MALICIOUS — virussign.com_927392a3240d27abb48382b8bcc9abf0.vir
MALICIOUS — virussign.com_927392a3240d27abb48382b8bcc9abf0.vir is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (86/100), attributed to the Neshuta family. 4 of 52 detection engines flagged it.
Identification
- SHA-256:
0f6b50514697292ab978aa330d08cda081b5d639386039910f8dde82249c80b5 - SHA-1:
111cd862e9566884a20c1ae3f566c2cf7c3c07c7 - MD5:
927392a3240d27abb48382b8bcc9abf0 - imphash:
9f4693fc0c511135129493f2161d1e86 - ssdeep:
49152:N3SjbhjG7YaVmWDSzYNVQ2QtfTupnO96:NObL2dPNNQxupO96 - TLSH:
T19E5A33267AE4831FCD97C62194CCB5FCD16339752A4A2C6EE9D6087DB348C63F52006A - Submitted as: virussign.com_927392a3240d27abb48382b8bcc9abf0.vir
- File type: pe · Size: 2130432 bytes
- Verdict: malicious (86/100) · Family: Neshuta
Source: VirusSign · first seen 2026-08-12T00:00:00.000Z · SHA-256 verified
Detections (4 of 52 engines)
- ClamAV (daily): Win.Trojan.Neshuta-1
- Microsoft Defender: Virus:Win32/Neshta.A
- Emsisoft (Emergency Kit): Win32.Neshta.A
- Kaspersky (KVRT): Virus.Win32.Neshta.a
Why this verdict
The malicious score of 86/100 is the fusion of 1 weighted signal:
- ClamAV (daily) flagged Win.Trojan.Neshuta-1 (rule
Win.Trojan.Neshuta-1) - engine signal, weight 0.90, confidence 0.95
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
More Neshuta samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report