SUSPICIOUS — virussign.com_ec2bbe8663904d5f17dd7e9f5797ed90.vir
SUSPICIOUS — virussign.com_ec2bbe8663904d5f17dd7e9f5797ed90.vir is a html sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (54/100). 0 of 54 detection engines flagged it.
Identification
- SHA-256:
075d383f933bd85b00284d27c4453e560af2266b5b11954c0adad4eb885e43f9 - SHA-1:
a4179e94f691939508b99b911b9debb28e35071c - MD5:
ec2bbe8663904d5f17dd7e9f5797ed90 - ssdeep:
3072:g1PJrjkElUhw2h4TZm+yvloXGSSjkDImEMlBEJoNZkxqbreZmU:faGSSjkDQo3kxqbreZb - TLSH:
T1BC425C61231D2ECFEA94050DF59C286E09A2E7DB481034A5C6D4CF8FAD25DB1B4CD1AB - Submitted as: virussign.com_ec2bbe8663904d5f17dd7e9f5797ed90.vir
- File type: html · Size: 210659 bytes
- Verdict: suspicious (54/100)
Source: VirusSign · first seen 2026-08-23T00:00:00.000Z · SHA-256 verified
Detections (0 of 54 engines)
No engine flagged this sample.
Why this verdict
The suspicious score of 54/100 is the fusion of 4 weighted signals:
- Obfuscated javascript script: dynamic-exec, defense-evasion (rule
script-deobfuscation) - static signal, weight 0.55, confidence 0.75 - Contacted 16 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: https://nivavostore.com/, https://fonts.shopifycdn.com, http://nivavostore.com/cdn/shop/files/NIVAVOSTORE.png?v=1761488572 - static signal, weight 0.35, confidence 0.60
- Extracted generic config (11 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
286 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- c.pki.goog
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
- ctldl.windowsupdate.com
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- windows.msn.com
- www.msn.com
- settings-win.data.microsoft.com
- assets.msn.com
Embedded URLs
- https://nivavostore.com/
- https://fonts.shopifycdn.com
- http://nivavostore.com/cdn/shop/files/NIVAVOSTORE.png?v=1761488572
- https://nivavostore.com/cdn/shop/files/NIVAVOSTORE.png?v=1761488572
- https://cdn.shopify.com/shopifycloud/shop-js
- https://cdn.shopify.com/shopifycloud/storefront-forms-hcaptcha/ce_storefront_forms_captcha_hcaptcha.v1.5.2.iife.js
- https://nivavostore.com/cdn/shopifycloud/portable-wallets/latest/portable-wallets.pl.js
- https://nivavostore.com/cdn/shopifycloud/privacy-banner/storefront-banner.js
- https://timer.samita.io
- https://cdn.shopify.com/storefront/web-components/chat.js
- https://cdn.shopify.com/extensions/01a00e06-8024-7b5e-85f3-9af50f187752/aov-bundle-upsell-152/assets/aov-offer.js
- https://cdn.shopify.com/extensions/019ffb76-b9fc-703c-a000-e94b0d27e4ab/countdown-timer-bar-samita-113/assets/samita.countdowns.index.js
- https://monorail-edge.shopifysvc.com
- https://monorail-edge.shopifysvc.com/v1/produce
- https://nivavostore.com
- https://extensions.shopifycdn.com/cdn/shopifycloud/web-pixels-manager
- https://nivavostore.com/.well-known/shopify/monorail/unstable/produce_batch
- https://nivavostore.com/cdn
- https://nivavostore.com/cdn/shopifycloud/perf-kit/shopify-perf-kit-3.8.4.min.js
- https://nivavostore.com/api/collect
- http://www.w3.org/2000/svg
- https://nivavostore.com/customer_authentication/redirect?locale=pl®ion_country=PL
- https://www.facebook.com/profile.php?id=61575061651428
- https://www.instagram.com/nivavostore/
- http://schema.org
Embedded domains
- nivavostore.com
- fonts.shopifycdn.com
- 80e8uw-nc.myshopify.com
- cdn.shopify.com
- cdn.hextom.com
- tools.luckyorange.com
- json-schema.org
- timer.samita.io
- link.link
- li.ga
- monorail-edge.shopifysvc.com
- x.name
- entry.name
- extensions.shopifycdn.com
- api.trustoo.io
- api.parcelpanel.com
- gmail.com
- www.w3.org
- www.facebook.com
- www.instagram.com
- schema.org
- x1.c.lencr.org
- x2.c.lencr.org
- ye.c.lencr.org
- yr.c.lencr.org
Embedded IP addresses
- 14.07.21.35
- 07.07.14.21
- 21.07.35.14
- 49.14.21.35
- 63.14.77.35
- 14.21.21.49
- 1.05.35.21
- 21.35.56.35
- 49.14.14.28
- 21.49.21.28
- 1.12.35.28
- 77.28.14.35
- 40.74.98.198
- 52.123.252.234
- 4.230.171.124
- 20.42.179.204
- 52.230.60.54
- 74.178.240.51
- 4.150.223.97
- 74.178.76.128
- 20.42.65.88
- 172.64.154.167
- 72.145.35.110
- 52.148.114.188
- 52.110.12.31
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report