Classification: Malicious
HuoRon_Safe_x86.exe is a malicious file sample. Reported by 2 threat sources, last seen 2026-06-05. Detected by 43 antivirus engines.
Detection summary
- 43 antivirus detections
- 4 IDS alerts
- 0 processes observed
- 2 contacted hosts
- 1 DNS requests
Blacklist sightings
| Description |
Source |
First seen |
Last seen |
Labels |
MITRE ATT&CK |
| Generic Malware |
Hybrid-Analysis |
2026-06-05 11:45:04 |
2026-06-05 11:45:04 |
malicious-activity
|
|
| ValleyRAT |
MalwareBazaar Abuse.ch |
2026-06-05 11:33:07 |
2026-06-05 11:33:07 |
malicious-activity
|
|
Sample information
- Filenames
- HuoRon_Safe_x86.exe
- File type
- PE32 executable for MS Windows 6.01 (GUI), Intel i ...
- MD5
47e57856a0675a38e7b8937d4ffbb467
- SHA-1
788f69e61d640f2da5e59bd5c625c5455142637c
- SHA-256
c9460a533e8f214768cbfaa68c486f454083be425e41e0df63777dd41281194c
- First indexed
- 2026-06-05 11:16:17
- Last updated
- 2026-09-03 00:48:16
Antivirus detections
| Engine | Detection |
| ALYac | QD:Trojan.GenericKDQ.0D96178502 |
| AVG | Win32:MalwareX-gen [Drp] |
| AhnLab-V3 | Trojan/Win.Generic.C5893552 |
| Alibaba | Trojan:Win32/ValleyRat.a3729ac6 |
| Antiy-AVL | Trojan/Win32.FakeApp |
| Arcabit | QD:Trojan.GenericQ.0D96178502 |
| Avast | Win32:MalwareX-gen [Drp] |
| Avira | TR/W32.Evo |
| BitDefender | QD:Trojan.GenericKDQ.0D96178502 |
| CTX | exe.trojan.shellcoderunner |
| DeepInstinct | MALICIOUS |
| ESET-NOD32 | Win32/ShellcodeRunner.AFJ trojan |
| Emsisoft | QD:Trojan.GenericKDQ.0D96178502 (B) |
| F-Secure | Dropper.DR/W32.MalwareX |
| Fortinet | W32/ShellcodeRunner.AFJ!tr |
| GData | QD:Trojan.GenericKDQ.0D96178502 |
| Google | Detected |
| K7AntiVirus | Trojan ( 006e11871 ) |
| K7GW | Trojan ( 006e11871 ) |
| Kaspersky | Trojan-Dropper.Win32.Agent.tkgfbf |
| Kingsoft | Win32.Trojan-Dropper.Agent.tkgfbf |
| MaxSecure | Trojan.Malware.689119401.susgen |
| McAfeeD | ti!C9460A533E8F |
| MicroWorld-eScan | QD:Trojan.GenericKDQ.0D96178502 |
| Microsoft | Trojan:Win32/ValleyRat!MSR |
| Paloalto | generic.ml |
| Panda | Trj/PhxBzA.A |
| Rising | Dropper.Agent!8.2F (CLOUD) |
| Sangfor | Trojan.Win32.Silverfox.Cont |
| Skyhigh | Artemis |
| Sophos | Mal/Generic-S |
| Symantec | Trojan.Gen.MBT |
| Tencent | Malware.Win32.Gencirc.10c4851c |
| TrellixENS | Artemis!47E57856A067 |
| TrendMicro | Trojan.Win32.ZYX.USBLF526 |
| TrendMicro-HouseCall | Trojan.Win32.ZYX.USBLF526 |
| VBA32 | Backdoor.Pallas |
| VIPRE | QD:Trojan.GenericKDQ.0D96178502 |
| Varist | W32/ABmTrojan.CONY-2088 |
| VirIT | Trojan.Win32.DelphGen.JUB |
| Xcitium | Malware@#1qfk7dchygke7 |
| alibabacloud | Trojan[dropper]:Win/ShellcodeRunner.A#U |
| huorong | HEUR:Trojan/FakeApp.aam |