MALICIOUS — virussign.com_592bd9790aac4a26f25fdf3530a13f40.vir
MALICIOUS — virussign.com_592bd9790aac4a26f25fdf3530a13f40.vir is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (97/100), attributed to the Floxif family. 5 of 52 detection engines flagged it.
Identification
- SHA-256:
19fc6633100d4edfbe193d9fecc1809c0f87ebccb0105cd50656d72885fcf150 - SHA-1:
d5bae8976db7de9280329570406c3857475d2c90 - MD5:
592bd9790aac4a26f25fdf3530a13f40 - imphash:
af010173fe44e392897bd69e1f443733 - ssdeep:
12288:EpLHRs9oZJ3Ix6BZNk3R8AyevPaBjvrEH7l:EpDRsmZJ3IUSeAXnsrEH7l - TLSH:
T1094A9E951602A654E5B29E506C805F5D60A3FCCFE27F344C62C7D6AF37CAC8B202E196 - Submitted as: virussign.com_592bd9790aac4a26f25fdf3530a13f40.vir
- File type: pe · Size: 447431 bytes
- Verdict: malicious (97/100) · Family: Floxif
Detections (5 of 52 engines)
- ClamAV (daily): Win.Virus.Pioneer-9111434-0
- YARA: Yara-Rules community: YR_AntiDebug_Checks
- Microsoft Defender: Virus:Win32/Floxif.H
- Emsisoft (Emergency Kit): Win32.Floxif.A
- Kaspersky (KVRT): Virus.Win32.Pioneer.cz
Why this verdict
The malicious score of 97/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Win.Virus.Pioneer-9111434-0 (rule
Win.Virus.Pioneer-9111434-0) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Virus:Win32/Floxif.H (rule
Virus:Win32/Floxif.H) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Win32.Floxif.A (rule
Win32.Floxif.A) - engine signal, weight 0.55, confidence 0.85 - YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
File paths
- C:\OIDD
More Floxif samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report