MALICIOUS — virussign.com_981ee0db7b5c8134d67da3d9c47afa60.vir
MALICIOUS — virussign.com_981ee0db7b5c8134d67da3d9c47afa60.vir is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Viking family. 7 of 55 detection engines flagged it, exhibiting 7 ATT&CK techniques.
Identification
- SHA-256:
1fb8140104c26a8321232c7b9a49d5d4f63df8df8d67e60eca0971ea1b5f4330 - SHA-1:
5a79953923b10d0deb3ce9e98654d84088fb1749 - MD5:
981ee0db7b5c8134d67da3d9c47afa60 - imphash:
87bed5a7cba00c7e1f4015f1bdae2183 - ssdeep:
98304:iLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLLx:0jJ/ - TLSH:
T14E62D0EFE1B6F603FFF384A5442CA04D916114ADE5B0790C76D2A82A40D3C5BA93527E - Submitted as: virussign.com_981ee0db7b5c8134d67da3d9c47afa60.vir
- File type: pe · Size: 4353325 bytes
- Verdict: malicious (100/100) · Family: Viking
Source: VirusSign · first seen 2026-08-19T00:00:00.000Z · SHA-256 verified
Detections (7 of 55 engines)
- MalwareAnalyser heuristics (entropy/packer): Borland Delphi
- ClamAV (daily): Win.Trojan.Philis-21
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- Detect It Easy (packer/type): DIE:Borland Delphi
- Microsoft Defender: Trojan:Win32/Phonzy.B!ml
- Emsisoft (Emergency Kit): Generic.Viking.45BA6F7B
- Kaspersky (KVRT): Worm.Win32.Viking.ae
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 12 weighted signals:
- ClamAV (daily) flagged Win.Trojan.Philis-21 (rule
Win.Trojan.Philis-21) - engine signal, weight 0.90, confidence 0.95 - Memory forensics: 2 finding(s), e.g. SSDT hook (rule
windows.ssdt.SSDT) - memory signal, weight 0.50, confidence 0.85 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - 3 behavioral detection(s): Windows Service Installation [medium] (rule
tl-service-install) - dynamic signal, weight 0.40, confidence 0.90 - Contacted 26 external host(s) at runtime (21 HTTP) - network signal, weight 0.40, confidence 0.80
- Anti-analysis: T1497, T1082, T1622 - dynamic signal, weight 0.40, confidence 0.75
- YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - Detect It Easy (packer/type) flagged DIE:Borland Delphi (rule
DIE:Borland Delphi) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://d.symcb.com/rpa0, http://sf.symcb.com/sf.crl0W, http://sf.symcb.com/sf.crt0 - static signal, weight 0.35, confidence 0.60
- Packing/obfuscation: Borland Delphi - static signal, weight 0.25, confidence 0.55
- Dropped 4 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
70775 behavior events · 2 ATT&CK techniques · 7 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- config.edge.skype.com
- v20.events.data.microsoft.com
- windows.msn.com
- oneocsp.microsoft.com
- www.msn.com
- officeclient.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\Temp\tsk_cc1011f71b444b14.exe.exe -
a5bfb538aafc7c6c88aaba4ccda0cd1f775c87aa01ac975081f23c216f392816 - C:\Program Files\Eclipse Adoptium\jdk-21.0.5+11-jre\legal\jdk.accessibility\_desktop.ini -
bf338b34373be371e656c2348ef628bb1afde20017d7c8cc3a19088398d512eb - C:\Windows\Dll.dll -
58902ae17338af4211e7e21eddb09671507b48740fa7056b9b7f7ab307da0168 - C:\Users\analyst\AppData\Local\Temp\$$a819.bat -
da7acfac7e2d5e4df1473d12e3026633df90430a3b84b4257b866bc3b2b67cab - C:\Windows\Logo1_.exe -
5c6ca16525876afba9f88ae6809b550793501ed5c5a73b8a800d4029ff92c98c - addcdf552ee93610faa62f6a9dc131addd5726441fbdef509aa60c737010c2aa -
