288a8 pe
0x0 4d5a90000300000004000000ffff0000 MZ..............Entry point in writable scrambled UPX section
0x10 8b000000000000004000000000000000 ........@.......
0x20 00000000000000000000000000000000 ................
0x30 00000000000000000000000080000000 ................
0x40 0e1fba0e00b409cd21b8014ccd215468 ........!..L.!Th
0x50 69732070726f6772616d2063616e6e6f is program canno
0x60 74206265 t be
0x168 00000000000000000000000000000000 ................
0x178 55505830000000000050860000100000 UPX0.....P......
0x188 00000000000200000000000000000000 ................
0x198 00000000800000e05550583100000000 ........UPX1....
0x1a8 00403200006086000036320000020000 .@2..`...62.....
0x1b8 000000000000000000000000 ............
0x1f0 352e303200555058210d090e0a66763f 5.02.UPX!....fv?
0x200 b1567c27c9a36bb8007428320000e0b1 .V|'..k..t(2....Entry point in writable scrambled UPX section
0x210 00263400631a030045810067d4e53538 .&4.c...E..g..58
0x220 1879eaf33c5d377b3d8620d493d100f2 .y..<]7{=. .....
0x230 91d190dc51452a40163145f2e3caf438 ....QE*@.1E....8
0x240 a8eda86ef19398d26bddedb0485068 ...n....k...HPh
0x3237f0 00000000000000000000000000000000 ................
0x323800 0000000000000000000000003ca0b800 ............<...Entry point in writable scrambled UPX section
0x323810 28a0b800000000000000000000000000 (...............
0x323820 00000000 ....

Objectives

Micro-behaviors

Metadata

anti-static

hostile severity, 100% confident.
packer/upx UPX decompression failed: IO error: No such file or directory (os error 2)
suspicious severity, 100% confident.
packer Binary contains a UPX packing marker

Identity

SHA-256 43d178652432d3e7e9c5e673df3255440529309aaaeb5e0e0533080fd2c288a8
Filename HEUR-Trojan-PSW.Win32.Convagent.gen-43d178652432d3e7e9c5e673df3255440529309aaaeb5e0e0533080fd2c288a8

Origin

Source harvest
Feed datasets
Ecosystem MalwareBazaar

Timeline

First seen 1 May 2026 14:09 UTC
First analyzed 12 May 2026 10:56 UTC
Last analyzed 21 Jun 2026 23:35 UTC
Last updated 21 Jun 2026 23:35 UTC

Labeling

Label bad
Label source harvest
Traits version 1f35f