MALICIOUS — virussign.com_e53d1b1a8f99b065072a346567aa8f10.vir
MALICIOUS — virussign.com_e53d1b1a8f99b065072a346567aa8f10.vir is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100), attributed to the Crypted family. 4 of 56 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
022a9fa20757d57e820c0b6e8211a490dfbe62b8304121939d503eb17d6fd2ba - SHA-1:
9105dabdba2070d53ac51c5fbaed14bdd3fdccee - MD5:
e53d1b1a8f99b065072a346567aa8f10 - imphash:
7c9c55b28dfdff534d6d018346b846d1 - ssdeep:
768:EJ8qQrQQ0DET36r3QF7cRLLv+S21rQ99IqY9oj0PUPaSKyDTLKR2p/1H5hXdnhfH:CJoTqTpC+GH9+FPasPKR2LlOy - TLSH:
T1D9354B72A608B69CDFB99526476DFD9CBA91B03D60FA0AC50C12E052DD470DBFD1D088 - Submitted as: virussign.com_e53d1b1a8f99b065072a346567aa8f10.vir
- File type: pe · Size: 60445 bytes
- Verdict: malicious (99/100) · Family: Crypted
Source: VirusSign · first seen 2026-08-25T00:00:00.000Z · SHA-256 verified
Detections (4 of 56 engines)
- ClamAV (daily): Win.Trojan.Crypted-30
- Microsoft Defender: Trojan:Win32/Cerber!pz
- Emsisoft (Emergency Kit): GenPack:Generic.Dacic.1.Backdoor.Hangup.A.9A660621
- Kaspersky (KVRT): Trojan-Proxy.Win32.Qukart.vih
MITRE ATT&CK
Why this verdict
The malicious score of 99/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Win.Trojan.Crypted-30 (rule
Win.Trojan.Crypted-30) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Trojan:Win32/Cerber!pz (rule
Trojan:Win32/Cerber!pz) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged GenPack:Generic.Dacic.1.Backdoor.Hangup.A.9A660621 (rule
GenPack:Generic.Dacic.1.Backdoor.Hangup.A.9A660621) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged Trojan-Proxy.Win32.Qukart.vih (rule
Trojan-Proxy.Win32.Qukart.vih) - engine signal, weight 0.55, confidence 0.85 - Contacted 1 external host(s) and 5 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Dropped 106 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
3482 behavior events · 1 ATT&CK techniques · 106 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- update.googleapis.com
- login.live.com
- licensing.mp.microsoft.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- www.msn.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- assets.msn.com
- www.bing.com
- th.bing.com
- tas02.sls.update.microsoft.com
- settings-win.data.microsoft.com
- v10.events.data.microsoft.com
Dropped files
- C:\Windows\System32\Lmldcbeb.dll -
8d218b465b7e5d691a7c3c85b739c723a44ce7b70401694a44adeea530db52d5 - C:\Windows\System32\Llofkg32.dll -
20c5ecc0447f62e53cbbe81793334f0c59ecb694feecc1b624c3cc9f8225d28b - C:\Windows\System32\Odlqbg32.dll -
a4bee715c7fb6a71a9e0eccd3c5b1fdc01f0396d53a3b32e0f9452a641d2c838 - C:\Windows\System32\Dbileh32.dll -
53873b09ebd599878588117d75fe5e729acac486a0492416110e254b8199ae2f - C:\Windows\System32\Pcdoiqfj.dll -
6b2c7341651ef4bf263b9a0d6d35fe3b952add87571fdc9ee6d69001860c4df0 - C:\Windows\System32\Oefcbfio.exe -
de7f4ab5b589b206aace3b8a34e558ba49f547749d7a84fff788b248cd64d2d7 - C:\Windows\System32\Amepal32.dll -
d976c1d18a3e6cdd70a3ccba00f55e2620eaf6be4346b864d1fcb16a1c7257c6 - C:\Windows\System32\Ahbnlgjd.exe -
a093afafe1077ac026085b64369d28e4139bac0154eebe2f9c7206c1cc72eb4c - C:\Windows\System32\Hqejka32.exe -
79b4291d8c27c3e97e0a7053fa00da67ad609441378056ff3340351475f95c83 - C:\Windows\System32\Jpeokc32.dll -
7ecf72e0a0fe9066e35b0e631c4b2bc1bd21b1ed2051c3eed3cba6b3396a84c4 - C:\Windows\System32\Koejbhhk.exe -
21ff5f905831c0f888a5088c9cbd01a3b6cf1e0869fb450ee5a99e04ad46d576 - C:\Windows\System32\Ohjija32.exe -
14deef71108b3d315d1af4186fbc2d168f3f03138162bc55972fd61a9b8fba9a - C:\Windows\System32\Aolppkgm.dll -
ec692e61c8e3baea92ec9c862b65760c59343f23f451ea67f6888c105e42b268 - C:\Windows\System32\Iabjmb32.dll -
ecfee0cff8a54a58a6aa5f13755c7c06fef65f1a441f078a8855645a718c3520 - C:\Windows\System32\Dikghmib.dll -
cdd270fb2fc9d8d036f3e7891e2b4b42dbe221db0f8055c6f7c17ad3580935c5
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Embedded IP addresses
- 4.144.132.223
- 52.168.117.175
- 52.123.252.224
- 4.230.171.124
- 104.18.33.89
- 40.79.167.10
- 135.232.92.137
- 40.84.97.4
- 135.232.92.97
- 20.165.94.63
- 51.132.193.104
- 172.66.2.5
- 135.233.45.221
- 52.110.12.33
- 52.110.12.55
- 72.145.35.110
- 52.148.114.188
- 92.223.78.30
- 52.110.12.26
- 52.110.12.44
More Crypted samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report