addcdf552ee93610faa62f6a9dc131addd5726441fbdef509aa60c737010c2aa - 60e43186a29b159850407172906f190a886ed12303da45318e4419a411772d65 -
60e43186a29b159850407172906f190a886ed12303da45318e4419a411772d65
Embedded URLs
- http://crl.thawte.com/ThawteTimestampingCA.crl0
- http://ts-aia.ws.symantec.com/tss-ca-g2.cer0
- http://ts-crl.ws.symantec.com/tss-ca-g2.crl0
- https://www.verisign.com/rpa
- https://d.symcb.com/rpa0
- http://sf.symcb.com/sf.crl0W
- http://sf.symcb.com/sf.crt0
- https://www.verisign.com/cps0*
- https://www.verisign.com/rpa0
- http://logo.verisign.com/vslogo.gif04
- http://crl.verisign.com/pca3-g5.crl04
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/753bb2df-a166-494f-aa7d-5678b1ef0c56/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/753bb2df-a166-494f-aa7d-5678b1ef0c56?P1=1787764913&P2=404&P3=2&P4=JRz%2bxzigymaraUkYGXdnmAYlZ3z6WQeorThYRe6lzSZB59YNu8HB8kapLaC6uvVJ8qXTeUy8R7tkh7JfcjCksA%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c74a5353-3e6a-42b7-94d6-9b96c560c89a/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c74a5353-3e6a-42b7-94d6-9b96c560c89a?P1=1787765029&P2=404&P3=2&P4=dEDicvT4w%2bBnG8B9995rtIABHzpQ2ktUn0tBOYWG%2fLNAIVLIm8BNHEeeq%2bn9uJWLzZaTLOLQZ3Nl2jYe4rWPlg%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Embedded domains
- crl.thawte.com
- ts-aia.ws.symantec.com
- ts-crl.ws.symantec.com
- www.verisign.com
- d.symcb.com
- sf.symcb.com
- crl.microsoft.com
- logo.verisign.com
- crl.verisign.com
Embedded IP addresses
- 10.244.254.168
- 172.17.2.83
- 10.244.64.19
- 10.244.144.192
- 10.244.74.73
- 10.244.254.64
- 10.244.64.65
- 10.244.86.128
- 10.244.86.159
- 10.244.64.0
- 10.244.144.221
- 10.244.144.208
- 172.17.2.80
- 10.244.74.159
- 10.244.64.34
- 10.244.86.188
- 10.244.74.190
- 10.244.254.188
- 10.244.64.25
- 10.244.86.138
- 10.244.86.157
- 10.244.254.82
- 10.244.74.128
- 10.244.86.158
- 10.244.144.226
File paths
- c:\dvs\p4\build\sw\tools\win32\msvc90\VC\atlmfc\include\atlsafe.h
- c:\dvs\p4\build\sw\rel\gpu_drv\installer_core\inc\TypedEnum.h
- c:\dvs\p4\build\sw\tools\win32\msvc90\VC\atlmfc\include\atlchecked.h
- c:\dvs\p4\build\sw\tools\win32\msvc90\VC\atlmfc\include\atlcore.h
- c:\dvs\p4\build\sw\tools\win32\msvc90\VC\atlmfc\include\atlcomcli.h
- c:\dvs\p4\build\sw\tools\win32\msvc90\VC\atlmfc\include\cstringt.h
- c:\dvs\p4\build\sw\rel\gpu_drv\installer_core\inc\NVI2Defns.h
- c:\dvs\p4\build\sw\rel\gpu_drv\installer_core\inc\AutoString.h
- c:\dvs\p4\build\sw\rel\gpu_drv\installer_core\inc\Handles.h
- c:\dvs\p4\build\sw\rel\gpu_drv\installer_core\inc\DllManager.h
- c:\dvs\p4\build\sw\rel\gpu_drv\installer_core\inc\Registry.h
- c:\dvs\p4\build\sw\rel\gpu_drv\installer_core\inc\NVProp.h
- c:\dvs\p4\build\sw\rel\gpu_drv\installer_core\inc\Collection.h
- c:\dvs\p4\build\sw\rel\gpu_drv\installer_core\inc\RefCounted.h
- c:\dvs\p4\build\sw\tools\win32\msvc90\VC\atlmfc\include\atlsimpstr.h
- c:\dvs\p4\build\sw\tools\win32\msvc90\VC\atlmfc\include\atlalloc.h
- c:\dvs\p4\build\sw\tools\win32\msvc90\VC\atlmfc\include\atlcoll.h
- C:\dvs\p4\build\sw\rel\gpu_drv\installer_core\Build\Core\Out\Win32\Release\setup.pdb
- X:\:`:d:
- P:\:
- T:\:p:x:
- T:\:d:l:t:
More Viking samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report