SUSPICIOUS — virussign.com_af8ba4b138c3d449185bfb688334f730.vir
SUSPICIOUS — virussign.com_af8ba4b138c3d449185bfb688334f730.vir is a pe sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (40/100), attributed to the AntiDebug family. 4 of 51 detection engines flagged it.
Identification
- SHA-256:
372b532fc202c5d1071ae7f60778c1a773e0a3a4961cebc4eb9bf9219c28af67 - SHA-1:
a61fbc96394423af3d43d08102e37444dd97c52d - MD5:
af8ba4b138c3d449185bfb688334f730 - imphash:
542863a264e826bf130b0880664f67e4 - ssdeep:
98304:c7GpL4IFkDS1foMqv4Yop7IyoB+QBPDE7u4kV+EsDp4kyIXs9:c7GpZ31foMqtB+QBPDEVs9 - TLSH:
T15C6A8DA063A43595EBFA1D78FC68956E37B3A02219B6C3DC0385700650E61FF4A3C5E6 - Submitted as: virussign.com_af8ba4b138c3d449185bfb688334f730.vir
- File type: pe · Size: 9808026 bytes
- Verdict: suspicious (40/100) · Family: AntiDebug
Source: VirusSign · first seen 2026-08-02T00:00:00.000Z · SHA-256 verified
Detections (4 of 51 engines)
- YARA: Yara-Rules community: YR_AntiDebug_Checks
- Microsoft Defender: Trojan:Win32/Zusy.KK!MTB
- Emsisoft (Emergency Kit): Gen:Variant.Fragtor.905234
- Kaspersky (KVRT): HEUR:Trojan.Win32.Agent.pef
Why this verdict
The suspicious score of 40/100 is the fusion of 2 weighted signals:
- YARA: Yara-Rules community flagged YR_AntiDebug_Checks (rule
YR_AntiDebug_Checks) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://gcc.gnu.org/bugs/ - static signal, weight 0.35, confidence 0.60
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- https://gcc.gnu.org/bugs/
Embedded domains
- gcc.gnu.org
- tinfo.cc
- vterminate.cc
- fstream-inst.cc
- functexcept.cc
- ios-inst.cc
- ios.cc
- iostream-inst.cc
- istream-inst.cc
- locale-inst.cc
- ostream-inst.cc
- streambuf-inst.cc
- string-inst.cc
- wlocale-inst.cc
- dyncast.cc
- locale.cc
- codecvt.cc
- istream.cc
- stdexcept.cc
- streambuf.cc
- cow-stdexcept.cc
- cow-string-inst.cc
- cow-wstring-inst.cc
- ctype.cc
- cxx11-locale-inst.cc
File paths
- X:\:`:d:h:l:p:t:x:
- X:\:h:l:p:
More AntiDebug samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report