MALICIOUS — virussign.com_78112f32240ec72a01fdaec5a3552f30.vir
MALICIOUS — virussign.com_78112f32240ec72a01fdaec5a3552f30.vir is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Porcupine family. 5 of 55 detection engines flagged it, exhibiting 6 ATT&CK techniques.
Identification
- SHA-256:
225490428b7f8a924d1d5455295d4a494459b3c632c6cd0bcedf42136a93e880 - SHA-1:
2bdbef4d281cd3a13c9511a765e9fb49443b7b46 - MD5:
78112f32240ec72a01fdaec5a3552f30 - imphash:
f34d5f2d4577ed6d9ceec516c1f5a744 - ssdeep:
24576:b+y3UKdaQsyxPmi4KMHLt4XPUDIm65ecIS/k9+nOumMxIHcQJ85LpzvZgeZ:bnQQsgm9LM35ecS9+nOaOMLBZge - TLSH:
T12B57ADDFA51C1610CEE4D47A245821EEACD1A896C0FDB3D9CFA25C2201DFD33A879466 - Submitted as: virussign.com_78112f32240ec72a01fdaec5a3552f30.vir
- File type: pe · Size: 1478656 bytes
- Verdict: malicious (100/100) · Family: Porcupine
Source: VirusSign · first seen 2026-08-20T00:00:00.000Z · SHA-256 verified
Detections (5 of 55 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-sections:.text
- ClamAV feed: SaneSecurity foxhole_generic: Porcupine.Malware.58887.UNOFFICIAL
- Microsoft Defender: Trojan:MSIL/FormBook.RSS!MTB
- Emsisoft (Emergency Kit): Gen:Variant.FormBook.827
- Kaspersky (KVRT): HEUR:Trojan.MSIL.Crypt.gen
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 11 weighted signals:
- ClamAV feed: SaneSecurity foxhole_generic flagged Porcupine.Malware.58887.UNOFFICIAL (rule
Porcupine.Malware.58887.UNOFFICIAL) - engine signal, weight 0.90, confidence 0.95 - 3 behavioral detection(s): Registry Run Key Persistence [high] (rule
tl-run-key) - dynamic signal, weight 0.60, confidence 0.90 - Observed at runtime: Registry Run Key Persistence (T1547.001) (rule
Registry Run Key Persistence) - dynamic signal, weight 0.40, confidence 0.90 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - Dropped a suspicious payload: ModuleAnalysisCache - dynamic signal, weight 0.40, confidence 0.90
- Contacted 28 external host(s) at runtime (22 HTTP) - network signal, weight 0.40, confidence 0.80
- Anti-analysis: T1497, T1497.001, T1082, T1622 - dynamic signal, weight 0.40, confidence 0.75
- Extracted Formbook config (0 C2) - engine signal, weight 0.45, confidence 0.60
- Embedded network infrastructure: 14.3.7.0 - static signal, weight 0.35, confidence 0.60
- Packing/obfuscation: high-entropy-sections:.text - static signal, weight 0.25, confidence 0.55
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
25016 behavior events · 3 ATT&CK techniques · 28 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- to-do.office.com
- staging.to-do.officeppe.com
- teams.cloud.microsoft
- outlook.office.com
- outlook.office365.com
- outlook.cloud.microsoft
- ctldl.windowsupdate.com
- login.live.com
- ocsp.digicert.com
- desktop-hsgcbep
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- oneocsp.microsoft.com
- www.msn.com
- licensing.mp.microsoft.com
Dropped files
- C:\Users\analyst\AppData\Local\Microsoft\Windows\PowerShell\ModuleAnalysisCache -
9429fb123c90f8d5130515bc7f73b0157a5bc3c6a7558f336c80cc2680b9dca2 - C:\Users\analyst\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive -
