MALICIOUS — virussign.com_2c2c5ba7fd6cadadee92ba42e9c51ea0.vir
MALICIOUS — virussign.com_2c2c5ba7fd6cadadee92ba42e9c51ea0.vir is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (99/100), attributed to the Fesber family. 7 of 51 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
160afd4c2c365087175ef92dc090cae16ff684ec6ebaa8b3d7dc6628ad907d40 - SHA-1:
e1b5cc668df8858d766a9f4366e16eb157921307 - MD5:
2c2c5ba7fd6cadadee92ba42e9c51ea0 - imphash:
8679c8c71268858668c3b616f436e78f - ssdeep:
6144:/moPA4fzTdlYWcAp/y+3G+h6pny8Lg7oUGysT4196:/moDbhcApl3G+hqnlLg7lMT296 - TLSH:
T13345ADB6D2811A0CCFA786821CC5157E14E39CBA6C6D28C1E317CCED32DB46B29506F5 - Submitted as: virussign.com_2c2c5ba7fd6cadadee92ba42e9c51ea0.vir
- File type: pe · Size: 272567 bytes
- Verdict: malicious (99/100) · Family: Fesber
Source: VirusSign · first seen 2026-07-29T00:00:00.000Z · SHA-256 verified
Detections (7 of 51 engines)
- ClamAV (daily): Win.Trojan.Delf-6717398-0
- YARA: delivr.to detections: DLV_Maldoc_VBA_AutoExec
- YARA: JPCERT/CC: JPCERT_Emotet
- YARA: Stratosphere IPS: STRATO_IRC_Botnet
- Microsoft Defender: Worm:Win32/Fesber!pz
- Emsisoft (Emergency Kit): Gen:Variant.Adware.Babar.21817
- Kaspersky (KVRT): Trojan.Win32.IRCbot.aibn
MITRE ATT&CK
Why this verdict
The malicious score of 99/100 is the fusion of 7 weighted signals:
- ClamAV (daily) flagged Win.Trojan.Delf-6717398-0 (rule
Win.Trojan.Delf-6717398-0) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Worm:Win32/Fesber!pz (rule
Worm:Win32/Fesber!pz) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Gen:Variant.Adware.Babar.21817 (rule
Gen:Variant.Adware.Babar.21817) - engine signal, weight 0.55, confidence 0.85 - YARA: delivr.to detections flagged DLV_Maldoc_VBA_AutoExec (rule
DLV_Maldoc_VBA_AutoExec) - engine signal, weight 0.35, confidence 0.70 - YARA: JPCERT/CC flagged JPCERT_Emotet (rule
JPCERT_Emotet) - engine signal, weight 0.35, confidence 0.70 - YARA: Stratosphere IPS flagged STRATO_IRC_Botnet (rule
STRATO_IRC_Botnet) - engine signal, weight 0.35, confidence 0.70 - communicate over HTTP (rule
communicate over HTTP) - capa signal, weight 0.30, confidence 0.60
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
Embedded domains
- irc.lcirc.net
More Fesber samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report