MALICIOUS — virussign.com_93c650f98779ad9b099f68a15e7ccab0.vir
MALICIOUS — virussign.com_93c650f98779ad9b099f68a15e7ccab0.vir is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Socks family. 7 of 53 detection engines flagged it, exhibiting 2 ATT&CK techniques.
Identification
- SHA-256:
20142be6fdfbef674a1a3fb4425fa36fde7c5abed7caeedf8a996c97b81dab84 - SHA-1:
39d105532e8fcba08f3cdd2cb5a7784709d6e675 - MD5:
93c650f98779ad9b099f68a15e7ccab0 - imphash:
178689c38c1294cbf87aafcafb2357ed - ssdeep:
12288:ACCs5xOKx2Nht6igCFM6ZzUopB5F/JkXekRPiYoSgD1Z/6:AU5xOuiPX26zpvFxtk9hgT/6 - TLSH:
T1354F23A190C2292CCA265F1D15502DBF891AC74C72C22B11D9D4B9238F9E85B5773E3F - Submitted as: virussign.com_93c650f98779ad9b099f68a15e7ccab0.vir
- File type: pe · Size: 752492 bytes
- Verdict: malicious (100/100) · Family: Socks
Source: VirusSign · first seen 2026-07-16T00:00:00.000Z · SHA-256 verified
Detections (7 of 53 engines)
- MalwareAnalyser heuristics (entropy/packer): UPX
- ClamAV (daily): Win.Worm.Socks-10058896-0
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- Detect It Easy (packer/type): DIE:UPX 3.02
- Microsoft Defender: Worm:Win32/Autorun
- Emsisoft (Emergency Kit): Trojan.Stealer.557
- Kaspersky (KVRT): HEUR:Trojan.Win32.Generic
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 13 weighted signals:
- ClamAV (daily) flagged Win.Worm.Socks-10058896-0 (rule
Win.Worm.Socks-10058896-0) - engine signal, weight 0.90, confidence 0.95 - Memory forensics: 4 finding(s), e.g. RWX/private injected region in taskhostw.exe (pid 6956) (rule
windows.malfind.Malfind) - memory signal, weight 0.60, confidence 0.85 - Microsoft Defender flagged Worm:Win32/Autorun (rule
Worm:Win32/Autorun) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Trojan.Stealer.557 (rule
Trojan.Stealer.557) - engine signal, weight 0.55, confidence 0.85 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - 1 behavioral detection(s): Windows Service Installation [medium] (rule
tl-service-install) - dynamic signal, weight 0.40, confidence 0.90 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - 1 behavioral detection(s): Windows Service Installation [medium] (rule
tl-service-install) - dynamic signal, weight 0.40, confidence 0.90 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - Detect It Easy (packer/type) flagged DIE:UPX 3.02 (rule
DIE:UPX 3.02) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: UPX, UPX 3.02 - static signal, weight 0.25, confidence 0.55
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90 - Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
9958 behavior events · 2 ATT&CK techniques · 18 dropped files.
Runtime network
- searchapp.bundleassets.example
- www.msftconnecttest.com
- staging.to-do.officeppe.com
- bublikiadministrator.com
- bublikimanager.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- www.bing.com
- config.edge.skype.com
- desktop-hsgcbep
- dns.msftncsi.com
- to-do.microsoft.com
- ctldl.windowsupdate.com
- settings-win.data.microsoft.com
- staging.to-do.microsoft.com
- edge.microsoft.com
- aps.prod.windows.com
- teams.microsoft.com
- watson.events.data.microsoft.com
Dropped files
- /opt/CAPEv2/storage/analyses/3468/files/b6c70b711cbd0dfb0332de21cb3e85dcb7d0627e42b2476f59fea70be2304003 -