b43d3c222b5478fc1747ba56a1ef3226b10b701b80b48bf8c5b6ef497641d794 - C:\Users\analyst\AppData\Local\Temp\__PSScriptPolicyTest_w0qilavd.5a5.psm1 -
96ad1146eb96877eab5942ae0736b82d8b5e2039a80d3d6932665c1a4c87dcf7 - 3287b55ecd9aaf33c0e795e86188137b9e07fade7d6a3bbf173a235cf267a1d6 -
3287b55ecd9aaf33c0e795e86188137b9e07fade7d6a3bbf173a235cf267a1d6 - e281fb476265b5b541d1317ec2291ccf29351ff77244579c7c76a3b7d370e359 -
e281fb476265b5b541d1317ec2291ccf29351ff77244579c7c76a3b7d370e359 - e592ec0ed6bc8c8090c6ba5b38c57b2ade3240f8288d01bfea828e53532e323e -
e592ec0ed6bc8c8090c6ba5b38c57b2ade3240f8288d01bfea828e53532e323e - 7a5817384eced5498468f8e50ba24d31302250ba0a41571958153e3261145e39 -
7a5817384eced5498468f8e50ba24d31302250ba0a41571958153e3261145e39 - e72302a29793db2a57e3a7d440b84e1da7e8f004aa2dc556e3c0f226529bba09 -
e72302a29793db2a57e3a7d440b84e1da7e8f004aa2dc556e3c0f226529bba09 - 6f3544bd41a7b86c5214a28772a3b09d73c295bfb4d0f0e980b18a42f485f547 -
6f3544bd41a7b86c5214a28772a3b09d73c295bfb4d0f0e980b18a42f485f547 - 417fc3568708427f4d9fa3303ff5ff2444e99a785454afb4ba7099d5817492cb -
417fc3568708427f4d9fa3303ff5ff2444e99a785454afb4ba7099d5817492cb - e81008c41bd8f58bf0e610507b4001bc8647cdd4bb0ae3fc43156e3c47481e8c -
e81008c41bd8f58bf0e610507b4001bc8647cdd4bb0ae3fc43156e3c47481e8c - e8b8d5af759c9a3d0e489cc78b60ff71a3e0fa6a08ed3e8d92d16c58ea463f31 -
e8b8d5af759c9a3d0e489cc78b60ff71a3e0fa6a08ed3e8d92d16c58ea463f31 - 83539df3b404ce94f5e013bcbffcd41822324ccdab1cb33d2ecbb0568b2920d0 -
83539df3b404ce94f5e013bcbffcd41822324ccdab1cb33d2ecbb0568b2920d0 - 578685fda31bfd5e7073ec2c733de9f0f9ee4081ca677cb7b2e1188935eef3e4 -
578685fda31bfd5e7073ec2c733de9f0f9ee4081ca677cb7b2e1188935eef3e4 - 5655d667e4c9c096a3cc0735c614158f9cbcd53226c7a71e6c504be4371a57c4 -
5655d667e4c9c096a3cc0735c614158f9cbcd53226c7a71e6c504be4371a57c4
Embedded URLs
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://203.26.79.13/filestreamingservice//files/753bb2df-a166-494f-aa7d-5678b1ef0c56/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/753bb2df-a166-494f-aa7d-5678b1ef0c56?P1=1787849445&P2=404&P3=2&P4=j7mWLkm%2bY12SYbZvmIqJfq9DWzD1nDxaTeyEg23DhxADFFv9RKC%2bC%2bJlfuhyERbtjzBUV1TtZ8GlgzsJO4Ak%2fQ%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice//files/c74a5353-3e6a-42b7-94d6-9b96c560c89a/pieceshash?cacheHostOrigin=dl.delivery.mp.microsoft.com
- http://203.26.79.13/filestreamingservice/files/c74a5353-3e6a-42b7-94d6-9b96c560c89a?P1=1787849502&P2=404&P3=2&P4=PIjZXNKsALrYc9KrAXPCKbl6E62MgFde7LIRkd%2fjMwjDDShi%2fGW%2bcSHs2tLPAzHTrQWMLHzjhsy9LLiC1JU45w%3d%3d&cacheHostOrigin=msedge.b.tlu.dl.delivery.mp.microsoft.com
Embedded IP addresses
- 14.3.7.0
- 20.184.175.18
- 52.123.252.215
- 20.247.185.124
- 4.230.171.124
- 40.84.85.40
- 85.210.193.152
- 135.232.92.137
- 52.123.252.213
- 135.232.92.34
- 40.79.163.155
- 20.165.94.54
- 203.26.79.13
- 20.236.44.162
- 52.123.129.14
- 52.123.128.14
- 172.66.2.5
- 20.42.179.192
- 135.233.45.223
- 52.148.114.188
- 20.42.73.24
- 20.50.201.195
- 92.223.78.30
- 135.234.160.246
- 72.145.35.100
More Porcupine samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report