MALICIOUS — virussign.com_cc4af38de646e9b45803a88a2ae6d630.vir
MALICIOUS — virussign.com_cc4af38de646e9b45803a88a2ae6d630.vir is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (91/100), attributed to the Cuegoe family. 4 of 52 detection engines flagged it.
Identification
- SHA-256:
10c46126368731f36ec2277a3fa39504b25295c27eb1e365edc94c0284f931fd - SHA-1:
71e0ec18aaaff4a7be94f7fe1d11be8edd1698b0 - MD5:
cc4af38de646e9b45803a88a2ae6d630 - imphash:
6dca3e9fb3928bbdb54dbce669943ec8 - ssdeep:
49152:w/OJDMuZNGEADt7i+/yTukuFGNLrkBirx:EOKuZchrSiGdkBirx - TLSH:
T133607FCE07263705C23989257D459DEDA072F8C069B9F93C4F46A03A41E3437EE726A6 - Submitted as: virussign.com_cc4af38de646e9b45803a88a2ae6d630.vir
- File type: pe · Size: 3767296 bytes
- Verdict: malicious (91/100) · Family: Cuegoe
Source: VirusSign · first seen 2026-08-10T00:00:00.000Z · SHA-256 verified
Detections (4 of 52 engines)
- ClamAV (daily): Win.Trojan.Cuegoe-6336261-0
- YARA: JPCERT/CC: JPCERT_Emotet
- Kaspersky (KVRT): HEUR:Backdoor.Win32.Salgorea.gen
- Microsoft Defender: TrojanDownloader:Win32/Upatre
Why this verdict
The malicious score of 91/100 is the fusion of 3 weighted signals:
- ClamAV (daily) flagged Win.Trojan.Cuegoe-6336261-0 (rule
Win.Trojan.Cuegoe-6336261-0) - engine signal, weight 0.90, confidence 0.95 - YARA: JPCERT/CC flagged JPCERT_Emotet (rule
JPCERT_Emotet) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://www.facebook.com/dialog/oauth?display=popup&response_type=token&client_id=, https://graph.facebook.com/v2.1, https://login.windows.local - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://schemas.microsoft.com/SMI/2005/WindowsSettings
- http://schemas.microsoft.com/ado/2007/08/dataservices/metadata
- http://schemas.microsoft.com/ado/2007/06/edmx
- http://schemas.microsoft.com/ado/2006/04/edm
- http://schemas.microsoft.com/ado/2007/05/edm
- http://schemas.microsoft.com/ado/2008/01/edm
- http://www.w3.org/2001/XMLSchema-instance
- http://schemas.microsoft.com/ado/2008/01/edm:OpenType
- http://schemas.microsoft.com/ado/2008/09/edm
- http://schemas.microsoft.com/ado/2006/04/edm/ssdl
- http://schemas.microsoft.com/ado/2009/02/edm/annotation
- http://schemas.microsoft.com/ado/2007/08/dataservices/scheme
- http://www.w3.org/2005/Atom
- http://www.w3.org/2000/xmlns/
- http://schemas.microsoft.com/ado/2006/04/edm/ssdl:StoreGeneratedPattern
- https://www.facebook.com/dialog/oauth?display=popup&response_type=token&client_id=
- https://graph.facebook.com/v2.1
- https://login.microsoft.com
- https://login.windows.local
- https://skyapi.live.net/API/2
- https://api.onedrive.com/v1.0
- https://bn2.notify.windows.com/?token=AwYAAABKhSFaJL06TZgvAzxo0hbS1uz3DhcDx62G5o5IgqmUYpV9pf4y%2fWlN1xUUx5o0rOTHLYX5ABJ7%2bsfubHYFIX5KCgi0ZMvJnUhkxXmQq8QD5mnbpdZQFWUam4eTxLnHc50%3d
- https://media.photos.microsoft.com/v1
- https://media.photos-dev.microsoft.com/v1
- https://groups.photos.microsoft.com/v1
Embedded domains
- schemas.microsoft.com
- www.w3.org
- dev.virtualearth.net
- ns.microsoft.com
- www.facebook.com
- graph.facebook.com
- remix3d.com
- photos.microsoft.com
- sway.com
- ssl.live.com
- login.microsoft.com
- skyapi.live.net
- api.onedrive.com
- ls.users.storage.live.com
- bn2.notify.windows.com
- media.photos.microsoft.com
- media.photos-dev.microsoft.com
- groups.photos.microsoft.com
- groups.photos-dev.microsoft.com
- projects.photos.microsoft.com
- projects.photos-dev.microsoft.com
- users.photos.microsoft.com
- users.photos-dev.microsoft.com
- cloudtile.photos.microsoft.com
- cloudtile.photos-dev.microsoft.com
File paths
- D:\:p:
- f:\dd\tools\devdiv\EcmaPublicKey.snk
- U:\:c:j:q:x:
- P:\:d:
- c:\ba\153\s\photos\packages\microsoft.photos.platformutils.1711.14001\build\inc\StringUtils.h
- C:\BA\153\s\Photos\App\App.Windows\Edit\DelayLoadContentControl.cpp
- C:\BA\153\s\Photos\App\App.Windows\Edit\EditPipelineFrameProcessor.cpp
- C:\BA\153\s\Photos\App\App.Windows\Edit\ImageSavingService.cpp
- c:\ba\153\s\photos\packages\microsoft.photos.imaging.1711.2002\build\inc\XmpSerializerBase.h
- C:\BA\153\s\Photos\packages\Microsoft.Photos.Imaging.1711.2002\Build\inc\CodecMetadataUtil.h
- C:\BA\153\s\Photos\App\App.Windows\Edit\LivingImageEditor.cpp
- C:\BA\153\s\Photos\App\App.Windows\Edit\NewMainImageViewport.cpp
- C:\BA\153\s\Photos\App\App.Windows\Edit\MainImageViewport.cpp
- C:\BA\153\s\Photos\App\App.Windows\Edit\SaveHelper.cpp
- C:\BA\153\s\Photos\App\App.Windows\Viewer\ThumbnailGenerator.cpp
- C:\BA\153\s\Photos\App\App.Windows\Viewer\VideoViewerItem.cpp
- C:\BA\153\s\Photos\App\App.Windows\Viewer\ViewerItemCollection.cpp
- C:\BA\133\s\SmartPropVariant.cpp
- c:\ba\133\s\StringUtils.h
- C:\BA\133\s\BingLocation.cpp
- C:\BA\133\s\Download.cpp
- C:\BA\162\s\CodecStreamUtil.cpp
- C:\BA\162\s\CreateImagingFactory.cpp
- C:\BA\162\s\CodecMetadataUtil.cpp
- c:\ba\162\s\XmpSerializerBase.h
More Cuegoe samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report