MALICIOUS — virussign.com_7b5aea6f2a1db0836d67ef91d55d4960.vir
MALICIOUS — virussign.com_7b5aea6f2a1db0836d67ef91d55d4960.vir is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (100/100), attributed to the Credential family. 6 of 56 detection engines flagged it, exhibiting 6 ATT&CK techniques.
Identification
- SHA-256:
386b73eefc965e65c1fb1dff6def4afa240458ee841101d5bf343ffd3587de43 - SHA-1:
ba4b0306c931f85c885c934191ef599a28b72db5 - MD5:
7b5aea6f2a1db0836d67ef91d55d4960 - imphash:
0de4a5bb41ce454482fd41a503170aed - ssdeep:
98304:+ebGH420Z1Taw8c2fk2S9BoLexvNo+yGoP6cmGH49Pa/VQryN7r772QfpOr:+0s420bTaw+i0k1oZBzm8b/GryNzGr - TLSH:
T1DF632254361BABA6ED09C814AE784D2EA2839D3760690E1CC453D12DA3CF4B7D3D23D9 - Submitted as: virussign.com_7b5aea6f2a1db0836d67ef91d55d4960.vir
- File type: pe · Size: 4950873 bytes
- Verdict: malicious (100/100) · Family: Credential
Source: VirusSign · first seen 2026-08-25T00:00:00.000Z · SHA-256 verified
Detections (6 of 56 engines)
- MalwareAnalyser heuristics (entropy/packer): Microsoft Linker
- YARA: PhishingKit (t4d): PK_Credential_Exfil_Telegram
- Detect It Easy (packer/type): DIE:Microsoft Linker
- Microsoft Defender: Trojan:Win32/Lazy.PGLl!MTB
- Emsisoft (Emergency Kit): Gen:Variant.Draftor.4182
- Kaspersky (KVRT): HEUR:Backdoor.Win32.Agent.gen
MITRE ATT&CK
Why this verdict
The malicious score of 100/100 is the fusion of 19 weighted signals:
- 2 behavioral detection(s) across 2 rule(s): Registry Run Key Persistence [high] (rule
tl-run-key) - dynamic signal, weight 0.63, confidence 0.90 - YARA: PhishingKit (t4d) flagged PK_Credential_Exfil_Telegram (rule
PK_Credential_Exfil_Telegram) - engine signal, weight 0.70, confidence 0.70 - Microsoft Defender flagged Trojan:Win32/Lazy.PGLl!MTB (rule
Trojan:Win32/Lazy.PGLl!MTB) - engine signal, weight 0.55, confidence 0.85 - Emsisoft (Emergency Kit) flagged Gen:Variant.Draftor.4182 (rule
Gen:Variant.Draftor.4182) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Backdoor.Win32.Agent.gen (rule
HEUR:Backdoor.Win32.Agent.gen) - engine signal, weight 0.55, confidence 0.85 - 1 IDS alert(s): ThreatLens Telegram bot C2/exfil - network signal, weight 0.50, confidence 0.80
- Observed at runtime: Registry Run Key Persistence (T1547.001) (rule
Registry Run Key Persistence) - dynamic signal, weight 0.40, confidence 0.90 - Observed at runtime: Windows Service (T1543.003) (rule
Windows Service) - dynamic signal, weight 0.40, confidence 0.90 - Contacted 7 external host(s) and 16 HTTP request(s) at runtime - network signal, weight 0.40, confidence 0.80
- Anti-analysis: T1082, T1622 - dynamic signal, weight 0.40, confidence 0.75
- Detect It Easy (packer/type) flagged DIE:Microsoft Linker (rule
DIE:Microsoft Linker) - engine signal, weight 0.35, confidence 0.70 - MalwareAnalyser heuristics (entropy/packer) flagged Microsoft Linker (rule
Microsoft Linker) - engine signal, weight 0.35, confidence 0.70 - persist via registry run key (rule
persist via registry run key) - capa signal, weight 0.35, confidence 0.60 - Embedded network infrastructure: https://api.telegram.org/bot - static signal, weight 0.35, confidence 0.60
- communicate over HTTP (rule
communicate over HTTP) - capa signal, weight 0.30, confidence 0.60 - Packing/obfuscation: Microsoft Linker - static signal, weight 0.25, confidence 0.55
- enumerate processes (rule
enumerate processes) - capa signal, weight 0.20, confidence 0.60 - Dropped 1 executable file(s) at runtime - dynamic signal, weight 0.20, confidence 0.60
- Observed at runtime: Modify Registry (T1112) (rule
Modify Registry) - dynamic signal, weight 0.12, confidence 0.90
Dynamic analysis (windows)
27700 behavior events · 3 ATT&CK techniques · 17 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- api.telegram.org
- api.github.com
- raw.githubusercontent.com
- yr.c.lencr.org
- yr1.c.lencr.org
- update.googleapis.com
