Threat Database Trojans Trojan.Sivis

Trojan.Sivis

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 16,134
Threat Level: 80 % (High)
Infected Computers: 624
First Seen: September 25, 2012
Last Seen: January 15, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.Sivis
Signature status: No Signature

Known Samples

MD5: fe95d6f2f67500c841e5dc00df48c5c0
SHA1: df145341b70fd5028f9c5bf7dd8d0ba41af12f2a
SHA256: 8C3E7776B4DE824C93CDFFAA7769DA9D53699EC26E437AFBF363578B927686A7
File Size: 9.29 MB, 9286656 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have relocations information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
File Description Plants vs. Zombies
File Version 1.0.0.1051
Internal Name Plants vs. Zombies
Legal Copyright Copyright (C) 2009
Original Filename PlantsVsZombies.exe
Product Name Plants vs. Zombies
Product Version 1.0.0.1051

File Traits

  • 2+ executable sections
  • x86

Block Information

Total Blocks: 7,609
Potentially Malicious Blocks: 3,175
Whitelisted Blocks: 3,217
Unknown Blocks: 1,217

Visual Map

0 ? x x ? 0 x x ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x x 0 0 0 x x x x x x 0 0 x x 0 0 x 0 0 0 x 0 x 0 x x x x x ? x x x x x x x x 0 x x ? x ? 0 0 x x x x x x x x x x x 0 x x x x x 0 x x ? ? 0 ? ? ? ? ? 0 ? ? ? 0 x x x 0 0 0 0 0 x x ? ? ? x x x x ? ? ? ? ? x x x x x ? ? x x x x x x 0 x x x x x 0 x x x x x ? ? x x x x ? ? 0 0 x x x x x ? x ? x x x 0 ? ? ? ? 0 x x x x ? ? x x x ? ? 0 ? ? ? ? 0 0 ? 0 ? 0 0 ? ? ? 0 ? x x x ? ? x 0 ? 0 ? ? 0 ? 0 ? 0 ? ? ? 0 0 0 0 ? 0 0 ? 0 x ? 0 ? ? ? ? ? ? ? 0 x x x ? 0 ? 0 x x x ? ? 0 ? 0 x x x x x x x x x x ? ? 0 x x x 0 ? 0 x ? ? ? 0 ? ? 0 0 0 0 0 0 0 0 0 x x x x x x x x x 0 0 ? ? 0 0 ? ? ? ? ? ? ? ? ? 0 x ? ? ? 0 0 ? x ? ? 0 ? 0 x x x x x x x ? 0 0 0 x ? x 0 x x x x x ? 0 0 0 ? ? ? 0 ? 0 0 x x ? x x x x x x x x x x x x x x x x x x x x x x ? 0 0 ? x ? x x x x 0 x x x x ? ? ? ? 0 ? x x x x x 0 0 x x x x x x x x x 0 0 0 x x x x 0 x x 0 x x x 0 0 x x 0 x x 0 0 0 0 x x x ? 0 ? ? ? x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x x x x x x x x x 0 x x ? ? ? x x x 0 ? x x 0 x x ? 0 ? 0 0 x ? ? 0 ? 0 ? ? 0 ? 0 ? ? x x x x x 0 x x x x x x ? x x x 0 ? x x x x x x 0 x x x x x x x x x x x 0 x 0 x x x x x x x x x 0 0 x 0 x x ? ? 0 0 x x x x x x x x x ? ? x x x x x x x 0 x x 0 x x x x x x x x 0 x 0 x x x 0 x 0 x x x x x x x x x x x x x x ? ? x x x ? ? x x ? ? 0 0 ? 0 0 x x 0 0 0 ? 0 ? ? ? ? ? ? ? x ? ? x x x x x x 0 x x x x x x x 0 x x x x x x x x x ? x x x ? x x x x x ? x ? x ? ? x x x x x x x x x x ? 