MALICIOUS — virussign.com_4e9370874594d94ef04fedfa11865db0.vir
MALICIOUS — virussign.com_4e9370874594d94ef04fedfa11865db0.vir is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100), attributed to the Sality family. 4 of 52 detection engines flagged it.
Identification
- SHA-256:
1d5b3e7a9dc42b3687c1593a82c2f475df666edb01c1f5c22d0a222693ea6183 - SHA-1:
06aaa9bb08b755b09b5338adf0f9eb2caa37c67e - MD5:
4e9370874594d94ef04fedfa11865db0 - imphash:
b9aff912a075cd9014ac7f401226f8e5 - ssdeep:
98304:PKQeMxlLsAAa/7JNzJwjI5klUigKYkBEvHPILz1p/kjRm4OWL22ImljBV:5eUlZF6bUpMBF1p/kjRm4OWi2b - TLSH:
T10866336E0A1AF542FAF6954465C00C2F25E3A0C74DBD8D494A8BC17F7AD2977E230C1A - Submitted as: virussign.com_4e9370874594d94ef04fedfa11865db0.vir
- File type: pe · Size: 6569428 bytes
- Verdict: malicious (98/100) · Family: Sality
Detections (4 of 52 engines)
- ClamAV (daily): Win.Malware.Generic-6651554-0
- Microsoft Defender: Virus:Win32/Sality.AT
- Emsisoft (Emergency Kit): Win32.Sality.3
- Kaspersky (KVRT): Virus.Win32.Sality.sil
Why this verdict
The malicious score of 98/100 is the fusion of 4 weighted signals:
- ClamAV (daily) flagged Win.Malware.Generic-6651554-0 (rule
Win.Malware.Generic-6651554-0) - engine signal, weight 0.90, confidence 0.95 - Microsoft Defender flagged Virus:Win32/Sality.AT (rule
Virus:Win32/Sality.AT) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Win32.Sality.3 (rule
Win32.Sality.3) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged Virus.Win32.Sality.sil (rule
Virus.Win32.Sality.sil) - engine signal, weight 0.55, confidence 0.85
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded domains
- e.tv
- 2.to
- j.pro
- i.ai
File paths
- T:\:d:l:t:
- d:\+9y
More Sality samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report