Open-source atomic malware analysis

Analyze another

Trojan.Danger_Trojan.GenericKD.72677122_145.vir

PE
Verdict: HOSTILE
Mal-ecule
KO₆(As₉Er₂C₅IP₂S)H₂(FPo₃)Md₅(Bi₆SiPa)
Size 48.0 KB download
First seen 54 days ago
Analyzed 45 days ago
Ecosystem datamaliciousorder

Well-known

hostile severity, 98% confident.
malware/dropper Chocolatey-mimic dropper with Linux tool decoys

Objectives

notable severity, 75% confident.
anti-static/obfuscation Minimal PE imports with dynamic loading
notable severity, 82% confident.
evasion/self-delete cmd /c del argument fragment

Micro-behaviors

notable severity, 80% confident.
fs/path References legacy DOS/Windows boot configuration files
notable severity, 95% confident.
process/inject Dynamic LoadLibraryA resolution for remote injection
baseline severity, 95% confident.
mem/protect Modify memory page protection

Metadata

notable severity, 92% confident.
binary Overlay exceeds one-third
notable severity, 90% confident.
encoded-payload Encoded payload detected: xor
notable severity, 80% confident.
signed::unsigned-pe-executable PE executable is unsigned
notable severity, 100% confident.
unsigned Binary is not digitally signed
baseline severity, 95% confident.
binary/section UPX packed section name
baseline severity, 95% confident.
dylib::kernel32 links KERNEL32.DLL (LoadLibraryA, ExitProcess, GetProcAddress, VirtualProtect)
baseline severity, 95% confident.
dylib::mfc42 links MFC42.DLL (ORDINAL 859)
baseline severity, 95% confident.
dylib::msvcrt links MSVCRT.dll (exit)
baseline severity, 95% confident.
dylib::shell32 links SHELL32.dll (SHChangeNotify)
baseline severity, 95% confident.
dylib::user32 links USER32.dll (LoadIconA)
baseline severity, 100% confident.
hardening Writable and executable section (W^X violation)
baseline severity, 100% confident.
hardening::no-pie Binary is not position-independent (fixed load address)
baseline severity, 100% confident.
signed::unsigned Binary is not digitally signed

binary

notable severity, 90% confident.
embedded Embedded PE binary at file offset 0x28fa (~69632 bytes)

20 of 44 traits shown

Identity

SHA-256 8932e9fe7509d707b08ab75218b131249a5134c6d4b3bd9ffdb63ae4f3f43f1a
Filename Trojan.Danger_Trojan.GenericKD.72677122_145.vir

Origin

Source harvest
Feed datasets
Ecosystem datamaliciousorder

Timeline

First seen 24 Apr 2026 16:14 UTC
Last analyzed 3 May 2026 07:43 UTC
Last updated 4 May 2026 14:48 UTC

Labeling

Label bad
Label source harvest
Traits version b2c18