0 ? x x x ? ? ? x 0 x x x x x x x x x x x 0 0 0 x x 0 0 0 x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x x x x x x x x x 0 0 x x x x 0 x x x x x x x x x 0 0 0 0 x 0 0 0 0 0 0 0 0 x 0 0 x x x x 0 x x x x 0 0 x x x x 0 0 0 0 x x x x x x x x x x x x x x x x x 0 x x 0 x x x 0 0 0 0 0 0 ? 0 x x x 0 x x x x x x x ? x x x x x ? ? 0 ? ? ? 0 0 ? ? ? x x x x x x x x x x x x x x x x x x x x x x ? x x ? 0 ? x ? ? x ? ? x x x x x x x x x x x x x x x ? ? x x x x x x 0 0 0 x x 0 x 0 x 0 x x 0 x x x x x x x ? 0 x x x x x x x x x x x 0 0 x x x x x x x x x x x x x x x x x x 0 0 0 0 0 x 0 0 0 0 0 x 0 0 0 0 0 0 x x x x x x x x x x x x x x x x x x 0 x 0 x x x x x x x x x 0 0 x x 0 x x x x x x ? x x x x x ? ? x 0 x x x x x 0 0 0 0 0 0 0 0 0 0 x x x x x 0 x ? ? ? ? ? ? 0 ? ? x x x ? ? ? 0 ? x ? ? x x x ? 0 ? ? x 0 0 x ? 0 ? ? ? ? ? 0 0 ? 0 ? ? ? ? 0 0 x x x x x x ? ? ? ? 0 0 0 ? ? ? x x x x ? ? ? ? x ? 0 ? 0 0 0 ? ? 0 0 x ? ? ? 0 x x x x x x ? 0 ? ? ? x x x 0 x x x x x x x x x x ? ? x ? 0 ? ? ? ? x ? x 0 ? x x ? ? x 0 ? x x ? 0 ? x x ? ? x x ? ? ? ? ? ? ? ? ? x ? ? x x x x x x x x ? ? ? ? 0 ? x x x x ? ? 0 0 ? x ? x x x x ? ? ? ? x 0 x ? 0 ? x x 0 x ? ? x 0 ? ? ? ? 0 ? 0 0 0 0 x ? ? ? ? ? ? x 0 x x x 0 x x x x 0 x 0 x 0 x x x x x x x x x x x x 0 x x x x x x 0 x x x x 0 x x x x x 0 x 0 0 x x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x x x x x x 0 ? ? 0 x x x x x x ? ? ? ? ? ? ? x ? x ? ? ? ? ? ? ? ? x 0 ? ? x 0 ? ? x x x x x ? ? ? 0 ? ? ? 0 x x x ? x x 0 x x x x 0 0 x 0 x x x 0 0 0 x 0 x 0 x x x 0 0 x x x x x 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x x x x x x x x ? ? ? x x x x x x x x x x x x x x x x x x ? ? x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x x x x x x x 0 x x x x x x x x x x x x x x x x ? ? ? ? x ? ? x ? 0 x x ? x ? ? ? ? ? 0 ? 0 ? ? ? 0 ? 0 x x x ? ? x ? ? ? ? ? x 0 x ? x ? x ? 0 0 ? 0 x x x x x 0 0 x x x ? ? ? ? 0 ? 0 x x x x x x x x x x ? x x 0 x x x x x x x x x x x x x x x x x ? x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x x x x x x x x x x x 0 x x x x x x x x x x x x x x x x x x x x x x x 0 x x x x x x 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x x x x x x x x x x x x x x x x 0 x x x x x x x x x x x x x x x x x 0 x x x x x x 0 x x x x x x x x x x x x 0 x x x x x x x x 0 x x x x x x x x x x x 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x x x x x x x x x x x x x x x x x x x x x x x 0 x x x x x x x x x x x x x x x x x x x x x x x 0 x x x x x x x x x x x x x x x x x 0 x x x x x x x x x x x x x x x x x x x x x x 0 x x x x x x x x x x
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Trending

Most Viewed

Loading...