b6c70b711cbd0dfb0332de21cb3e85dcb7d0627e42b2476f59fea70be2304003 - /opt/CAPEv2/storage/analyses/3468/files/815358cfe90ad4d395ea85434efe706e14c7b5f4d25b4b14be4637413bad7494 -
815358cfe90ad4d395ea85434efe706e14c7b5f4d25b4b14be4637413bad7494 - /opt/CAPEv2/storage/analyses/3468/files/3dc3718862643e000b4fe43e85d6df30b4ca8b35feb977902030c966f38c133a -
3dc3718862643e000b4fe43e85d6df30b4ca8b35feb977902030c966f38c133a - /opt/CAPEv2/storage/analyses/3468/files/e69a5843dad07fa48fb2a11229ab4d4cd78fccd537c51296e5da6fa402f05796 -
e69a5843dad07fa48fb2a11229ab4d4cd78fccd537c51296e5da6fa402f05796 - /opt/CAPEv2/storage/analyses/3468/files/456935be3c139eac85efe8bb94b34c10422b3e25e862d03ad5284948ebc235c7 -
456935be3c139eac85efe8bb94b34c10422b3e25e862d03ad5284948ebc235c7 - /opt/CAPEv2/storage/analyses/3468/files/9123d5b0824b35cd8035a69f1ae818d99449848809f6b081579ab00ab60e0536 -
9123d5b0824b35cd8035a69f1ae818d99449848809f6b081579ab00ab60e0536 - /opt/CAPEv2/storage/analyses/3468/files/fdeee5c76d5094ac39a86a0b9ae9c6149915bdf614da5bea3c9ee4029445b4c5 -
fdeee5c76d5094ac39a86a0b9ae9c6149915bdf614da5bea3c9ee4029445b4c5 - /opt/CAPEv2/storage/analyses/3468/files/089f54c1a176bd95acf6e3bb12577893045100e3f99c3292cf21d60518d8c274 -
089f54c1a176bd95acf6e3bb12577893045100e3f99c3292cf21d60518d8c274 - /opt/CAPEv2/storage/analyses/3468/files/0581bc3b0d1a370d4ce61e91a319908d8257570f875e38321b11c82cadcc9ca9 -
0581bc3b0d1a370d4ce61e91a319908d8257570f875e38321b11c82cadcc9ca9 - /opt/CAPEv2/storage/analyses/3468/files/708e375cb5fe09d4bbd61dd5622f3ce1b5a11c5c4648cb7c4ce87d96f9c6151c -
708e375cb5fe09d4bbd61dd5622f3ce1b5a11c5c4648cb7c4ce87d96f9c6151c - /opt/CAPEv2/storage/analyses/3468/files/5614e4fef76f03346ad0d480c8c5479b34dad4b6b22a0a2db01e3b450a713dc6 -
5614e4fef76f03346ad0d480c8c5479b34dad4b6b22a0a2db01e3b450a713dc6 - /opt/CAPEv2/storage/analyses/3468/files/ec040789c0f969e94bb5bbd42a0cb632c3a5f0232d64384d07aeca05b75e3f34 -
ec040789c0f969e94bb5bbd42a0cb632c3a5f0232d64384d07aeca05b75e3f34 - /opt/CAPEv2/storage/analyses/3468/files/b399f3927c2a8ca79739ac2262d1120d86fb11b37cbf09bf0b05a3d3f04b1542 -
b399f3927c2a8ca79739ac2262d1120d86fb11b37cbf09bf0b05a3d3f04b1542 - /opt/CAPEv2/storage/analyses/3468/files/1a5d80f36aab9b975562ae627b87129f6ac385e49f3e127eba298d854c4dbe7c -
1a5d80f36aab9b975562ae627b87129f6ac385e49f3e127eba298d854c4dbe7c - /opt/CAPEv2/storage/analyses/3468/files/17f3cf455242695d719cc5ae5a94934f6e14e693d1c487b025521647200b4a74 -
17f3cf455242695d719cc5ae5a94934f6e14e693d1c487b025521647200b4a74
Embedded domains
- staging.to-do.officeppe.com
- bublikiadministrator.com
- bublikimanager.com
- teams.cloud.microsoft
- searchapp.bundleassets.example
- www.msftconnecttest.com
- outlook.office.com
- outlook.office365.com
- www.bing.com
- config.edge.skype.com
- dns.msftncsi.com
- to-do.microsoft.com
- ctldl.windowsupdate.com
- settings-win.data.microsoft.com
- staging.to-do.microsoft.com
- edge.microsoft.com
- aps.prod.windows.com
- teams.microsoft.com
- watson.events.data.microsoft.com
- ecs.office.com
- g.live.com
- self.events.data.microsoft.com
- fs.microsoft.com
- www.msftncsi.com
- msedge.api.cdp.microsoft.com
More Socks samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report