MALICIOUS — virussign.com_b4e386cf5c39fdd0c1168a1cc41200e0.vir
MALICIOUS — virussign.com_b4e386cf5c39fdd0c1168a1cc41200e0.vir is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (93/100), attributed to the LockBit family. 3 of 56 detection engines flagged it, exhibiting 4 ATT&CK techniques.
Identification
- SHA-256:
1b856fa5c7e58529b15a5ff4917d1276ea6c822378e547ad41beda15fcaf9c8d - SHA-1:
2f19cdfc447a020dfbf5b1ce658ac91f5186288a - MD5:
b4e386cf5c39fdd0c1168a1cc41200e0 - imphash:
d41d8cd98f00b204e9800998ecf8427e - ssdeep:
49152:bknS58A7VXtw+EXcE5bTMP5Z0gP/Z27j8zATj+yg2eXQ7ktvBrrfGCbcg9xOTBcW:zcJMPNZCWtnb9OT0cYj9D+IiDfadW - TLSH:
T117677DB6021F60B1B1F7ECC46C2CEFCDC8A1B198546B8F989503AE5DC89103799D57A8 - Submitted as: virussign.com_b4e386cf5c39fdd0c1168a1cc41200e0.vir
- File type: pe · Size: 6900615 bytes
- Verdict: malicious (93/100) · Family: LockBit
Source: VirusSign · first seen 2026-08-25T00:00:00.000Z · SHA-256 verified
Detections (3 of 56 engines)
- capa (capabilities): capability:execution/powershell
- YARA: Trellix/McAfee ATR: ATR_LockBit_Ransomware
- Emsisoft (Emergency Kit): Trojan.GenericKDZ.118710
MITRE ATT&CK
Why this verdict
The malicious score of 93/100 is the fusion of 8 weighted signals:
- YARA: Trellix/McAfee ATR flagged ATR_LockBit_Ransomware (rule
ATR_LockBit_Ransomware) - engine signal, weight 0.85, confidence 0.70 - Emsisoft (Emergency Kit) flagged Trojan.GenericKDZ.118710 (rule
Trojan.GenericKDZ.118710) - engine signal, weight 0.55, confidence 0.85 - execute via PowerShell (rule
execute via PowerShell) - capa signal, weight 0.40, confidence 0.80 - capture keystrokes (rule
capture keystrokes) - capa signal, weight 0.40, confidence 0.80 - capa (capabilities) flagged capability:execution/powershell (rule
capability:execution/powershell) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: 4.2.1.0, 5.29.10.5, 29.19.5.29 - static signal, weight 0.35, confidence 0.60
- enumerate processes (rule
enumerate processes) - capa signal, weight 0.20, confidence 0.60 - encrypt data (rule
encrypt data) - capa signal, weight 0.15, confidence 0.60
Dynamic analysis (windows)
0 behavior events · 0 ATT&CK techniques · 0 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- licensing.mp.microsoft.com
- config.edge.skype.com
- windows.msn.com
- www.msn.com
- officeclient.microsoft.com
- odc.officeapps.live.com
- www.bing.com
- assets.msn.com
- th.bing.com
- fe3cr.delivery.mp.microsoft.com
- settings-win.data.microsoft.com
- slscr.update.microsoft.com
Embedded URLs
- http://www.w3.org/1999/xhtml
- https://aka.ms/nativeaot-compatibilit
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
Embedded domains
- github.com
- www.w3.org
- rdpwrap.in
- my.splashtop.com
- aka.ms
Embedded IP addresses
- 4.2.1.0
- 5.29.10.5
- 29.19.5.29
- 152.5.29.3
- 5.29.35.5
- 29.37.5.29
- 17.5.29.141
- 0.0.27.0
- 192.168.0.2
- 1.12.10.1
- 1.9.16.1
- 1.9.16.2
- 1.9.16.3
- 3.2.8.1
- 1.101.2.1
- 1.101.3.4
- 85.192.49.13
- 20.42.73.25
- 4.144.132.114
- 4.230.171.124
- 135.232.92.97
- 135.233.95.144
- 48.211.4.16
- 51.116.246.104
- 172.64.154.167
Registry keys
- HKLM\SOFTWARE\RealVNC\vncserve
- HKLM\SOFTWARE\TightVNC\Serve
- HKLM\System\CurrentControlSet\Control\Terminal
File paths
- C:\Program
- C:\ProgramData\RustDesk\config\RustDesk.tom
- C:\ProgramData\cred_keys.tx
- C:\User
More LockBit samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report