MALICIOUS — virussign.com_6f43e459f966ad17f6fc04526e7d4cd0.vir
MALICIOUS — virussign.com_6f43e459f966ad17f6fc04526e7d4cd0.vir is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100), attributed to the Muldrop family. 4 of 51 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
13a7c74884f5221c18f42f8f5262305d8e5750b8c9896f4808d27f6eaff2bc0a - SHA-1:
e5bf17a24f343dcb9258b9f44bca49a6df3c64ba - MD5:
6f43e459f966ad17f6fc04526e7d4cd0 - imphash:
b7b1d154ca47a083b83fddc13f54b733 - ssdeep:
3072:GEdXV+o5HbU4kx6+FXUo9y6sY3vMqgviui:GEeoqd6+39psY3Eqgviu - TLSH:
T1B6418EAF309249BFC30A63847BD018CC17E353DA21575CAAE148DA99D9B53FBAD90071 - Submitted as: virussign.com_6f43e459f966ad17f6fc04526e7d4cd0.vir
- File type: pe · Size: 188428 bytes
- Verdict: malicious (99/100) · Family: Muldrop
Source: VirusSign · first seen 2026-07-29T00:00:00.000Z · SHA-256 verified
Detections (4 of 51 engines)
- ClamAV (daily): Win.Malware.Midie-6847893-0
- Microsoft Defender: TrojanDropper:Win32/Muldrop.V!MTB
- Emsisoft (Emergency Kit): Gen:Heur.Conjar.9
- Kaspersky (KVRT): HEUR:Trojan.Win32.Agent.pef
MITRE ATT&CK
Why this verdict
The malicious score of 99/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Win.Malware.Midie-6847893-0 (rule
Win.Malware.Midie-6847893-0) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged TrojanDropper:Win32/Muldrop.V!MTB (rule
TrojanDropper:Win32/Muldrop.V!MTB) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Gen:Heur.Conjar.9 (rule
Gen:Heur.Conjar.9) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Trojan.Win32.Agent.pef (rule
HEUR:Trojan.Win32.Agent.pef) - engine signal, weight 0.55, confidence 0.85 - Contacted 62 external host(s) at runtime (3 HTTP) - network signal, weight 0.40, confidence 0.80
- Embedded network infrastructure: http://purl.org/dc/elements/1.1/, http://www.iec.ch - static signal, weight 0.35, confidence 0.60
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
11319 behavior events · 1 ATT&CK techniques · 0 dropped files.
Runtime network
- settings-win.data.microsoft.com
- 250.255.255.239.in-addr.arpa
- www.msftconnecttest.com
- login.live.com
- desktop-hsgcbep
- ctldl.windowsupdate.com
- 1.0.240.10.in-addr.arpa
- 2.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 251.0.0.224.in-addr.arpa
- 3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa
- 252.0.0.224.in-addr.arpa
- ocsp.digicert.com
- 172.30.101.151.in-addr.arpa
- 19.167.190.20.in-addr.arpa
- 157.37.11.23.in-addr.arpa
- tas02.sls.update.microsoft.com
- v10.events.data.microsoft.com
- 137.92.232.135.in-addr.arpa
- _dosvc._tcp.local
Embedded URLs
- http://www.w3.org/1999/02/2r-rdf-syntax-ns#
- http://ns.adobe.com/xap/1.0/
- http://purl.org/dc/elements/1.1/
- http://ns.adobe.com/photoshop/1.0/
- http://ns.adobe.com/xap/1.0/mm/
- http://ns.adobe.com/xap/1.0/sType/ResourceRef#
- http://www.iec.ch
Embedded domains
- ns.adobe.com
- www.w3.org
- purl.org
- www.iec.ch
Embedded IP addresses
- 74.178.232.29
- 135.232.92.137
- 52.123.252.246
- 52.168.117.168
- 172.172.255.218
- 20.42.179.204
- 89.238.68.201
- 40.84.97.4
- 4.247.188.233
- 52.168.117.174
- 57.155.101.212
- 20.42.65.90
- 4.247.188.224
- 57.154.63.210
- 57.155.104.224
- 13.89.179.15
- 48.211.4.16
- 72.154.7.111
- 135.234.160.246
- 20.165.94.63
- 52.148.114.188
- 172.178.240.162
- 20.42.65.84
- 135.233.45.221
- 172.172.255.216
File paths
- C:\Program
More Muldrop samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report