MALICIOUS — virussign.com_04ff60e9d9710fc2f0e3bd3680ea16d0.vir
MALICIOUS — virussign.com_04ff60e9d9710fc2f0e3bd3680ea16d0.vir is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (93/100), attributed to the Razy family. 6 of 52 detection engines flagged it.
Identification
- SHA-256:
1c37563a0376c5dd1546c8aeaf16298bbf832e978e8b5d95f4e63839f2405d2d - SHA-1:
0fe93c7f7a12e0b902da47e350900da9c8474be6 - MD5:
04ff60e9d9710fc2f0e3bd3680ea16d0 - imphash:
6ed4f5f04d62b18d96b26d6db7c18840 - ssdeep:
24576:m4bSqKgwug20PBxSFxPC+o3F/hT0IUDY9bRhKCAGstXKMgJTww7Y+WTkA:hKgNRsyPC+o316Do7KN9yUw7Y+m - TLSH:
T1635AD0AE71E8574FCD7DCC5E889407AD523620F672B8DC6C87419294B8DA533AF2403A - Submitted as: virussign.com_04ff60e9d9710fc2f0e3bd3680ea16d0.vir
- File type: pe · Size: 1976832 bytes
- Verdict: malicious (93/100) · Family: Razy
Source: VirusSign · first seen 2026-08-08T00:00:00.000Z · SHA-256 verified
Detections (6 of 52 engines)
- MalwareAnalyser heuristics (entropy/packer): UPX
- ClamAV (daily): Win.Malware.Razy-9857221-0
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- Microsoft Defender: Trojan:Win32/Injector.RAQ!MTB
- Emsisoft (Emergency Kit): Gen:Variant.Lazy.719836
- Kaspersky (KVRT): HEUR:Trojan.Win32.Copak.pef
Why this verdict
The malicious score of 93/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Win.Malware.Razy-9857221-0 (rule
Win.Malware.Razy-9857221-0) - engine signal, weight 0.90, confidence 0.95 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://example-cmdline.test, http://example.test/path, http://example2.test/?query - static signal, weight 0.35, confidence 0.60
- Packing/obfuscation: UPX, high-entropy-sections:UPX1 - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://schemas.microsoft.com/SMI/2005/WindowsSettings
- http://example-cmdline.test
- http://example.test/path
- http://example2.test/?query
- http://example.test.file
- http://example.test
- http://example2.test
- https://www.example.com/
- https://clients1.google.com/tbproxy
- https://content-autofill.googleapis.com/
- http://www.google.com/
- https://example.com/
- https://chromium.org
- https://chromium.org/
- https://www.google.com
- http://foo.com/
- http://foo.com/#:~:text=hello%20world
- http://foo.com/#:~:text=hello
- http://facebook.com/my-profile
- http://foo.com/#bar
- http://foo.com/#bar:~:text=hello%20world
- http://foo.com/#bar:~:text=baz
- http://foo.com/#bar:~:text=baz&text=qux
- http://foo.com/#bar:~:baz=keep&text=remove&baz=keep2
- http://foo.com/#bar:~:baz=keep&baz=keep2&text=hello%20world
Embedded domains
- schemas.microsoft.com
- stack.cc
- field.cc
- logging.cc
- blink.net
- crbug.com
- zip.cc
- pickle.cc
- crx3.pb.cc
- common.cc
- arena.cc
- values.cc
- thread.cc
- www.example.com
- initech.com
- gmail.com
- a.com
- b.com
- clients1.google.com
- content-autofill.googleapis.com
- bounds.top
- wonderland.com
- www.google.com
- foo.com
- example.com
File paths
- O:\_
- u:\GP.
More Razy samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report