Will XAMAS(Xcitium Automated Malware Analysis Service) be added to Xcitium Verdict Cloud?

hi @Nik

I got feedback from the team and they said that this is the normal behavior and there is no issues, those are PE file attributes and there might be some modification like, debug version, packer, crypted and so on. Also having a few suspicious attributes it doesn’t mean the file/sample needs to have final verdict as malware.

no i said that PE Sections are not suspicious like in 2016 or 2017 i have seen that it was SUSPICIOUS but now it doesnt work so pls fix it

I will check with the team for PE section

1 Like

also how can Xcitium rate this as Clean if its rated from SLA as Malicious???

@Nik

kindly share the sha1 , our team will look into it and analyse and mark the file accordingly.

Regarding the PE section our Valkyrie team analysed the images and shared their feedback as " ndata it is a section which will contain the unpacked code from the installer , and entropy can also point to an installer or an packer, these are informational and not decisive when marking a sample as malware "

e7af06c555fa086172b595631de59bd006aae2c6 SHA1

no no no you did not understand me The latest PE Sections wont label as SUSPICIOUS and i saw in 2016 or 2017 it was SUSPICIOUS so thaths the problem that the team needs to fix

about XAMAS


it works perfectly

1 Like

I conveyed to the Valkyrie team to validate the details and investigate further .

1 Like

@nivedithab and fix Static Analysis Overall Verdict and Analysis Problem

@QuickSilverST i have analysed ur sample called ada.exe Xcitium Cloud Verdict
image

@nivedithab also sub to @QuickSilverST JITech Solutions - YouTube

@nik
The team has informed that the issues will be fixed in the newer version of Verdict when it is released.

Regarding the malware file the team will be analysing it.

1 Like

So Static Analysis Overall Verdict and PE Sections and Analysis Problem will be fixed in the new version of Verdict Cloud

@nivedithab right the team said that?

as per the team the issue should be resolved in the newer version.

1 Like

and PE Sections will be also SUSPICIOUS in the new version of Verdict Cloud
wow nice @nivedithab thx

I will recheck with team again to ensure that the issues are resolved in newest version . I have already shared the screenshot and other details with the team

1 Like


, could you check this file again from your end