SUSPICIOUS — virussign.com_1328df8017d95a796c4f03d820ab6cb0.vir
SUSPICIOUS — virussign.com_1328df8017d95a796c4f03d820ab6cb0.vir is a archive sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (35/100). 1 of 54 detection engines flagged it.
Identification
- SHA-256:
00bd8a0bddc4ca0c3934848985f561cf6e5e4cac96962cc381fb950f07b2bd1c - SHA-1:
75abfd27e92b683694ed92c6fbac644a04720cd2 - MD5:
1328df8017d95a796c4f03d820ab6cb0 - ssdeep:
768:pV1WBrgYTVdM9X5GPaw6xTh08p/k5Nm90PjIHl:pV1WBpVmgaFTh0q/GNv8F - TLSH:
T1EE2DE19F7637B5DA5E8F11E94BB903C744B095D20E30EC91CF58D82D13AB5A0B502A5C - Submitted as: virussign.com_1328df8017d95a796c4f03d820ab6cb0.vir
- File type: archive · Size: 27208 bytes
- Verdict: suspicious (35/100)
Source: VirusSign · first seen 2026-08-23T00:00:00.000Z · SHA-256 verified
Detections (1 of 54 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
Why this verdict
The suspicious score of 35/100 is the fusion of 2 weighted signals:
- MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report