MALICIOUS — virussign.com_7d85cc3831ff4aaacd92bd0b41a65f70.vir
MALICIOUS — virussign.com_7d85cc3831ff4aaacd92bd0b41a65f70.vir is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (86/100), attributed to the Porcupine family. 5 of 52 detection engines flagged it.
Identification
- SHA-256:
3ad8fabe1acb98193f0dd1f1109375a07bfae1a4d00790ad87d5e27cf63ba4f3 - SHA-1:
877599ff94c884215b27d2854bd67043d61263e0 - MD5:
7d85cc3831ff4aaacd92bd0b41a65f70 - imphash:
ba0705dc1860fce6276434770084940d - ssdeep:
3072:n6jx9GcQ0OGPQp3ZyDU39uWjE0DDEAYQEeaSYDnxkRFB1:na9G1/GPyyDs9uB1BQ71snKbB1 - TLSH:
T14A3DBFD10A572366F0F3B86464318ADE841378647176EDCEE203E31DA1EAE37885B6D4 - Submitted as: virussign.com_7d85cc3831ff4aaacd92bd0b41a65f70.vir
- File type: pe · Size: 130149 bytes
- Verdict: malicious (86/100) · Family: Porcupine
Source: VirusSign · first seen 2026-08-08T00:00:00.000Z · SHA-256 verified
Detections (5 of 52 engines)
- ClamAV feed: SaneSecurity foxhole_generic: Porcupine.Malware.58887.UNOFFICIAL
- Microsoft Defender: Ransom:Win64/Azov.psyA!MTB
- Emsisoft (Emergency Kit): Trojan.Ransom.Azov.1
- Trellix Stinger (McAfee): Trojan-FXIH!7D85CC3831FF
- Kaspersky (KVRT): HEUR:Trojan.Win32.Generic
Why this verdict
The malicious score of 86/100 is the fusion of 1 weighted signal:
- ClamAV feed: SaneSecurity foxhole_generic flagged Porcupine.Malware.58887.UNOFFICIAL (rule
Porcupine.Malware.58887.UNOFFICIAL) - engine signal, weight 0.90, confidence 0.95
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded URLs
- http://www.microsoft.com/pki/certs/MicrosoftTimeStampPCA.crt0
- http://crl.microsoft.com/pki/crl/products/microsoftrootcert.crl0T
Embedded domains
- crl.microsoft.com
- www.microsoft.com
More Porcupine samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report