- login.live.com
- desktop-hsgcbep
- licensing.mp.microsoft.com
- v20.events.data.microsoft.com
- config.edge.skype.com
- windows.msn.com
- www.msn.com
- settings-win.data.microsoft.com
- officeclient.microsoft.com
- odc.officeapps.live.com
Dropped files
- C:\Users\analyst\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\D0E1C4B6144E7ECAB3F020E4A19EFC29_A16793B4EA930C0E219244CEE32C9A44 -
e97b5a54ef704938c0e828699a7eb0801d4ba6ae30a988ecf568d2a7fc96859b - C:\Users\analyst\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\103621DE9CD5414CC2538780B4B75751 -
91aff122ee939e39e2afe215354e244e9c1c8f8cd9b493d4f0d9eafa768d5ad3 - C:\Users\analyst\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\DF2B6F1E6BCC61CEBCA21A02089A3B19_4F548F7827F125ACC54E53397A41333A -
4deb7808f34540de888dea441ec0037c9ab3e7fff265e9423f8966e096d8a6b2 - C:\Users\analyst\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\103621DE9CD5414CC2538780B4B75751 -
3dd5ea8a14eb665ba6057d424f94e5e83757ffaab456578dbf038af04053b19e - C:\Users\analyst\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\18159EBD3277736D0444419407768451_2FD781D15115165DD3192E4E42E088C7 -
9066534b093088a317bb7df20fec902d509d2b711c016a7d7600e2716cb4a79f - C:\Users\analyst\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\18159EBD3277736D0444419407768451_2FD781D15115165DD3192E4E42E088C7 -
be8cc4c05e85649c1878a1862781690e509994d5aa79e03465ef4bad48f038b7 - C:\Users\analyst\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\49A7F8B8A2FD8A9E65352CD7C88B1D10 -
3661ccd9e48248843f8b2fc402929073236270270f64d31013c7d7cfe51c0c2c - C:\Users\analyst\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\223DE96EE265046957A660ED7C9DD9E7_EFF9B9BA98DEAA773F261FA85A0B1771 -
46192fd99dd14ff84abbad0a5fe7f97bd5c0f69f6ccece10e35b752d5fdf0001 - C:\Users\analyst\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\F15827BEC5BABE89C21DCDAE77464BF1 -
108dd34232a3088b45534933d0486409616a2bbad94fd8f7ab5991c01ff179b6 - C:\Users\analyst\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\09EC553619BC82A45E441B5D9BEB4136 -
55fc8e1cdf129ad0a0206ec4abb9519e7ad53b812897eb11a2c62d6bb15f62c3 - C:\Users\analyst\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\DF2B6F1E6BCC61CEBCA21A02089A3B19_4F548F7827F125ACC54E53397A41333A -
4ce2b314c02b6366b457504874137b6284e8740b14cc2ef2891f3ad1f1ae681c - C:\Users\analyst\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\49A7F8B8A2FD8A9E65352CD7C88B1D10 -
b302dbd702b4cfaa86d83f0aa87546eb24b6efee66062e006c0ee752c9182dc7 - C:\Users\analyst\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\D0E1C4B6144E7ECAB3F020E4A19EFC29_A16793B4EA930C0E219244CEE32C9A44 -
06e16fc816cd78ffb99afac3ddb8b50e6aec5ca8ccc83e66de02bdcaae6d3567 - C:\Users\analyst\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\09EC553619BC82A45E441B5D9BEB4136 -
ba5433fbfaf5e3f9e71dd2beaee7d71d1701c4db7e36d74b89c88a4a46036a15 - C:\Users\analyst\AppData\Roaming\Microsoft\Windows\Explorer\WindowsInternal.exe -
e697a1ca257d934161f229fe15e0eef3a13f57ac89483b6c80a1ecfc6933f960
Embedded URLs
- https://api.telegram.org/bot
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- http://yr.c.lencr.org/
- http://yr1.c.lencr.org/127.crl
Embedded domains
- api.github.com
- raw.githubusercontent.com
- api.telegram.org
- of.au
- no.ai
- x1.c.lencr.org
- yr.c.lencr.org
- yr1.c.lencr.org
Embedded IP addresses
- 20.247.185.124
- 52.168.112.66
- 172.215.188.225
- 4.230.171.124
- 74.178.240.51
- 52.168.117.169
- 135.233.95.144
- 172.64.154.167
- 4.237.22.34
- 52.182.143.212
- 20.42.73.31
- 149.154.166.110
- 192.124.249.117
- 185.199.108.133
- 104.18.20.213
- 172.64.149.23
- 104.18.38.233
- 135.233.45.222
- 72.154.7.107
- 52.148.114.188
- 52.110.12.21
- 52.110.12.32
File paths
- p:\#8
- n:\Vv[
- G:\xLL
More Credential samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report