HuoRon_Safe_x86.exe

Classification: Malicious

HuoRon_Safe_x86.exe is a malicious file sample. Reported by 2 threat sources, last seen 2026-06-05. Detected by 43 antivirus engines.

Detection summary

  • 43 antivirus detections
  • 4 IDS alerts
  • 0 processes observed
  • 2 contacted hosts
  • 1 DNS requests

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Generic Malware Hybrid-Analysis 2026-06-05 11:45:04 2026-06-05 11:45:04 malicious-activity
ValleyRAT MalwareBazaar Abuse.ch 2026-06-05 11:33:07 2026-06-05 11:33:07 malicious-activity

Sample information

Filenames
HuoRon_Safe_x86.exe
File type
PE32 executable for MS Windows 6.01 (GUI), Intel i ...
MD5
47e57856a0675a38e7b8937d4ffbb467
SHA-1
788f69e61d640f2da5e59bd5c625c5455142637c
SHA-256
c9460a533e8f214768cbfaa68c486f454083be425e41e0df63777dd41281194c
First indexed
2026-06-05 11:16:17
Last updated
2026-09-03 00:48:16

Antivirus detections

EngineDetection
ALYacQD:Trojan.GenericKDQ.0D96178502
AVGWin32:MalwareX-gen [Drp]
AhnLab-V3Trojan/Win.Generic.C5893552
AlibabaTrojan:Win32/ValleyRat.a3729ac6
Antiy-AVLTrojan/Win32.FakeApp
ArcabitQD:Trojan.GenericQ.0D96178502
AvastWin32:MalwareX-gen [Drp]
AviraTR/W32.Evo
BitDefenderQD:Trojan.GenericKDQ.0D96178502
CTXexe.trojan.shellcoderunner
DeepInstinctMALICIOUS
ESET-NOD32Win32/ShellcodeRunner.AFJ trojan
EmsisoftQD:Trojan.GenericKDQ.0D96178502 (B)
F-SecureDropper.DR/W32.MalwareX
FortinetW32/ShellcodeRunner.AFJ!tr
GDataQD:Trojan.GenericKDQ.0D96178502
GoogleDetected
K7AntiVirusTrojan ( 006e11871 )
K7GWTrojan ( 006e11871 )
KasperskyTrojan-Dropper.Win32.Agent.tkgfbf
KingsoftWin32.Trojan-Dropper.Agent.tkgfbf
MaxSecureTrojan.Malware.689119401.susgen
McAfeeDti!C9460A533E8F
MicroWorld-eScanQD:Trojan.GenericKDQ.0D96178502
MicrosoftTrojan:Win32/ValleyRat!MSR
Paloaltogeneric.ml
PandaTrj/PhxBzA.A
RisingDropper.Agent!8.2F (CLOUD)
SangforTrojan.Win32.Silverfox.Cont
SkyhighArtemis
SophosMal/Generic-S
SymantecTrojan.Gen.MBT
TencentMalware.Win32.Gencirc.10c4851c
TrellixENSArtemis!47E57856A067
TrendMicroTrojan.Win32.ZYX.USBLF526
TrendMicro-HouseCallTrojan.Win32.ZYX.USBLF526
VBA32Backdoor.Pallas
VIPREQD:Trojan.GenericKDQ.0D96178502
VaristW32/ABmTrojan.CONY-2088
VirITTrojan.Win32.DelphGen.JUB
XcitiumMalware@#1qfk7dchygke7
alibabacloudTrojan[dropper]:Win/ShellcodeRunner.A#U
huorongHEUR:Trojan/FakeApp.aam

Network contacts

118.107.9.185 121.199.251.28

DNS requests

update.huorong.cn