MALICIOUS — virussign.com_698554c4d20c392595430416891e2aa0.vir
MALICIOUS — virussign.com_698554c4d20c392595430416891e2aa0.vir is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (96/100), attributed to the DarkKomet family. 4 of 51 detection engines flagged it.
Identification
- SHA-256:
1af54b641cbb9eafbf85e8d25ae0b7fe8429d6e69e8638c82fec869ca6b403cd - SHA-1:
42495fbc93b93501148a23851de1639a8e26f0a0 - MD5:
698554c4d20c392595430416891e2aa0 - imphash:
bcb2984bb21f1c40fe33fe33b54f6fa8 - ssdeep:
3072:tiUPBWryHbT6s37SD85NOXc9vSHGR+Hgoh36iW/IQdQuHxmp:11T6g/sc9eV1l2Iaxmp - TLSH:
T121407B108A188F32C57606D25071E61F65E396F9AEAF78841196B87FC38399B5400FFB - Submitted as: virussign.com_698554c4d20c392595430416891e2aa0.vir
- File type: pe · Size: 172048 bytes
- Verdict: malicious (96/100) · Family: DarkKomet
Source: VirusSign · first seen 2026-07-29T00:00:00.000Z · SHA-256 verified
Detections (4 of 51 engines)
- ClamAV (daily): Win.Dropper.DarkKomet-9996694-0
- Microsoft Defender: Backdoor:Win32/Xtrat.A
- Emsisoft (Emergency Kit): Gen:Variant.Symmi.3424
- Kaspersky (KVRT): Worm.Win32.WBNA.ipi
Why this verdict
The malicious score of 96/100 is the fusion of 3 weighted signals:
- ClamAV (daily) flagged Win.Dropper.DarkKomet-9996694-0 (rule
Win.Dropper.DarkKomet-9996694-0) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Backdoor:Win32/Xtrat.A (rule
Backdoor:Win32/Xtrat.A) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Gen:Variant.Symmi.3424 (rule
Gen:Variant.Symmi.3424) - engine signal, weight 0.55, confidence 0.85
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- none
File paths
- C:\Windows\system32\msvbvm60.dll\3
More DarkKomet samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report