MALICIOUS — virussign.com_f0efe5df53c012202ce100a07ba49cc0.vir
MALICIOUS — virussign.com_f0efe5df53c012202ce100a07ba49cc0.vir is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (94/100), attributed to the Crypted family. 6 of 55 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
0206af42c59e8a4687b5b8150f73435f65a58004f28b14e1e618c1bd876642d7 - SHA-1:
97c022480c8b29eaeedd0ba8826320eb29e65d5f - MD5:
f0efe5df53c012202ce100a07ba49cc0 - imphash:
0b36fc85e0cb5e337c80982db5210969 - ssdeep:
1536:rdeHMC6ZZXz50NmtBGkE60wxtsSDcSHzZuYDPU:rdE6vXz5umx7DueTZuY7U - TLSH:
T123364B66AD306504CDB8E567604EFB6E897F21787F7B27300135A861A4C205B7FE20B9 - Submitted as: virussign.com_f0efe5df53c012202ce100a07ba49cc0.vir
- File type: pe · Size: 65653 bytes
- Verdict: malicious (94/100) · Family: Crypted
Source: VirusSign · first seen 2026-08-20T00:00:00.000Z · SHA-256 verified
Detections (6 of 55 engines)
- ClamAV (daily): Win.Trojan.Crypted-29
- YARA: Yara-Rules community: YR_AntiDebug_Checks
- Kaspersky (KVRT): Trojan-Proxy.Win32.Qukart.gen
- Microsoft Defender: Trojan:Win32/Cerber!pz
- Emsisoft (Emergency Kit): Dropped:Backdoor.Padodor.BJ
- Trellix Stinger (McAfee): Trojan-FUGH!F0EFE5DF53C0
MITRE ATT&CK
Why this verdict
The malicious score of 94/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Win.Trojan.Crypted-29 (rule
Win.Trojan.Crypted-29) - engine signal, weight 0.90, confidence 0.95 - Contacted 24 external host(s) at runtime (21 HTTP) - network signal, weight 0.40, confidence 0.80
- YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70 - Dropped 92 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
2947 behavior events · 1 ATT&CK techniques · 92 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- oneocsp.microsoft.com
- licensing.mp.microsoft.com
- www.msn.com
Dropped files
- C:\Windows\System32\Okhbkcaj.dll -
fc6d8a6d94d2ed857b456bac50c0da2ae08d4fd4b4e88509efd15acd01fd9dee - C:\Windows\System32\Mnciepal.dll -
b2da8675a8d8136a7d24eefe37302633ace95bfb3b392de39255a9f758b4a28d - C:\Windows\System32\Abeaqfea.dll -
cae9a5b0a4f98f60b5b842e0ebc570d71b65f3eab2590b91d0979da9a6ecc3f8 - C:\Windows\System32\Jacfokcc.dll -
d3bc1f20f3b1d48bcfe138da2688eb1889e54fb5d5b9c3dd141d87a6ac1393da - C:\Windows\System32\Egjncm32.exe -
e8d4e66a70474b697295583584b93126ad74e340f7949033e5dc5ae222907cf7 - C:\Windows\System32\Moeheamp.dll -
2749ece478ab1b7ec341486e78bb3a6805523b8ea0f5716877509c7ab8bd19d8 - C:\Windows\System32\Pekckd32.dll -
9f542ea4d3faa5f7925726b793ca23ded4c2733b71a9496c2fc5773e4784005b - C:\Windows\System32\Okpapaba.exe -
06dd7e8315f63dad851d27963176f014cd2a829d8fd50efcaca74863000a8592 - C:\Windows\System32\Nnemcc32.dll -
27370e77e13dcef812d587f1d3996bbd8e79c3b60688592718fb4ed47857b86d - C:\Windows\System32\Eoheoj32.dll -
05c8785ff0827dc03cd9439c5c82f6340dc319ff4dd985368ae7cdeb9dadf402 - C:\Windows\System32\Oeipgjif.dll -
1a90b162b2b48a45397b2d446a5f7c990a70f7f6b602afb3e2b1e6490828b52e - C:\Windows\System32\Hjaohioc.exe -
3b332cfe0531ec4cee5381adc56342a09ddeded594a88aad517dde604ad8b14a - C:\Windows\System32\Glcdnpdi.exe -
ef989a0c2844d26c2feac192bbfd7d1699d65277efff77f94320767a44ad0b6f - C:\Windows\System32\Dnlogjpl.exe -
f74a93967dfac1c6874d083663c2af2f919add333f6c994eb9a2ab37704968a9 - C:\Windows\System32\Iocibl32.exe -
115a2f0404b77b3b46e83715a50bd39099f9b794b3693419cf258dec17b56338
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/753bb2df-a166-494f-aa7d-5678b1ef0c56/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/753bb2df-a166-494f-aa7d-5678b1ef0c56?P1=1787849709&P2=404&P3=2&P4=QUrzyOEmwvz%2bQaEV1kGsNe32WNkRR0EApnI0CFOqwXCVauPtzRq8zoWLGToRnLsxnuKVESQMyQe7YgUaT%2bbfow%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c74a5353-3e6a-42b7-94d6-9b96c560c89a/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c74a5353-3e6a-42b7-94d6-9b96c560c89a?P1=1787849809&P2=404&P3=2&P4=nt0K%2fdDJ1aVtYXmF9xrBcGJfzVG7w2oWHRUW%2bozHKlhNl76oiyV%2faVJQ5BFVbZcs90G8%2frCmRF2DEB9L%2b2ctnA%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Embedded IP addresses
- 4.150.223.98
- 4.144.132.223
- 4.230.171.124
- 85.210.196.11
- 74.178.240.61
- 52.182.143.212
- 74.179.77.164
- 52.123.128.14
- 20.112.250.133
- 40.99.133.210
- 203.26.79.13
- 52.168.117.170
- 172.178.240.162
- 92.223.78.30
- 74.178.76.44
- 52.148.114.188
- 72.153.5.62
- 52.110.12.26
- 52.110.12.48
- 135.233.45.223
- 40.84.85.40
- 4.150.223.109
- 4.150.223.113
- 52.110.12.1
More Crypted samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report