MALICIOUS — virussign.com_e2d1b8ec127f483ce7f4b0a55ff6d560.vir
MALICIOUS — virussign.com_e2d1b8ec127f483ce7f4b0a55ff6d560.vir is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (95/100), attributed to the Pioneer family. 7 of 52 detection engines flagged it.
Identification
- SHA-256:
269b7229f4802947b7a00896a2783af7b1edbc0c35fa6d0461f78c058dd00bf2 - SHA-1:
f1066e5e711a1406aceda85591a88cd90de08836 - MD5:
e2d1b8ec127f483ce7f4b0a55ff6d560 - imphash:
416476cccd1ea2fa776eb7ee848ac9eb - ssdeep:
24576:llD3OzRzBM/0n01AcF58k4os2+brEH7X:l13oRF01AK+k4os2+K - TLSH:
T1B6526C502602A30BE6B4B6957C700A4D2163F89E75BBE5ECF387D19E13D7C8B811C2A5 - Submitted as: virussign.com_e2d1b8ec127f483ce7f4b0a55ff6d560.vir
- File type: pe · Size: 935543 bytes
- Verdict: malicious (95/100) · Family: Pioneer
Source: VirusSign · first seen 2026-08-04T00:00:00.000Z · SHA-256 verified
Detections (7 of 52 engines)
- ClamAV (daily): Win.Virus.Pioneer-9111434-0
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- YARA: Yara-Rules community: YR_AntiDebug_Checks
- LIEF (executable format parser): lief:invalid-authenticode
- Kaspersky (KVRT): Virus.Win32.Pioneer.cz
- Microsoft Defender: Virus:Win32/Floxif.H
- Emsisoft (Emergency Kit): Win32.Floxif.A
Why this verdict
The malicious score of 95/100 is the fusion of 5 weighted signals:
- ClamAV (daily) flagged Win.Virus.Pioneer-9111434-0 (rule
Win.Virus.Pioneer-9111434-0) - engine signal, weight 0.90, confidence 0.95 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70 - YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70 - LIEF (executable format parser) flagged lief:invalid-authenticode (rule
lief:invalid-authenticode) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: http://sf.symcb.com/sf.crl0f, https://d.symcb.com/rpa0, http://sf.symcb.com/sf.crt0 - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://www.verisign.com/rpa
- http://sf.symcb.com/sf.crl0f
- https://d.symcb.com/rpa0
- http://sf.symcb.com/sf.crt0
- https://www.verisign.com/cps0*
- https://www.verisign.com/rpa0
- http://logo.verisign.com/vslogo.gif04
- http://crl.verisign.com/pca3-g5.crl04
Embedded domains
- crl.usertrust.com
- www.verisign.com
- sf.symcb.com
- d.symcb.com
- crl.microsoft.com
- logo.verisign.com
- crl.verisign.com
File paths
- c:\dvs\p4\build\sw\tools\win32\msvc90\VC\atlmfc\include\atlsafe.h
- c:\dvs\p4\build\sw\tools\win32\msvc90\VC\atlmfc\include\atlsimpstr.h
- c:\dvs\p4\build\sw\rel\gpu_drv\installer_core\inc\NVExtensionSite.h
- c:\dvs\p4\build\sw\rel\gpu_drv\installer_core\inc\TypedEnum.h
- c:\dvs\p4\build\sw\rel\gpu_drv\r340\r340_00\drivers\ui\logging\logging.lib\RegistryKey.h
- c:\dvs\p4\build\sw\tools\win32\msvc90\VC\atlmfc\include\atlcore.h
- c:\dvs\p4\build\sw\tools\win32\msvc90\VC\atlmfc\include\atlcomcli.h
- c:\dvs\p4\build\sw\tools\win32\msvc90\VC\atlmfc\include\cstringt.h
- c:\dvs\p4\build\sw\rel\gpu_drv\installer_core\inc\NVI2Defns.h
- c:\dvs\p4\build\sw\rel\gpu_drv\installer_core\inc\AutoString.h
- c:\dvs\p4\build\sw\rel\gpu_drv\installer_core\inc\Handles.h
- c:\dvs\p4\build\sw\rel\gpu_drv\installer_core\inc\Registry.h
- c:\dvs\p4\build\sw\rel\gpu_drv\installer_core\inc\NVProp.h
- C:\dvs\p4\build\sw\rel\gpu_drv\installer_core\Inc\InModuleDispatch.h
- c:\dvs\p4\build\sw\rel\gpu_drv\installer_core\inc\Collection.h
- c:\dvs\p4\build\sw\rel\gpu_drv\installer_core\inc\RefCounted.h
- c:\dvs\p4\build\sw\tools\win32\msvc90\VC\atlmfc\include\atlcoll.h
- c:\dvs\p4\build\sw\rel\gpu_drv\installer_core\inc\DevContext.h
- c:\dvs\p4\build\sw\tools\win32\msvc90\VC\atlmfc\include\atlalloc.h
- C:\dvs\p4\build\sw\rel\gpu_drv\r340\r340_00\installer2.0\Build\Extensions\Out\NV3DVision\Win32\Release\NV3DVisionExt.pdb
- X:\:`:d:h:
- L:\:`:p:t:x:
- D:\:l:p:
- P:\:d:
- T:\:d:l:t:
More Pioneer samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report