MALICIOUS — virussign.com_997c0cd29249b373cbf508b4c9247240.vir
MALICIOUS — virussign.com_997c0cd29249b373cbf508b4c9247240.vir is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (86/100), attributed to the Razy family. 4 of 52 detection engines flagged it.
Identification
- SHA-256:
326d24c16d2e629d677f8dbd02e53eaadd3ff135f613069b7c497d928c0f44e8 - SHA-1:
9d33018fce2f5ff226bbffd19cfca411c09323c7 - MD5:
997c0cd29249b373cbf508b4c9247240 - imphash:
3c2e1c95b87b1cf3c33906bf62025007 - ssdeep:
768:Q1eRH+9lFh0ul16sh7iQroCHANAISFlyeLB:Q0l+Z16sh7iQroCYSf - TLSH:
T1C83230CC81681B5AC33B11B9A93DCE5E9197B0D219ACB70D1D9E913E40C24E3ECB1976 - Submitted as: virussign.com_997c0cd29249b373cbf508b4c9247240.vir
- File type: pe · Size: 46320 bytes
- Verdict: malicious (86/100) · Family: Razy
Source: VirusSign · first seen 2026-08-09T00:00:00.000Z · SHA-256 verified
Detections (4 of 52 engines)
- ClamAV (daily): Win.Downloader.Razy-9935848-0
- Microsoft Defender: Trojan:Win32/Zbot.HBAI!MTB
- Trellix Stinger (McAfee): Trojan-FXIX!997C0CD29249
- Kaspersky (KVRT): Trojan-PSW.Win32.LdPinch.hij
Why this verdict
The malicious score of 86/100 is the fusion of 1 weighted signal:
- ClamAV (daily) flagged Win.Downloader.Razy-9935848-0 (rule
Win.Downloader.Razy-9935848-0) - engine signal, weight 0.90, confidence 0.95
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded domains
- tern32.de
File paths
- C:\RVmMhSdN.exe
- C:\Users\Bruno\Desktop\program.exe
- C:\Users\Frank\Desktop\JTcsaqaw.exe
- C:\Users\azure\Downloads\2490d3a3962530b346cde5527af15cc60cd8333a3637faa92756d50ee9ec4036.exe
- C:\Users\Frank\Desktop\edjOXGpp.exe
- C:\Users\azure\Downloads\ca95b5c9148346818db7013966b7c0da5df0aa22f3d1fef79e00b858658da1a3.exe
- C:\Users\Janet
- C:\Users\Admin\AppData\Local\Temp\e45d408f0509f3c57c119922fa9c855b08b8fbf12e468e6e48a13393a1d06cc5.exe
- C:\Users\Frank\Desktop\dllfULZE.exe
- C:\Users\Frank\Desktop\eaXlOWgg.exe
- C:\gPF94HBW.exe
- C:\f5LogwyU.exe
- C:\Users\Frank\Desktop\eiaoyJbP.exe
- C:\Users\Bruno\Desktop\executable.exe
- C:\Users\Admin\AppData\Local\Temp\12c6f64488a5ceda893f0f28ba1c25fbb77a4cfb9a0ae812175d6e003cd90a5b.exe
- C:\Users\Lisa\Desktop\OqIRbcaK.exe
- C:\Users\Admin\AppData\Local\Temp\72d5a73b49c940a50c788a07e112897a48d3e33185a498cb072c24b8720c93bc.exe
- C:\Users\Frank\Desktop\trlvykRy.exe
- C:\Users\azure\Downloads\e3b31e9a91f2b5c8a889bd53f07dac08425b4066a3fca31b3a161d28a5a303c4.exe
- C:\Users\Admin\AppData\Local\Temp\3cccb3c62de95a0ab5ffadd7296aa3de7a784bed1b6f82acef090920100b94f1.exe
- C:\Users\Lisa\Desktop\fOKSkzRG.exe
- C:\bFFWmCaN.exe
- C:\Users\azure\Downloads\9e6423b1bc143a93f854e67b21c4095b.exe
- C:\LvCDzwEc.exe
- C:\Users\Bruno\Desktop\software.exe
More Razy samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report